This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Pop-up Warning: possible spyware.. Click here" an

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Oh yes, I have noticed from the scan that there were other viruses detected. I have not noticed anything 'wrong' with my cmpt., however. As well, you had asked about my Avast! not running. I did turn it off to preform some of the work done yesterday, but I also had the internet unplugged. It has since been turned on as a result of a re-boot. Thx and Good night, for now.
Hi

1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\Documents and Settings\Leilani\My Documents\Adware Help\SDFix\SDFix\backups\backups.zip

Folder::
C:\WINDOWS\privacy_danger(3)
C:\WINDOWS\privacy_danger(2)

DirLook::
C:\WINDOWS\CD95F661A5C444F5A6AAECDD91C240B5.TMP
C:\WINDOWS\A149DEA21D5B11D59F7600C04F6BC7A1.TMP

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Are you having any more problems or suspicions with your computer at the moment?

Thanks.
Hi JP,

My cmpt. is running without any pop-ups or noticable adware.
Yeah!!!!

Here are the latest results.

ComoFix_log

ComboFix 08-03-04.1 - Leilani 2008-03-04 16:56:36.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.662 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Leilani\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\Documents and Settings\Leilani\My Documents\Adware Help\SDFix\SDFix\backups\backups.zip
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Leilani\My Documents\Adware Help\SDFix\SDFix\backups\backups.zip
C:\WINDOWS\privacy_danger(2)
C:\WINDOWS\privacy_danger(2)\images(2)\capt.gif
C:\WINDOWS\privacy_danger(2)\images(2)\danger.jpg
C:\WINDOWS\privacy_danger(2)\images(2)\down.gif
C:\WINDOWS\privacy_danger(2)\images(2)\spacer.gif
C:\WINDOWS\privacy_danger(2)\index.htm
C:\WINDOWS\privacy_danger(3)
C:\WINDOWS\privacy_danger(3)\images(2)\capt.gif
C:\WINDOWS\privacy_danger(3)\images(2)\danger.jpg
C:\WINDOWS\privacy_danger(3)\images(2)\down.gif
C:\WINDOWS\privacy_danger(3)\images(2)\spacer.gif
C:\WINDOWS\privacy_danger(3)\index.htm

.
((((((((((((((((((((((((( Files Created from 2008-02-05 to 2008-03-05 )))))))))))))))))))))))))))))))
.

2008-03-03 18:23 . 2008-03-03 18:23 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-03-03 18:23 . 2008-03-03 18:23 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-02 20:24 . 2008-03-02 20:47 d——– C:\Program Files\SpywareBlaster
2008-03-02 20:24 . 2008-03-02 20:47 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-02 19:57 . 2008-03-02 19:57 d——– C:\Deckard
2008-03-02 19:31 . 2008-03-02 19:32 d——– C:\WINDOWS\ERUNT
2008-03-02 14:15 . 2008-03-02 14:15 d——– C:\Program Files\TaxTron 2007
2008-03-02 14:00 . 2008-03-02 14:00 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-03-02 09:56 . 2008-03-02 20:25 d——– C:\ie-spyad_zo
2008-03-01 09:49 . 2008-03-01 09:49 d——– C:\Documents and Settings\Leilani\Application Data\Talkback
2008-03-01 09:48 . 2008-03-02 13:49 d——– C:\Program Files\Mozilla Firefox(2)
2008-03-01 09:48 . 2008-03-01 09:48 0 –a—— C:\WINDOWS\nsreg.dat
2008-02-24 13:22 . 2008-02-24 13:20 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-02-24 13:19 . 2008-02-24 13:22 d——– C:\Documents and Settings\Leilani\.housecall6.6
2008-02-24 13:05 . 2008-02-24 13:06 163 –a—— C:\WINDOWS\wininit.ini
2008-02-24 12:27 . 2008-02-24 12:26 691,545 –a—— C:\WINDOWS\unins000.exe
2008-02-24 12:27 . 2008-02-24 12:27 2,551 –a—— C:\WINDOWS\unins000.dat
2008-02-24 12:04 . 2008-02-24 12:04 d——– C:\WINDOWS\CD95F661A5C444F5A6AAECDD91C240B5.TMP
2008-02-24 12:03 . 2008-02-24 12:03 d——– C:\Skunk Studios
2008-02-24 12:03 . 2008-02-24 12:03 d——– C:\Program Files\Flt
2008-02-21 18:45 . 2008-02-24 12:03 d——– C:\Program Files\Spyware Doctor(2)
2008-02-21 17:57 . 2008-02-21 18:37 d——– C:\Program Files\Enigma Software Group
2008-02-16 12:47 . 2008-02-24 12:04 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-16 12:36 . 2008-02-24 12:04 d——– C:\Program Files\Lavasoft
2008-02-10 23:01 . 2008-02-10 23:02 d——– C:\Documents and Settings\All Users\Application Data\WinZip
2008-02-10 22:29 . 2004-08-03 22:58 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2008-02-10 22:29 . 2004-08-03 22:58 15,104 –a–c— C:\WINDOWS\system32\dllcache\usbscan.sys
2008-02-10 22:27 . 2004-08-03 23:01 25,856 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2008-02-10 22:27 . 2004-08-03 23:01 25,856 –a–c— C:\WINDOWS\system32\dllcache\usbprint.sys
2008-02-10 22:26 . 2004-08-03 23:08 31,616 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys
2008-02-10 22:26 . 2004-08-03 23:08 31,616 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-02-10 22:17 . 2008-02-10 22:25 d——– C:\Temp\HP_WebRelease
2008-02-10 22:17 . 2008-02-10 22:17 d——– C:\Temp
2008-02-10 12:15 . 2008-02-10 12:15 15,360 –ahs—- C:\WINDOWS\Thumbs.db
2008-02-10 12:15 . 2008-02-10 12:15 5,120 –ahs—- C:\WINDOWS\system32\Thumbs.db
2008-02-09 14:11 . 2008-02-09 14:11 d——– C:\WINDOWS\Extras
2008-02-08 19:27 . 2004-03-29 16:23 90,112 –a—— C:\WINDOWS\unvise32.exe
2008-02-05 18:39 . 2008-02-05 18:40 d——– C:\Program Files\BitTorrent
2008-02-05 18:29 . 2008-02-24 12:03 d——– C:\Program Files\Google
2008-02-05 15:40 . 2008-02-05 16:41 d——– C:\test
2008-02-05 12:02 . 2008-02-05 12:02 d——– C:\Documents and Settings\.housecall6.6\report
2008-02-05 12:02 . 2008-02-05 12:02 d——– C:\Documents and Settings\.housecall6.6\debug
2008-02-05 12:02 . 2008-02-05 12:02 11 –a—— C:\AuResult.ini
2008-02-05 11:14 . 2008-02-05 11:14 d——– C:\Documents and Settings\Leilani\Application Data\Autodesk
2008-02-05 11:14 . 2008-02-05 11:14 d——– C:\Documents and Settings\Leilani\Application Data\Apple Computer
2008-02-05 11:14 . 2008-02-05 11:14 d——– C:\Documents and Settings\Leilani\Application Data\Ahead
2008-02-05 11:14 . 2008-02-05 11:14 d——– C:\Documents and Settings\Leilani\Application Data\AdobeUM
2008-02-05 11:14 . 2008-02-05 11:14 d——– C:\Documents and Settings\Leilani\Application Data\AdobeAUM
2008-02-05 11:14 . 2008-02-05 11:14 d——– C:\Documents and Settings\Leilani\Application Data\.bittorrent
2008-02-05 11:11 . 2008-02-05 11:11 d——– C:\Documents and Settings\Leilani\Application Data\Microsoft Games
2008-02-05 11:11 . 2008-02-05 11:11 d——– C:\Documents and Settings\Leilani\Application Data\Leadertech
2008-02-05 11:11 . 2008-02-05 11:11 d——– C:\Documents and Settings\Leilani\Application Data\Image Zone Express
2008-02-05 11:11 . 2008-02-05 11:11 d——– C:\Documents and Settings\Leilani\Application Data\HP
2008-02-05 11:11 . 2008-02-05 11:11 d——– C:\Documents and Settings\Leilani\Application Data\ESRI
2008-02-05 11:11 . 2008-02-05 11:11 d——– C:\Documents and Settings\Leilani\Application Data\BitTorrent
2008-02-05 11:10 . 2008-02-05 11:10 d——– C:\Documents and Settings\Leilani\Application Data\uTorrent
2008-02-05 11:10 . 2008-02-05 11:10 d——– C:\Documents and Settings\Leilani\Application Data\Red Chair Software
2008-02-05 10:57 . 2008-02-05 10:58 d——– C:\WINDOWS\nview
2008-02-05 10:57 . 2005-07-20 20:07 176,128 –a—— C:\WINDOWS\system32\nvudisp.exe
2008-02-05 10:57 . 2008-03-04 16:52 29,204 –a—— C:\WINDOWS\system32\nvapps.xml
2008-02-05 10:57 . 2005-07-20 20:07 14,757 –a—— C:\WINDOWS\system32\nvdisp.nvu

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-02 18:15 ——— d—–w C:\Program Files\Trend Micro
2008-03-02 17:21 96,160 —-a-w C:\Documents and Settings\Leilani\Application Data\GDIPFONTCACHEV1.DAT
2008-02-24 21:17 ——— d—–w C:\Program Files\Java
2008-02-24 20:36 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-24 20:29 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-02-10 19:57 ——— d—–w C:\Program Files\GameSpy Arcade
2008-02-10 05:19 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-05 19:19 ——— d—–w C:\Documents and Settings\Leilani\Application Data\Skype
2008-02-05 19:14 ——— d—–w C:\Documents and Settings\Leilani\Application Data\.bittorrent
2008-02-05 19:10 ——— d—–w C:\Documents and Settings\Leilani\Application Data\Symantec
2008-02-05 01:52 ——— d—–w C:\Program Files\Accurate Outlook Express Mail Expert
2008-02-05 00:18 ——— d—–w C:\Documents and Settings\Leilani\Application Data\vlc
2008-02-05 00:12 ——— d—–w C:\Program Files\Windows Media Connect 2
2008-02-04 22:50 ——— d—–w C:\Program Files\AvRack
2008-02-04 22:49 ——— d—–w C:\Program Files\VIA Technologies, Inc
2008-02-04 05:24 ——— d—–w C:\Program Files\MSXML 6.0
2008-02-04 00:49 ——— d—–w C:\Program Files\Common Files\L&H;
2008-02-03 23:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-03 23:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-02-03 09:03 ——— d—–w C:\Documents and Settings\Leilani\Application Data\Microsoft Web Folders
2008-02-03 05:42 ——— d—–w C:\Documents and Settings\Riley\Application Data\HP
2008-02-03 05:42 ——— d—–w C:\Documents and Settings\Riley\Application Data\Apple Computer
2008-02-03 05:42 ——— d—–w C:\Documents and Settings\Riley\Application Data\.bittorrent
2008-02-03 05:41 ——— d—–w C:\Documents and Settings\Riley\Application Data\Skype
2008-02-03 05:41 ——— d—–w C:\Documents and Settings\Riley\Application Data\Microsoft Games
2008-02-03 05:10 ——— d—–w C:\Program Files\Nero
2008-02-03 05:10 ——— d—–w C:\Program Files\MSXML 4.0
2008-02-03 05:09 ——— d—–w C:\Program Files\MSN Messenger
2008-02-03 05:05 ——— d—a-w C:\Program Files\Maxis
2008-02-03 05:05 ——— d—–w C:\Program Files\Microsoft ActiveSync
2008-02-03 05:04 ——— d—–w C:\Program Files\Macromedia
2008-02-03 05:04 ——— d—–w C:\Program Files\Luxor
2008-02-03 05:03 ——— d—–w C:\Program Files\Logitech
2008-02-03 04:59 ——— d—–w C:\Program Files\Kodak
2008-02-03 04:57 ——— d—–w C:\Program Files\iTunes
2008-02-03 04:57 ——— d—–w C:\Program Files\iPod
2008-02-03 04:57 ——— d—–w C:\Program Files\iPhoto Plus 4
2008-02-03 04:52 ——— d—–w C:\Program Files\HP
2008-02-03 04:52 ——— d—–w C:\Program Files\Hewlett-Packard
2008-02-03 04:52 ——— d—–w C:\Program Files\FutureTax 2006
2008-02-03 04:52 ——— d—–w C:\Program Files\FlexVoice
2008-02-03 04:51 ——— d—–w C:\Program Files\FileMaker
2008-02-03 04:51 ——— d—–w C:\Program Files\ESRI
2008-02-03 04:40 ——— d—–w C:\Program Files\EA GAMES
2008-02-03 04:40 ——— d—–w C:\Program Files\DivX
2008-02-03 04:40 ——— d—–w C:\Program Files\DIFX
2008-02-03 04:40 ——— d—–w C:\Program Files\Creative
2008-02-03 04:39 ——— d—a-w C:\Program Files\Common Files\Ahead
2008-02-03 04:39 ——— d—–w C:\Program Files\Common Files\Autodesk Shared
2008-02-03 04:39 ——— d—–w C:\Program Files\Common Files\Adobe
2008-02-03 04:38 ——— d—–w C:\Program Files\Common Files\HP
2008-02-03 04:38 ——— d—–w C:\Program Files\Common Files\Hewlett-Packard
2008-02-03 04:38 ——— d—–w C:\Program Files\Common Files\ESRI
2008-02-03 04:38 ——— d—–w C:\Program Files\Common Files\DirectX
2008-02-03 04:38 ——— d—–w C:\Program Files\Common Files\DEVConcept Shared
2008-02-03 04:38 ——— d—–w C:\Program Files\Common Files\Bentley Shared
2008-02-03 04:37 ——— d—–w C:\Program Files\Common Files\Kodak
2008-02-03 04:37 ——— d—–w C:\Program Files\Common Files\Java
2008-02-03 04:37 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-02-03 04:36 ——— d—–w C:\Program Files\Common Files\LogiShrd
2008-02-03 04:36 ——— d—–w C:\Program Files\Common Files\L&H; Shared
2008-02-03 04:35 ——— d—–w C:\Program Files\Common Files\Macrovision Shared
2008-02-03 04:35 ——— d—–w C:\Program Files\Common Files\Logitech
2008-02-03 04:33 ——— d—a-w C:\Program Files\Common Files\Symantec Shared
2008-02-03 04:33 ——— d—a-w C:\Program Files\Common Files\Panda Software
2008-02-03 04:33 ——— d—–w C:\Program Files\Common Files\Sonic Shared
2008-02-03 04:33 ——— d—–w C:\Program Files\Common Files\Skype
2008-02-03 04:33 ——— d—–w C:\Program Files\Common Files\Real
2008-02-03 04:33 ——— d—–w C:\Program Files\Common Files\Pure Networks Shared
2008-02-03 04:33 ——— d—–w C:\Program Files\Common Files\Mindmaker
2008-02-03 04:32 ——— d—–w C:\Program Files\Common Files\xing shared
2008-02-03 04:31 ——— d—–w C:\Program Files\Chuzzle Deluxe
2008-02-03 04:31 ——— d—–w C:\Program Files\CCleaner
2008-02-03 04:31 ——— d—–w C:\Program Files\Canon
2008-02-03 04:31 ——— d—–w C:\Program Files\Byteswarm
2008-02-03 04:31 ——— d—–w C:\Program Files\Bentley
2008-02-03 04:28 ——— d—–w C:\Program Files\Autodesk
2008-02-03 04:28 ——— d—–w C:\Program Files\AutoCAD 2004
2008-02-03 04:25 ——— d—–w C:\Program Files\ArcGIS
2008-02-03 04:15 ——— d—–w C:\Program Files\Apple Software Update
2008-02-03 04:15 ——— d—–w C:\Program Files\AnswerWorks 4.0
2008-02-03 04:14 ——— d—–w C:\Program Files\Alwil Software
2008-02-03 04:14 ——— d—–w C:\Program Files\Ahead
2008-02-03 04:13 ——— d—a-w C:\Program Files\Accessories
2008-02-03 04:13 ——— d—–w C:\Program Files\Yahoo!
2008-02-03 04:12 ——— d—–w C:\Program Files\WildTangent Games
2008-02-03 04:12 ——— d—–w C:\Program Files\WiFiConnector
2008-02-03 04:12 ——— d—–w C:\Program Files\War Chess
2008-02-03 04:12 ——— d—–w C:\Program Files\VideoLAN
2008-02-03 04:12 ——— d—–w C:\Program Files\VIAudioi
2008-02-03 04:11 ——— d—–w C:\Program Files\Universal Document Converter
2008-02-03 04:11 ——— d—–w C:\Program Files\Unitype
2008-02-03 04:11 ——— d—–w C:\Program Files\UltraVNC
2008-02-03 04:11 ——— d—–w C:\Program Files\Trymedia
2008-02-03 04:10 ——— d—–w C:\Program Files\TLI
2008-02-03 04:10 ——— d—–w C:\Program Files\TextBridge Classic
2008-02-03 04:09 ——— d—a-w C:\Program Files\Symantec
2008-02-03 04:09 ——— d—–w C:\Program Files\Skype
2008-02-03 04:08 ——— d—a-w C:\Program Files\Silicon Prairie Software
2008-02-03 04:08 ——— d—–w C:\Program Files\ReflexiveArcade
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\WINDOWS\A149DEA21D5B11D59F7600C04F6BC7A1.TMP —-


—- Directory of C:\WINDOWS\CD95F661A5C444F5A6AAECDD91C240B5.TMP —-

2008-02-10 23:01 6805 –a—— C:\WINDOWS\CD95F661A5C444F5A6AAECDD91C240B5.TMP\WiseData.ini


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 08:24 1694208]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-09-16 04:39 69632 C:\WINDOWS\soundman.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-07-20 20:07 7110656]
"nwiz"="nwiz.exe" [2005-07-20 20:07 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-07-20 20:07 86016]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 05:00 79224]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-05 18:31 185632]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]

C:\Documents and Settings\Leilani\Start Menu\Programs\Startup\
BitTorrent.lnk - C:\Program Files\BitTorrent\bittorrent.exe [2006-02-02 23:42:04 153088]
MemTurbo.lnk - C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe [2005-10-02 11:05:15 221696]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04 83360]
VIA RAID TOOL.lnk - C:\Program Files\VIA\RAID\raid_tool.exe [2005-10-02 10:41:54 565248]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\WINDOWS\\system32\\rundll32.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

S3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2004-12-16 13:36]

.
Contents of the 'Scheduled Tasks' folder
"2008-03-01 17:59:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-04 16:58:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-03-04 16:59:30
ComboFix-quarantined-files.txt 2008-03-05 00:59:15
ComboFix2.txt 2008-03-04 02:16:00
.
2008-03-02 21:55:27 — E O F —




hijackthis_mar4



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:03:00 PM, on 3/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\Exe Program Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: BitTorrent.lnk = C:\Program Files\BitTorrent\bittorrent.exe
O4 - Startup: MemTurbo.lnk = C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin…ows-i586-jc.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 5200 bytes




It looks as though you have worked a miracle!!!!

***Divna :)
Hi

We need to upload a file to Jotti

1. Click HERE to get to Jotti's site.

2. At the top of the Jotti window, use the Browse button to locate the following file on your system:

C:\WINDOWS\CD95F661A5C444F5A6AAECDD91C240B5.TMP\WiseData.ini

3. Once you have located the file, click SUBMIT and the content of the file will be uploaded by the site and analysed.

4. Please provide me with the results of the analysis.


Your Java Runtime Environment is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 5.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 5, The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation, Multi-language and save it to your desktop.
  • Close any programs you may have running - especially any web browsers.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u5-windowsi586.exe to install the newest version.

You don't appear to be running any third party Firewall software.

Install a firewall! Without a firewall you are very susceptible to being hacked, and people could gain access to your computer. If you don't have a firewall I strongly recommend you download ONE of the following:
1) Comodo
2) Agnitum
3) Sunbelt/Kerio


Please reboot and post a new HijackThis log, along with the results of the Jotti scan.

Thanks.
Good Evening "JP",

I have run the Jotti, Java, installed Comodo and run Hijack this.
My cmpt. is running well, with no more pop-ups. Thank-you!!
I am wondering why the Windows Firewall was not detected, as my security centre said that it has been running all along? However, I have since installed Comodo, as I said, and it is asking me for permission for every-single thing (ugh!).
I see that it says that it is "learning", though, so I think that after about a week of my regular cmpt usage, that these Comodo pop-ups will stop.
Am I correct?

Here are the results from the last 'fix' that you had me run (thanks again!!)

jottiResults

Jotti's malware scan 2.99-TRANSITION_TO_3.00-R1

File to upload & scan:
Service
Service load: 0% 100%

File: WiseData.ini
Status: OK
MD5: 5b56919940f9f94f8a3ce8189001535f
Packers detected: -
Bit9 reports: File not found

Scanner results
Scan taken on 09 Mar 2008 02:54:05 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Rising Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing

Powered by

Disclaimer
This service is by no means 100% safe. If this scanner says 'OK', it does not necessarily mean the file is clean. There could be a whole new virus on the loose. NEVER EVER rely on one single product only, not even this service, even though it utilizes several products. Therefore, We cannot and will not be held responsible for any damage caused by results presented by this non-profit online service.

Also, we are aware of the implications of a setup like this. We are sure this whole thing is by no means scientifically correct, since this is a fully automated service (although manual correction is possible). We are aware, in spite of efforts to proactively counter these, false positives might occur, for example. We do not consider this a very big issue, so please do not e-mail us about it. This is a simple online scan service, not the university of Wichita.

Scanning can take a while, since several scanners are being used, plus the fact some scanners use very high levels of (time consuming) heuristics. Scanners used are Linux versions, differences with Windows scanners may or may not occur. Another note: some scanners will only report one virus when scanning archives with multiple pieces of malware.

Virus definitions are updated every hour. There is a 10Mb limit per file. Please refrain from uploading tons of hex-edited or repacked variants of the same sample.

Please do not ask for viruses uploaded here, unless you work for an anti-virus vendor. They are not for trade. This is a legitimate service, not a VX site. Viruses uploaded here will be distributed to antivirus vendors without exception. Read more about this in our privacy policy. If you do not want your files to be distributed, please do not send them at all.

Sponsored by HotelScraper.com.
——————————————————————————–


Statistics
Last file scanned at least one scanner reported something about: misswe.exe (MD5: 9146a5eaf74af0202bd12796dabf3ed6, size: 191232 bytes), detected by:

Scanner Malware name
A-Squared X
AntiVir HEUR/Crypted
ArcaVir X
Avast Win32:Havar-O
AVG Antivirus X
BitDefender DeepScan:Generic.Malware.PV!bPkWk!.48E94616
ClamAV X
CPsecure X
Dr.Web X
F-Prot Antivirus X
F-Secure Anti-Virus X
Fortinet X
Ikarus X
Kaspersky Anti-Virus X
NOD32 probably a variant of Win32/Genetik
Norman Virus Control X
Panda Antivirus X
Rising Antivirus Hack.Anti.Win32.Agent.e
Sophos Antivirus Sus/UnkPacker
VirusBuster X
VBA32 X


You're free to (mis)interpret these automated, flawed statistics at your own discretion. For antivirus comparisons, visit AV comparatives
We are not affiliated with any third parties that conduct tests using this service.





Frequently asked questions - Feedback - Privacy policy



Page generated by JTPL

© 2004-2008 Jordi Bosveld <[removed]>



hijackthis_afterJotti

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:26:59 PM, on 3/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Exe Program Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: BitTorrent.lnk = C:\Program Files\BitTorrent\bittorrent.exe
O4 - Startup: MemTurbo.lnk = C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 5391 bytes



I'll check in again tomorrow (Sunday).
Enjoy your evening :)

Divna
Hi Divna

Sorry about the delays, I have been away for a few days.

Comodo, as I said, and it is asking me for permission for every-single thing (ugh!).
I see that it says that it is "learning", though, so I think that after about a week of my regular cmpt usage, that these Comodo pop-ups will stop.
Am I correct?

Yes, thats perfectly normal with Comodo. It will indeed calm down after you have been using it for a while :thumbup:

Log looks good :thumbup:


Click Start >> Run, and then type ComboFix /u and hit enter.
You can now delete any other tools I had you download and use.


Now that you appear to be clean, theres just a few steps I'd like you to take to prevent any future infections.
  • Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis.

  • Make sure you update your Anti-Virus software regularly, new viruses are being developed all the time.

  • Some more programs that it would be useful to have [OPTIONAL but RECOMMENDED]:

    SpywareBlaster is another real-time scanner that prevents most spyware from even being installed.
    Freely available: Download SpywareBlaster

    Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.
Also, please read this great article by Tony Klein: So How Did I Get Infected In First Place

Glad we could be of assistance.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Stay Clean!

jpshortstuff
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI