This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Grandpa's computer

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Not sure what my grandpa downloaded to get it, but his computer all of the sudden is being bombarded with some adware removing program. Ever since it showed up his McAfee that he's paying good money for is saying he has a trojan, but it can't seem to get rid of it. So I guess McAfee is good for telling you you have a problem, and then letting you figure out how to deal with it yourself. Anyways, here's his log file I just processed, I see it named in this log, but want to hear exactly what I need to do from you experts. Thanks for any help you can provide.

Logfile of HijackThis v1.99.1
Scan saved at 3:37:47 PM, on 2/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\HP\KBD\KBD.EXE
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\WINDOWS\system32\3ug3kf.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\msiconf.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\SiteAdvisor\6172\SAService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/def…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O2 - BHO: (no name) - {159DED13-F340-4998-8573-2DE006DE1E66} - C:\WINDOWS\system32\cdmt.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: TwcToolbarBhoApp Class - {AA1F9DDB-E605-4ba6-81D4-E427DEE012AD} - C:\WINDOWS\system32\TwcToolbarBho.dll
O2 - BHO: (no name) - {D91A6085-59C5-45BC-844D-527928FA5AAC} - c:\windows\system32\cnbjmong.dll
O3 - Toolbar: The Weather Channel Toolbar - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\WINDOWS\system32\TwcToolbarIe7.dll
O3 - Toolbar: (no name) - {4AD56E6F-7074-41EE-8A40-583C2C76EFCD} - (no file)
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiVirus Pro 2007\mav_startupmon.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\Run: [3ug3kf] C:\WINDOWS\system32\3ug3kf.exe
O4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [3ug3kf] C:\WINDOWS\system32\3ug3kf.exe
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe /a /b
O4 - HKCU\..\Run: [AdwareRemover2007] C:\Program Files\AdwareRemover2007\AdwareRemover2007.exe
O4 - HKCU\..\Run: [msiconf.exe] msiconf.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra 'Tools' menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O20 - Winlogon Notify: pqxkximi - C:\WINDOWS\SYSTEM32\cnbjmong.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe


Stephen Schaal
Hello, and welcome to the forum.

My name is Simon V., and I'll be glad to help you with your computer problems.

Please download and install CCleaner.

Open CCleaner. On the Windows tab, leave the default options alone.

  • On the Applications tab, check (tick) all the boxes except Saved Form Information. This will remove all your saved passwords if you leave this box checked.
  • Click on the Run Cleaner button at the bottom right hand corner.
  • When the cleaner has completed, click Tools in the Left Pane.
  • Verify that Uninstall is highlighted in color, or click on it.
  • In the lower right, click Save to Text File.
  • Pull down the arrow at the top of the Save dialog and choose Desktop as the location.
  • You can leave the filename as install.txt.
  • Click Save, then exit Ccleaner.

___________________

Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Post the log from ComboFix (C:\Combofix.txt) when you've accomplished that, along with a new HijackThis log and the CCleaner Uninstall List (install.txt)
Okay so here's the update:

I went through your instructions, and the instructions for the programs you referred to completely. The CCleaner worked just fine. I had a problem with the ComboFix, but I figured it out I believe. Below are the CCleaner, HijackThis, and ComboFix logs in that order.

Thanks for you help,
Stephen

CCleaner

Adobe Flash Player ActiveX
CCleaner (remove only)
Coloreal
CompuServe
Disc2Phone
Fisher-Price® Big Action Garage
Hijackthis 1.99.1
HijackThis 1.99.1
Inactive HP Printer Drivers (Remove only)
Indeo® Software
Intel® 82845G Graphics Driver Software
J2SE Runtime Environment 5.0 Update 3
Java 2 Runtime Environment Standard Edition v1.3.1_02
Java 2 Runtime Environment, SE v1.4.0_01
KBD
Learn2 Player (Uninstall Only)
Lebanon High School
Macromedia Shockwave Player
McAfee SecurityCenter
Microsoft .NET Framework (English) v1.0.3705
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Money 2002
Microsoft Money 2002 System Pack
Microsoft Office XP Professional with FrontPage
Microsoft Works 7.0
Microsoft XML Parser
mIRC
MSXML 4.0 SP2 (KB936181)
Netscape (7.0)
NVIDIA Windows 2000/XP Display Drivers
OpenMG Limited Patch 3.4-03-12-16-01
OpenMG Secure Module 3.4.00
Personal Legal Forms 1.0.0
Python 2.2 combined Win32 extensions
Python 2.2.1
Quicken 2003 New User Edition
QuickTime
RecordNow
RecordNow Update Manager
S3Display
S3Gamma2
S3Info2
S3Overlay
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB946026)
Simple Installer - Multilanguage Version
SonicStage 2.0.02
Sony Ericsson PC Suite 1.20.224
The Weather Channel Desktop
The Weather Channel Toolbar
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
Virtual Assistant from EMBARQ
Weather Services
WebFldrs XP
WildTangent Web Driver
Windows Installer 3.1 (KB893803)
Windows Live Messenger
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
Yahoo! Essentials
Yahoo! extras
Yahoo! Install Manager
Yahoo! Search Protection
Yahoo! Toolbar


HijackThis

Logfile of HijackThis v1.99.1
Scan saved at 8:36:48 PM, on 2/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe
C:\WINDOWS\system32\3ug3kf.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: TwcToolbarBhoApp Class - {AA1F9DDB-E605-4ba6-81D4-E427DEE012AD} - C:\WINDOWS\system32\TwcToolbarBho.dll
O3 - Toolbar: The Weather Channel Toolbar - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\WINDOWS\system32\TwcToolbarIe7.dll
O3 - Toolbar: (no name) - {4AD56E6F-7074-41EE-8A40-583C2C76EFCD} - (no file)
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe
O4 - HKLM\..\Run: [3ug3kf] C:\WINDOWS\system32\3ug3kf.exe
O4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [3ug3kf] C:\WINDOWS\system32\3ug3kf.exe
O4 - HKCU\..\Run: [AdwareRemover2007] C:\Program Files\AdwareRemover2007\AdwareRemover2007.exe
O4 - HKCU\..\Run: [msiconf.exe] msiconf.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra 'Tools' menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: McAfee Application Installer Cleanup (0087871203383427) (0087871203383427mcinstcleanup) - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\008787~1.EXE (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe


ComboFix

ComboFix 08-02-17.2 - Owner 2008-02-18 20:25:32.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.252 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\salesmonitor
C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2007
C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2007\Data\Abbr
C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2007\Data\ActivationCode
C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2007\Data\ProductCode
C:\Documents and Settings\Owner\Application Data\WinAntiVirus Pro 2007
C:\Documents and Settings\Owner\Application Data\WinAntiVirus Pro 2007\avtasks.dat
C:\Documents and Settings\Owner\Application Data\WinAntiVirus Pro 2007\CookieList.dat
C:\Documents and Settings\Owner\Application Data\WinAntiVirus Pro 2007\history.db
C:\Documents and Settings\Owner\Application Data\WinAntiVirus Pro 2007\Logs\update.log
C:\Documents and Settings\Owner\Application Data\WinAntiVirus Pro 2007\Logs\wa7Support.log
C:\Documents and Settings\Owner\Application Data\WinAntiVirus Pro 2007\Logs\winav.log
C:\Documents and Settings\Owner\Application Data\WinAntiVirus Pro 2007\PGE.dat
C:\Documents and Settings\Owner\err.log
C:\Documents and Settings\Owner\ResErrors.log
C:\Program Files\Common Files\companion wizard
C:\Program Files\Common Files\winantivirus pro 2007
C:\Program Files\Common Files\winantivirus pro 2007\err.log
C:\Program Files\inetget2
C:\Program Files\install provider
C:\Program Files\install provider\InstallProvider.dll
C:\Program Files\install provider\My Downloads.ico
C:\UWA7P
C:\WINDOWS\keyboard61.dat
C:\WINDOWS\keyboard71.dat
C:\WINDOWS\system32\~.exe
C:\WINDOWS\system32\cdmt.dll
C:\WINDOWS\system32\cnbjmong.dll
C:\WINDOWS\system32\drivers\ugedlekr.dat
C:\WINDOWS\system32\msiconf.exe
C:\WINDOWS\system32\stera.job
C:\WINDOWS\system32\stera.log
C:\WINDOWS\Tasks.\At1.job
C:\WINDOWS\uninst2.htm
C:\WINDOWS\unist1.htm
C:\WINDOWS\xpupdate.exe
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_DJQLVFHX
——-\LEGACY_FOPN
——-\LEGACY_NETWORK_MONITOR
——-\LEGACY_WTEFSTWX
——-\djqlvfhx
——-\wtefstwx


((((((((((((((((((((((((( Files Created from 2008-01-19 to 2008-02-19 )))))))))))))))))))))))))))))))
.

2008-02-18 19:47 . 2008-02-18 19:47 d——– C:\Program Files\CCleaner
2008-02-18 17:20 . 2008-02-18 17:20 d——– C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-02-17 22:27 . 2008-02-17 22:27 d——– C:\Program Files\Disc2Phone
2008-02-16 19:33 . 2008-02-17 09:39 d——– C:\Program Files\SpyShredder
2008-02-16 19:03 . 2008-02-18 20:10 d——– C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-02-16 18:59 . 2008-02-16 18:59 d——– C:\Program Files\McAfee.com
2008-02-16 18:58 . 2008-02-16 19:00 d——– C:\Program Files\Common Files\McAfee
2008-02-16 18:57 . 2008-02-17 02:35 d——– C:\Program Files\McAfee
2008-02-16 18:33 . 2008-02-16 19:04 d——– C:\Documents and Settings\All Users\Application Data\McAfee
2008-02-15 22:38 . 2008-02-15 22:38 d——– C:\Documents and Settings\Owner\Application Data\PCSuperCharger
2008-02-15 22:27 . 2008-02-16 18:20 d——– C:\Documents and Settings\All Users\Application Data\PCSuperCharger
2008-02-12 19:39 . 2008-02-12 19:39 268 –ah—– C:\sqmdata02.sqm
2008-02-12 19:39 . 2008-02-12 19:39 244 –ah—– C:\sqmnoopt02.sqm
2008-02-10 22:15 . 2008-02-17 12:48 d——– C:\Program Files\AdwareRemover2007
2008-02-08 19:32 . 2007-09-17 14:39 263,160 –a—— C:\WINDOWS\system32\drivers\Tmfilter.sys
2008-02-08 19:32 . 2007-10-06 16:38 12,358 –a—— C:\WINDOWS\system32\drivers\tmfilter.cat
2008-02-08 19:32 . 2007-09-17 14:41 3,418 –a—— C:\WINDOWS\system32\drivers\tmpreflt.inf
2008-02-08 19:32 . 2007-09-17 14:41 2,557 –a—— C:\WINDOWS\system32\drivers\tmxpflt.inf
2008-02-08 19:32 . 2007-09-17 14:31 2,518 –a—— C:\WINDOWS\system32\drivers\vsapint.inf
2008-02-04 23:45 . 2008-02-04 23:45 1,188,375 –a—— C:\WINDOWS\system32\libeay32.dll
2008-02-04 23:45 . 2008-02-04 23:45 741,632 –a—— C:\WINDOWS\system32\tlszaqpa.dat
2008-02-04 23:45 . 2008-02-04 23:45 246,545 –a—— C:\WINDOWS\system32\libssl32.dll
2008-02-04 23:45 . 2008-02-04 23:45 42,752 –a—— C:\WINDOWS\system32\aafslwgd.dat
2008-02-04 23:45 . 2008-02-14 15:27 36,608 –a—— C:\WINDOWS\system32\scmqhips.dat
2008-02-04 23:45 . 2008-02-04 23:45 35,072 –a—— C:\WINDOWS\system32\tzsgkgjf.dat
2008-02-03 23:42 . 2008-02-07 14:33 120,576 –a—— C:\WINDOWS\system32\mktzqtxg.dat
2008-02-03 23:36 . 2004-08-04 02:56 84,480 –a—— C:\WINDOWS\system32\cnbjmong.dll.bak
2008-02-03 23:35 . 2008-02-09 12:21 d——– C:\WINDOWS\system32\AppCert
2008-02-03 23:35 . 2007-12-03 12:20 16,384 –a—— C:\WINDOWS\system32\3ug3kf.exe
2008-02-03 23:34 . 2008-02-12 21:49 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-03 23:34 . 2008-02-03 23:34 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-28 18:31 . 2008-01-28 18:31 244 –ah—– C:\sqmnoopt01.sqm
2008-01-28 18:31 . 2008-01-28 18:31 232 –ah—– C:\sqmdata01.sqm

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-19 01:01 ——— d—–w C:\Program Files\mIRC
2008-02-18 22:20 ——— d—–w C:\Program Files\Yahoo!
2008-02-17 00:07 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-02-16 23:22 ——— d—–w C:\Program Files\Common Files\Scanner
2008-02-16 23:19 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-16 23:18 ——— d—–w C:\Program Files\iPod
2008-02-13 02:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-13 02:54 ——— d—–w C:\Program Files\Symantec
2008-02-11 22:26 ——— d—–w C:\Program Files\Trend Micro
2008-02-11 22:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\Trend Micro
2008-02-11 22:12 ——— d—–w C:\Program Files\Common Files\Adobe
2008-02-05 03:38 ——— d—–w C:\Program Files\LimeWire
2008-01-19 04:54 ——— d—–w C:\Program Files\Virtual Assistant
2008-01-19 04:54 ——— d—–w C:\Program Files\Common Files\Motive
2008-01-19 04:53 ——— d—–w C:\Program Files\Motive
2008-01-02 00:28 ——— d—–w C:\Program Files\The Weather Channel Toolbar
2008-01-02 00:23 ——— d—–w C:\Program Files\The Weather Channel FW
2007-12-30 08:10 ——— d—–w C:\Documents and Settings\Owner\Application Data\Teleca
2007-12-30 08:00 ——— d—–w C:\Program Files\MSXML 4.0
2007-12-29 19:13 ——— d—–w C:\Program Files\Common Files\Teleca Shared
2007-12-29 19:13 ——— d—–w C:\Documents and Settings\All Users\Application Data\Teleca
2007-12-29 19:13 ——— d—–w C:\Documents and Settings\All Users\Application Data\Sony Ericsson
2007-12-29 19:12 ——— d—–w C:\Program Files\Sony Ericsson
2007-08-27 00:44 75,016 —-a-w C:\Documents and Settings\Owner\Application Data\PerfomanceOptimizerPre_Installer[1].exe
2006-04-14 21:40 27,712 —-a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2006-03-31 19:08 4,096 —-a-w C:\Documents and Settings\Owner\setup.exe
2006-03-31 16:28 220 —-a-w C:\Documents and Settings\Owner\n.bat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MoneyAgent"="c:\Program Files\Microsoft Money\System\Money Express.exe" [2001-07-25 20:00 184376]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 09:59 224248]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"DW4"="C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe" [2007-12-20 08:10 715888]
"3ug3kf"="C:\WINDOWS\system32\3ug3kf.exe" [2007-12-03 12:20 16384]
"AdwareRemover2007"="C:\Program Files\AdwareRemover2007\AdwareRemover2007.exe" [2008-02-17 12:22 442368]
"msiconf.exe"="msiconf.exe" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KBD"="C:\HP\KBD\KBD.EXE" [2001-07-07 00:56 61440]
"NvCplDaemon"="NvQTwk" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-12-24 20:52 155648]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 09:59 224248]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 17:17 159744]
"Motive SmartBridge"="C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe" [2006-04-21 15:41 438359]
"3ug3kf"="C:\WINDOWS\system32\3ug3kf.exe" [2007-12-03 12:20 16384]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [ ]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\appcertdlls]
appsecdll REG_EXPAND_SZ C:\WINDOWS\system32\AppCert\wsil32.dll

R1 ewido security suite driver;ewido security suite driver;C:\Program Files\ewido anti-malware\guard.sys [2005-12-30 06:12]
S2 0087871203383427mcinstcleanup;McAfee Application Installer Cleanup (0087871203383427);C:\DOCUME~1\Owner\LOCALS~1\Temp\008787~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog []
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\w300bus.sys [2006-03-13 09:49]
S3 w300mdfl;Sony Ericsson W300 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w300mdfl.sys [2006-03-13 16:50]
S3 w300mdm;Sony Ericsson W300 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w300mdm.sys [2006-03-13 16:50]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w300mgmt.sys [2005-12-28 12:48]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w300obex.sys [2005-12-28 12:49]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4698d632-c0fd-11da-ab49-0040ca4a70b5}]
\Shell\AutoRun\command - F:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{932f1e6e-c7bc-11da-ab4f-f9d737729cc7}]
\Shell\AutoRun\command - F:\MRI.EXE

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d75144a4-c7f9-11da-ab57-0040ca4a70b5}]
\Shell\AutoRun\command - F:\LaunchU3.exe

*Newly Created Service* - 0087871203383427MCINSTCLEANUP
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-18 20:30:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
.
**************************************************************************
.
Completion time: 2008-02-18 20:34:37 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-19 01:34:17
.
2008-02-13 03:26:43 — E O F —
Hi :)

Please copy and paste the text in the code box into Notepad (Go to Start > Run, type Notepad and hit Enter)

@echo off
swreg query "HKLM\system\currentcontrolset\control\session manager\AppCertDlls" /s >log.txt
Vfind -ltf "%windir%\system32\AppCert\*" >>log.txt
Start Notepad log.txt
Nircmd cmdwait 1500
del log.txt
del %0

Go to File > Save As:. Save the file as "Look.bat" (Including the quotes)

Double-click on Look.bat to run the file.

A Notepad file should open. Please post its contents in your next reply.
One day I really hope to be able to understand what that .bat file just did, lol. But here is what the log stated: SteelWerX Registry Console Tool 2.0 Written by Bobbi Flekman 2006 © HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\appcertdlls AppSecDll REG_EXPAND_SZ C:\WINDOWS\system32\AppCert\wsil32.dll —-a-w 24 2008-02-05 02:27:08 C:\WINDOWS\system32\AppCert\filter.drv —-a-w 86,016 2008-02-05 02:27:21 C:\WINDOWS\system32\AppCert\hb13a.dll —-a-w 1 2008-02-04 04:35:31 C:\WINDOWS\system32\AppCert\options.dat —-a-w 67,492 2004-08-04 07:56:46 C:\WINDOWS\system32\AppCert\wnl32.dll Entries: 4 (4) Directories: 0 Files: 4 Bytes: 153,533 Blocks: 302 Thanks, Stephen
Hi :)

One day I really hope to be able to understand what that .bat file just did, lol.

Basically, it shows me a part of your computer's registry (the place where Windows saves its settings).

A little bit more information is needed before we start fixing, please do the following -

- Launch Notepad, and copy/paste the contents of the quote box below into a new Notepad file. Save it with file name options.txt and save as file type: All files to your desktop.

RegSearch Options File

[Search]

wsil32.dll
filter.drv
hb13a.dll
wnl32.dll

[Exclude]

[Options]
Filter=KVDLUI


- Download Registry Search to your desktop.

  • Right-click on the compressed RegSearch folder, and choose Extract All. In the box that pops open, click Next, then Next again, and then Finish. You now have another RegSearch folder on your desktop.
  • Open the new folder, and double click on regsearch.exe.
  • Click Import in the lower left corner and browse to the options.txt file that you just saved on your desktop. Do not choose the one in the RegSearch folder itself.
  • Click OK and Registry Search will scan your registry for the file(s). A Notepad box will open with a report, please save the report on your desktop.
________________________________________

Please copy and paste the text in the code box into Notepad (Go to Start > Run, type Notepad and hit Enter)

@echo off
swreg query "HKLM\SOFTWARE\Microsoft\AppCert" /s >log.txt
Start Notepad log.txt
Nircmd cmdwait 1500
del log.txt
del %0

Go to File > Save As:. Save the file as "Export.bat" (Including the quotes)

Double-click on Export.bat to run the file.

A Notepad file will open. Please post its contents, along with the RegSearch report in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI