This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] help with trojan

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I have had someone come and "fix" my computer…paid 95.00 bucks and still the same problem…have tried just about everything to remove bitsprx.dll but comes back! I am a novice so afraid to follow other directions withou one on one thanks
Hello hollyplus2 and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem.


Download HijackThis from Here .
  • Choose the default location of C:\Program Files\Trend Micro\HijackThis as the destination. HJT needs to be in its own folder so that the program itself isn't deleted by accident. Having the backups could be VITAL to restoring your system if something went wrong in the FIX process!
  • Click the Install button.
  • Accept the license agreement .
  • Click Do a system scan and save a log file. A Notepad file will open.
  • Select all the text by hitting the [Ctrl+A] keys, then copy your selection to the clipboard by pressing the [Ctrl+C] keys.
  • Paste the log into this thread by hitting the [Ctrl+V] keys.
  • when you click Save Log) (Ctrl-A to'select all', Ctrl-C to 'copy')
  • POST the log into this thread using 'Add Reply' (Ctrl-V to 'paste')


DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL WE CHECK THE LOG, AS MOST OF THE FILES ARE LEGIT AND VITAL TO THE FUNCTION OF YOUR COMPUTER
Wow thanks so much for the help! This is what came up.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:47:40 PM, on 3/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\AT&T\Internet Security Wizard\ISW.exe
C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us6.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us6.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie6.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.att.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Yahoo!
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {E0CB3110-537E-4374-A78A-E668818C34A8} - C:\WINDOWS\System32\bitsprx.dll
O4 - HKLM\..\Run: [hpsysdrv] :c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [NvCplDaemon] :RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] :nwiz.exe /install
O4 - HKLM\..\Run: [CamMonitor] :c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [KBD] :C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] :"C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] :C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IgfxTray] :C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] :C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] :C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] :"C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [DVDBitSet] :"C:\Program Files\HP CD-DVD\Umbrella\DVDBitSet.exe" /NOUI
O4 - HKLM\..\Run: [DVDTray] :"C:\Program Files\HP CD-DVD\Umbrella\DVDTray.exe
O4 - HKLM\..\Run: [TkBellExe] :"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] :C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] :"C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IntelliPoint] :"C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [ISW.exe] "C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" /AUTORUN
O4 - HKLM\..\Run: [HelpCenter4.1] C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe /P HelpCenter4.1
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] :C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [ISUSPM] :"C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [MSI Configuration] msiconf.exe
O4 - S-1-5-18 Startup: PowerReg Scheduler V3.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: PowerReg Scheduler V3.exe (User 'Default user')
O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
O4 - .DEFAULT User Startup: PowerReg Scheduler V3.exe (User 'Default user')
O4 - Startup: ~Disabled
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\pmremind.exe
O4 - Global Startup: Forget Me Not.lnk = C:\Program Files\Broderbund\AG CreataCard\AGremind.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.yahoo.com
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.fastaccess.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebpr…etup1.0.0.6.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} (SupportSoft External Control) - http://connect.comcast.com/dl/Comcast%20Ac…%20Controls.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-17.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/2595aeb3bc5b94…ip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1167873514950
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.143/code/PWActiveXImgCtl.CAB
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1167873497903
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://stuartphoto.lifepics.com/net/Upload…geUploader3.cab
O16 - DPF: {AE6C4705-0F11-4ACB-BDD4-37F138BEF289} (Image Uploader Control) - http://stuartphoto.lifepics.com/net/Upload…PUploader41.cab
O16 - DPF: {D44C75D8-C827-473E-8F68-A77E42500782} (Uploader Class) - http://photo.walmart.com/photo/uploads/WebUploadClient.cab
O16 - DPF: {DADE1C2F-5A48-445C-82B5-3A5F102E84DF} (LifePicsUploader.UserControl1) - http://stuartphoto.lifepics.com/common/Use…icsUploader.CAB
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup141.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://photo.walmart.com/photo/upload/XUpload.ocx
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O24 - Desktop Component 0: (no name) - http://www.buccaneers.com/media/graphics/f…768_alstott.jpg

–
End of file - 11692 bytes
A. First we must disable some of your security programs so that they do not interfere with the running of our tools:

NORTON ANTIVIRUS
Please navigate to the system tray on the bottom right hand corner and look for a [external image: Posted Image] sign.
  • right-click it -> chose "Disable Auto-Protect."
  • select a duration of 5 hours (this assures no interference with the cleanup of your pc)
  • click "Ok."
  • a popup will warn that protection will now be disabled and the sign will now look like this: [external image: Posted Image]
You succesfully disabled the Norton Antivirus Guard.


SPYWARE DOCTOR
  • Click the Spyware Doctor icon in the System Tray.
  • Click Settings.
  • Click Startup Settings under Pick a Category.
  • Uncheck "Run at Windows startup".
  • Click Apply and Exit Spyware Doctor.
  • From within Spyware Doctor, click the "OnGuard" button on the left side.
  • Uncheck "Activate OnGuard".
  • (When we are done, you can reenable Spyware Doctor)


B. Please RUN HijackThis
  • Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
    O2 - BHO: (no name) - {E0CB3110-537E-4374-A78A-E668818C34A8} - C:\WINDOWS\System32\bitsprx.dll
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebpr…etup1.0.0.6.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/2595aeb3bc5b94…ip/RdxIE601.cab


  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.



C. Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • ComboFix will automatically start. Any monitoring programs will be shut down like your antivirus, antispyware programs for example.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
I had a couple of problems… I could not find the place to turn off the symantic for a certian duration
I could not find these
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com

I also kept getting a pop up of auto protect results..so not sure If I had symantic fully off? I did my best…here are the rusults


ComboFix 08-03-05.3 - Owner 2008-03-06 16:44:49.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.180 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Local Settings\Temporary Internet Files\Content.IE5\0ZJVDRF0\ComboFix[1].exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\Installr\1.bin\F3EZSETP.DLL
C:\Program Files\FunWebProducts\Installr\Cache\006FDD73
C:\Program Files\FunWebProducts\Installr\Cache\006FDF38
C:\Program Files\FunWebProducts\Installr\Cache\006FE0A0
C:\Program Files\FunWebProducts\Installr\Cache\006FE207
C:\Program Files\FunWebProducts\Installr\Cache\006FE39D
C:\Program Files\FunWebProducts\Installr\Cache\files.ini
C:\Program Files\FunWebProducts\PopSwatr\History\allowed
C:\Program Files\FunWebProducts\PopSwatr\History\notallow
C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MailStampBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MySignatureInsertBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MySignaturePreviewBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyStationeryBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
C:\Program Files\MyWay
C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
C:\Program Files\MyWay\myBar\History\search
C:\Program Files\MyWay\myBar\Settings\prevcfg.htm
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
C:\Program Files\MyWebSearch\bar\History\search
C:\Program Files\MyWebSearch\bar\Settings\prevcfg.htm
C:\Program Files\MyWebSearch\bar\Settings\settings.dat
C:\Program Files\MyWebSearch\bar\Settings\settings.dat.bak
C:\Program Files\MyWebSearch\bar\Settings\settings.htm
C:\Program Files\MyWebSearch\bar\Settings\settings.htm.bak
C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
C:\Program Files\MyWebSearch\SrchAstt\1.bin\UNINSTAL.INF
C:\Program Files\MyWebSearch\SrchAstt\Cache\00028245
C:\Program Files\MyWebSearch\SrchAstt\Cache\0002BC51
C:\Program Files\MyWebSearch\SrchAstt\Cache\0002CD39
C:\Program Files\MyWebSearch\SrchAstt\Cache\files.ini
C:\WINDOWS\system32\bitsprx.dll
C:\WINDOWS\system32\drivers\sxpouezw.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_MXOJIKVP
——-\mxojikvp


((((((((((((((((((((((((( Files Created from 2008-02-06 to 2008-03-06 )))))))))))))))))))))))))))))))
.

2008-03-06 14:16 . 2007-12-06 21:21 6,066,176 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2008-03-06 14:16 . 2007-06-30 22:31 2,455,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-03-06 14:16 . 2007-06-30 22:36 991,232 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-03-06 14:16 . 2007-12-06 21:21 459,264 —–c— C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-03-06 14:16 . 2007-12-06 21:21 383,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-03-06 14:16 . 2007-12-06 21:21 267,776 —–c— C:\WINDOWS\system32\dllcache\iertutil.dll
2008-03-06 14:16 . 2007-12-06 21:21 63,488 —–c— C:\WINDOWS\system32\dllcache\icardie.dll
2008-03-06 14:16 . 2007-12-06 21:21 52,224 —–c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-03-06 14:16 . 2007-12-06 06:00 13,824 —–c— C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-03-06 14:00 . 2007-08-13 18:54 33,792 –a–c— C:\WINDOWS\system32\dllcache\custsat.dll
2008-03-06 12:46 . 2008-03-06 12:46 d——– C:\Program Files\Trend Micro
2008-03-05 15:52 . 2008-03-05 15:52 d——– C:\6f38f6c62d28b5008bf07c4bd417b24b
2008-03-05 13:38 . 2008-03-05 13:38 d——– C:\Documents and Settings\LocalService\Application Data\AdobeUM
2008-03-05 12:59 . 2008-03-06 01:56 d——– C:\Program Files\Spyware Doctor
2008-03-05 12:59 . 2008-03-05 12:59 d——– C:\Documents and Settings\Owner\Application Data\PC Tools
2008-03-05 12:59 . 2007-12-10 14:53 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-03-05 12:59 . 2007-12-10 14:53 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-03-05 12:59 . 2008-02-01 12:55 42,376 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-03-05 12:59 . 2007-12-10 14:53 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-03-05 12:56 . 2003-02-28 18:26 139,536 –a—— C:\WINDOWS\system32\javaee.dll
2008-03-04 23:01 . 2006-08-21 04:14 128,896 —–c— C:\WINDOWS\system32\dllcache\fltmgr.sys
2008-03-04 23:01 . 2006-08-21 04:14 23,040 —–c— C:\WINDOWS\system32\dllcache\fltmc.exe
2008-03-04 23:01 . 2006-08-21 07:21 16,896 —–c— C:\WINDOWS\system32\dllcache\fltlib.dll
2008-03-04 14:40 . 2007-06-04 17:36 1,230,336 –a—— C:\WINDOWS\system32\msxml4.dll
2008-03-04 14:35 . 2008-03-04 14:35 d——– C:\Program Files\ATT
2008-03-04 14:26 . 2008-03-04 14:26 d——– C:\WINDOWS\Motive
2008-03-04 14:26 . 2008-03-04 14:26 d——– C:\Program Files\BellSouth Application Management
2008-03-04 14:26 . 2008-03-04 14:40 d——– C:\Program Files\BellSouth
2008-03-04 14:21 . 2008-03-04 14:21 d——– C:\Program Files\AT&T
2008-03-04 14:21 . 2008-03-04 14:21 d——– C:\Documents and Settings\Owner\Application Data\AT&T
2008-03-04 14:21 . 2008-03-04 14:21 d——– C:\Documents and Settings\All Users\Application Data\AT&T
2008-03-04 13:50 . 2008-03-04 13:50 d——– C:\Program Files\att-nap
2008-03-04 13:49 . 2008-03-04 14:26 d——– C:\Program Files\Common Files\Motive
2008-03-04 12:50 . 2007-07-09 08:09 584,192 —–c— C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-03-04 12:42 . 2006-06-22 05:47 181,248 —–c— C:\WINDOWS\system32\dllcache\rasmans.dll
2008-03-03 15:36 . 2004-08-04 00:56 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2008-03-03 15:25 . 2004-08-04 00:56 2,897,920 ——— C:\WINDOWS\system32\xpsp2res.dll
2008-03-03 15:24 . 2004-07-17 11:40 19,528 –a—— C:\WINDOWS\003559_.tmp
2008-03-03 13:21 . 2008-03-03 13:21 0 –a—— C:\WINDOWS\vpc32.INI
2008-03-03 13:12 . 2006-06-26 12:37 148,480 —–c— C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-03-03 13:12 . 2006-06-26 12:37 8,192 —–c— C:\WINDOWS\system32\dllcache\rasadhlp.dll
2008-03-03 13:08 . 2005-05-13 19:50 123,488 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-03-03 13:08 . 2005-05-13 19:50 91,856 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2008-03-03 13:07 . 2008-03-03 13:10 d——– C:\Program Files\Symantec
2008-03-03 13:06 . 2008-03-06 16:40 d——– C:\Program Files\Symantec AntiVirus
2008-03-03 13:05 . 2008-03-06 14:17 1,355 –a—— C:\WINDOWS\imsins.BAK
2008-03-03 13:04 . 2006-09-06 17:43 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2008-03-03 12:55 . 2006-06-22 00:06 1,435,648 —–c— C:\WINDOWS\system32\dllcache\query.dll
2008-03-03 12:55 . 2006-06-22 00:06 69,120 —–c— C:\WINDOWS\system32\dllcache\ciodm.dll
2008-03-03 12:28 . 2008-03-03 13:07 d–h—– C:\_GatorPC
2008-02-25 07:56 . 2007-04-18 10:47 802,816 –a—— C:\Program Files\WinsockFix.exe
2008-02-25 07:56 . 2002-06-23 11:19 270,336 –a—— C:\Program Files\BHODemon.exe
2008-02-18 14:19 . 2008-03-03 13:44 d——– C:\Program Files\PC Tools AntiVirus
2008-02-15 12:22 . 2008-03-06 16:54 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-14 19:49 . 2008-03-06 14:18 d–h—– C:\WINDOWS\$hf_mig$
2008-02-14 19:48 . 2007-04-18 11:12 2,854,400 –a—— C:\WINDOWS\system32\msi.dll
2008-02-14 13:54 . 2007-03-21 20:39 1,060,864 –a—— C:\WINDOWS\system32\MFC71.DLL
2008-02-14 13:54 . 2007-03-21 20:33 503,808 –a—— C:\WINDOWS\system32\MSVCP71.DLL
2008-02-14 13:54 . 2007-03-21 20:33 348,160 –a—— C:\WINDOWS\system32\MSVCR71.DLL
2008-02-13 20:42 . 2008-02-13 20:42 0 –a—— C:\WINDOWS\Unsetup.INI
2008-02-13 14:49 . 2008-02-27 13:33 d——– C:\Program Files\Norton 360
2008-02-12 13:59 . 2008-02-13 20:39 d——– C:\Documents and Settings\Owner\Application Data\AVG7
2008-02-12 13:58 . 2008-02-12 13:58 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-12 13:58 . 2008-02-13 20:39 d——– C:\Documents and Settings\All Users\Application Data\avg7
2008-02-07 14:02 . 2008-03-04 14:40 d——– C:\Program Files\Common Files\SupportSoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-04 19:26 53,934 —-a-w C:\Program Files\INSTALL.LOG
2008-03-04 19:15 ——— d—–w C:\Documents and Settings\Owner\Application Data\Motive
2008-03-04 18:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\Motive
2008-03-03 18:20 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-03-03 18:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-03 18:03 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-03-03 18:02 ——— d—–w C:\Program Files\PC-Doctor for Windows XP
2008-03-03 18:01 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-03-03 17:57 ——— d—–w C:\Program Files\The Cleaner
2008-03-03 17:41 59 —-a-w C:\Program Files\BHODemon.INI
2008-03-03 17:41 0 —-a-w C:\Program Files\BHODemon.LOG.XML
2008-02-18 23:48 ——— d—–w C:\Program Files\DIGStream
2008-02-18 19:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\DIGStream
2008-02-17 20:46 ——— d—–w C:\Program Files\Enigma Software Group
2008-02-14 18:35 ——— d—–w C:\Documents and Settings\Owner\Application Data\Symantec
2008-02-14 14:35 ——— d—–w C:\Program Files\ViRobotXP
2008-02-14 01:38 ——— d—–w C:\Program Files\Lavasoft
2008-02-14 01:38 ——— d—–w C:\Documents and Settings\Owner\Application Data\Lavasoft
2008-02-07 19:02 ——— d—–w C:\Program Files\Support.com
2008-02-07 19:02 ——— d—–w C:\Documents and Settings\Owner\Application Data\AdobeUM
2003-08-13 13:34 168,640 —-a-w C:\Program Files\FixBlast.exe
2003-08-13 13:32 2,408,512 —-a-w C:\Program Files\lusetup.exe
2003-08-13 12:12 5,814,560 —-a-w C:\Program Files\WindowsXP-KB823980-ia64-ENU.exe
2003-08-13 12:12 1,291,040 —-a-w C:\Program Files\WindowsXP-KB823980-x86-ENU.exe
2003-04-24 00:38 8,746,546 —-a-w C:\Program Files\QuickTimeInstallCache.qdat
2003-04-24 00:32 545,776 —-a-w C:\Program Files\QuickTimeInstaller.exe
2003-04-12 17:54 2,598,120 —-a-w C:\Program Files\Install_AIM.exe
2003-04-11 13:30 477,432 —-a-w C:\Program Files\PopUpStopperFree.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"=":C:\Program Files\Yahoo!\Messenger\ypager.exe" [ ]
"ISUSPM"=":C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [ ]
"MSI Configuration"="msiconf.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"=":c:\windows\system\hpsysdrv.exe" [ ]
"NvCplDaemon"=":NvQTwk" []
"nwiz"=":nwiz.exe" []
"CamMonitor"=":c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe" [ ]
"KBD"=":C:\HP\KBD\KBD.EXE" [ ]
"StorageGuard"=":C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" [ ]
"Recguard"=":C:\WINDOWS\SMINST\RECGUARD.EXE" [ ]
"IgfxTray"=":C:\WINDOWS\System32\igfxtray.exe" [ ]
"HotKeysCmds"=":C:\WINDOWS\System32\hkcmd.exe" [ ]
"PS2"=":C:\WINDOWS\system32\ps2.exe" [ ]
"SpeedTouch USB Diagnostics"=":C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" [ ]
"DVDBitSet"=":C:\Program Files\HP CD-DVD\Umbrella\DVDBitSet.exe" [ ]
"DVDTray"=":C:\Program Files\HP CD-DVD\Umbrella\DVDTray.exe" [ ]
"TkBellExe"=":C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ]
"SunJavaUpdateSched"=":C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe" [ ]
"QuickTime Task"=":C:\Program Files\QuickTime\qttask.exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-04-27 11:25 257088]
"IntelliPoint"=":C:\Program Files\Microsoft IntelliPoint\point32.exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-06-02 09:21 48752]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2005-06-23 19:27 85696]
"ISW.exe"="C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" [2007-05-03 13:12 2061816]
"HelpCenter4.1"="C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe" [2007-06-28 19:02 198184]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 12:55 1103240]
"RegistryMechanic"="" []
"SBI"="C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\PKO75T45\installer_sbd_en[1].exe" [ ]

C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2002-12-26 10:11:39 225280]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06 29696]
Event Reminder.lnk - C:\Program Files\Broderbund\PrintMaster\pmremind.exe [2002-12-05 18:19:17 331776]
Forget Me Not.lnk - C:\Program Files\Broderbund\AG CreataCard\AGremind.exe [2003-05-20 20:52:58 319488]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\att-nap\\McciBrowser.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R2 McciCMService;McciCMService;"C:\Program Files\Common Files\Motive\McciCMService.exe" [2008-01-28 15:56]
R3 EraserUtilDrv10741;EraserUtilDrv10741;C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10741.sys [2008-02-13 14:21]
S3 MREMP50;MREMP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [2007-01-19 12:53]
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MRESP50;MRESP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [2007-01-19 12:53]
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []

.
Contents of the 'Scheduled Tasks' folder
"2008-02-17 20:56:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-06 16:56:26
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-03-06 17:07:20 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2008-03-06 22:07:12
.
2008-03-06 19:19:40 — E O F —
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:25:37 PM, on 3/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\AT&T\Internet Security Wizard\ISW.exe
C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\explorer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us6.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.att.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [hpsysdrv] :c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [NvCplDaemon] :RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] :nwiz.exe /install
O4 - HKLM\..\Run: [CamMonitor] :c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [KBD] :C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] :"C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] :C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IgfxTray] :C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] :C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] :C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] :"C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [DVDBitSet] :"C:\Program Files\HP CD-DVD\Umbrella\DVDBitSet.exe" /NOUI
O4 - HKLM\..\Run: [DVDTray] :"C:\Program Files\HP CD-DVD\Umbrella\DVDTray.exe
O4 - HKLM\..\Run: [TkBellExe] :"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] :C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] :"C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IntelliPoint] :"C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [ISW.exe] "C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" /AUTORUN
O4 - HKLM\..\Run: [HelpCenter4.1] C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe /P HelpCenter4.1
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [SBI] C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\PKO75T45\installer_sbd_en[1].exe
O4 - HKCU\..\Run: [Yahoo! Pager] :C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [ISUSPM] :"C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [MSI Configuration] msiconf.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: PowerReg Scheduler V3.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: PowerReg Scheduler V3.exe (User 'Default user')
O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
O4 - .DEFAULT User Startup: PowerReg Scheduler V3.exe (User 'Default user')
O4 - Startup: ~Disabled
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\pmremind.exe
O4 - Global Startup: Forget Me Not.lnk = C:\Program Files\Broderbund\AG CreataCard\AGremind.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.yahoo.com
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.fastaccess.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} (SupportSoft External Control) - http://connect.comcast.com/dl/Comcast%20Ac…%20Controls.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-17.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1167873514950
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.143/code/PWActiveXImgCtl.CAB
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1167873497903
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://stuartphoto.lifepics.com/net/Upload…geUploader3.cab
O16 - DPF: {AE6C4705-0F11-4ACB-BDD4-37F138BEF289} (Image Uploader Control) - http://stuartphoto.lifepics.com/net/Upload…PUploader41.cab
O16 - DPF: {D44C75D8-C827-473E-8F68-A77E42500782} (Uploader Class) - http://photo.walmart.com/photo/uploads/WebUploadClient.cab
O16 - DPF: {DADE1C2F-5A48-445C-82B5-3A5F102E84DF} (LifePicsUploader.UserControl1) - http://stuartphoto.lifepics.com/common/Use…icsUploader.CAB
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup141.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://photo.walmart.com/photo/upload/XUpload.ocx
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O24 - Desktop Component 0: (no name) - http://www.buccaneers.com/media/graphics/f…768_alstott.jpg

–
End of file - 11011 bytes

Running from: C:\Documents and Settings\[removed]\Local Settings\Temporary Internet Files\Content.IE5\0ZJVDRF0\ComboFix[1].exe


The above indicates that you have 2 copies of ComboFix on your system which is a big nono. Second, you are running ComboFix from a place other than your Desktop which is totally contrary to the directions given. Please delete all copies of ComboFix that you have on your system as well as this folder C:\ComboFix. Re download ComboFix and run it according to the directions originally provided and post the log along with the following Kaspersky log.

OK. There appears to be something quite serious going on here or has already happened. Most of the files in your startup list are either damaged or missing. That is usually the sign of the work of a file infector trojan. We had better put your system through a complete check so we know exactly what we are dealing with before making any possible wrong moves. This following scan takes quite a long time (60 minutes) and does not remove anything but is a great diagnostic aid.


Using Internet Explorer, please do a Kaspersky Online Scan

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will provide a report if your system is infected. It does not provide an option to clean/disinfect. We only require a report from it.

    [external image: Posted Image]

  • Click the Save as Text button to save the file to your desktop and post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan
I just want to thank you so much for not giving up on me. I did not know I downloaded it two times..my power went out and interupted the download and novice me…just downloaded again. also deleting files…I was not sure how to do that …I went to search and plugged in combofix.. I hope that is what you meant. Still not sure if my virus protection is on or off? Well…here is the scan.. ASPERSKY ONLINE SCANNER REPORT Thursday, March 06, 2008 9:40:56 PM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 7/03/2008 Kaspersky Anti-Virus database records: 607190 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: false Scan Target - My Computer: A:\ C:\ D:\ E:\ F:\ Scan Statistics: Total number of scanned objects: 106645 Number of viruses found: 6 Number of infected objects: 10 Number of suspicious objects: 0 Duration of the scan process: 01:56:30 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Broderbund Software\Print\PrintMaster\PMWPRINT.INI Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Owner\Application Data\AT&T\Internet Security Wizard\client_gateway.log Object is locked skipped C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\SupportSoft\HelpCenter4.1\Owner\state\logs\sprtcmd.log Object is locked skipped C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Owner\ntuser.dat Object is locked skipped C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped C:\Program Files\AdwareFilter\quarantine\f8 Infected: Trojan.JS.Zapchast.a skipped C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped C:\Program Files\Symantec AntiVirus\SAVRT\0060NAV~.TMP Object is locked skipped C:\Program Files\Symantec AntiVirus\SAVRT\0099NAV~.TMP Object is locked skipped C:\QooBox\Quarantine\C\Program Files\FunWebProducts\Installr\1.bin\F3EZSETP.DLL.vir Infected: not-a-virus:Downloader.Win32.FunWeb skipped C:\QooBox\Quarantine\C\Program Files\MyWay\myBar\1.bin\MYBAR.DLL.vir Infected: not-a-virus:AdWare.Win32.MyWay.g skipped C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL.vir Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped C:\QooBox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL.vir Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped C:\QooBox\Quarantine\C\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL.vir Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\sxpouezw.dat.vir Object is locked skipped C:\QooBox\Quarantine\catchme2008-03-06_165431.92.zip/sxpouezw.dat Infected: Rootkit.Win32.Agent.aap skipped C:\QooBox\Quarantine\catchme2008-03-06_165431.92.zip/sxpouezw.dat.1 Infected: Rootkit.Win32.Agent.aap skipped C:\QooBox\Quarantine\catchme2008-03-06_165431.92.zip ZIP: infected - 2 skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{B762F5BE-1DFD-40DA-9793-F321C2185D05}\RP1\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\cmd.ftp Infected: Trojan-Downloader.BAT.Ftp.u skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Tasks\SCHEDLGU.TXT Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped D:\System Volume Information\_restore{B762F5BE-1DFD-40DA-9793-F321C2185D05}\RP1\change.log Object is locked skipped Scan process completed.

Re download ComboFix and run it according to the directions originally provided and post the log


The Kaspersky log does not look too bad.

Please follow the above instructions( full set of instructions can be found in my second post to you) and post a new ComboFix log followed by a new HijackThis log, in that order..


We will get through this slowly so do not worry. If there is anything that you do not understand in my instructions, please ask me for clarification before continuing.
Ok good…I got a little worried! Thanks for hanging in there with me…before I begin…do you want me to remove hijack this or is the version I downlaoded earlier ok?
Wow remember me??? So sorry I have not been back to you. My whole household came down with the flu including me! I guess I have all kind of viruses here!!! Ha Ha. Finally felling better. Anyway..I think you are my hero…The virus is gone. the combo fix got rid of it. I ran Registry mechanic and deleted the other viruses fine. IT is running well now…I did run a scan on hijack this and did not find any of the items there to delete. What do you think? I also like all the pc tools…not symantic I think I am going to take it off and use the pc tools. The guy who came to fix my computer put on the symantic…what do you think?
I need you to post the results of the ComboFix run. You can find the report here C:\ComboFix. I bet you that there are still "baddies" remaining.

Trevuren
ComboFix 08-03-10.1 - Owner 2008-03-13 14:11:42.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-02-13 to 2008-03-13 )))))))))))))))))))))))))))))))
.

2008-03-06 19:06 . 2008-03-06 19:06 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-03-06 19:06 . 2008-03-06 19:06 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-06 14:16 . 2007-12-06 21:21 6,066,176 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2008-03-06 14:16 . 2007-06-30 22:31 2,455,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-03-06 14:16 . 2007-06-30 22:36 991,232 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-03-06 14:16 . 2007-12-06 21:21 459,264 —–c— C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-03-06 14:16 . 2007-12-06 21:21 383,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-03-06 14:16 . 2007-12-06 21:21 267,776 —–c— C:\WINDOWS\system32\dllcache\iertutil.dll
2008-03-06 14:16 . 2007-12-06 21:21 63,488 —–c— C:\WINDOWS\system32\dllcache\icardie.dll
2008-03-06 14:16 . 2007-12-06 21:21 52,224 —–c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-03-06 14:16 . 2007-12-06 06:00 13,824 —–c— C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-03-06 14:00 . 2007-08-13 18:54 33,792 –a–c— C:\WINDOWS\system32\dllcache\custsat.dll
2008-03-06 12:46 . 2008-03-06 12:46 d——– C:\Program Files\Trend Micro
2008-03-05 15:52 . 2008-03-05 15:52 d——– C:\6f38f6c62d28b5008bf07c4bd417b24b
2008-03-05 13:38 . 2008-03-05 13:38 d——– C:\Documents and Settings\LocalService\Application Data\AdobeUM
2008-03-05 12:59 . 2008-03-12 10:22 d——– C:\Program Files\Spyware Doctor
2008-03-05 12:59 . 2008-03-05 12:59 d——– C:\Documents and Settings\Owner\Application Data\PC Tools
2008-03-05 12:59 . 2007-12-10 14:53 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-03-05 12:59 . 2007-12-10 14:53 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-03-05 12:59 . 2008-02-01 12:55 42,376 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-03-05 12:59 . 2007-12-10 14:53 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-03-05 12:56 . 2003-02-28 18:26 139,536 –a—— C:\WINDOWS\system32\javaee.dll
2008-03-04 23:01 . 2006-08-21 04:14 128,896 —–c— C:\WINDOWS\system32\dllcache\fltmgr.sys
2008-03-04 23:01 . 2006-08-21 04:14 23,040 —–c— C:\WINDOWS\system32\dllcache\fltmc.exe
2008-03-04 23:01 . 2006-08-21 07:21 16,896 —–c— C:\WINDOWS\system32\dllcache\fltlib.dll
2008-03-04 14:40 . 2007-06-04 17:36 1,230,336 –a—— C:\WINDOWS\system32\msxml4.dll
2008-03-04 14:35 . 2008-03-04 14:35 d——– C:\Program Files\ATT
2008-03-04 14:26 . 2008-03-04 14:26 d——– C:\WINDOWS\Motive
2008-03-04 14:26 . 2008-03-04 14:26 d——– C:\Program Files\BellSouth Application Management
2008-03-04 14:26 . 2008-03-04 14:40 d——– C:\Program Files\BellSouth
2008-03-04 14:21 . 2008-03-04 14:21 d——– C:\Program Files\AT&T
2008-03-04 14:21 . 2008-03-04 14:21 d——– C:\Documents and Settings\Owner\Application Data\AT&T
2008-03-04 14:21 . 2008-03-04 14:21 d——– C:\Documents and Settings\All Users\Application Data\AT&T
2008-03-04 13:50 . 2008-03-04 13:50 d——– C:\Program Files\att-nap
2008-03-04 13:49 . 2008-03-04 14:26 d——– C:\Program Files\Common Files\Motive
2008-03-04 12:50 . 2007-07-09 08:09 584,192 —–c— C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-03-04 12:42 . 2006-06-22 05:47 181,248 —–c— C:\WINDOWS\system32\dllcache\rasmans.dll
2008-03-03 15:36 . 2004-08-04 00:56 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2008-03-03 15:25 . 2004-08-04 00:56 2,897,920 ——— C:\WINDOWS\system32\xpsp2res.dll
2008-03-03 15:24 . 2004-07-17 11:40 19,528 –a—— C:\WINDOWS\003559_.tmp
2008-03-03 13:21 . 2008-03-03 13:21 0 –a—— C:\WINDOWS\vpc32.INI
2008-03-03 13:12 . 2006-06-26 12:37 148,480 —–c— C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-03-03 13:12 . 2006-06-26 12:37 8,192 —–c— C:\WINDOWS\system32\dllcache\rasadhlp.dll
2008-03-03 13:08 . 2005-05-13 19:50 123,488 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-03-03 13:08 . 2005-05-13 19:50 91,856 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2008-03-03 13:07 . 2008-03-03 13:10 d——– C:\Program Files\Symantec
2008-03-03 13:06 . 2008-03-13 14:04 d——– C:\Program Files\Symantec AntiVirus
2008-03-03 13:05 . 2008-03-06 14:19 1,355 –a—— C:\WINDOWS\imsins.BAK
2008-03-03 13:04 . 2006-09-06 17:43 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2008-03-03 12:55 . 2006-06-22 00:06 1,435,648 —–c— C:\WINDOWS\system32\dllcache\query.dll
2008-03-03 12:55 . 2006-06-22 00:06 69,120 —–c— C:\WINDOWS\system32\dllcache\ciodm.dll
2008-03-03 12:28 . 2008-03-03 13:07 d–h—– C:\_GatorPC
2008-02-25 07:56 . 2007-04-18 10:47 802,816 –a—— C:\Program Files\WinsockFix.exe
2008-02-25 07:56 . 2002-06-23 11:19 270,336 –a—— C:\Program Files\BHODemon.exe
2008-02-18 14:19 . 2008-03-03 13:44 d——– C:\Program Files\PC Tools AntiVirus
2008-02-15 12:22 . 2008-03-13 14:03 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-14 19:49 . 2008-03-08 14:26 d–h—– C:\WINDOWS\$hf_mig$
2008-02-14 19:48 . 2007-04-18 11:12 2,854,400 –a—— C:\WINDOWS\system32\msi.dll
2008-02-14 13:54 . 2007-03-21 20:39 1,060,864 –a—— C:\WINDOWS\system32\MFC71.DLL
2008-02-14 13:54 . 2007-03-21 20:33 503,808 –a—— C:\WINDOWS\system32\MSVCP71.DLL
2008-02-14 13:54 . 2007-03-21 20:33 348,160 –a—— C:\WINDOWS\system32\MSVCR71.DLL
2008-02-13 20:42 . 2008-02-13 20:42 0 –a—— C:\WINDOWS\Unsetup.INI
2008-02-13 14:49 . 2008-02-27 13:33 d——– C:\Program Files\Norton 360

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-04 19:40 ——— d—–w C:\Program Files\Common Files\SupportSoft
2008-03-04 19:26 53,934 —-a-w C:\Program Files\INSTALL.LOG
2008-03-04 19:15 ——— d—–w C:\Documents and Settings\Owner\Application Data\Motive
2008-03-04 18:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\Motive
2008-03-03 18:20 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-03-03 18:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-03 18:03 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-03-03 18:02 ——— d—–w C:\Program Files\PC-Doctor for Windows XP
2008-03-03 18:01 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-03-03 17:57 ——— d—–w C:\Program Files\The Cleaner
2008-03-03 17:41 59 —-a-w C:\Program Files\BHODemon.INI
2008-03-03 17:41 0 —-a-w C:\Program Files\BHODemon.LOG.XML
2008-02-18 23:48 ——— d—–w C:\Program Files\DIGStream
2008-02-18 19:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\DIGStream
2008-02-17 20:46 ——— d—–w C:\Program Files\Enigma Software Group
2008-02-14 18:35 ——— d—–w C:\Documents and Settings\Owner\Application Data\Symantec
2008-02-14 14:35 ——— d—–w C:\Program Files\ViRobotXP
2008-02-14 01:39 ——— d—–w C:\Documents and Settings\Owner\Application Data\AVG7
2008-02-14 01:39 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2008-02-14 01:38 ——— d—–w C:\Program Files\Lavasoft
2008-02-14 01:38 ——— d—–w C:\Documents and Settings\Owner\Application Data\Lavasoft
2008-02-12 18:58 ——— d—–w C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-07 19:02 ——— d—–w C:\Program Files\Support.com
2008-02-07 19:02 ——— d—–w C:\Documents and Settings\Owner\Application Data\AdobeUM
2003-08-13 13:34 168,640 —-a-w C:\Program Files\FixBlast.exe
2003-08-13 13:32 2,408,512 —-a-w C:\Program Files\lusetup.exe
2003-08-13 12:12 5,814,560 —-a-w C:\Program Files\WindowsXP-KB823980-ia64-ENU.exe
2003-08-13 12:12 1,291,040 —-a-w C:\Program Files\WindowsXP-KB823980-x86-ENU.exe
2003-04-24 00:38 8,746,546 —-a-w C:\Program Files\QuickTimeInstallCache.qdat
2003-04-24 00:32 545,776 —-a-w C:\Program Files\QuickTimeInstaller.exe
2003-04-12 17:54 2,598,120 —-a-w C:\Program Files\Install_AIM.exe
2003-04-11 13:30 477,432 —-a-w C:\Program Files\PopUpStopperFree.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"=":C:\Program Files\Yahoo!\Messenger\ypager.exe" [ ]
"ISUSPM"=":C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [ ]
"MSI Configuration"="msiconf.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"=":c:\windows\system\hpsysdrv.exe" [ ]
"NvCplDaemon"=":NvQTwk" []
"nwiz"=":nwiz.exe" []
"CamMonitor"=":c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe" [ ]
"KBD"=":C:\HP\KBD\KBD.EXE" [ ]
"StorageGuard"=":C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" [ ]
"Recguard"=":C:\WINDOWS\SMINST\RECGUARD.EXE" [ ]
"IgfxTray"=":C:\WINDOWS\System32\igfxtray.exe" [ ]
"HotKeysCmds"=":C:\WINDOWS\System32\hkcmd.exe" [ ]
"PS2"=":C:\WINDOWS\system32\ps2.exe" [ ]
"SpeedTouch USB Diagnostics"=":C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" [ ]
"DVDBitSet"=":C:\Program Files\HP CD-DVD\Umbrella\DVDBitSet.exe" [ ]
"DVDTray"=":C:\Program Files\HP CD-DVD\Umbrella\DVDTray.exe" [ ]
"TkBellExe"=":C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ]
"SunJavaUpdateSched"=":C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-04-27 11:25 257088]
"IntelliPoint"=":C:\Program Files\Microsoft IntelliPoint\point32.exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-06-02 09:21 48752]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2005-06-23 19:27 85696]
"ISW.exe"="C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" [2007-05-03 13:12 2061816]
"HelpCenter4.1"="C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe" [2007-06-28 19:02 198184]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 12:55 1103240]
"RegistryMechanic"="" []
"SBI"="C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\PKO75T45\installer_sbd_en[1].exe" [ ]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06 29696]
Event Reminder.lnk - C:\Program Files\Broderbund\PrintMaster\pmremind.exe [2002-12-05 18:19:17 331776]
Forget Me Not.lnk - C:\Program Files\Broderbund\AG CreataCard\AGremind.exe [2003-05-20 20:52:58 319488]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\att-nap\\McciBrowser.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R2 McciCMService;McciCMService;"C:\Program Files\Common Files\Motive\McciCMService.exe" [2008-01-28 15:56]
S3 MREMP50;MREMP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [2007-01-19 12:53]
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MRESP50;MRESP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [2007-01-19 12:53]
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []

.
Contents of the 'Scheduled Tasks' folder
"2008-02-17 20:56:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-13 14:22:47
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-03-13 14:36:11
ComboFix-quarantined-files.txt 2008-03-13 19:36:03
.
2008-03-12 21:48:34 — E O F —
Note: You may notice that some of your programs either no longer start up automatically as they used to or that they no longer work at all. This is due to the infection that was present. You may want to UNINSTALL the following programs then re install them:

Yahoo Pager
Microsoft IntelliPoint



A. First we must disable some of your security programs so that they do not interfere with the running of our tools:

NORTON ANTIVIRUS
Please navigate to the system tray on the bottom right hand corner and look for a [external image: Posted Image] sign.
  • right-click it -> chose "Disable Auto-Protect."
  • select a duration of 5 hours (this assures no interference with the cleanup of your pc)
  • click "Ok."
  • a popup will warn that protection will now be disabled and the sign will now look like this: [external image: Posted Image]
You succesfully disabled the Norton Antivirus Guard.


SPYWARE DOCTOR
  • Click the Spyware Doctor icon in the System Tray.
  • Click Settings.
  • Click Startup Settings under Pick a Category.
  • Uncheck "Run at Windows startup".
  • Click Apply and Exit Spyware Doctor.
  • From within Spyware Doctor, click the "OnGuard" button on the left side.
  • Uncheck "Activate OnGuard".
  • (When we are done, you can reenable Spyware Doctor)


B. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\WINDOWS\system32\cmd.ftp
C:\WINDOWS\003559_.tmp
C:\WINDOWS\vpc32.INI
C:\WINDOWS\imsins.BAK

Folder::
C:\6f38f6c62d28b5008bf07c4bd417b24b
C:\Program Files\AdwareFilter\quarantine\f8

Driver::
MREMP50a64

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"=-
"ISUSPM"=-
"MSI Configuration"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"=-
"NvCplDaemon"=-
"nwiz"="-
"CamMonitor"=-
"KBD"=-
"StorageGuard"=-
"Recguard"=-
"IgfxTray"=-
"HotKeysCmds"=-
"PS2"=-
"SpeedTouch USB Diagnostics"=-
"DVDBitSet"=-
"DVDTray"="-
"TkBellExe"="-
"SunJavaUpdateSched"=-
"IntelliPoint"="-
"AlcxMonitor"=-
"SBI"=-
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

5. All your monitoring programs (Antivirus/Antispyware, Guards and Shields) will be stopped.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
before I start..I have had trouble turnint off that symantec. The icon is different from yours and when I right click, it only gives me open symantec antivirus or Enable auto protect… no time choice…I think this is like a company version?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI