This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Popups windows and slow performance etc.

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

having problems with popup windows coming up when i start IE. also sometimes when i close IE the screen goes blank except for the background for a few seconds. I have also noticed when I boot up it takes longer then normal. I have done scans with AVG, Spyware doctor, and Ad-Aware, but they dont detect anything. here is my hijackthis log, any help would be great. Thanks.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:19:09 PM, on 3/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\DNA\btdna.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\nohiding.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.youtube.com/
O2 - BHO: (no name) - {504E8806-274E-4F68-BEC9-7D3F50D7F9F5} - C:\WINDOWS\system32\jkhfc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {85A9C42E-29DB-438A-8D09-A056493B9471} - C:\WINDOWS\system32\awtsqpp.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [BMafe87858] Rundll32.exe "C:\WINDOWS\system32\kbndgkuj.dll",s
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AOL Instant Messenger (SM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1190333714279
O20 - Winlogon Notify: awtsqpp - C:\WINDOWS\SYSTEM32\awtsqpp.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe

–
End of file - 5117 bytes

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the HJT forum and wait for help.


Unless informed of in advance, failure to post replies within 5 days will result in this thread being closed.


Hi sync

I'm Gary R, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Perform all actions in the order given.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with it till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
If you can do these things, everything should go smoothly.
  • Please note you'll need to have Administrator privileges to perform the fixes. (XP accounts are Administrator by default)

Before we go any further, I need you to install Recovery Console to your computer.

This is purely a precautionary procedure, but it is essential.

There are some new infections going round that damage your ability to boot if they are removed. Whilst I don't see signs of them on your computer, it's always easier to be cautious now than sorry later.

Recovery Console gives us the ability to recover your computer if such a thing happens.

Nothing is going to change on your computer other than we're going to install Recovery Console.

  • Download combofix.exe by sUBs to your Desktop (it must be in this location).
  • Alternate Download
  • If you already have a previous version, delete it and download a new version.
  • Do not attempt to run Combofix other than in the method described below.
  • Go to Microsoft's website
  • Select the download that's appropriate for your Operating System (if you have XP Media Centre, use download for XP Pro)

[external image: Posted Image]

  • Download the file & save it as it's originally named, to your Desktop.

[external image: Posted Image]

  • Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it.
  • Follow the prompts to start ComboFix.
  • When prompted, agree to the End-User License Agreement to install Microsoft Recovery Console.
  • When complete, a log named CF_RC.txt will open.
  • Please post the contents of that log.

Please do not shutdown or reboot your machine until we have reviewed the log.
ok, Ive done what you said so far and everything went smoothly here is the log. WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
Ok, Boot.ini file looks good (CF_RC.txt).

Reboot your computer to complete the install of Recovery Console.

When your computer boots up from now on, there will be a brief halt where you have an option to boot into normal mode or Recovery Console, after 2 seconds if you do nothing it will continue to boot into normal mode as usual. This shouldn't really inconvenience you, but we will have the option of booting to Recovery Console if you ever have problems with normal boot.

Next

Run a scan with Combofix

  • Double click combofix.exe & follow the prompts.
  • Note: Combofix will automatically disconnect your Internet connection when it runs, do not reconnect it.
  • When finished, it will
    • Produce a log for you. (it can also be found at C:\Combofix.txt)
    • Restore your Internet connection.
  • Post the log in your next reply please.
  • Now run a new HJT scan and send me the log from that as well please.
IMPORTANT
  • Do not use your computer while Combofix is running.
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • If you've lost your Internet connection when Combofix has completely finished, re-start your computer to restore it.

If you have any problems with these instructions, a detailed Tutorial for how to use Combofix is available here.
ok, I finished doing all that and overall everything seems to be working at its original state here are the logs the first is the combofix log then the HJT log

ComboFix 08-03-08.2 - new user 2008-03-08 23:36:18.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1607 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\BMafe87858.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\cfhkj.ini
C:\WINDOWS\system32\cfhkj.ini2
C:\WINDOWS\system32\dnjgikkb.dll
C:\WINDOWS\system32\jkhfc.dll
C:\WINDOWS\system32\nucjpakq.dll
C:\WINDOWS\system32\ttstv.ini2

.
((((((((((((((((((((((((( Files Created from 2008-02-09 to 2008-03-09 )))))))))))))))))))))))))))))))
.

2008-03-08 21:12 . 2008-03-08 21:12 d——– C:\Documents and Settings\LocalService\Application Data\Xfire
2008-03-06 23:03 . 2008-03-06 23:03 1,762 –a—— C:\WINDOWS\system32\tmp.reg
2008-03-06 23:02 . 2007-09-05 23:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-03-06 23:02 . 2008-03-01 23:12 86,016 –a—— C:\WINDOWS\system32\VACFix.exe
2008-03-06 23:02 . 2008-03-05 22:29 82,432 –a—— C:\WINDOWS\system32\IEDFix.exe
2008-03-06 23:02 . 2007-10-03 23:36 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2008-03-06 22:54 . 2006-04-27 16:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-03-06 22:54 . 2003-06-05 20:13 53,248 –a—— C:\WINDOWS\system32\Process.exe
2008-03-06 22:54 . 2004-07-31 17:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-03-06 22:42 . 2008-03-06 22:42 d——– C:\Program Files\GiPo@Utilities
2008-03-06 22:42 . 2008-03-06 22:42 d——– C:\Program Files\Common Files\Gibinsoft Shared
2008-03-06 22:16 . 2008-03-06 22:16 d——– C:\Program Files\Trend Micro
2008-03-06 19:45 . 2008-03-06 19:46 d——– C:\Program Files\The KMPlayer
2008-03-06 00:06 . 2008-03-06 00:24 d——– C:\Program Files\Spyware Doctor
2008-03-06 00:06 . 2008-03-06 00:06 d——– C:\Documents and Settings\new user\Application Data\PC Tools
2008-03-06 00:06 . 2007-10-04 17:10 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-03-06 00:06 . 2007-10-04 17:10 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-03-06 00:06 . 2007-10-04 17:10 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-03-06 00:06 . 2007-10-04 17:11 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-03-06 00:03 . 2005-09-23 07:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2008-03-05 23:59 . 2008-03-06 19:39 d——– C:\Program Files\Security Task Manager
2008-03-05 23:59 . 2008-03-06 23:32 d——– C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-03-04 23:47 . 2007-01-29 21:03 118,520 –a—— C:\WINDOWS\system32\pxinsi64.exe
2008-03-04 23:47 . 2007-01-29 21:03 116,472 –a—— C:\WINDOWS\system32\pxcpyi64.exe
2008-02-29 23:22 . 2008-02-29 23:22 d——– C:\Program Files\DNA
2008-02-29 23:22 . 2008-02-29 23:22 d——– C:\Program Files\BitTorrent
2008-02-29 23:22 . 2008-03-08 23:42 d——– C:\Documents and Settings\new user\Application Data\DNA
2008-02-29 23:22 . 2008-03-07 23:52 d——– C:\Documents and Settings\new user\Application Data\BitTorrent
2008-02-21 22:44 . 2008-02-21 22:44 d——– C:\Documents and Settings\All Users\Application Data\WinZip
2008-02-21 21:54 . 2008-02-21 21:54 d——– C:\Documents and Settings\new user\Application Data\AVSMedia
2008-02-21 21:54 . 2008-02-21 21:54 d——– C:\Documents and Settings\All Users\Application Data\AVS4YOU
2008-02-21 21:50 . 2008-03-08 19:48 d——– C:\Program Files\Common Files\AVSMedia
2008-02-21 21:46 . 2008-02-21 21:46 58,903,352 –a—— C:\Program Files\avsvideotools.exe
2008-02-21 21:46 . 2007-02-27 19:36 1,700,352 –a—— C:\WINDOWS\system32\GdiPlus.dll
2008-02-20 17:57 . 2008-02-20 17:57 54,608 –a—— C:\WINDOWS\system32\xfcodec.dll
2008-02-19 11:51 . 2008-02-19 11:51 d——– C:\Program Files\Game Cam V2
2008-02-11 21:51 . 2008-02-11 21:51 d——– C:\Program Files\1964
2008-02-11 20:50 . 2008-02-11 20:50 117,970 –a—— C:\Program Files\Cxbx-0[1].7.8c.zip
2008-02-11 20:12 . 2008-02-11 20:12 286,715 –a—— C:\Program Files\ePSXe.zip
2008-02-11 19:35 . 2008-02-23 14:59 d——– C:\Program Files\Project64 1.6
2008-02-11 18:56 . 2008-02-11 18:56 2,080,797 –a—— C:\Program Files\Project64.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-09 07:45 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-09 07:35 ——— d—–w C:\Documents and Settings\new user\Application Data\Xfire
2008-03-09 05:12 ——— d—–w C:\Program Files\Diablo
2008-03-09 04:13 ——— d—–w C:\Documents and Settings\new user\Application Data\AVG7
2008-03-07 04:39 ——— d—–w C:\Program Files\Xfire
2008-03-05 17:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-03-05 08:36 ——— d—–w C:\Program Files\DivX
2008-03-05 01:00 ——— d—–w C:\Program Files\PeerGuardian2
2008-03-04 00:36 ——— d—–w C:\Program Files\Diablo II
2008-03-02 07:55 ——— d—–w C:\Program Files\hent
2008-03-02 05:28 45 —-a-w C:\Program Files\from kev.txt
2008-03-02 00:27 ——— d—–w C:\Program Files\Warcraft III
2008-02-16 03:33 ——— d—–w C:\Program Files\muzak
2008-02-04 08:18 ——— d—–w C:\Documents and Settings\new user\Application Data\acccore
2008-02-04 08:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-02-04 08:17 ——— d—–w C:\Program Files\Common Files\AOL
2008-02-04 08:17 ——— d—–w C:\Program Files\AIM6
2008-02-04 08:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-02-01 07:57 ——— d—–w C:\Program Files\LimeWire
2008-01-26 07:39 ——— d—–w C:\Program Files\World of Warcraft
2008-01-24 19:31 ——— d—–w C:\Program Files\Lavasoft
2008-01-24 19:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-24 19:30 20,907,376 —-a-w C:\Program Files\aaw2007.exe
2008-01-24 19:30 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-24 19:28 ——— d—–w C:\Documents and Settings\new user\Application Data\Lavasoft
2008-01-22 09:34 373,462 —-a-w C:\Program Files\Jnes.zip
2008-01-22 09:33 867,785 —-a-w C:\Program Files\ZSNES.zip
2008-01-18 10:44 ——— d—–w C:\Program Files\Porn
2008-01-10 00:19 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2008-01-10 00:18 ——— d—–w C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-10 00:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-07 02:36 42,295 —-a-w C:\Program Files\xPick.zip
2007-09-22 17:42 125,020 —-a-w C:\Program Files\hacks_sting_hackmap_d2hackmap_v2[1].10_lite.zip
2007-09-21 03:36 14,869 —-a-w C:\Program Files\CCGOLDXPPATCH.ZIP
2007-09-20 23:28 6,221,304 —-a-w C:\Program Files\winamp535_full_emusic-7plus.exe
2007-07-09 06:36 1,181,812 -c–a-w C:\Program Files\FLVPlayerSetup.exe
2007-03-18 03:52 6,683,864 —-a-w C:\Program Files\videoraipodconverter_Installer.exe
2007-03-10 07:01 37,844,544 —-a-w C:\Program Files\iTunesSetup.exe
2007-03-03 08:54 11,776 —-a-w C:\Program Files\Winamp_keygen.exe
2007-02-08 06:44 14,705,768 —-a-w C:\Program Files\DivXInstaller.exe
2007-02-04 20:26 5,392,539 —-a-w C:\Program Files\Hero_Editor_Full_V95.zip
2007-01-17 22:22 18,257,616 —-a-w C:\Program Files\avg75free_432a904.exe
2005-10-31 14:56 700,416 —-a-w C:\Program Files\StubInstaller.exe
2005-10-24 07:24 2,855,080 —-a-w C:\Program Files\aawsepersonal.exe
2005-09-15 01:42 1,934,096 —-a-w C:\Program Files\dMC-r11.exe
2005-08-16 17:41 217,329 —-a-w C:\Program Files\gspot221.exe
2005-08-13 04:20 2,665,472 —-a-w C:\Program Files\AIM.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-06-01 12:32 94208]
"Aim6"="" []
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-02-29 23:22 287040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2006-05-25 07:43 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2006-05-25 07:43 126976]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-26 07:04 53248]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2008-03-06 22:27 122939]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 00:01 110592]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 09:54 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-02 14:24 257088]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"NWEReboot"="" []
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-09 16:19 579072]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-10-02 16:27 1065288]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-09 16:17 219136]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtsqpp]
awtsqpp.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\Diablo\\Diablo.exe"=
"C:\\Program Files\\AIM95\\aim.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=

R3 ICAM3NT5;Intel USB Video Camera III;C:\WINDOWS\system32\Drivers\Icam3.sys [2001-08-17 14:05]

.
Contents of the 'Scheduled Tasks' folder
"2008-03-03 22:53:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-08 23:44:44
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-03-08 23:47:13 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-09 07:47:10
.
2008-02-13 11:40:30 — E O F —




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:50:47 PM, on 3/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\nohiding.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.youtube.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AOL Instant Messenger (SM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1190333714279
O20 - Winlogon Notify: awtsqpp - awtsqpp.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe

–
End of file - 5485 bytes


if this fixed everything, thank you so much for you help it is much appreciated! :notworthy:
Looking better.

Run a scan with HJT and when finished check the following items (if found).

O20 - Winlogon Notify: awtsqpp - awtsqpp.dll (file missing)

Now close all open windows and click Fix Checked to remove them.

I'd like to run a couple of scans on your system, HJT and Combofix are great tools, but they only look in certain areas of your computer. I'd like a more overall view of what's on board.

First

  • Click Start > Run and type cleanmgr then click OK.
  • This will bring up the Disk Cleanup window.
  • Check the following entries.
    • Temporary Internet Files.
    • Recycle Bin.
    • Temporary Files.
  • Click OK.
  • When a prompt pops up click Yes.

Then

Please download Malwarebytes' Anti-Malware to your Desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.

  • Click on the Malwarebytes' Anti-Malware icon to launch the programme.
    • Click the Updates tab.
    • Click Check for Updates and allow the programme to download the latest definitions.
  • Click the Scanner tab.
    • Check Perform Quick Scan.
    • Click Scan and wait for the scan to complete.
    • When the scan is complete, click OK, then Show Results.
    • Ensure all items are checked then click Remove Selected.
    • A box will pop-up telling you that files have been quarantined.
    • A log will pop-up.
  • Post the log in your next reply please.

You can also access the log by doing the following
  • Click on the Logs tab.
  • Click on the log at the bottom of those listed to highlight it.
  • Click Open

Next

Please do an online scan with Kaspersky Online Scanner

Note: You must be using Internet Explorer as your browser as it will be necessary to install an Active X component to your computer.

Important If you have previously used Kaspersky Online Scanner (before 8th Aug 2006), you will have to uninstall the old version using Add/Remove Programs in Control Panel before you can use the new version.

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings.
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:
      • Extended (If available otherwise Standard)
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK.
  • Now under select a target to scan select My Computer.
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Save the file to your desktop.
    • From the Save as type: box, click on the Text file (*.txt) button.
  • Copy and paste that information in your next post please.

Note: The Kaspersky online scanner is not yet fully compatible with IE7. You may get returned to a window without the Accept/Decline buttons after allowing the ActiveX control. The buttons are there - you just can't see them! Click on the zoom button (bottom, right of the window) and change it from 100% to 75%. You should now see the buttons. Reset to 100% once the license has been accepted.

Finally

IMPORTANT
  • It is unclear from your log whether or not you have a firewall installed.
  • If you have one running, please disregard this.
  • If it is disabled, please enable it.
  • If you are using the firewall that comes with Windows, or Service Pack 2, you should replace it. It doesn't monitor outgoing traffic, so anything on your computer can 'phone home' at will.
Below is a list of some free firewalls (in no order of preference).
It is important to note that you should only have one firewall installed at a time, but you can download to your Desktop and install each in turn to see which one you prefer.

Summary of the logs I need from you in your next post:
  • Malwarebytes' Anti-Malware log
  • Kaspersky log
  • New HJT log


Please post each log separately to prevent them being cut off by the forum post size limiter.
ok, her is the malwarebytes log Malwarebytes' Anti-Malware 1.08 Database version: 474 Scan type: Quick Scan Objects scanned: 26622 Time elapsed: 3 minute(s), 27 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
ok now I finished the Kaspersky scan here is the log ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Monday, March 10, 2008 2:22:44 AM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 10/03/2008 Kaspersky Anti-Virus database records: 621729 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ Scan Statistics: Total number of scanned objects: 69366 Number of viruses found: 3 Number of infected objects: 12 Number of suspicious objects: 0 Duration of the scan process: 00:42:21 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\SecTaskMan\kbndgkuj.dll.q_8046A41_q Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\new user\Cookies\index.dat Object is locked skipped C:\Documents and Settings\new user\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\new user\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\new user\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\new user\Local Settings\History\History.IE5\MSHist012008031020080311\index.dat Object is locked skipped C:\Documents and Settings\new user\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\new user\ntuser.dat Object is locked skipped C:\Documents and Settings\new user\ntuser.dat.LOG Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP116\A0035914.exe Infected: Trojan-PSW.Win32.Nilage.afd skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP116\A0035916.exe Infected: Trojan-PSW.Win32.Nilage.afd skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP117\A0035950.exe Infected: Trojan-PSW.Win32.Nilage.afd skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP117\A0035954.exe Infected: Trojan-PSW.Win32.Nilage.afd skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP120\A0036177.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP123\A0036278.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP125\A0036340.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP125\A0036359.dll Object is locked skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP125\A0036360.dll Object is locked skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP125\A0036375.dll Object is locked skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP126\A0036684.dll Object is locked skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP126\A0036685.dll Object is locked skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP127\A0036814.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP127\A0036814.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP127\A0036814.exe RarSFX: infected - 2 skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP127\A0036827.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP127\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped Scan process completed.
and last but not least here is the HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:27:45 AM, on 3/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\nohiding.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.youtube.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SoftPerfect Personal Firewall] "C:\Program Files\SoftPerfect Personal Firewall\fw.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AOL Instant Messenger (SM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1190333714279
O20 - Winlogon Notify: awtsqpp - awtsqpp.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe

–
End of file - 5328 bytes
OK, your System Restore files are infected, but provided you don't do a restore they can't re-infect you, we'll clean them out in due course.

There is however a file showing in the Kaspersky scan I'd like to dispose of.

  • Click Start > Run type Notepad click OK.
  • This will open an empty Notepad file.
  • Copy/Paste the contents of the box below into Notepad.
File::
C:\Documents and Settings\All Users\Application Data\SecTaskMan\kbndgkuj.dll.q_8046A41_q
C:\Documents and Settings\All Users\Application Data\SecTaskMan\kbndgkuj.dll

Folder::
C:\Documents and Settings\All Users\Application Data\SecTaskMan

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtsqpp]
  • Click Format and ensure Wordwrap is unchecked.
  • Save as CFScript.txt to your Desktop.
[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Combofix will now process that file.

When finished, it will produce a log for you. Post that log in your next reply please, along with a new HJT log. (it can also be found at C:\Combofix.txt)

Please run another scan with Kaspersky and post me the log from that as well please.

Summary of the logs I need from you in your next post:
  • New Combofix log
  • New Kaspersky log
  • New HJT log


Please post each log separately to prevent them being cut off by the forum post size limiter.
alright heres combofix log


ComboFix 08-03-08.2 - new user 2008-03-10 22:53:23.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1501 [GMT -7:00]
Running from: C:\Program Files\ComboFix.exe
Command switches used :: C:\Documents and Settings\new user\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\Documents and Settings\All Users\Application Data\SecTaskMan\kbndgkuj.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\kbndgkuj.dll.q_8046A41_q
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\SecTaskMan
C:\Documents and Settings\All Users\Application Data\SecTaskMan\_10
C:\Documents and Settings\All Users\Application Data\SecTaskMan\_aawservice296AF560
C:\Documents and Settings\All Users\Application Data\SecTaskMan\_avgemc19563406
C:\Documents and Settings\All Users\Application Data\SecTaskMan\_awtsqpp14EF9E00
C:\Documents and Settings\All Users\Application Data\SecTaskMan\_btdnaCB46144
C:\Documents and Settings\All Users\Application Data\SecTaskMan\_dnjgikkb10C65A41
C:\Documents and Settings\All Users\Application Data\SecTaskMan\_entreelist.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\_enviewlist.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\_hkcmdE71F001
C:\Documents and Settings\All Users\Application Data\SecTaskMan\_iPodService1CADA447
C:\Documents and Settings\All Users\Application Data\SecTaskMan\_jkhfcDAD7604
C:\Documents and Settings\All Users\Application Data\SecTaskMan\_kbndgkuj12216A41
C:\Documents and Settings\All Users\Application Data\SecTaskMan\_klg1B628401
C:\Documents and Settings\All Users\Application Data\SecTaskMan\_rhjitjfi12CE6641
C:\Documents and Settings\All Users\Application Data\SecTaskMan\_smumhook27D62F4A
C:\Documents and Settings\All Users\Application Data\SecTaskMan\_tfswshx18E0D03B
C:\Documents and Settings\All Users\Application Data\SecTaskMan\_vtstt13658604
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_0B79C053C7D38EE4AB9A00CB3B5D2472
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_0B79C053C7D38EE4AB9A00CB3B5D2472.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_0DEF1459F7230FD4B869FE75FE26F291
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_0DEF1459F7230FD4B869FE75FE26F291.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_12341
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_12345
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_166F59DC4C5A5F446AAACEDD192C045B
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_166F59DC4C5A5F446AAACEDD192C045B.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_19F4AD9090A22324BAC8B67C0490D63E
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_19F4AD9090A22324BAC8B67C0490D63E.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_224B062A1E072E1459D77FF62A21665D
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_224B062A1E072E1459D77FF62A21665D.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_297DD19418DAC924E94B68DDD3223E33
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_297DD19418DAC924E94B68DDD3223E33.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_29FE602138E29584CABC02843CBCD76A
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_29FE602138E29584CABC02843CBCD76A.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_3ED418C3471784143A2E34FF4C2F0133
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_3ED418C3471784143A2E34FF4C2F0133.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_3FB590517D3AFDD41B39A39486180E30
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_3FB590517D3AFDD41B39A39486180E30.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_56A968A049C8C7F45A7C79D2C3C8DEE9
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_56A968A049C8C7F45A7C79D2C3C8DEE9.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_571368E5D58E6A4498862805D743EAF7
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_571368E5D58E6A4498862805D743EAF7.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_62287FAB00234BD4EB33D429A2978904
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_62287FAB00234BD4EB33D429A2978904.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_80915B10FE20B354789A1815288E2C2F
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_80915B10FE20B354789A1815288E2C2F.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_84C581F9B595A1041A6DAA3B4298D04C
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_84C581F9B595A1041A6DAA3B4298D04C.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_8A0F842331866D117AB7000B0D610002
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_8A0F842331866D117AB7000B0D610002.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_8A0F842331866D117AB7000B0D610003
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_8A0F842331866D117AB7000B0D610003.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_AC7F955943E573242A9D8D6564A47D72
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_AC7F955943E573242A9D8D6564A47D72.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_B0B35DEDC76B4424EAA66DDFC3821DFE
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_B0B35DEDC76B4424EAA66DDFC3821DFE.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_b25099274a207264182f8181add555d0
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_b25099274a207264182f8181add555d0.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_D6461317C3DC4F04799BDCE9E42626FE
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_D6461317C3DC4F04799BDCE9E42626FE.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_DB58B1D770AA8B8408D8764A60F76CDB
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_DB58B1D770AA8B8408D8764A60F76CDB.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_DDE7F2BCF1D91C3409CFF425AE1E271A
C:\Documents and Settings\All Users\Application Data\SecTaskMan\icn_DDE7F2BCF1D91C3409CFF425AE1E271A.dll
C:\Documents and Settings\All Users\Application Data\SecTaskMan\kbndgkuj.dll.q_8046A41_q
C:\Documents and Settings\All Users\Application Data\SecTaskMan\kbndgkuj.dll.q_8046A41_q.ini

.
((((((((((((((((((((((((( Files Created from 2008-02-11 to 2008-03-11 )))))))))))))))))))))))))))))))
.

2008-03-10 02:27 . 2008-03-10 02:27 d——– C:\Program Files\SoftPerfect Personal Firewall
2008-03-10 02:27 . 2004-07-19 21:47 15,594 –a—— C:\WINDOWS\system32\drivers\spfdrv.sys
2008-03-10 02:26 . 2008-03-10 02:26 950,260 –a—— C:\Program Files\firewall_setup.exe
2008-03-10 00:44 . 2008-03-10 00:44 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-03-10 00:44 . 2008-03-10 00:44 d——– C:\WINDOWS\LastGood
2008-03-10 00:44 . 2008-03-10 00:44 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-10 00:38 . 2008-03-10 00:38 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-03-10 00:38 . 2008-03-10 00:38 d——– C:\Documents and Settings\new user\Application Data\Malwarebytes
2008-03-10 00:38 . 2008-03-10 00:38 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-10 00:35 . 2008-03-10 00:35 1,447,960 –a—— C:\Program Files\mbam-setup.exe
2008-03-08 22:12 . 2008-03-08 22:12 d——– C:\Documents and Settings\LocalService\Application Data\Xfire
2008-03-08 21:07 . 2008-03-08 21:07 1,584,016 –a—— C:\Program Files\ComboFix.exe
2008-03-08 21:01 . 2008-03-08 21:01 4,608,744 –a—— C:\Program Files\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
2008-03-07 00:03 . 2008-03-07 00:03 1,762 –a—— C:\WINDOWS\system32\tmp.reg
2008-03-07 00:02 . 2007-09-06 00:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-03-07 00:02 . 2008-03-02 00:12 86,016 –a—— C:\WINDOWS\system32\VACFix.exe
2008-03-07 00:02 . 2008-03-05 23:29 82,432 –a—— C:\WINDOWS\system32\IEDFix.exe
2008-03-07 00:02 . 2007-10-04 00:36 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2008-03-06 23:54 . 2006-04-27 17:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-03-06 23:54 . 2003-06-05 21:13 53,248 –a—— C:\WINDOWS\system32\Process.exe
2008-03-06 23:54 . 2004-07-31 18:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-03-06 23:16 . 2008-03-06 23:16 d——– C:\Program Files\Trend Micro
2008-03-06 20:45 . 2008-03-06 20:46 d——– C:\Program Files\The KMPlayer
2008-03-06 01:06 . 2008-03-06 01:24 d——– C:\Program Files\Spyware Doctor
2008-03-06 01:06 . 2008-03-06 01:06 d——– C:\Documents and Settings\new user\Application Data\PC Tools
2008-03-06 01:06 . 2007-10-04 18:10 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-03-06 01:06 . 2007-10-04 18:10 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-03-06 01:06 . 2007-10-04 18:10 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-03-06 01:06 . 2007-10-04 18:11 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-03-06 01:03 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2008-03-06 00:59 . 2008-03-06 20:39 d——– C:\Program Files\Security Task Manager
2008-03-05 18:02 . 2008-03-05 18:02 7,799,416 –a—— C:\Program Files\Windows-KB890830-V1.38.exe
2008-03-05 00:47 . 2007-01-29 22:03 118,520 –a—— C:\WINDOWS\system32\pxinsi64.exe
2008-03-05 00:47 . 2007-01-29 22:03 116,472 –a—— C:\WINDOWS\system32\pxcpyi64.exe
2008-03-01 00:22 . 2008-03-01 00:22 d——– C:\Program Files\DNA
2008-03-01 00:22 . 2008-03-01 00:22 d——– C:\Program Files\BitTorrent
2008-03-01 00:22 . 2008-03-10 22:44 d——– C:\Documents and Settings\new user\Application Data\DNA
2008-03-01 00:22 . 2008-03-08 00:52 d——– C:\Documents and Settings\new user\Application Data\BitTorrent
2008-02-21 23:44 . 2008-02-21 23:44 d——– C:\Documents and Settings\All Users\Application Data\WinZip
2008-02-21 22:54 . 2008-02-21 22:54 d——– C:\Documents and Settings\new user\Application Data\AVSMedia
2008-02-21 22:54 . 2008-02-21 22:54 d——– C:\Documents and Settings\All Users\Application Data\AVS4YOU
2008-02-21 22:50 . 2008-03-08 20:48 d——– C:\Program Files\Common Files\AVSMedia
2008-02-21 22:46 . 2008-02-21 22:46 58,903,352 –a—— C:\Program Files\avsvideotools.exe
2008-02-21 22:46 . 2007-02-27 20:36 1,700,352 –a—— C:\WINDOWS\system32\GdiPlus.dll
2008-02-20 18:57 . 2008-02-20 18:57 54,608 –a—— C:\WINDOWS\system32\xfcodec.dll
2008-02-19 12:51 . 2008-02-19 12:51 d——– C:\Program Files\Game Cam V2
2008-02-11 22:51 . 2008-02-11 22:51 d——– C:\Program Files\1964
2008-02-11 21:50 . 2008-02-11 21:50 117,970 –a—— C:\Program Files\Cxbx-0[1].7.8c.zip
2008-02-11 21:12 . 2008-02-11 21:12 286,715 –a—— C:\Program Files\ePSXe.zip
2008-02-11 20:35 . 2008-02-23 15:59 d——– C:\Program Files\Project64 1.6
2008-02-11 19:56 . 2008-02-11 19:56 2,080,797 –a—— C:\Program Files\Project64.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-11 05:53 ——— d—–w C:\Documents and Settings\new user\Application Data\Xfire
2008-03-11 04:48 ——— d—–w C:\Program Files\Diablo II
2008-03-10 08:23 ——— d—–w C:\Documents and Settings\new user\Application Data\AVG7
2008-03-10 07:30 43,520 —-a-w C:\WINDOWS\system32\CmdLineExt03.dll
2008-03-09 08:49 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-09 05:12 ——— d—–w C:\Program Files\Diablo
2008-03-07 04:39 ——— d—–w C:\Program Files\Xfire
2008-03-05 17:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-03-05 08:36 ——— d—–w C:\Program Files\DivX
2008-03-05 01:00 ——— d—–w C:\Program Files\PeerGuardian2
2008-03-02 07:55 ——— d—–w C:\Program Files\hent
2008-03-02 05:28 45 —-a-w C:\Program Files\from kev.txt
2008-03-02 00:27 ——— d—–w C:\Program Files\Warcraft III
2008-02-16 03:33 ——— d—–w C:\Program Files\muzak
2008-02-04 08:18 ——— d—–w C:\Documents and Settings\new user\Application Data\acccore
2008-02-04 08:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-02-04 08:17 ——— d—–w C:\Program Files\Common Files\AOL
2008-02-04 08:17 ——— d—–w C:\Program Files\AIM6
2008-02-04 08:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-02-01 07:57 ——— d—–w C:\Program Files\LimeWire
2008-01-26 07:39 ——— d—–w C:\Program Files\World of Warcraft
2008-01-24 19:31 ——— d—–w C:\Program Files\Lavasoft
2008-01-24 19:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-24 19:30 20,907,376 —-a-w C:\Program Files\aaw2007.exe
2008-01-24 19:30 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-24 19:28 ——— d—–w C:\Documents and Settings\new user\Application Data\Lavasoft
2008-01-22 09:34 373,462 —-a-w C:\Program Files\Jnes.zip
2008-01-22 09:33 867,785 —-a-w C:\Program Files\ZSNES.zip
2008-01-18 10:44 ——— d—–w C:\Program Files\Porn
2008-01-07 02:36 42,295 —-a-w C:\Program Files\xPick.zip
2007-12-14 19:32 12,632 —-a-w C:\WINDOWS\system32\lsdelete.exe
2007-09-22 17:42 125,020 —-a-w C:\Program Files\hacks_sting_hackmap_d2hackmap_v2[1].10_lite.zip
2007-09-21 03:36 14,869 —-a-w C:\Program Files\CCGOLDXPPATCH.ZIP
2007-09-20 23:28 6,221,304 —-a-w C:\Program Files\winamp535_full_emusic-7plus.exe
2007-07-09 06:36 1,181,812 -c–a-w C:\Program Files\FLVPlayerSetup.exe
2007-03-18 03:52 6,683,864 —-a-w C:\Program Files\videoraipodconverter_Installer.exe
2007-03-10 07:01 37,844,544 —-a-w C:\Program Files\iTunesSetup.exe
2007-03-03 08:54 11,776 —-a-w C:\Program Files\Winamp_keygen.exe
2007-02-08 06:44 14,705,768 —-a-w C:\Program Files\DivXInstaller.exe
2007-02-04 20:26 5,392,539 —-a-w C:\Program Files\Hero_Editor_Full_V95.zip
2007-01-17 22:22 18,257,616 —-a-w C:\Program Files\avg75free_432a904.exe
2005-10-31 14:56 700,416 —-a-w C:\Program Files\StubInstaller.exe
2005-10-24 07:24 2,855,080 —-a-w C:\Program Files\aawsepersonal.exe
2005-09-15 01:42 1,934,096 —-a-w C:\Program Files\dMC-r11.exe
2005-08-16 17:41 217,329 —-a-w C:\Program Files\gspot221.exe
2005-08-13 04:20 2,665,472 —-a-w C:\Program Files\AIM.exe
.

((((((((((((((((((((((((((((( snapshot@2008-03-08_23.46.54.51 )))))))))))))))))))))))))))))))))))))))))
.
- 2000-08-31 16:00:00 163,328 —-a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2000-08-31 15:00:00 163,328 —-a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
- 2000-08-31 16:00:00 28,160 —-a-w C:\WINDOWS\Nircmd.exe
+ 2000-08-31 15:00:00 28,160 —-a-w C:\WINDOWS\Nircmd.exe
+ 2005-05-24 19:27:16 213,048 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 22:47:20 94,208 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 22:49:54 950,272 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
- 2008-03-06 08:08:01 70,124 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-03-09 23:50:01 70,124 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2008-03-06 08:08:01 436,360 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-03-09 23:50:01 436,360 —-a-w C:\WINDOWS\system32\perfh009.dat
- 2000-08-31 16:00:00 161,792 —-a-w C:\WINDOWS\system32\swreg.exe
+ 2000-08-31 15:00:00 161,792 —-a-w C:\WINDOWS\system32\swreg.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-06-01 13:32 94208]
"Aim6"="" []
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-03-01 00:22 287040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2006-05-25 08:43 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2006-05-25 08:43 126976]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-26 08:04 53248]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2008-03-06 23:27 122939]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 01:01 110592]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-02 15:24 257088]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"NWEReboot"="" []
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40 155648]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-09 17:19 579072]
"SoftPerfect Personal Firewall"="C:\Program Files\SoftPerfect Personal Firewall\fw.exe" [2005-07-15 01:30 1328128]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-09 17:17 219136]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\Diablo\\Diablo.exe"=
"C:\\Program Files\\AIM95\\aim.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=

R3 ICAM3NT5;Intel USB Video Camera III;C:\WINDOWS\system32\Drivers\Icam3.sys [2001-08-17 15:05]

.
Contents of the 'Scheduled Tasks' folder
"2008-03-10 21:53:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-10 22:54:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-03-10 22:55:14
ComboFix-quarantined-files.txt 2008-03-11 05:54:59
.
2008-02-13 11:40:30 — E O F —
heres kaspersky ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Monday, March 10, 2008 11:39:47 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 11/03/2008 Kaspersky Anti-Virus database records: 622698 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ Scan Statistics: Total number of scanned objects: 69405 Number of viruses found: 3 Number of infected objects: 12 Number of suspicious objects: 0 Duration of the scan process: 00:42:27 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\new user\Cookies\index.dat Object is locked skipped C:\Documents and Settings\new user\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\new user\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\new user\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\new user\Local Settings\History\History.IE5\MSHist012008031020080311\index.dat Object is locked skipped C:\Documents and Settings\new user\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\new user\ntuser.dat Object is locked skipped C:\Documents and Settings\new user\ntuser.dat.LOG Object is locked skipped C:\QooBox\Quarantine\C\Documents and Settings\All Users\Application Data\SecTaskMan\kbndgkuj.dll.q_8046A41_q.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP116\A0035914.exe Infected: Trojan-PSW.Win32.Nilage.afd skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP116\A0035916.exe Infected: Trojan-PSW.Win32.Nilage.afd skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP117\A0035950.exe Infected: Trojan-PSW.Win32.Nilage.afd skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP117\A0035954.exe Infected: Trojan-PSW.Win32.Nilage.afd skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP120\A0036177.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP123\A0036278.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP125\A0036340.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP125\A0036359.dll Object is locked skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP125\A0036360.dll Object is locked skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP125\A0036375.dll Object is locked skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP126\A0036684.dll Object is locked skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP126\A0036685.dll Object is locked skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP127\A0036814.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP127\A0036814.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP127\A0036814.exe RarSFX: infected - 2 skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP127\A0036827.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP128\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped E:\System Volume Information\_restore{CA85D9A0-7733-448E-8DCB-852CC40E1906}\RP128\change.log Object is locked skipped Scan process completed.
and heres HJT, the kaspersky didnt seem to change at all…


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:42:08 PM, on 3/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Xfire\xfire.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\nohiding.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.youtube.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SoftPerfect Personal Firewall] "C:\Program Files\SoftPerfect Personal Firewall\fw.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AOL Instant Messenger (SM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1190333714279
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe

–
End of file - 5302 bytes

and heres HJT, the kaspersky didnt seem to change at all…


You are wrong, it changed in one significant way. It showed me that the files I asked you to remove with Combofix had been removed (I knew this already from the CF log), and importantly, that no new files had been generated to replace them (this often happens if we remove infection files and we haven't got rid of everything).

There is always a reason for the things we do, even if they're not always obvious. I know running repeated scans can be a nuisance, but we only ask for them so that we can be sure you're not going to be re-infected because we've missed something.

OK, as far as I can see your computer looks clear of infection now.

Your System Restore points are infected, but they can't re-infect you unless you do a restore. We're going to remove them next though, to take away that possibility.

Let's clear out Combofix and the files/folders it created
  • Click Start > Run
  • Copy/Paste ComboFix /u into the Run box.
  • Click OK
  • The following items will now be processed.
    • Deletes the following files/folders:
    • ComboFix.exe
    • %system%\swxcacls.exe
    • %system%\swsc.exe
    • %system%\VFind.exe
    • %system%\moveex.exe
    • %system%\swreg.exe
    • %systemroot%\catchme.exe
    • \ComboFix
    • \Qoobox
    • \VundoFix Backups
    • \Deckard
    • \_OTMoveIt
    • %systemroot%\erdnt\subs
  • Resets the clock settings.
  • Hides file extensions
  • Hides System/Hidden files
  • Clears System Restore cache and create new Restore point. (This will clear out the infected System Restore files)

IMPORTANT
  • Do not use your computer while Combofix is running.
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

You can keep Malwarebytes' Anti-Malware, or not, as you wish (it's Freeware). If you don't want it, Uninstall it using Control Panel > Add/Remove Programs

I notice you use P2P filesharing progammes Limewire, BitTorrent

Use of P2P (Person to Person) file sharing programmes

We have noticed an increasing number of people coming to us with infections contracted from the use of P2P programmes.

P2P programmes form a direct conduit onto your computer, their security measures are easily circumvented, and Malware writers are increasingly exploiting them to spread their wares onto your computer. Further to that, if your P2P programme is not configured correctly you may be sharing more files than you realise. There have been cases where people's Passwords, Address Books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured programme.

This article from InfoWorld illustrates perfectly the dangers of a poorly configured P2P progamme.
http://www.infoworld.com/article/07/09/06/…ID-theft_1.html

Many of the programmes come bundled with other unwanted programmes, but even the ones free of any bundled software are not safe to use.

When you use them you are downloading software from an unknown source directly onto your computer, bypassing your Firewall and Anti-Virus software. Hardly surprising then that many of these Downloads are being targeted to carry infections.


As far as I can see, your computer looks clear of infection now.

Are you still noticing any problems ?
  • If you are let me know about them.
  • If not it's time to make your computer more secure.
Below are a series of recommendations which will help you keep more secure online.

Obviously you have already taken care of some of the issues mentioned, but it is important that you read through them, and address any that you may have missed.

Please follow these steps to remove older version Java components. This is important as it's still possible to get infected through an old install even if you're using the latest version of Java.

  • Close any programmes you may have running, ESPECIALLY your web browser
  • Click Start > Control Panel.
  • Click Add/Remove Programs.
  • Check any item with Java Runtime Environment (JRE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove all versions of Java.
  • Reboot your computer once all Java components are removed.
Download the latest version of Java Runtime Environment (JRE) 6u5, and install it to your computer.

Updating Windows and Internet Explorer
It is essential you keep your Operating System up to date with all the latest patches. The bad guys watch for the latest exploits, as soon as Microsoft brings out a patch, the bad guys will bring out an infection to exploit that vulnerability. If you don't have all the latest patches your computer is vulnerable. Please go to the windows update site and get the critical updates.

Use a "secure" browser
Install Internet Explorer 7 or an alternative browser like Firefox or Opera for more secure surfing.
Please remember that there is no such thing as a totally secure browser. Your browsing habits will be the major factor in determining just how safe you are online. If you visit, Crack/Warez sites, Porn sites, or other sites of a questionable nature, you still run a severe risk of getting infected.

The following are free programs that are designed to keep your computer clean. A brief description is included with each item, click on name to go to download site.

  • Spybot S & D
    Spybot is a scanner. It scans for spyware and other malicious programs. It is important to have at least one malware scanner on your computer. Spybot has preventitive tools that stop programs from even installing on your computer.
    To see how to set this up as well as more spybot features, see here
  • WinPatrol by BillPStudios is a programme that monitors your computer and notifies you if there are any unauthorised changes made to it. It gives you the option to allow or forbid the changes, thus guarding you against Malware installations. I consider this one a must have.

    If you find you like it, you can get a lifetime upgrade to the Plus version for a small one time fee.
  • SpywareBlaster
    Spyware blaster is a program that stops known malicious activex controls from installing on your computer. It works by changing settings in your registry. It makes "kill bits" in the registry, so that certain activex controls can't install.
    If you don't know what activex controls are, see here
  • IE Spyad
    It puts many bad webpages on your restricted zones LIST. This means that you can still view the "bad" webpages, but the webpages can't do certain things (such as use javascripts and cookies). Use IE Spyad for single account computers, and IE Spyad 2 for multi account computers.
  • Hosts file:
  • Make sure you read the instructions on how to install the hosts file, here.

    • Every version of windows has a hosts file as part of them.
    • In a very basic sense, they are used to locate webpages.
    • We can customize a hosts file so that it blocks certain webpages.
    • However, it can slow down certain computers.
  • If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
    • Click the start button (at the lower left hand corner of your screen)
    • Click run
    • In the dialog box, type services.msc
    • hit enter, then locate dns client
    • Highlight it, then double-click it.
    • On the dropdown box, change the setting from automatic to manual.
    • Click ok
  • Use an Anti Virus Software - It's very important that your computer has an anti-virus software running. This alone can save you a lot of trouble with malware in the future. See this link for a listing of some on line & their stand-alone anti virus programs:
    Computer Safety On line - LIST of free Anti virus programs
  • Use a Firewall - I cannot stress enough how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check this webpage out.
    See here to choose one.
  • Site Advisor This is a utility that can be downloaded and installed. It loads an icon to the taskbar of your browser (versions for IE and Firefox), indicating the trustworthiness of the site you are on. Green for safe, Red for suspicious. Click on the icon to access details that SiteAdvisor has about the site.

Here's links to a few articles which are well worth reading

Finally

NOW is the time you can start to hit back at the people who infected you.
[external image: Posted Image]
Please take the time to go and complain - that forum has a topic for your infection which is Vundo……. (if not, post in the Is your infection not listed here? topic). Please post as a reply, you do not need to register to do so (but you can if you wish). It will also have a list of other places you can go to to register your complaint, depending on the country you are resident in. Please read the topics and complain, it is only with such complaints to government or government agencies that something will get done.

and heres HJT, the kaspersky didnt seem to change at all…


You are wrong, it changed in one significant way. It showed me that the files I asked you to remove with Combofix had been removed (I knew this already from the CF log), and importantly, that no new files had been generated to replace them (this often happens if we remove infection files and we haven't got rid of everything).

There is always a reason for the things we do, even if they're not always obvious. I know running repeated scans can be a nuisance, but we only ask for them so that we can be sure you're not going to be re-infected because we've missed something.


ok, i just didnt realize that it had changed i didnt mean for my post to sound negitive i know it takes awhile to get everything right and i am grateful for your help! thank you sooo much! :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI