This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] help please - something sending emails from my computer

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I keep getting loads and loads of pop up messages from Symantec while connected to the internet :


"Your email message was unable to be sent because your mail server rejected the message".

My computer seems to be sending around 100 every minute. I got so many popups it was impossible to use the computer while online. I've stopped the "out-going message scan" on my antivirus to prevent little popup messages, but my computer will still be sending the spam. So far ive tried nortons, AVG, Spyware blaster and smitfraud and an online check buy nothing has fixed this problem. I checked forums and have found a few people with similar or same problems but either there was no solution to there post or it didnt work. This is my hijackthis log - thanks for any help:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:47:03 PM, on 24/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Documents and Settings\Cameron\Application Data\??sks\??erinit.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\DOCUME~1\Cameron\MYDOCU~1\MCROSO~1.NET\javaw.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Norton AntiVirus\OPScan.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 195.175.37.70:8080
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {3138C2C3-5D70-5AAE-0461-5900BBBBD8C9} - C:\WINDOWS\system32\kgnwdcs.dll (file missing)
O2 - BHO: (no name) - {31E00143-96FD-C877-D389-C76932DBD9CE} - C:\WINDOWS\system32\zfkpl.dll (file missing)
O2 - BHO: (no name) - {353791C1-5979-00FC-0661-5900BBBA8B98} - C:\WINDOWS\system32\jscdznn.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {D794A86A-31D9-3409-A2DF-671344A93897} - C:\WINDOWS\system32\kgpdr.dll (file missing)
O2 - BHO: (no name) - {E36FC7AE-E1C1-45AB-84DE-F2B54D85EEEE} - C:\WINDOWS\system32\ati3d1a.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ALi5289] C:\Program Files\ULI5289\ALi5289.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [8ddef2a.exe] C:\WINDOWS\system32\8ddef2a.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SpySpotter System Defender] C:\Program Files\SpySpotter3\Defender.exe -startup
O4 - HKCU\..\Run: [Swcl] "C:\DOCUME~1\Cameron\MYDOCU~1\MCROSO~1.NET\javaw.exe" -vt ndrv
O4 - HKCU\..\Run: [Mkww] C:\DOCUME~1\Cameron\MYDOCU~1\ECURIT~1\TSKMGR~1.EXE
O4 - HKCU\..\Run: [Nqt] C:\WINDOWS\a?sembly\w?nword.exe
O4 - HKCU\..\Run: [Onee] C:\WINDOWS\W?nSxS\r?gedit.exe
O4 - HKCU\..\Run: [Iiyhdjkb] C:\WINDOWS\system32\?ecurity\w?aclt.exe
O4 - HKCU\..\Run: [Vmtayuwh] C:\WINDOWS\??crosoft.NET\u?erinit.exe
O4 - HKCU\..\Run: [Eej] C:\WINDOWS\F?nts\n?tdde.exe
O4 - HKCU\..\Run: [Oqo] "C:\Program Files\??pPatch\s?chost.exe"
O4 - HKCU\..\Run: [Pehgzeg] "C:\Program Files\??curity\w?nlogon.exe"
O4 - HKCU\..\Run: [Afhbuxnl] "C:\Documents and Settings\Cameron\My Documents\M?crosoft.NET\w?auclt.exe"
O4 - HKCU\..\Run: [Vulb] "C:\Documents and Settings\Cameron\Application Data\?ymantec\n?pdb.exe"
O4 - HKCU\..\Run: [Ekxs] "C:\Documents and Settings\Cameron\Application Data\?ystem32\d?dplay.exe"
O4 - HKCU\..\Run: [Fchfku] C:\WINDOWS\system32\?ymbols\w?wexec.exe
O4 - HKCU\..\Run: [Bhd] C:\WINDOWS\system32\?racle\w?wexec.exe
O4 - HKCU\..\Run: [Filiaimk] "C:\Program Files\Common Files\?ssembly\?hkntfs.exe"
O4 - HKCU\..\Run: [Jkmlpf] "C:\Program Files\W?nSxS\w?nspool.exe"
O4 - HKCU\..\Run: [Kguizm] "C:\Documents and Settings\Cameron\Application Data\s?stem32\m?dtc.exe"
O4 - HKCU\..\Run: [Hdzgu] C:\WINDOWS\S?mantec\w?nspool.exe
O4 - HKCU\..\Run: [Mtpvvnuq] "C:\Documents and Settings\Cameron\My Documents\?ymantec\r?gedit.exe"
O4 - HKCU\..\Run: [Waefng] "C:\Program Files\??crosoft\j?vaw.exe"
O4 - HKCU\..\Run: [Undgyub] "C:\Program Files\Common Files\?racle\l?gonui.exe"
O4 - HKCU\..\Run: [Gifazo] "C:\Program Files\?ppPatch\w?aclt.exe"
O4 - HKCU\..\Run: [Aaa] "C:\Documents and Settings\Cameron\Application Data\?ecurity\w?wexec.exe"
O4 - HKCU\..\Run: [Fuhbmbcc] "C:\Program Files\Common Files\??sembly\n?tdde.exe"
O4 - HKCU\..\Run: [Mayqbtr] C:\WINDOWS\system32\??curity\?pool32.exe
O4 - HKCU\..\Run: [Hpmgouj] "C:\Documents and Settings\Cameron\My Documents\A?pPatch\m?iexec.exe"
O4 - HKCU\..\Run: [Pmbm] "C:\Documents and Settings\Cameron\My Documents\?racle\?hkdsk.exe"
O4 - HKCU\..\Run: [Xedndv] "C:\Program Files\S?mantec\u?erinit.exe"
O4 - HKCU\..\Run: [DLD.EXE] C:\Program Files\Download Direct\DLD.exe
O4 - HKCU\..\Run: [Scmt] "C:\Documents and Settings\Cameron\My Documents\?dobe\n?tdde.exe"
O4 - HKCU\..\Run: [Gwfnzeeq] "C:\Documents and Settings\Cameron\Application Data\?icrosoft\??xplore.exe"
O4 - HKCU\..\Run: [Zpzxmoj] "C:\Documents and Settings\Cameron\My Documents\s?stem\w?nword.exe"
O4 - HKCU\..\Run: [Xms] "C:\Program Files\Common Files\F?nts\?hkntfs.exe"
O4 - HKCU\..\Run: [Fsvgodg] "C:\Documents and Settings\Cameron\My Documents\?asks\r?gsvr32.exe"
O4 - HKCU\..\Run: [Imijkl] "C:\Program Files\s?curity\?ti2evxx.exe"
O4 - HKCU\..\Run: [Hhtkdh] "C:\Program Files\Common Files\??crosoft\??rvices.exe"
O4 - HKCU\..\Run: [Xtpc] C:\WINDOWS\??stem32\??xplore.exe
O4 - HKCU\..\Run: [Zlmwgqbm] "C:\Program Files\Common Files\?racle\w?nword.exe"
O4 - HKCU\..\Run: [Bvvcrle] "C:\Program Files\?racle\w?wexec.exe"
O4 - HKCU\..\Run: [Yvhr] "C:\Program Files\??sembly\??rvices.exe"
O4 - HKCU\..\Run: [Rhbcz] "C:\Documents and Settings\Cameron\Application Data\??crosoft.NET\t?skmgr.exe"
O4 - HKCU\..\Run: [Sff] "C:\Program Files\s?stem\??plorer.exe"
O4 - HKCU\..\Run: [Aumpnqsc] "C:\Documents and Settings\Cameron\Application Data\?dobe\??ool32.exe"
O4 - HKCU\..\Run: [Oyabe] "C:\Program Files\W?nSxS\s?oolsv.exe"
O4 - HKCU\..\Run: [Abfu] C:\WINDOWS\??curity\d?dplay.exe
O4 - HKCU\..\Run: [Dys] C:\WINDOWS\M?crosoft\d?xplore.exe
O4 - HKCU\..\Run: [Uwlqw] "C:\Program Files\Common Files\?dobe\??xplore.exe"
O4 - HKCU\..\Run: [Pqs] C:\WINDOWS\system32\T?sks\s?oolsv.exe
O4 - HKCU\..\Run: [Dqqq] "C:\Documents and Settings\Cameron\My Documents\s?mbols\?ttrib.exe"
O4 - HKCU\..\Run: [Rjh] "C:\Documents and Settings\Cameron\My Documents\?dobe\?serinit.exe"
O4 - HKCU\..\Run: [Eeyq] C:\WINDOWS\F?nts\w?wexec.exe
O4 - HKCU\..\Run: [Kjcwth] "C:\Program Files\??mantec\d?xplore.exe"
O4 - HKCU\..\Run: [Uykvntpe] C:\WINDOWS\system32\M?crosoft.NET\r?gedit.exe
O4 - HKCU\..\Run: [Buakg] "C:\Documents and Settings\Cameron\My Documents\a?sembly\m?iexec.exe"
O4 - HKCU\..\Run: [Ulmwk] "C:\Program Files\Common Files\?icrosoft.NET\w?auboot.exe"
O4 - HKCU\..\Run: [Bnhathyp] "C:\Documents and Settings\Cameron\Application Data\s?curity\l?gonui.exe"
O4 - HKCU\..\Run: [Ebgxcgst] "C:\Documents and Settings\Cameron\Application Data\??sks\??erinit.exe"
O4 - HKUS\S-1-5-18\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: PartyGammon.com - {59A861EE-32B3-42cd-8CCA-FC130EDF3A44} - C:\Program Files\PartyGaming\PartyGammon\RunBackGammon.exe
O9 - Extra 'Tools' menuitem: PartyGammon.com - {59A861EE-32B3-42cd-8CCA-FC130EDF3A44} - C:\Program Files\PartyGaming\PartyGammon\RunBackGammon.exe
O9 - Extra button: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe
O9 - Extra 'Tools' menuitem: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/haphazard/raptisoftgameloader.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1141432931234
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O20 - AppInit_DLLs: dllhost.dll
O20 - Winlogon Notify: winuns32 - winuns32.dll (file missing)
O20 - Winlogon Notify: WLCtrl32 - C:\WINDOWS\SYSTEM32\WLCtrl32.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

–
End of file - 15410 bytes
Hi and welcome to the forums. :) I'm Markka and I will be helping you with your malware issues. I'll check your HijackThis log. Right now I'm MRU Undergrad, everything that I post to you must be checked by teachers of Malware Removal University. Please be patient. :)
Hello :)

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall!

Post:
- A fresh HijackThis log
- Contents of C:\ComboFix.txt
hi here is a new hijack this log and combofix log:



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:30:23 PM, on 25/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Documents and Settings\Cameron\Application Data\??sks\??erinit.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Norton AntiVirus\OPScan.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 195.175.37.70:8080
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {3138C2C3-5D70-5AAE-0461-5900BBBBD8C9} - C:\WINDOWS\system32\kgnwdcs.dll (file missing)
O2 - BHO: (no name) - {31E00143-96FD-C877-D389-C76932DBD9CE} - C:\WINDOWS\system32\zfkpl.dll (file missing)
O2 - BHO: (no name) - {353791C1-5979-00FC-0661-5900BBBA8B98} - C:\WINDOWS\system32\jscdznn.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {D794A86A-31D9-3409-A2DF-671344A93897} - C:\WINDOWS\system32\kgpdr.dll (file missing)
O2 - BHO: (no name) - {E36FC7AE-E1C1-45AB-84DE-F2B54D85EEEE} - C:\WINDOWS\system32\ati3d1a.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ALi5289] C:\Program Files\ULI5289\ALi5289.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [8ddef2a.exe] C:\WINDOWS\system32\8ddef2a.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SpySpotter System Defender] C:\Program Files\SpySpotter3\Defender.exe -startup
O4 - HKCU\..\Run: [Swcl] "C:\DOCUME~1\Cameron\MYDOCU~1\MCROSO~1.NET\javaw.exe" -vt ndrv
O4 - HKCU\..\Run: [Mkww] C:\DOCUME~1\Cameron\MYDOCU~1\ECURIT~1\TSKMGR~1.EXE
O4 - HKCU\..\Run: [Nqt] C:\WINDOWS\a?sembly\w?nword.exe
O4 - HKCU\..\Run: [Onee] C:\WINDOWS\W?nSxS\r?gedit.exe
O4 - HKCU\..\Run: [Iiyhdjkb] C:\WINDOWS\system32\?ecurity\w?aclt.exe
O4 - HKCU\..\Run: [Vmtayuwh] C:\WINDOWS\??crosoft.NET\u?erinit.exe
O4 - HKCU\..\Run: [Eej] C:\WINDOWS\F?nts\n?tdde.exe
O4 - HKCU\..\Run: [Oqo] "C:\Program Files\??pPatch\s?chost.exe"
O4 - HKCU\..\Run: [Pehgzeg] "C:\Program Files\??curity\w?nlogon.exe"
O4 - HKCU\..\Run: [Afhbuxnl] "C:\Documents and Settings\Cameron\My Documents\M?crosoft.NET\w?auclt.exe"
O4 - HKCU\..\Run: [Vulb] "C:\Documents and Settings\Cameron\Application Data\?ymantec\n?pdb.exe"
O4 - HKCU\..\Run: [Ekxs] "C:\Documents and Settings\Cameron\Application Data\?ystem32\d?dplay.exe"
O4 - HKCU\..\Run: [Fchfku] C:\WINDOWS\system32\?ymbols\w?wexec.exe
O4 - HKCU\..\Run: [Bhd] C:\WINDOWS\system32\?racle\w?wexec.exe
O4 - HKCU\..\Run: [Filiaimk] "C:\Program Files\Common Files\?ssembly\?hkntfs.exe"
O4 - HKCU\..\Run: [Jkmlpf] "C:\Program Files\W?nSxS\w?nspool.exe"
O4 - HKCU\..\Run: [Kguizm] "C:\Documents and Settings\Cameron\Application Data\s?stem32\m?dtc.exe"
O4 - HKCU\..\Run: [Hdzgu] C:\WINDOWS\S?mantec\w?nspool.exe
O4 - HKCU\..\Run: [Mtpvvnuq] "C:\Documents and Settings\Cameron\My Documents\?ymantec\r?gedit.exe"
O4 - HKCU\..\Run: [Waefng] "C:\Program Files\??crosoft\j?vaw.exe"
O4 - HKCU\..\Run: [Undgyub] "C:\Program Files\Common Files\?racle\l?gonui.exe"
O4 - HKCU\..\Run: [Gifazo] "C:\Program Files\?ppPatch\w?aclt.exe"
O4 - HKCU\..\Run: [Aaa] "C:\Documents and Settings\Cameron\Application Data\?ecurity\w?wexec.exe"
O4 - HKCU\..\Run: [Fuhbmbcc] "C:\Program Files\Common Files\??sembly\n?tdde.exe"
O4 - HKCU\..\Run: [Mayqbtr] C:\WINDOWS\system32\??curity\?pool32.exe
O4 - HKCU\..\Run: [Hpmgouj] "C:\Documents and Settings\Cameron\My Documents\A?pPatch\m?iexec.exe"
O4 - HKCU\..\Run: [Pmbm] "C:\Documents and Settings\Cameron\My Documents\?racle\?hkdsk.exe"
O4 - HKCU\..\Run: [Xedndv] "C:\Program Files\S?mantec\u?erinit.exe"
O4 - HKCU\..\Run: [DLD.EXE] C:\Program Files\Download Direct\DLD.exe
O4 - HKCU\..\Run: [Scmt] "C:\Documents and Settings\Cameron\My Documents\?dobe\n?tdde.exe"
O4 - HKCU\..\Run: [Gwfnzeeq] "C:\Documents and Settings\Cameron\Application Data\?icrosoft\??xplore.exe"
O4 - HKCU\..\Run: [Zpzxmoj] "C:\Documents and Settings\Cameron\My Documents\s?stem\w?nword.exe"
O4 - HKCU\..\Run: [Xms] "C:\Program Files\Common Files\F?nts\?hkntfs.exe"
O4 - HKCU\..\Run: [Fsvgodg] "C:\Documents and Settings\Cameron\My Documents\?asks\r?gsvr32.exe"
O4 - HKCU\..\Run: [Imijkl] "C:\Program Files\s?curity\?ti2evxx.exe"
O4 - HKCU\..\Run: [Hhtkdh] "C:\Program Files\Common Files\??crosoft\??rvices.exe"
O4 - HKCU\..\Run: [Xtpc] C:\WINDOWS\??stem32\??xplore.exe
O4 - HKCU\..\Run: [Zlmwgqbm] "C:\Program Files\Common Files\?racle\w?nword.exe"
O4 - HKCU\..\Run: [Bvvcrle] "C:\Program Files\?racle\w?wexec.exe"
O4 - HKCU\..\Run: [Yvhr] "C:\Program Files\??sembly\??rvices.exe"
O4 - HKCU\..\Run: [Rhbcz] "C:\Documents and Settings\Cameron\Application Data\??crosoft.NET\t?skmgr.exe"
O4 - HKCU\..\Run: [Sff] "C:\Program Files\s?stem\??plorer.exe"
O4 - HKCU\..\Run: [Aumpnqsc] "C:\Documents and Settings\Cameron\Application Data\?dobe\??ool32.exe"
O4 - HKCU\..\Run: [Oyabe] "C:\Program Files\W?nSxS\s?oolsv.exe"
O4 - HKCU\..\Run: [Abfu] C:\WINDOWS\??curity\d?dplay.exe
O4 - HKCU\..\Run: [Dys] C:\WINDOWS\M?crosoft\d?xplore.exe
O4 - HKCU\..\Run: [Uwlqw] "C:\Program Files\Common Files\?dobe\??xplore.exe"
O4 - HKCU\..\Run: [Pqs] C:\WINDOWS\system32\T?sks\s?oolsv.exe
O4 - HKCU\..\Run: [Dqqq] "C:\Documents and Settings\Cameron\My Documents\s?mbols\?ttrib.exe"
O4 - HKCU\..\Run: [Rjh] "C:\Documents and Settings\Cameron\My Documents\?dobe\?serinit.exe"
O4 - HKCU\..\Run: [Eeyq] C:\WINDOWS\F?nts\w?wexec.exe
O4 - HKCU\..\Run: [Kjcwth] "C:\Program Files\??mantec\d?xplore.exe"
O4 - HKCU\..\Run: [Uykvntpe] C:\WINDOWS\system32\M?crosoft.NET\r?gedit.exe
O4 - HKCU\..\Run: [Buakg] "C:\Documents and Settings\Cameron\My Documents\a?sembly\m?iexec.exe"
O4 - HKCU\..\Run: [Ulmwk] "C:\Program Files\Common Files\?icrosoft.NET\w?auboot.exe"
O4 - HKCU\..\Run: [Bnhathyp] "C:\Documents and Settings\Cameron\Application Data\s?curity\l?gonui.exe"
O4 - HKCU\..\Run: [Ebgxcgst] "C:\Documents and Settings\Cameron\Application Data\??sks\??erinit.exe"
O4 - HKCU\..\Run: [MSI Configuration] msiconf.exe
O4 - HKUS\S-1-5-18\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: PartyGammon.com - {59A861EE-32B3-42cd-8CCA-FC130EDF3A44} - C:\Program Files\PartyGaming\PartyGammon\RunBackGammon.exe
O9 - Extra 'Tools' menuitem: PartyGammon.com - {59A861EE-32B3-42cd-8CCA-FC130EDF3A44} - C:\Program Files\PartyGaming\PartyGammon\RunBackGammon.exe
O9 - Extra button: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe
O9 - Extra 'Tools' menuitem: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/haphazard/raptisoftgameloader.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1141432931234
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O20 - AppInit_DLLs: dllhost.dll
O20 - Winlogon Notify: winuns32 - winuns32.dll (file missing)
O20 - Winlogon Notify: WLCtrl32 - C:\WINDOWS\SYSTEM32\WLCtrl32.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

–
End of file - 15426 bytes


ComboFix 08-02-25.2 - Cameron 2008-02-25 17:35:24.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.92 [GMT 11:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Cameron\Application Data\APPATC~1
C:\Documents and Settings\Cameron\Application Data\ASEMBL~1
C:\Documents and Settings\Cameron\Application Data\ASKS~1
C:\Documents and Settings\Cameron\Application Data\CROSOF~1
C:\Documents and Settings\Cameron\Application Data\CROSOF~1.NET
C:\Documents and Settings\Cameron\Application Data\DOBE~1
C:\Documents and Settings\Cameron\Application Data\DOBE~2
C:\Documents and Settings\Cameron\Application Data\ECURIT~1
C:\Documents and Settings\Cameron\Application Data\FNTS~1
C:\Documents and Settings\Cameron\Application Data\FNTS~2
C:\Documents and Settings\Cameron\Application Data\ICROSO~1
C:\Documents and Settings\Cameron\Application Data\ICROSO~1.NET
C:\Documents and Settings\Cameron\Application Data\ICROSO~2
C:\Documents and Settings\Cameron\Application Data\macromedia\Flash Player\#SharedObjects\7EQHGCDP\www.broadcaster.com
C:\Documents and Settings\Cameron\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\Cameron\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Documents and Settings\Cameron\Application Data\MANTEC~1
C:\Documents and Settings\Cameron\Application Data\MCROSO~1
C:\Documents and Settings\Cameron\Application Data\MCROSO~1.NET
C:\Documents and Settings\Cameron\Application Data\PPPATC~1
C:\Documents and Settings\Cameron\Application Data\RACLE~1
C:\Documents and Settings\Cameron\Application Data\SCURIT~1
C:\Documents and Settings\Cameron\Application Data\SEMBLY~1
C:\Documents and Settings\Cameron\Application Data\SKS~1
C:\Documents and Settings\Cameron\Application Data\SKS~1\??erinit.exe
C:\Documents and Settings\Cameron\Application Data\SSEMBL~1
C:\Documents and Settings\Cameron\Application Data\SSTEM3~1
C:\Documents and Settings\Cameron\Application Data\STEM32~1
C:\Documents and Settings\Cameron\Application Data\TSKS~1
C:\Documents and Settings\Cameron\Application Data\YMANTE~1
C:\Documents and Settings\Cameron\Application Data\YMBOLS~1
C:\Documents and Settings\Cameron\Application Data\YSTEM3~1
C:\Documents and Settings\Cameron\My Documents\APPATC~1
C:\Documents and Settings\Cameron\My Documents\ASEMBL~1
C:\Documents and Settings\Cameron\My Documents\ASKS~1
C:\Documents and Settings\Cameron\My Documents\CROSOF~1.NET
C:\Documents and Settings\Cameron\My Documents\DOBE~1
C:\Documents and Settings\Cameron\My Documents\DOBE~2
C:\Documents and Settings\Cameron\My Documents\ECURIT~1
C:\Documents and Settings\Cameron\My Documents\FNTS~1
C:\Documents and Settings\Cameron\My Documents\ICROSO~1.NET
C:\Documents and Settings\Cameron\My Documents\MCROSO~1.NET
C:\Documents and Settings\Cameron\My Documents\MCROSO~1.NET\javaw.exe
C:\Documents and Settings\Cameron\My Documents\MCROSO~1.NET\MCROSO~1.NET\ctxad-570.0000
C:\Documents and Settings\Cameron\My Documents\MCROSO~1.NET\MCROSO~1.NET\ctxad-570.0001
C:\Documents and Settings\Cameron\My Documents\MCROSO~1.NET\MCROSO~1.NET\ctxad-570.0002
C:\Documents and Settings\Cameron\My Documents\MCROSO~1.NET\MCROSO~1.NET\ctxad-570.0003
C:\Documents and Settings\Cameron\My Documents\MCROSO~1.NET\MCROSO~1.NET\ctxad-570.0004
C:\Documents and Settings\Cameron\My Documents\RACLE~1
C:\Documents and Settings\Cameron\My Documents\SMBOLS~1
C:\Documents and Settings\Cameron\My Documents\SSTEM~1
C:\Documents and Settings\Cameron\My Documents\WNSXS~1
C:\Documents and Settings\Cameron\My Documents\YMANTE~1
C:\Documents and Settings\Cameron\My Documents\YSTEM~1
C:\Documents and Settings\Cameron\My Documents\YSTEM3~1
C:\Documents and Settings\Cameron\Start Menu\Programs\Outerinfo
C:\Documents and Settings\Cameron\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\Cameron\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Program Files\asembl~1
C:\Program Files\asks~1
C:\Program Files\Common Files\asembl~1
C:\Program Files\Common Files\asks~1
C:\Program Files\Common Files\asks~2
C:\Program Files\Common Files\crosof~1
C:\Program Files\Common Files\crosof~1.net
C:\Program Files\Common Files\curity~1
C:\Program Files\Common Files\dobe~1
C:\Program Files\Common Files\dobe~2
C:\Program Files\Common Files\ecurit~1
C:\Program Files\Common Files\fnts~1
C:\Program Files\Common Files\fnts~2
C:\Program Files\Common Files\icroso~1
C:\Program Files\Common Files\icroso~1.net
C:\Program Files\Common Files\mbols~1
C:\Program Files\Common Files\mcroso~1
C:\Program Files\Common Files\mcroso~1.net
C:\Program Files\Common Files\pppatc~1
C:\Program Files\Common Files\racle~1
C:\Program Files\Common Files\racle~2
C:\Program Files\Common Files\scurit~1
C:\Program Files\Common Files\sembly~1
C:\Program Files\Common Files\sks~1
C:\Program Files\Common Files\smante~1
C:\Program Files\Common Files\smbols~1
C:\Program Files\Common Files\ssembl~1
C:\Program Files\Common Files\stem~1
C:\Program Files\Common Files\tsks~1
C:\Program Files\Common Files\ymbols~1
C:\Program Files\cowabanga
C:\Program Files\cowabanga\License.txt
C:\Program Files\cowabanga\uninstaller.exe
C:\Program Files\crosof~1
C:\Program Files\curity~1
C:\Program Files\dobe~1
C:\Program Files\fnts~1
C:\Program Files\icroso~1.net
C:\Program Files\mantec~1
C:\Program Files\mcroso~1
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\FF.dll
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\outerinfo\OiUninstaller.exe
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\ppatch~1
C:\Program Files\pppatc~1
C:\Program Files\pppatc~2
C:\Program Files\racle~1
C:\Program Files\racle~2
C:\Program Files\scurit~1
C:\Program Files\sembly~1
C:\Program Files\sks~1
C:\Program Files\sks~2
C:\Program Files\smante~1
C:\Program Files\smbols~1
C:\Program Files\ssembl~1
C:\Program Files\sstem~1
C:\Program Files\sstem3~1
C:\Program Files\stem~1
C:\Program Files\stem32~1
C:\Program Files\wnsxs~1
C:\Program Files\ymbols~1
C:\Program Files\ystem~1
C:\Program Files\ystem3~1
C:\WINDOWS\asembl~1
C:\WINDOWS\asks~1
C:\WINDOWS\crosof~1
C:\WINDOWS\crosof~1.net
C:\WINDOWS\curity~1
C:\WINDOWS\ecurit~1
C:\WINDOWS\fnts~1
C:\WINDOWS\fnts~2
C:\WINDOWS\icroso~1
C:\WINDOWS\icroso~1.net
C:\WINDOWS\mantec~1
C:\WINDOWS\mbols~1
C:\WINDOWS\mcroso~1
C:\WINDOWS\pppatc~1
C:\WINDOWS\pppatc~2
C:\WINDOWS\racle~1
C:\WINDOWS\racle~2
C:\WINDOWS\scurit~1
C:\WINDOWS\sks~1
C:\WINDOWS\sks~2
C:\WINDOWS\smante~1
C:\WINDOWS\smbols~1
C:\WINDOWS\ssembl~1
C:\WINDOWS\sstem~1
C:\WINDOWS\stem~1
C:\WINDOWS\stem32~1
C:\WINDOWS\system32\8_exception.nls
C:\WINDOWS\system32\appatc~1
C:\WINDOWS\system32\asembl~1
C:\WINDOWS\system32\ati3d1a.dll
C:\WINDOWS\system32\crosof~1.net
C:\WINDOWS\system32\curity~1
C:\WINDOWS\system32\dobe~1
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\drivers\Qux14.sys
C:\WINDOWS\system32\drivers\utmgksbb.dat
C:\WINDOWS\system32\ecurit~1
C:\WINDOWS\system32\fnts~1
C:\WINDOWS\system32\fnts~2
C:\WINDOWS\system32\icroso~1.net
C:\WINDOWS\system32\install.exe
C:\WINDOWS\system32\jscdznn.dll
C:\WINDOWS\system32\mantec~1
C:\WINDOWS\system32\mcroso~1.net
C:\WINDOWS\system32\msiconf.exe
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\ppatch~1
C:\WINDOWS\system32\ppatch~2
C:\WINDOWS\system32\pppatc~1
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\racle~1
C:\WINDOWS\system32\racle~2
C:\WINDOWS\system32\scurit~1
C:\WINDOWS\system32\sembly~1
C:\WINDOWS\system32\sks~1
C:\WINDOWS\system32\sks~2
C:\WINDOWS\system32\smbols~1
C:\WINDOWS\system32\sstem~1
C:\WINDOWS\system32\sstem3~1
C:\WINDOWS\system32\stem~1
C:\WINDOWS\system32\tsks~1
C:\WINDOWS\system32\wanpacket.dll
C:\WINDOWS\system32\wnsxs~1
C:\WINDOWS\system32\wpcap.dll
C:\WINDOWS\system32\ymbols~1
C:\WINDOWS\system32\ystem3~1
C:\WINDOWS\wnsxs~1
C:\WINDOWS\ymante~1
C:\WINDOWS\ymbols~1

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_NHLPIPWG
——-\LEGACY_NPF
——-\LEGACY_QUX14
——-\LEGACY_RUNTIME
——-\nhlpipwg
——-\NPF
——-\Qux14
——-\runtime


((((((((((((((((((((((((( Files Created from 2008-01-25 to 2008-02-25 )))))))))))))))))))))))))))))))
.

2008-02-24 19:41 . 2008-02-24 19:41 14,336 –a—— C:\WINDOWS\system32\drivers\dumplog.exe
2008-02-24 18:51 . 2008-02-24 18:55 d——– C:\Program Files\SpywareBlaster
2008-02-24 18:51 . 2005-08-25 18:19 115,920 –a—— C:\WINDOWS\system32\MSINET.OCX
2008-02-24 18:40 . 2008-02-24 18:40 d——– C:\Program Files\Trend Micro
2008-02-24 13:48 . 2008-02-24 13:54 2,644 –a—— C:\WINDOWS\system32\tmp.reg
2008-02-22 09:40 . 2008-02-22 09:40 d——– C:\Documents and Settings\LocalService\Application Data\Symantec
2008-02-21 18:17 . 2008-02-21 18:17 d——– C:\Documents and Settings\Cameron\Application Data\Grisoft
2008-02-21 18:16 . 2008-02-21 18:16 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-21 18:16 . 2007-05-30 23:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-21 18:00 . 2008-02-21 18:00 51,968 –a—— C:\WINDOWS\system32\drivers\nkv2.sys
2008-02-20 22:52 . 2008-02-25 17:21 7,168 –a—— C:\WINDOWS\system32\WLCtrl32.dll
2008-02-17 09:47 . 2008-02-17 09:47 0 –a—— C:\WINDOWS\ativpsrm.bin
2008-02-11 13:04 . 2008-02-12 20:44 d——– C:\Program Files\Common Files\?icrosoft.NET
2008-02-02 16:48 . 2008-02-02 16:49 d——– C:\Program Files\4PLAY 4
2008-01-27 13:36 . 2008-01-27 13:36 d——– C:\Program Files\DVD Decrypter

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-23 05:54 ——— d—–w C:\Program Files\PartyGaming
2008-02-21 22:48 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-02-21 12:19 ——— d—–w C:\Program Files\ewido anti-malware
2008-02-20 12:10 ——— d—–w C:\Program Files\Google
2008-02-20 10:33 ——— d—–w C:\Documents and Settings\Cameron\Application Data\uTorrent
2008-02-20 09:04 ——— d—–w C:\Program Files\mIRC
2008-02-12 09:44 ——— d—–w C:\Program Files\Common Files\?icrosoft.NET
2008-02-03 12:40 ——— d—–w C:\Program Files\WM Recorder 10
2008-01-13 08:52 ——— d—–w C:\Program Files\Replay Media Catcher
2008-01-13 07:50 ——— d—–w C:\Program Files\Orbitdownloader
2008-01-13 07:50 ——— d—–w C:\Documents and Settings\Cameron\Application Data\Orbit
2008-01-13 07:42 ——— d—–w C:\Program Files\Flash Favorite
2008-01-13 07:41 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-13 04:52 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-01-13 03:42 22,328 —-a-w C:\Documents and Settings\Cameron\Application Data\PnkBstrK.sys
2008-01-13 03:41 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-13 03:30 ——— d—–w C:\Program Files\Activision
2008-01-02 09:56 1,568 —-a-w C:\Documents and Settings\Cameron\Application Data\mpauth.dat
2007-12-29 04:28 ——— d—–w C:\Documents and Settings\Cameron\Application Data\Microgaming
2007-12-28 12:07 ——— d—–w C:\Program Files\ICOO Loader
2007-12-27 11:56 ——— d—–w C:\Documents and Settings\Cameron\Application Data\Logitech
2007-12-27 11:56 ——— d—–w C:\Documents and Settings\All Users\Application Data\LogiShrd
2007-12-27 11:55 0 —ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-12-27 11:55 0 —ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2007-12-27 11:54 ——— d—–w C:\Program Files\Logitech
2007-12-27 11:54 ——— d—–w C:\Program Files\Common Files\Logishrd
2007-12-27 11:54 ——— d—–w C:\Documents and Settings\Cameron\Application Data\InstallShield
2007-12-27 11:54 ——— d—–w C:\Documents and Settings\All Users\Application Data\Logitech
2006-08-26 02:06 49,891 —-a-w C:\Program Files\uninstal.log
2006-03-25 10:43 32 —-a-r C:\Documents and Settings\All Users\hash.dat
2006-02-25 10:42 5,180,760 —-a-w C:\Documents and Settings\Cameron\CONFIGW.EXE
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3138C2C3-5D70-5AAE-0461-5900BBBBD8C9}]
C:\WINDOWS\system32\kgnwdcs.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{31E00143-96FD-C877-D389-C76932DBD9CE}]
C:\WINDOWS\system32\zfkpl.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D794A86A-31D9-3409-A2DF-671344A93897}]
C:\WINDOWS\system32\kgpdr.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-12-16 12:57 94208]
"SpySpotter System Defender"="C:\Program Files\SpySpotter3\Defender.exe" [ ]
"Swcl"="C:\DOCUME~1\Cameron\MYDOCU~1\MCROSO~1.NET\javaw.exe" [ ]
"Mkww"="C:\DOCUME~1\Cameron\MYDOCU~1\ECURIT~1\TSKMGR~1.EXE" [ ]
"Nqt"="C:\WINDOWS\a?sembly\w?nword.exe" [ ]
"Onee"="C:\WINDOWS\W?nSxS\r?gedit.exe" [ ]
"Iiyhdjkb"="C:\WINDOWS\system32\?ecurity\w?aclt.exe" [ ]
"Vmtayuwh"="C:\WINDOWS\??crosoft.NET\u?erinit.exe" [ ]
"Eej"="C:\WINDOWS\F?nts\n?tdde.exe" [ ]
"Oqo"="C:\Program Files\??pPatch\s?chost.exe" [ ]
"Pehgzeg"="C:\Program Files\??curity\w?nlogon.exe" [ ]
"Afhbuxnl"="C:\Documents and Settings\Cameron\My Documents\M?crosoft.NET\w?auclt.exe" [ ]
"Vulb"="C:\Documents and Settings\Cameron\Application Data\?ymantec\n?pdb.exe" [ ]
"Ekxs"="C:\Documents and Settings\Cameron\Application Data\?ystem32\d?dplay.exe" [ ]
"Fchfku"="C:\WINDOWS\system32\?ymbols\w?wexec.exe" [ ]
"Bhd"="C:\WINDOWS\system32\?racle\w?wexec.exe" [ ]
"Filiaimk"="C:\Program Files\Common Files\?ssembly\?hkntfs.exe" [ ]
"Jkmlpf"="C:\Program Files\W?nSxS\w?nspool.exe" [ ]
"Kguizm"="C:\Documents and Settings\Cameron\Application Data\s?stem32\m?dtc.exe" [ ]
"Hdzgu"="C:\WINDOWS\S?mantec\w?nspool.exe" [ ]
"Mtpvvnuq"="C:\Documents and Settings\Cameron\My Documents\?ymantec\r?gedit.exe" [ ]
"Waefng"="C:\Program Files\??crosoft\j?vaw.exe" [ ]
"Undgyub"="C:\Program Files\Common Files\?racle\l?gonui.exe" [ ]
"Gifazo"="C:\Program Files\?ppPatch\w?aclt.exe" [ ]
"Aaa"="C:\Documents and Settings\Cameron\Application Data\?ecurity\w?wexec.exe" [ ]
"Fuhbmbcc"="C:\Program Files\Common Files\??sembly\n?tdde.exe" [ ]
"Mayqbtr"="C:\WINDOWS\system32\??curity\?pool32.exe" [ ]
"Hpmgouj"="C:\Documents and Settings\Cameron\My Documents\A?pPatch\m?iexec.exe" [ ]
"Pmbm"="C:\Documents and Settings\Cameron\My Documents\?racle\?hkdsk.exe" [ ]
"Xedndv"="C:\Program Files\S?mantec\u?erinit.exe" [ ]
"DLD.EXE"="C:\Program Files\Download Direct\DLD.exe" [ ]
"Scmt"="C:\Documents and Settings\Cameron\My Documents\?dobe\n?tdde.exe" [ ]
"Gwfnzeeq"="C:\Documents and Settings\Cameron\Application Data\?icrosoft\??xplore.exe" [ ]
"Zpzxmoj"="C:\Documents and Settings\Cameron\My Documents\s?stem\w?nword.exe" [ ]
"Xms"="C:\Program Files\Common Files\F?nts\?hkntfs.exe" [ ]
"Fsvgodg"="C:\Documents and Settings\Cameron\My Documents\?asks\r?gsvr32.exe" [ ]
"Imijkl"="C:\Program Files\s?curity\?ti2evxx.exe" [ ]
"Hhtkdh"="C:\Program Files\Common Files\??crosoft\??rvices.exe" [ ]
"Xtpc"="C:\WINDOWS\??stem32\??xplore.exe" [ ]
"Zlmwgqbm"="C:\Program Files\Common Files\?racle\w?nword.exe" [ ]
"Bvvcrle"="C:\Program Files\?racle\w?wexec.exe" [ ]
"Yvhr"="C:\Program Files\??sembly\??rvices.exe" [ ]
"Rhbcz"="C:\Documents and Settings\Cameron\Application Data\??crosoft.NET\t?skmgr.exe" [ ]
"Sff"="C:\Program Files\s?stem\??plorer.exe" [ ]
"Aumpnqsc"="C:\Documents and Settings\Cameron\Application Data\?dobe\??ool32.exe" [ ]
"Oyabe"="C:\Program Files\W?nSxS\s?oolsv.exe" [ ]
"Abfu"="C:\WINDOWS\??curity\d?dplay.exe" [ ]
"Dys"="C:\WINDOWS\M?crosoft\d?xplore.exe" [ ]
"Uwlqw"="C:\Program Files\Common Files\?dobe\??xplore.exe" [ ]
"Pqs"="C:\WINDOWS\system32\T?sks\s?oolsv.exe" [ ]
"Dqqq"="C:\Documents and Settings\Cameron\My Documents\s?mbols\?ttrib.exe" [ ]
"Rjh"="C:\Documents and Settings\Cameron\My Documents\?dobe\?serinit.exe" [ ]
"Eeyq"="C:\WINDOWS\F?nts\w?wexec.exe" [ ]
"Kjcwth"="C:\Program Files\??mantec\d?xplore.exe" [ ]
"Uykvntpe"="C:\WINDOWS\system32\M?crosoft.NET\r?gedit.exe" [ ]
"Buakg"="C:\Documents and Settings\Cameron\My Documents\a?sembly\m?iexec.exe" [ ]
"Ulmwk"="C:\Program Files\Common Files\?icrosoft.NET\w?auboot.exe" [ ]
"Bnhathyp"="C:\Documents and Settings\Cameron\Application Data\s?curity\l?gonui.exe" [ ]
"Ebgxcgst"="C:\Documents and Settings\Cameron\Application Data\??sks\??erinit.exe" [ ]
"MSI Configuration"="msiconf.exe" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-12-22 20:09 77824 C:\WINDOWS\SOUNDMAN.EXE]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-03-23 15:34 58992]
"ALi5289"="C:\Program Files\ULI5289\ALi5289.exe" [2005-03-10 17:56 405504]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2006-02-27 04:01 100056]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 16:17 159744]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-03-13 18:52 98304]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 20:24 32768]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"8ddef2a.exe"="C:\WINDOWS\system32\8ddef2a.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 03:10 55824 C:\WINDOWS\KHALMNPR.Exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 03:24 1694208]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-12-27 22:54:35 784912]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-03-22 12:00:00 65588]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 32 (0x20)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll 2007-11-15 10:10 72208 c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winuns32]
winuns32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WLCtrl32]
WLCtrl32.dll 2008-02-25 17:21 7168 C:\WINDOWS\system32\WLCtrl32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= dllhost.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\setup.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2008-02-08 12:16:05 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Cameron.job"
- C:\PROGRA~1\NORTON~1\Navw32.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-25 17:42:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\WLCtrl32.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\wdfmgr.exe
.
**************************************************************************
.
Completion time: 2008-02-25 17:45:24 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-25 06:45:20
.
2008-02-16 12:53:45 — E O F —
Hello :)

Open HijackThis, Click Do a system scan only, checkmark these. Then close all other windows except HijackThis and press fix checked.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
O2 - BHO: (no name) - {3138C2C3-5D70-5AAE-0461-5900BBBBD8C9} - C:\WINDOWS\system32\kgnwdcs.dll (file missing)
O2 - BHO: (no name) - {31E00143-96FD-C877-D389-C76932DBD9CE} - C:\WINDOWS\system32\zfkpl.dll (file missing)
O2 - BHO: (no name) - {353791C1-5979-00FC-0661-5900BBBA8B98} - C:\WINDOWS\system32\jscdznn.dll
O2 - BHO: (no name) - {D794A86A-31D9-3409-A2DF-671344A93897} - C:\WINDOWS\system32\kgpdr.dll (file missing)
O2 - BHO: (no name) - {E36FC7AE-E1C1-45AB-84DE-F2B54D85EEEE} - C:\WINDOWS\system32\ati3d1a.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [8ddef2a.exe] C:\WINDOWS\system32\8ddef2a.exe
O4 - HKCU\..\Run: [SpySpotter System Defender] C:\Program Files\SpySpotter3\Defender.exe -startup
O4 - HKCU\..\Run: [Swcl] "C:\DOCUME~1\Cameron\MYDOCU~1\MCROSO~1.NET\javaw.exe" -vt ndrv
O4 - HKCU\..\Run: [Mkww] C:\DOCUME~1\Cameron\MYDOCU~1\ECURIT~1\TSKMGR~1.EXE
O4 - HKCU\..\Run: [Nqt] C:\WINDOWS\a?sembly\w?nword.exe
O4 - HKCU\..\Run: [Onee] C:\WINDOWS\W?nSxS\r?gedit.exe
O4 - HKCU\..\Run: [Iiyhdjkb] C:\WINDOWS\system32\?ecurity\w?aclt.exe
O4 - HKCU\..\Run: [Vmtayuwh] C:\WINDOWS\??crosoft.NET\u?erinit.exe
O4 - HKCU\..\Run: [Eej] C:\WINDOWS\F?nts\n?tdde.exe
O4 - HKCU\..\Run: [Oqo] "C:\Program Files\??pPatch\s?chost.exe"
O4 - HKCU\..\Run: [Pehgzeg] "C:\Program Files\??curity\w?nlogon.exe"
O4 - HKCU\..\Run: [Afhbuxnl] "C:\Documents and Settings\Cameron\My Documents\M?crosoft.NET\w?auclt.exe"
O4 - HKCU\..\Run: [Vulb] "C:\Documents and Settings\Cameron\Application Data\?ymantec\n?pdb.exe"
O4 - HKCU\..\Run: [Ekxs] "C:\Documents and Settings\Cameron\Application Data\?ystem32\d?dplay.exe"
O4 - HKCU\..\Run: [Fchfku] C:\WINDOWS\system32\?ymbols\w?wexec.exe
O4 - HKCU\..\Run: [Bhd] C:\WINDOWS\system32\?racle\w?wexec.exe
O4 - HKCU\..\Run: [Filiaimk] "C:\Program Files\Common Files\?ssembly\?hkntfs.exe"
O4 - HKCU\..\Run: [Jkmlpf] "C:\Program Files\W?nSxS\w?nspool.exe"
O4 - HKCU\..\Run: [Kguizm] "C:\Documents and Settings\Cameron\Application Data\s?stem32\m?dtc.exe"
O4 - HKCU\..\Run: [Hdzgu] C:\WINDOWS\S?mantec\w?nspool.exe
O4 - HKCU\..\Run: [Mtpvvnuq] "C:\Documents and Settings\Cameron\My Documents\?ymantec\r?gedit.exe"
O4 - HKCU\..\Run: [Waefng] "C:\Program Files\??crosoft\j?vaw.exe"
O4 - HKCU\..\Run: [Undgyub] "C:\Program Files\Common Files\?racle\l?gonui.exe"
O4 - HKCU\..\Run: [Gifazo] "C:\Program Files\?ppPatch\w?aclt.exe"
O4 - HKCU\..\Run: [Aaa] "C:\Documents and Settings\Cameron\Application Data\?ecurity\w?wexec.exe"
O4 - HKCU\..\Run: [Fuhbmbcc] "C:\Program Files\Common Files\??sembly\n?tdde.exe"
O4 - HKCU\..\Run: [Mayqbtr] C:\WINDOWS\system32\??curity\?pool32.exe
O4 - HKCU\..\Run: [Hpmgouj] "C:\Documents and Settings\Cameron\My Documents\A?pPatch\m?iexec.exe"
O4 - HKCU\..\Run: [Pmbm] "C:\Documents and Settings\Cameron\My Documents\?racle\?hkdsk.exe"
O4 - HKCU\..\Run: [Xedndv] "C:\Program Files\S?mantec\u?erinit.exe"
O4 - HKCU\..\Run: [DLD.EXE] C:\Program Files\Download Direct\DLD.exe
O4 - HKCU\..\Run: [Scmt] "C:\Documents and Settings\Cameron\My Documents\?dobe\n?tdde.exe"
O4 - HKCU\..\Run: [Gwfnzeeq] "C:\Documents and Settings\Cameron\Application Data\?icrosoft\??xplore.exe"
O4 - HKCU\..\Run: [Zpzxmoj] "C:\Documents and Settings\Cameron\My Documents\s?stem\w?nword.exe"
O4 - HKCU\..\Run: [Xms] "C:\Program Files\Common Files\F?nts\?hkntfs.exe"
O4 - HKCU\..\Run: [Fsvgodg] "C:\Documents and Settings\Cameron\My Documents\?asks\r?gsvr32.exe"
O4 - HKCU\..\Run: [Imijkl] "C:\Program Files\s?curity\?ti2evxx.exe"
O4 - HKCU\..\Run: [Hhtkdh] "C:\Program Files\Common Files\??crosoft\??rvices.exe"
O4 - HKCU\..\Run: [Xtpc] C:\WINDOWS\??stem32\??xplore.exe
O4 - HKCU\..\Run: [Zlmwgqbm] "C:\Program Files\Common Files\?racle\w?nword.exe"
O4 - HKCU\..\Run: [Bvvcrle] "C:\Program Files\?racle\w?wexec.exe"
O4 - HKCU\..\Run: [Yvhr] "C:\Program Files\??sembly\??rvices.exe"
O4 - HKCU\..\Run: [Rhbcz] "C:\Documents and Settings\Cameron\Application Data\??crosoft.NET\t?skmgr.exe"
O4 - HKCU\..\Run: [Sff] "C:\Program Files\s?stem\??plorer.exe"
O4 - HKCU\..\Run: [Aumpnqsc] "C:\Documents and Settings\Cameron\Application Data\?dobe\??ool32.exe"
O4 - HKCU\..\Run: [Oyabe] "C:\Program Files\W?nSxS\s?oolsv.exe"
O4 - HKCU\..\Run: [Abfu] C:\WINDOWS\??curity\d?dplay.exe
O4 - HKCU\..\Run: [Dys] C:\WINDOWS\M?crosoft\d?xplore.exe
O4 - HKCU\..\Run: [Uwlqw] "C:\Program Files\Common Files\?dobe\??xplore.exe"
O4 - HKCU\..\Run: [Pqs] C:\WINDOWS\system32\T?sks\s?oolsv.exe
O4 - HKCU\..\Run: [Dqqq] "C:\Documents and Settings\Cameron\My Documents\s?mbols\?ttrib.exe"
O4 - HKCU\..\Run: [Rjh] "C:\Documents and Settings\Cameron\My Documents\?dobe\?serinit.exe"
O4 - HKCU\..\Run: [Eeyq] C:\WINDOWS\F?nts\w?wexec.exe
O4 - HKCU\..\Run: [Kjcwth] "C:\Program Files\??mantec\d?xplore.exe"
O4 - HKCU\..\Run: [Uykvntpe] C:\WINDOWS\system32\M?crosoft.NET\r?gedit.exe
O4 - HKCU\..\Run: [Buakg] "C:\Documents and Settings\Cameron\My Documents\a?sembly\m?iexec.exe"
O4 - HKCU\..\Run: [Ulmwk] "C:\Program Files\Common Files\?icrosoft.NET\w?auboot.exe"
O4 - HKCU\..\Run: [Bnhathyp] "C:\Documents and Settings\Cameron\Application Data\s?curity\l?gonui.exe"
O4 - HKCU\..\Run: [Ebgxcgst] "C:\Documents and Settings\Cameron\Application Data\??sks\??erinit.exe"
O4 - HKCU\..\Run: [MSI Configuration] msiconf.exe
O20 - AppInit_DLLs: dllhost.dll
O20 - Winlogon Notify: winuns32 - winuns32.dll (file missing)
O20 - Winlogon Notify: WLCtrl32 - C:\WINDOWS\SYSTEM32\WLCtrl32.dll

_________________

Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\jscdznn.dll
C:\WINDOWS\system32\ati3d1a.dll
C:\WINDOWS\system32\8ddef2a.exe
C:\WINDOWS\SYSTEM32\WLCtrl32.dll

Folder::
C:\Program Files\SpySpotter3


Save this as CFScript.txt

Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]

This will start ComboFix again. After reboot, (in case it asks to reboot).
________________

Use the Windows "search" tool
Start->Search
-> All files and folders
Click More advanced options

Checkmark these options:
"Search system folders"
"Search hidden files and folders"
"Search subfolders"


->Search for these and delete if found: dllhost.dll and msiconf.exe
____________________

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
______________________

Post:
- A fresh HijackThis log
- Logfile of ComboFix
- Contents of the Report.txt
hi done what you said here is a new hijack log cmbofix log and report.txt - thanks for your help.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:11:15 PM, on 26/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 195.175.37.70:8080
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ALi5289] C:\Program Files\ULI5289\ALi5289.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [LayoutM] KLayMgr.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-18\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: PartyGammon.com - {59A861EE-32B3-42cd-8CCA-FC130EDF3A44} - C:\Program Files\PartyGaming\PartyGammon\RunBackGammon.exe
O9 - Extra 'Tools' menuitem: PartyGammon.com - {59A861EE-32B3-42cd-8CCA-FC130EDF3A44} - C:\Program Files\PartyGaming\PartyGammon\RunBackGammon.exe
O9 - Extra button: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe
O9 - Extra 'Tools' menuitem: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/haphazard/raptisoftgameloader.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1141432931234
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

–
End of file - 9504 bytes


ComboFix 08-02-25.2 - Cameron 2008-02-26 17:43:32.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.209 [GMT 11:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Cameron\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\system32\8ddef2a.exe
C:\WINDOWS\system32\ati3d1a.dll
C:\WINDOWS\system32\jscdznn.dll
C:\WINDOWS\SYSTEM32\WLCtrl32.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\drivers\Xcf60.sys
C:\WINDOWS\SYSTEM32\WLCtrl32.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_XCF60
——-\Xcf60


((((((((((((((((((((((((( Files Created from 2008-01-26 to 2008-02-26 )))))))))))))))))))))))))))))))
.

2008-02-26 17:31 . 2008-02-25 15:14 d——– C:\SDFix
2008-02-25 18:25 . 2004-08-03 22:58 14,848 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys
2008-02-25 18:25 . 2004-08-03 22:58 14,848 –a–c— C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-02-25 18:24 . 2008-02-25 18:24 d——– C:\Program Files\HP USB Smart Card Keyboard
2008-02-25 18:23 . 2008-02-25 18:23 d——– C:\SWSetup
2008-02-24 19:41 . 2008-02-25 23:55 14,336 –a—— C:\WINDOWS\system32\drivers\dumplog.exe
2008-02-24 18:51 . 2008-02-24 18:55 d——– C:\Program Files\SpywareBlaster
2008-02-24 18:51 . 2005-08-25 18:19 115,920 –a—— C:\WINDOWS\system32\MSINET.OCX
2008-02-24 18:40 . 2008-02-24 18:40 d——– C:\Program Files\Trend Micro
2008-02-24 13:48 . 2008-02-24 13:54 2,644 –a—— C:\WINDOWS\system32\tmp.reg
2008-02-22 09:40 . 2008-02-22 09:40 d——– C:\Documents and Settings\LocalService\Application Data\Symantec
2008-02-21 18:17 . 2008-02-21 18:17 d——– C:\Documents and Settings\Cameron\Application Data\Grisoft
2008-02-21 18:16 . 2008-02-21 18:16 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-21 18:16 . 2007-05-30 23:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-21 18:00 . 2008-02-21 18:00 51,968 –a—— C:\WINDOWS\system32\drivers\nkv2.sys
2008-02-17 09:47 . 2008-02-17 09:47 0 –a—— C:\WINDOWS\ativpsrm.bin
2008-02-11 13:04 . 2008-02-12 20:44 d——– C:\Program Files\Common Files\?icrosoft.NET
2008-02-02 16:48 . 2008-02-02 16:49 d——– C:\Program Files\4PLAY 4
2008-01-27 13:36 . 2008-01-27 13:36 d——– C:\Program Files\DVD Decrypter

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-25 07:23 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-23 05:54 ——— d—–w C:\Program Files\PartyGaming
2008-02-21 22:48 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-02-21 12:19 ——— d—–w C:\Program Files\ewido anti-malware
2008-02-20 12:10 ——— d—–w C:\Program Files\Google
2008-02-20 10:33 ——— d—–w C:\Documents and Settings\Cameron\Application Data\uTorrent
2008-02-20 09:04 ——— d—–w C:\Program Files\mIRC
2008-02-12 09:44 ——— d—–w C:\Program Files\Common Files\?icrosoft.NET
2008-02-03 12:40 ——— d—–w C:\Program Files\WM Recorder 10
2008-01-13 08:52 ——— d—–w C:\Program Files\Replay Media Catcher
2008-01-13 07:50 ——— d—–w C:\Program Files\Orbitdownloader
2008-01-13 07:50 ——— d—–w C:\Documents and Settings\Cameron\Application Data\Orbit
2008-01-13 07:42 ——— d—–w C:\Program Files\Flash Favorite
2008-01-13 07:41 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-13 04:52 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-01-13 03:42 22,328 —-a-w C:\Documents and Settings\Cameron\Application Data\PnkBstrK.sys
2008-01-13 03:30 ——— d—–w C:\Program Files\Activision
2008-01-02 09:56 1,568 —-a-w C:\Documents and Settings\Cameron\Application Data\mpauth.dat
2007-12-29 04:28 ——— d—–w C:\Documents and Settings\Cameron\Application Data\Microgaming
2007-12-28 12:07 ——— d—–w C:\Program Files\ICOO Loader
2007-12-27 11:56 ——— d—–w C:\Documents and Settings\Cameron\Application Data\Logitech
2007-12-27 11:56 ——— d—–w C:\Documents and Settings\All Users\Application Data\LogiShrd
2007-12-27 11:55 0 —ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-12-27 11:55 0 —ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2007-12-27 11:54 ——— d—–w C:\Program Files\Logitech
2007-12-27 11:54 ——— d—–w C:\Program Files\Common Files\Logishrd
2007-12-27 11:54 ——— d—–w C:\Documents and Settings\Cameron\Application Data\InstallShield
2007-12-27 11:54 ——— d—–w C:\Documents and Settings\All Users\Application Data\Logitech
2006-08-26 02:06 49,891 —-a-w C:\Program Files\uninstal.log
2006-03-25 10:43 32 —-a-r C:\Documents and Settings\All Users\hash.dat
2006-02-25 10:42 5,180,760 —-a-w C:\Documents and Settings\Cameron\CONFIGW.EXE
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-12-16 12:57 94208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-12-22 20:09 77824 C:\WINDOWS\SOUNDMAN.EXE]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-03-23 15:34 58992]
"ALi5289"="C:\Program Files\ULI5289\ALi5289.exe" [2005-03-10 17:56 405504]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2006-02-27 04:01 100056]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 16:17 159744]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-03-13 18:52 98304]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 20:24 32768]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 03:10 55824 C:\WINDOWS\KHALMNPR.Exe]
"LayoutM"="KLayMgr.exe" [2004-08-26 14:17 45056 C:\WINDOWS\KLayMgr.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 03:24 1694208]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-12-27 22:54:35 784912]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-03-22 12:00:00 65588]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 32 (0x20)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll 2007-11-15 10:10 72208 c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=

R0 m5289;m5289;C:\WINDOWS\system32\DRIVERS\m5289.sys [2004-12-01 13:49]
R0 uliagpkx;ULi AGP Bus Filter Driver;C:\WINDOWS\system32\DRIVERS\agpkx.sys [2005-05-03 20:31]
S3 HPKBCCID;HP Keyboard Smart Card Driver;C:\WINDOWS\system32\DRIVERS\HPKBCCID.sys [2005-08-04 04:30]
S3 STC2DFU;STCII DFU Adapter;C:\WINDOWS\system32\DRIVERS\Stc2Dfu.SYS [2004-10-25 00:04]
S3 USB2_04;USB2_04 driver;C:\WINDOWS\system32\drivers\nkv2.sys [2008-02-21 18:00]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-08 12:16:05 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Cameron.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/task:
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-26 17:49:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
.
**************************************************************************
.
Completion time: 2008-02-26 17:52:20 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-26 06:52:15
ComboFix2.txt 2008-02-25 06:54:15
.
2008-02-16 12:53:45 — E O F —


SDFix: Version 1.147

Run by [removed] on Tue 26/02/2008 at 06:00 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :

Name:
USB2_04

Path:
\??\C:\WINDOWS\system32\drivers\nkv2.sys

USB2_04 - Deleted



Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\System32\drivers\nkv2.sys - Deleted





Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-26 18:03:47
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch]
"Epoch"=dword:00002d97
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s0"=dword:d860bf52
"s1"=dword:030033e7
"s2"=dword:d4aacd24
"h0"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
"h0"=dword:00000000
"ujdew"=hex:e0,ff,55,96,2e,6a,ed,c1,15,90,64,b6,8c,42,7f,a5,2e,d3,2d,79,36,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3B4060CA-E1BA-4FB3-9FD0-52260F25F4A0}]
"LeaseObtainedTime"=dword:47c3b9ca
"T1"=dword:47c3b9d4
"T2"=dword:47c3b9db
"LeaseTerminatesTime"=dword:47c3b9de
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{3B4060CA-E1BA-4FB3-9FD0-52260F25F4A0}\Parameters\Tcpip]
"LeaseObtainedTime"=dword:47c3b9ca
"T1"=dword:47c3b9d4
"T2"=dword:47c3b9db
"LeaseTerminatesTime"=dword:47c3b9de
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
"h0"=dword:00000000
"ujdew"=hex:e0,ff,55,96,2e,6a,ed,c1,15,90,64,b6,8c,42,7f,a5,2e,d3,2d,79,36,..

scanning hidden registry entries …

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{545FCD8A-D9D7-9405-9029-196CD35B557A}]
"iaahkpangkmhmdhdeb"=hex:6b,61,6c,6b,64,69,6c,67,62,6b,61,68,69,63,64,6c,63,69,65,64,6d,..
"jaaegolfinnfjhddpojd"=hex:62,61,6f,6a,00,00
"jaaegolfinnfjhddpond"=hex:62,61,63,66,00,00
"hagheabgmejlbmpg"=hex:6b,61,6c,6b,64,69,6c,67,62,6b,61,68,69,63,64,6c,63,69,65,64,6d,..
"iagheaiaadlfmkpajd"=hex:68,61,70,67,63,70,6a,6c,67,64,70,62,64,66,6b,63,00,cc
"jahhppjaodfjmcjhccgo"=hex:62,61,6b,6b,00,03
"bacb"=hex:63,61,6f,6a,6f,69,00,00
"badb"=hex:63,61,61,6b,68,69,00,00
"cafbch"=hex:64,61,64,66,6a,6c,61,6a,00,ed
"cafbbh"=hex:64,61,61,6b,63,68,6d,6b,00,ed
"iafgeadnkcgljlfail"=hex:65,61,6c,6b,65,69,6e,65,66,64,00,00
"iafgeadnkcgljlfadl"=hex:64,61,6a,6b,63,6c,62,68,00,64
"hamecdkbkbcdbmbd"=hex:61,61,00,00
"jafendmpdmkoodlgeehl"=hex:61,61,00,00

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\uTorrent\\utorrent.exe"="C:\\Program Files\\uTorrent\\utorrent.exe:*:Enabled:µTorrent"
"C:\\Program Files\\mIRC\\mirc.exe"="C:\\Program Files\\mIRC\\mirc.exe:*:Enabled:mIRC"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Fri 17 Nov 2006 51,200 ..SHR — "C:\Program Files\DominateGame\Setup.exe"
Mon 17 Feb 2003 82 A..H. — "C:\Program Files\xc2\._install.exe"
Sun 18 Jun 2006 4,348 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 13 Nov 2004 37,376 …H. — "C:\Program Files\Common Files\Adobe\ESD\DLMCleanup.exe"

Finished!


thanks
Hello :) We have still something to do ;)

Kaspersky online scanner works only with Internet Explorer!

Please run an online scanner with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:

    o Scan using the following Anti-Virus database:

    + Extended (If available otherwise Standard)

    o Scan Options:

    + Scan Archives
    + Scan Mail Bases

  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

Post:
- A fresh HijackThis log
- Kaspersky's report

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI