This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Please review my Log

32 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I appreciate any help given.
I had problems with a Trojan.Killav, i found it in my drivers folder and removed it myself, but it seemed to have done nothing.
I did a combofix routine, and my computer seemed to have gotten worse.
Thanks for any assistance.
also…its really screwing with my internet.. badly i was only able to log on twice today out of trying since morning and its 10:18p.m
and the taskbar next to the "Start" changes colors..it goes from the blue to the old white color
and my sound got uninstalled…


Logfile of HijackThis v1.99.1
Scan saved at 7:32:43 PM, on 2/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\drwtsn32.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1199413662829
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{08EAC639-0F1E-4130-9EA2-98E8C19E6BB2}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\..\{08EAC639-0F1E-4130-9EA2-98E8C19E6BB2}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS3\Services\Tcpip\..\{08EAC639-0F1E-4130-9EA2-98E8C19E6BB2}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Intern
I bought a anti spyware and virus programs and reposting a new log
i am not trying to bump, just showing a fresh log, things seem to be getting a bit better.
Sorry if this causes any troubles.





Logfile of HijackThis v1.99.1
Scan saved at 3:57:21 AM, on 2/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1199413662829
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{08EAC639-0F1E-4130-9EA2-98E8C19E6BB2}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\..\{08EAC639-0F1E-4130-9EA2-98E8C19E6BB2}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
_________________________________
Welcome to the Forums.

The fixes we will use are specific to your problems and should only be used for this issue on this machine.

Please only use this topic to reply to. Do not start another thread.
If any other issues arise let me know.
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear. So lets do this to the end!

  • All hijackthis logs I ask for should be done in normal mode ( not safe mode)
  • These logs should be done last after you have followed my instructions in the previous post.


Please if you decide to seek help at another forum let us know. There is a shortage of helpers and tying 2 of us up is a waste of time.
If you have any questions about any advice given here please STOP and ask!



_____________________________________
One of the reasons your log was skipped over is because you replied to your own topic. We as helpers here look for replies with 0 (zero) replies.
Keep that in mind if you need to be here again.

____________________________________________

You said you had used ComboFix. I need to see the log it had created.
It's located here,
c:/combofix.txt




______________________________

Download and install CCleaner from here


If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.

  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".


    Now run the program and click on Run Cleaner
    ( Do not use the Registry function to clean anything with this program. Having anything auto clean your regisrty is risky).


AVG Anti-Spyware:
________________________________________
Download the trial version of AVG Anti-Spyware from here and install it. When the program has been installed, and you click the Finish button, AVG Anti-Spyware will open. Do not run a scan yet.

If the program does not automatically update itself during installation, or you are unsure whether it has done so, please do the following:
  • Click the Update icon at the top and under Manual Update click the Start update button.
  • The program will either update or inform you that no update was available.
  • It is essential that you get the update - keep trying until successful. (Note: If you have problems getting the update, you can download an installer for the full database from here (save it on your desktop). Once you have downloaded the installer, make sure that AVG Anti-Spyware is closed and then double-click on avgas-signatures-full-current.exe to install the database).



    Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
  • Open up AVG anti Malware
Please set up the program as follows:
  • Click the Shield icon at the top and under Resident shield is… click active. This should now change to inactive.
  • Click the Update icon and untick the automatic update option.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
  • Under How to act? - make sure that Quarantine is selected.
  • Under How to scan? - All checkboxes should be ticked.
  • Under Possibly unwanted software - All checkboxes should be ticked.
  • Under Reports - Select Do not automatically generate reports.
  • Under What to scan? - Select Scan every file.
Close all open windows.
  • Click on Scanner on the toolbar.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan your computer.
  • When the scan has finished, follow the instructions below:
  • Make sure that Set all elements to: shows Quarantine
  • Important: Click on the Apply all Actions button (*** This must done before saving the report ***)
  • When the program has finished, it will display the message All actions have been applied.
  • Then click the Save Scan Report button.
  • Click the Save Report as button.
  • Save the report to your Desktop.
  • Right-click the AVG Tray Icon and select Exit.
  • Reboot in normal mode.
_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from AVG anti spyware
  • The report from comboFix
  • Was there a specific reason you ran comboFix ? This tool neds to be used with caution.
Hello bob4, thank you for your time, and assistance.

the reason why i used the combofix was in the past i had virus problem
with my wallpaper being changed to the Warning alert that I should use a "specific" program to remove the spyware and was giving me links.
Using the combofix routine fixed the wallpaper and other items. So I thought that using it again would eliminate the problems i had.


Here is the Avg Log

——————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 7:49:58 PM 2/24/2008

+ Scan result:



C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0068611.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\WINDOWS\system32\Macromed\Download\Install.exe -> Dropper.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP196\A0058460.exe -> Not-A-Virus.Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP264\A0068545.exe -> Not-A-Virus.Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0079329.sys -> Proxy.Agent.xo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0079533.sys -> Proxy.Agent.xo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0079539.sys -> Proxy.Agent.xo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0079601.sys -> Proxy.Agent.xo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0079608.sys -> Proxy.Agent.xo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0079815.sys -> Proxy.Agent.xo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0079829.sys -> Proxy.Agent.xo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0079835.sys -> Proxy.Agent.xo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0079905.sys -> Proxy.Agent.xo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0079950.sys -> Proxy.Agent.xo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0080023.sys -> Proxy.Agent.xo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0080085.sys -> Proxy.Agent.xo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0080150.sys -> Proxy.Agent.xo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0080160.sys -> Proxy.Agent.xo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0080171.sys -> Proxy.Agent.xo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0080648.sys -> Proxy.Agent.xo : Cleaned with backup (quarantined).
:mozilla.25:C:\Documents and Settings\Donald\Application Data\Mozilla\Firefox\Profiles\17fe3g0f.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.23:C:\Documents and Settings\Donald\Application Data\Mozilla\Firefox\Profiles\17fe3g0f.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.24:C:\Documents and Settings\Donald\Application Data\Mozilla\Firefox\Profiles\17fe3g0f.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.13:C:\Documents and Settings\Donald\Application Data\Mozilla\Firefox\Profiles\17fe3g0f.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\WINDOWS\system32\1024 -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ipv6devs.dll -> Trojan.Tanspy : Cleaned with backup (quarantined).


::Report end





The HJT Log.

Logfile of HijackThis v1.99.1
Scan saved at 8:04:49 PM, on 2/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1199413662829
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{08EAC639-0F1E-4130-9EA2-98E8C19E6BB2}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\..\{08EAC639-0F1E-4130-9EA2-98E8C19E6BB2}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe


The combofix Log

ComboFix 08-02-18.1 - Donald 2008-02-18 17:02:20.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.241 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-19 to 2008-02-19 )))))))))))))))))))))))))))))))
.

2008-02-18 05:33 . 2008-02-18 05:33 d——– C:\Documents and Settings\All Users\Application Data\Uniblue
2008-02-18 02:08 . 2008-02-18 02:12 d——– C:\Program Files\RegScrubXP
2008-02-18 02:06 . 2007-12-04 15:44 23,600 –a—— C:\WINDOWS\system32\drivers\TVICHW32.SYS
2008-02-18 01:55 . 2005-08-25 18:18 118,784 –a—— C:\WINDOWS\system32\MSSTDFMT.DLL
2008-02-18 01:28 . 2008-02-18 02:28 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-04 08:27 . 2008-02-13 17:12 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-04 08:27 . 2008-02-04 08:27 1,409 –a—— C:\WINDOWS\QTFont.for
2008-02-04 03:42 . 2008-02-04 03:41 78,848 -rahs—- C:\WINDOWS\taskmon.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-18 23:12 ——— d—–w C:\Program Files\Starcraft
2008-02-18 14:03 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-18 13:32 ——— d—–w C:\Documents and Settings\Donald\Application Data\Uniblue
2008-02-18 10:02 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-02-14 10:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-14 10:21 ——— d—–w C:\Program Files\QuickTime
2008-02-14 04:49 ——— d—–w C:\Program Files\Warcraft III
2008-01-31 06:58 ——— d—–w C:\Program Files\LimeWire
2008-01-31 05:39 ——— d—–w C:\Program Files\Microsoft Games
2008-01-08 23:57 94,208 —-a-w C:\WINDOWS\ScUnin.exe
2007-12-31 10:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-31 10:25 ——— d—–w C:\Program Files\System Security Suite 1.04
2007-12-29 14:44 ——— d—–w C:\Program Files\MSXML 4.0
2007-12-16 23:47 37,376 —-a-w C:\WINDOWS\mm_tmpgr.exe
2007-12-16 23:46 38,400 —-a-w C:\WINDOWS\mmyh_co.exe
2007-12-16 23:46 38,400 —-a-w C:\WINDOWS\mm_tmpyh_co.exe
2007-12-16 21:42 37,376 —-a-w C:\WINDOWS\mmgr.exe
2007-12-16 10:08 17,408 —-a-w C:\WINDOWS\system32\svchost.exe
2006-09-13 22:13 118,784 —-a-w C:\Documents and Settings\All Users\Application Data\AutoSearch.dll
.

——- Sigcheck ——-

"C:\WINDOWS\system32\svchost.exe"
-c—-w 12,800 2001-08-18 12:00:00 C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
-c—-w 14,336 2004-08-04 08:56:58 C:\WINDOWS\ServicePackFiles\i386\svchost.exe
—-a-w 17,408 2007-12-16 10:08:47 C:\WINDOWS\system32\svchost.exe

"C:\WINDOWS\system32\winlogon.exe"
-c—-w 430,080 2001-08-18 12:00:00 C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
-c—-w 502,272 2004-08-04 08:56:58 C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
—-a-w 506,368 2004-08-04 08:56:58 C:\WINDOWS\system32\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AAWTray"="C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 14:53 88024]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Documents and Settings\Donald\My Documents\My Pictures\bizzy, thugsta.jpg
FriendlyName=

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RSVP"=3 (0x3)

R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys [2004-08-03 22:31]
R3 tbcspud;Santa Cruz Driver;C:\WINDOWS\system32\drivers\tbcspud.sys [2002-04-03 15:51]
R3 tbcwdm;Santa Cruz WDM Driver;C:\WINDOWS\system32\drivers\tbcwdm.sys [2002-04-03 15:51]
S3 Aldebaran;Aldebaran - Storage Filter Drivers;C:\WINDOWS\system32\Drivers\Aldebaran.sys []
S3 iMSPQMn;iMSPQMn;C:\DOCUME~1\Donald\LOCALS~1\Temp\iMSPQMn.sys []
S3 sysrest.sys;sysrest.sys;C:\WINDOWS\system32\sysrest.sys []
S3 vtdg46xx;vtdg46xx;C:\PROGRA~1\TURTLE~1\SANTAC~1\CONTRO~1\vtdg46xx.sys [2002-03-21 19:44]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-18 13:47:01 C:\WINDOWS\Tasks\Uniblue SpyEraser Nag.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
"2008-02-18 13:46:58 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-18 17:05:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-18 17:06:57
ComboFix-quarantined-files.txt 2008-02-19 01:06:44
ComboFix2.txt 2008-02-18 14:17:53
It looks like you have been infected by a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

Its very possible that anything could have been installed on your computer by the remote attacker, including opening other backdoors and installing rootkits. While we can attempt to clean what we see in your logs, we can't guarantee that your computer will be completely in the clear since we have no way of knowing that has been done to the computer. Your computer could be completely compromised at this moment. It may be prudent to backup your information, reformat, and reinstall.

More information on Remote Access Trojans can be found
here

I suggest you do the following immediately:
  • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passords and transaction information.

If, however, you decide that the computer is not used for any sensitive work, or if you do not wish to reformat at this time, I can help you clean your computer to the best of my abilities.

Should you have any questions, please feel free to ask.

Please let me know what you decide to do in your next post.

Should you decide to clean this machine start by doing the following.


____________________________________________________________



________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

File:: 
C:\WINDOWS\mm_tmpgr.exe
C:\WINDOWS\mmyh_co.exe
C:\WINDOWS\mm_tmpyh_co.exe
C:\WINDOWS\mmgr.exe


NOTE: This script was done for this user specifically.
DO NOT ATTEMPT TO USE IT IF YOU ARE NOT THIS USER
YOU WILL HURT THE WORKINGS OF YOUR COMPUTER !!
.

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.



___________________________________
Open the control panel
choose display

choose desktop tab then Customize desktop

In there place a check mark by anything other than My current home page

then choose delete.





_________________________________

Download SDFix and save it to your Desktop.

Double click SDFix.exe and choose Install to extract it to its own folder on the Desktop. Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
  • In Safe Mode, right click the SDFix.zip folder and choose Extract All,
  • Open the extracted folder and double click RunThis.bat to start the script.
  • Type Y to begin the script.
  • It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • Your system will take longer that normal to restart as the fixtool will be running and removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
  • Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt back onto the forum with a new HijackThis log



_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from comboFix
  • S&D fix
I dont use this computer for business or anything related to my life, just play games on it and listen to music
I will choose the reformatting option, start off clean and watch what i browse and download.



Heres a HJT log

Logfile of HijackThis v1.99.1
Scan saved at 4:59:18 PM, on 2/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1199413662829
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{08EAC639-0F1E-4130-9EA2-98E8C19E6BB2}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\..\{08EAC639-0F1E-4130-9EA2-98E8C19E6BB2}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe


SdFix log

SDFix: Version 1.147

Run by [removed] on Mon 02/25/2008 at 04:42 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\DOCUME~1\Donald\Desktop\SDFix\SDFix

Checking Services :

Name:
sysrest.sys

Path:
\??\C:\WINDOWS\system32\sysrest.sys

sysrest.sys - Deleted



Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Missing SharedAccess Service

Rebooting


Checking Files :

No Trojan Files Found






Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-25 16:47:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

Remaining Files :



Files with Hidden Attributes :

Mon 14 Nov 2005 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 29 Aug 2000 557,056 A..H. — "C:\Program Files\Dell\Backup\DellBckp.exe"
Tue 19 Feb 2008 20,487 A.SHR — "C:\Program Files\McAfee\MQC\MRU.bak"
Tue 19 Feb 2008 211 A.SHR — "C:\Program Files\McAfee\MQC\qcconf.bak"
Thu 25 Jan 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"

Finished!



Combofix log


ComboFix 08-02-18.1 - Donald 2008-02-25 16:13:48.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.273 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Donald\Desktop\CFScript.txt.txt

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\mm_tmpgr.exe
C:\WINDOWS\mm_tmpyh_co.exe
C:\WINDOWS\mmgr.exe
C:\WINDOWS\mmyh_co.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\mm_tmpgr.exe
C:\WINDOWS\mmgr.exe

.
((((((((((((((((((((((((( Files Created from 2008-01-26 to 2008-02-26 )))))))))))))))))))))))))))))))
.

2008-02-24 17:41 . 2008-02-24 17:41 d——– C:\Documents and Settings\Donald\Application Data\Grisoft
2008-02-24 17:41 . 2007-05-30 04:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-24 17:35 . 2008-02-24 17:35 d——– C:\Program Files\CCleaner
2008-02-22 00:52 . 1998-09-24 13:03 171,967 –a—— C:\WINDOWS\system32\Odbcjet.hlp
2008-02-22 00:52 . 2001-05-14 18:15 10,368 –a—— C:\WINDOWS\system32\drivers\omci.sys
2008-02-22 00:52 . 1998-09-24 13:03 7,348 –a—— C:\WINDOWS\system32\Odbcjet.cnt
2008-02-20 00:09 . 2008-02-20 00:09 d——– C:\Program Files\Common Files\Turtle Beach
2008-02-19 21:32 . 2008-02-19 21:32 d——– C:\WINDOWS\tbcdata
2008-02-19 21:32 . 2002-04-03 15:47 290,816 –a—— C:\WINDOWS\system32\tbctray.exe
2008-02-19 21:31 . 2002-04-03 15:51 425,472 –a—— C:\WINDOWS\system32\tbc10.tmp
2008-02-19 18:01 . 2008-02-25 16:06 4,958 –a—— C:\WINDOWS\system32\Config.MPF
2008-02-19 17:58 . 2007-07-21 09:08 201,288 –a—— C:\WINDOWS\system32\drivers\mfehidk.sys
2008-02-19 17:58 . 2007-07-13 09:20 113,952 –a—— C:\WINDOWS\system32\drivers\Mpfp.sys
2008-02-19 17:58 . 2007-07-24 07:40 79,304 –a—— C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-02-19 17:58 . 2007-07-21 09:08 40,488 –a—— C:\WINDOWS\system32\drivers\mfesmfk.sys
2008-02-19 17:58 . 2007-07-21 09:08 35,240 –a—— C:\WINDOWS\system32\drivers\mfebopk.sys
2008-02-19 17:58 . 2007-07-24 12:02 33,800 –a—— C:\WINDOWS\system32\drivers\mferkdk.sys
2008-02-19 17:57 . 2008-02-19 17:57 d——– C:\Program Files\McAfee.com
2008-02-19 17:57 . 2008-02-19 18:42 d——– C:\Program Files\Common Files\McAfee
2008-02-19 17:56 . 2008-02-19 20:19 d——– C:\Program Files\McAfee
2008-02-19 17:27 . 2008-02-19 18:00 d——– C:\Documents and Settings\All Users\Application Data\McAfee
2008-02-18 18:07 . 2008-02-19 17:46 d——– C:\Program Files\Spyware Doctor
2008-02-18 18:07 . 2008-02-18 18:07 d——– C:\Documents and Settings\Donald\Application Data\PC Tools
2008-02-18 18:07 . 2005-09-23 07:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2008-02-18 18:07 . 2005-07-06 17:13 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2008-02-18 18:07 . 2005-07-06 17:13 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2008-02-18 18:07 . 2007-05-23 16:58 83,024 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-02-18 18:07 . 2007-05-23 16:58 57,424 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-02-18 18:07 . 2007-05-23 16:58 53,840 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-02-18 18:07 . 2007-05-23 16:58 39,376 –a—— C:\WINDOWS\system32\drivers\ikfileflt.sys
2008-02-18 18:07 . 2007-05-23 16:58 29,264 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-02-18 05:33 . 2008-02-18 05:33 d——– C:\Documents and Settings\All Users\Application Data\Uniblue
2008-02-18 02:08 . 2008-02-18 02:12 d——– C:\Program Files\RegScrubXP
2008-02-18 02:06 . 2007-12-04 15:44 23,600 –a—— C:\WINDOWS\system32\drivers\TVICHW32.SYS
2008-02-18 01:55 . 2005-08-25 18:18 118,784 –a—— C:\WINDOWS\system32\MSSTDFMT.DLL
2008-02-18 01:28 . 2008-02-24 06:58 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-04 08:27 . 2008-02-13 17:12 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-04 08:27 . 2008-02-04 08:27 1,409 –a—— C:\WINDOWS\QTFont.for

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-25 08:06 ——— d—–w C:\Program Files\Starcraft
2008-02-24 08:49 ——— d—–w C:\Program Files\Warcraft III
2008-02-22 08:54 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-20 01:51 16,896 —-a-w C:\WINDOWS\system32\svchost.exe
2008-02-20 01:39 14,336 —-a-w C:\WINDOWS\system32\lsass.exe
2008-02-20 01:39 110,080 —-a-w C:\WINDOWS\system32\services.exe
2008-02-19 03:40 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-02-19 03:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-18 13:32 ——— d—–w C:\Documents and Settings\Donald\Application Data\Uniblue
2008-02-14 10:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-14 10:21 ——— d—–w C:\Program Files\QuickTime
2008-01-31 06:58 ——— d—–w C:\Program Files\LimeWire
2008-01-31 05:39 ——— d—–w C:\Program Files\Microsoft Games
2008-01-08 23:57 94,208 —-a-w C:\WINDOWS\ScUnin.exe
2007-12-31 10:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-31 10:25 ——— d—–w C:\Program Files\System Security Suite 1.04
2007-12-29 14:44 ——— d—–w C:\Program Files\MSXML 4.0
.

——- Sigcheck ——-

"C:\WINDOWS\system32\svchost.exe"
-c—-w 12,800 2001-08-18 12:00:00 C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
-c—-w 14,336 2004-08-04 08:56:58 C:\WINDOWS\ServicePackFiles\i386\svchost.exe
—-a-w 16,896 2008-02-20 01:51:59 C:\WINDOWS\system32\svchost.exe

"C:\WINDOWS\system32\winlogon.exe"
-c—-w 430,080 2001-08-18 12:00:00 C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
-c—-w 502,272 2004-08-04 08:56:58 C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
—-a-w 506,368 2004-08-04 08:56:58 C:\WINDOWS\system32\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AAWTray"="C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 14:53 88024]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 22:33 582992]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 01:25 6731312]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Documents and Settings\Donald\My Documents\My Pictures\bizzy, thugsta.jpg
FriendlyName=

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RSVP"=3 (0x3)

R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys [2004-08-03 22:31]
R3 tbcspud;Santa Cruz Driver;C:\WINDOWS\system32\drivers\tbcspud.sys [2002-04-03 15:51]
S3 Aldebaran;Aldebaran - Storage Filter Drivers;C:\WINDOWS\system32\Drivers\Aldebaran.sys []
S3 iMSPQMn;iMSPQMn;C:\DOCUME~1\Donald\LOCALS~1\Temp\iMSPQMn.sys []
S3 sysrest.sys;sysrest.sys;C:\WINDOWS\system32\sysrest.sys []
S3 tbcwdm;Santa Cruz WDM Driver;C:\WINDOWS\system32\drivers\tbcwdm.sys [2002-04-03 15:51]
S3 vtdg46xx;vtdg46xx;C:\PROGRA~1\TURTLE~1\SANTAC~1\CONTRO~1\vtdg46xx.sys [2002-03-21 19:44]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-20 02:41:39 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-02-20 02:41:39 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2008-02-18 13:47:01 C:\WINDOWS\Tasks\Uniblue SpyEraser Nag.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
"2008-02-18 13:46:58 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-25 16:16:11
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-25 16:17:16
ComboFix-quarantined-files.txt 2008-02-26 00:17:13
ComboFix2.txt 2008-02-19 01:06:59
ComboFix3.txt 2008-02-18 14:17:53

I will choose the reformatting option, start off clean and watch what i browse and download.


If your going to go ahead and reformat we can stop here. Let me know if that is indeed your intentions.
yes, i want to reformat, but im not sure if i have every single cd I need edit:Question. This backdoor trojan, can still infect me and uploads spyware, but with the programs Ive bought and downloaded it can clear the spyware and virus's he/she puts on right? I have my sound working again, which was one of the main reasons why i wanted to reformat. Edit: Bahh, sound doesnt work for the games, so i will go through with the reformat because when I use the Santa Cruz control panel, it passes the first two tests, but not the last two the software configuration restore default settings
I'm not sure what you mean by

but with the programs Ive bought and downloaded it
can clear the spyware and virus's he/she puts on right?


I don't know what you have or what you have bought.
But if you reformat that will be the end of the Trojan. :popcorn:

About Back door Trojans:

Basically what happens is the back door trojan is placed on your machine. Now the hacker can actually take control of your computer without your knowledge.The hacker can do what ever he would like to your computer. Find passwords ,bank account info..load other programs and rootkits and keyloggers. It would be as if he was sitting at your computer with access to anything on your computer..



I think if you have other issues also, as sound ect… a nice clean install is the best option. It may take a while to get things back the way you like them but once your done theres nothing like a fresh install. Be sure this time to be security minded by getting a good anti virus program installed and a firewall.
yeah, im gonna go with the reformatting. Is their a list of the cd's im suppose to have for the reformatting? I have two drivers and utlites cd's, But i cannot find the bergundy coloured cd right now. Ok, i've found the operating system cd ready when you are
It's really quite simple to reformat.

First things first. Be sure you back up any pictures /documents and important records, email addresses anything you find important.. As once you reformat all that is there now will be lost. If you only have 1 hard drive you can back things up to a CD or usb flash drive.

Your basically going to place the operating system cd in the cd drive.
Reboot the computer and when asked you will press any key to boot from CD.
Follow the prompts, ( see the first link below)

I have 2 links for you to look at.

I suggest you take a look at both of those before you begin. There are some things you need to know if you have never done this before you may find helpful .
Once you get it started windows walks you through all you will need to do.


Here's a site complete with pictures of what you will be doing along with what your going to see.


_____________________________
Heres another site with some good advice on reformatting.

http://spyware-free.us/tutorials/reformat/


Let me know if you think you will need more help .
hi again, need help I cannot get to the boot cd sequence i pressed f2 and everything but it wont work Edit: Nevermind, im looking at the other link you posted and that seems better informed. sorry\ ok, i do need your help. I cannot even get past the first step, I put in my operating system cd in, But cannot get it to boot from cd I also did the whole f12 procedure any advice?
can you tell me how to use the boot to cd sequence with the whole f`12 thing when i tried it, it wouldnt boot from the cd, just booted regularly ive put cd rom in number one, my computer just wont boot from cd..

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI