This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] "wowfx.dll" virus

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, my dad's computer is giving him this error message.

"The application or DLL C:\WINDOWS\System32\wowfx.dll is not a valid Windows image. Please check this against your installation diskette." The error message has a window title of ____(the program) - Bad Image.

The error message occurs every time a process attempts to run. Whether it is IE, Itunes, Adaware etc. The programs do run, but require you to click "ok" before they start.

http://forums.whatthetech.com/wowfx_dll_errors_t87427.html
I found this thread and read through it, but I was not too sure of what that meant for me.
I downloaded ATF cleaner and combofix, but I wasnt sure what to do, so I didnt run them either.

Thanks in advance.

Here is my HJT log

Logfile of HijackThis v1.99.1
Scan saved at 1:02:53 PM, on 03/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Airlink101\AWLH5025\WLService.exe
C:\Program Files\Airlink101\AWLH5025\WLanCfgG.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\ThreatFire\TFService.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\StorageSync\StrgSync.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\userinit.exe
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\RealBar.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: 1-Click Answers - {7754C418-F62E-44aa-B169-E719E718BCFD} - C:\PROGRA~1\1-CLIC~1\IEToolbar\AnswersToolbarU.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [StrgSync.exe] C:\Program Files\StorageSync\StrgSync.exe -w
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [{93-32-2A-A6-ZN}] C:\Documents and Settings\mjhin\Local Settings\Temp\T0CHD001.exe CHD001
O4 - HKLM\..\Run: [nyrqlabq] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\nyrqlabq.dll"
O4 - HKLM\..\Run: [edypwrgp] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\edypwrgp.dll"
O4 - HKLM\..\Run: [plite731] C:\WINDOWS\plite731.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Zpocdw] C:\Program Files\icrosoft\ntepad.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://download.sleh.com/transfer/download.aspx?id=43
O16 - DPF: {3B0EA9E6-7003-4B38-B398-9B1B6DF439C5} - http://download1.answers.com/pub/AnswersSetup.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {F9463571-87CB-4A90-A1AC-2284B7F5AF4E} (Persits Software XEncrypt) - http://download.sleh.com/updates/AspEncrypt.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\wowfx.dll
O20 - Winlogon Notify: cbxutqp - cbxutqp.dll (file missing)
O20 - Winlogon Notify: cdleajuz - cdleajuz.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MIMO XR TM PCI Adapter WLService (MIMO XR TM PCI WLService) - Unknown owner - C:\Program Files\Airlink101\AWLH5025\WLService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
Hello algemar and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem.


A. First we must disable some of your security programs so that they do not interfere with the running of our tools:

NORTON ANTIVIRUS
Please navigate to the system tray on the bottom right hand corner and look for a [external image: Posted Image] sign.
  • right-click it -> chose "Disable Auto-Protect."
  • select a duration of 5 hours (this assures no interference with the cleanup of your pc)
  • click "Ok."
  • a popup will warn that protection will now be disabled and the sign will now look like this: [external image: Posted Image]
You succesfully disabled the Norton Antivirus Guard.


SPYWARE DOCTOR
  • Click the Spyware Doctor icon in the System Tray.
  • Click Settings.
  • Click Startup Settings under Pick a Category.
  • Uncheck "Run at Windows startup".
  • Click Apply and Exit Spyware Doctor.
  • From within Spyware Doctor, click the "OnGuard" button on the left side.
  • Uncheck "Activate OnGuard".
  • (When we are done, you can reenable Spyware Doctor)


B. Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • ComboFix will automatically start. Any monitoring programs will be shut down like your antivirus, antispyware programs for example.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
The wowfx.dll error message is no longer occuring!!!!…..but I have little faith in removing all problems 100%.

Here is my combofx log: Should I have installed the recovery console?


ComboFix 08-03-20.5 - mjhin 2008-03-20 17:38:23.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.895 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\mjhin\Application Data\macromedia\Flash Player\#SharedObjects\86PN6PN7\www.broadcaster.com
C:\Documents and Settings\mjhin\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\mjhin\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Documents and Settings\mjhin\My Documents\RACLE~1
C:\Documents and Settings\mjhin\My Documents\RACLE~1\?racle\
C:\Program Files\E404 Helper
C:\Program Files\icroso~1
C:\Program Files\ucleaner_setup.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\fCOe
C:\Temp\fCOe\tOasF.log
C:\temp\tn3
C:\WINDOWS\cookies.ini
C:\WINDOWS\ecurit~1
C:\WINDOWS\system32\cdleajuz.dllbox
C:\WINDOWS\system32\d3
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_1.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\box_3.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\cell_bg.gif
C:\WINDOWS\system32\drivers\cell_footer.gif
C:\WINDOWS\system32\drivers\cell_header_block.gif
C:\WINDOWS\system32\drivers\cell_header_remove.gif
C:\WINDOWS\system32\drivers\cell_header_scan.gif
C:\WINDOWS\system32\drivers\download_box.gif
C:\WINDOWS\system32\drivers\download_btn.jpg
C:\WINDOWS\system32\drivers\download_now_btn.gif
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_red_bg.gif
C:\WINDOWS\system32\drivers\header_red_free_scan.gif
C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
C:\WINDOWS\system32\drivers\product_1_header.gif
C:\WINDOWS\system32\drivers\product_1_name_small.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_3_header.gif
C:\WINDOWS\system32\drivers\product_3_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\rating.gif
C:\WINDOWS\system32\drivers\screenshot.jpg
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\shadow_bg.gif
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\spy_away_box.jpg
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\f22
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\oTt06e
C:\WINDOWS\system32\oTt08e
C:\WINDOWS\system32\p8
C:\WINDOWS\system32\s2
C:\WINDOWS\system32\v1
C:\WINDOWS\system32\wnsapiisv32.exe
C:\WINDOWS\system32\wowfx.dll

.
((((((((((((((((((((((((( Files Created from 2008-02-20 to 2008-03-20 )))))))))))))))))))))))))))))))
.

2008-03-17 18:17 . 2008-03-17 18:17 42 –a—— C:\WINDOWS\SYSTEM32\AK083E209605E394C.lie

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-20 22:53 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-20 17:48 ——— d—–w C:\Program Files\Spyware Doctor
2008-03-20 04:11 ——— d—–w C:\Documents and Settings\mjhin\Application Data\SlimBrowser
2008-03-19 23:34 ——— d—–w C:\Program Files\Google
2008-03-19 17:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-03-19 17:23 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-03-19 17:14 ——— d—–w C:\Program Files\Broderbund
2008-03-19 02:53 ——— d—–w C:\Documents and Settings\mjhin\Application Data\Lavasoft
2008-03-08 04:46 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-03-07 00:14 ——— d—–w C:\Program Files\Norton Security Scan
2008-02-09 03:13 ——— d—–w C:\Program Files\SlimBrowser
2008-02-09 01:20 ——— d—–w C:\Program Files\iTunes
2008-02-09 01:20 ——— d—–w C:\Program Files\iPod
2008-02-09 01:14 ——— d—–w C:\Program Files\QuickTime
2008-02-09 01:06 ——— d—–w C:\Program Files\Common Files\Apple
2007-10-27 01:29 117 —-a-w C:\Documents and Settings\mjhin\mit.bat
2007-11-04 17:52 410,453 –sh–w C:\WINDOWS\SYSTEM32\ffhkj.ini2
2007-12-08 03:00 6,535 –sha-w C:\WINDOWS\SYSTEM32\lnnmp.ini2
2007-12-06 03:46 428 –sha-w C:\WINDOWS\SYSTEM32\opqss.ini2
2007-12-13 09:15 6,559 –sha-w C:\WINDOWS\SYSTEM32\rqstv.ini2
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"Zpocdw"="C:\Program Files\icrosoft\ntepad.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AcctMgr"="C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe" [2004-08-18 12:41 586896]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-12-22 17:45 71280]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-19 08:59 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-19 08:59 126976]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2006-10-22 14:58 95960]
"StrgSync.exe"="C:\Program Files\StorageSync\StrgSync.exe" [2005-10-07 22:01 3032576]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-12 21:01 185632]
"ThreatFire"="C:\Program Files\ThreatFire\TFTray.exe" [2007-12-13 16:41 1238336]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-04 15:18 267048]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
"{93-32-2A-A6-ZN}"="C:\Documents and Settings\mjhin\Local Settings\Temp\T0CHD001.exe" [ ]
"plite731"="C:\WINDOWS\plite731.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2006-07-25 18:03 67264]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbxutqp]
cbxutqp.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cdleajuz]
cdleajuz.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^1-Click Answers.lnk]
backup=C:\WINDOWS\pss\1-Click Answers.lnkCommon Startup
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\1-Click Answers.lnk

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MiniMavis.lnk]
backup=C:\WINDOWS\pss\MiniMavis.lnkCommon Startup
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MiniMavis.lnk

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
–a—— 2007-01-01 16:22 3739648 C:\Program Files\Google\Google Talk\googletalk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-02-04 15:18 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMM2007RT]
C:\Program Files\PC MightyMax 2007\pcmm2007.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
C:\Program Files\Picasa2\PicasaMediaDetector.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra—— 2007-08-23 00:19 23120680 C:\Program Files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow!]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2007-09-12 21:01 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2004-08-06 15:33 2502656 C:\Program Files\Yahoo!\Messenger\ypager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPodService"=3 (0x3)
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"avast! Antivirus"=2 (0x2)
"aswUpdSv"=2 (0x2)
"IDriverT"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
"LxrSG20s"=3 (0x3)
"LxrJD31s"=2 (0x2)
"CCALib8"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\SlimBrowser\\sbrowser.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R0 TfFsMon;TfFsMon;C:\WINDOWS\system32\drivers\TfFsMon.sys [2007-12-21 21:52]
R0 TfSysMon;TfSysMon;C:\WINDOWS\system32\drivers\TfSysMon.sys [2007-12-21 21:52]
R2 MIMO XR TM PCI WLService;MIMO XR TM PCI Adapter WLService;C:\Program Files\Airlink101\AWLH5025\WLService.exe [2004-03-29 17:08]
R2 ThreatFire;ThreatFire;C:\Program Files\ThreatFire\TFService.exe service []
R3 TfNetMon;TfNetMon;C:\WINDOWS\system32\drivers\TfNetMon.sys [2007-12-13 16:42]
S3 LxrSG20d;LxrSG20d;C:\WINDOWS\system32\Drivers\LxrSG20d.sys [2006-08-13 16:34]
S3 PhilCam8116;Logitech QuickCam Pro 3000 (08B0);C:\WINDOWS\system32\DRIVERS\CamDrO21.sys [2001-08-17 14:05]
S3 PRISM_USB;Dell TrueMobile 1180 Wireless USB Adapter;C:\WINDOWS\system32\DRIVERS\DELUSB_51.sys [2002-08-09 15:46]
S3 ZSMC302;VIMICRO USB PC Camera;C:\WINDOWS\system32\Drivers\usbVM31b.sys [2004-09-07 03:11]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{01ecf298-366d-11d9-a294-00904b6791d2}]
\Shell\AutoRun\command - F:\JDSecure\Windows\JDSecure20.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{01ecf299-366d-11d9-a294-00904b6791d2}]
\Shell\AutoRun\command - F:\JDSecure\Windows\JDSecure31.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2ca6fbb6-6204-11db-a498-0014a50fdfbc}]
\Shell\AutoRun\command - F:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4d9ef045-1199-11da-a2fa-00904b6791d2}]
\Shell\AutoRun\command - F:\JDSecure\Windows\JDSecure31.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cf260ab2-6556-11db-a4a2-0014a50fdfbc}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2008-02-08 17:22:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-29 21:00:00 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2006-02-14 02:30:37 C:\WINDOWS\Tasks\XoftSpy.job"
- C:\Program Files\XoftSpy\XoftSpy.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-20 17:53:12
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\Program Files\Airlink101\AWLH5025\WLanCfgG.exe
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\ThreatFire\TFService.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-03-20 18:01:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-20 23:01:25
.
2008-03-14 05:02:24 — E O F —







Here is my new HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 18:10, on 2008-03-20
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Airlink101\AWLH5025\WLService.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\Program Files\Airlink101\AWLH5025\WLanCfgG.exe
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\ThreatFire\TFService.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\StorageSync\StrgSync.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\RealBar.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: 1-Click Answers - {7754C418-F62E-44aa-B169-E719E718BCFD} - C:\PROGRA~1\1-CLIC~1\IEToolbar\AnswersToolbarU.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [StrgSync.exe] C:\Program Files\StorageSync\StrgSync.exe -w
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [{93-32-2A-A6-ZN}] C:\Documents and Settings\mjhin\Local Settings\Temp\T0CHD001.exe CHD001
O4 - HKLM\..\Run: [plite731] C:\WINDOWS\plite731.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Zpocdw] C:\Program Files\icrosoft\ntepad.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://download.sleh.com/transfer/download.aspx?id=43
O16 - DPF: {3B0EA9E6-7003-4B38-B398-9B1B6DF439C5} - http://download1.answers.com/pub/AnswersSetup.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {F9463571-87CB-4A90-A1AC-2284B7F5AF4E} (Persits Software XEncrypt) - http://download.sleh.com/updates/AspEncrypt.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: cbxutqp - cbxutqp.dll (file missing)
O20 - Winlogon Notify: cdleajuz - cdleajuz.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MIMO XR TM PCI Adapter WLService (MIMO XR TM PCI WLService) - Unknown owner - C:\Program Files\Airlink101\AWLH5025\WLService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
A. Please ensure that your security programs are still disabled as directed in my first post.

B. Please RUN HijackThis
  • Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm


  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.


C. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\WINDOWS\SYSTEM32\AK083E209605E394C.lie
C:\WINDOWS\SYSTEM32\ffhkj.ini2
C:\WINDOWS\SYSTEM32\lnnmp.ini2
C:\WINDOWS\SYSTEM32\opqss.ini2
C:\WINDOWS\SYSTEM32\rqstv.ini2
C:\blank.htm

Folder::
C:\Documents and Settings\mjhin

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Zpocdw"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"{93-32-2A-A6-ZN}"=-
"plite731"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbxutqp]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cdleajuz]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMM2007RT]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow!]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]

Driver::
ThreatFire
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

5. All your monitoring programs (Antivirus/Antispyware, Guards and Shields) will be stopped.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


D. Using Internet Explorer, please do a Kaspersky Online Scan

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will provide a report if your system is infected. It does not provide an option to clean/disinfect. We only require a report from it.

    [external image: Posted Image]

  • Click the Save as Text button to save the file to your desktop and post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan
Sorry I took so long in responding.

I got as far as running the CFScipt with the combofix. However, after the computer restarted I started running into trouble.

All my dad's favorites got wiped, the shortcuts on the start menu got deleted, many of the files on the desktop are gone, ect…. These troubles are merely superficial… but annoying none the less.

More importantly however, is I'm having trouble resetting anything back to normal. In other words, when I try to change the desktop, I click apply and nothing happens. When I try to re-pin items to the start menu, create new shortcuts, and add new favorites, nothing occurs. The big problem is that the amount of space set to temp internet files/cookies etc, was reset to 0mb. However, I can't set it back to a higher amount(the default is 8mb I think). This means that browsing is slowed to the point of non-usefulness. I'm having to write this post on my own computer. Unfortunately my dad does not have Firefox installed, so I can't test that…..

Any help is appreciated. Should I try to go back to a previous system restore point? How would I go about doing that in the first place? Worse come to worse…. I'll just do a full wipe… but I'd rather not, since I've come this far.

Again, all obvious signs of the wowfx.dll virus seem to be gone……
I really do not have have any idea what has occurred other that it appears that all personal preference have been deleted and that could have something to do with when UserInit loads. That was an extremely infected machine and the files that were removed were definitely malware.


1. Are you sure that both Symantec and Spyware Doctor were still disabled?(Extremely important to know)

2. Are you able to find the most recent log for ComboFix.txt. If it was created, you would find it here C:\ComboFix.txt . There should be two of them, one titled ComboFix.txt and the other says that it is #2. If you find it on your father's machine, transfer it to removable media (CD, pen drive, and whatever both machines have in common) and please post it.


3. We will attempt to restore the different original hines so the result will be an infected machine again but hopefully one that we can continue to work with.

Using Windows Explorer, (Windows Key +E), please locate and :

Double click on C:\WINDOWS\ERDNT\Hiv-backup\erdnt.exe. This should set in motionthe restoration of your original settings prior to the initial run of ComboFix.


Please keep me informed how everything is going and try to get me the last ComboFix log.


Trevuren
Groan…… I just wrote 2 paragraphs that got deleted…..

To sum up what I said….
-Symantec was running, I didn't pay any notice, cause when it asked to allow or deny, I chose allow, and combofix ran normally.

-I tried to access a different account on my dads comp, the second part of combofix ran(the part where it says its creating the log after the restart), symantec again got in the way, and I chose allow again. The computer works fine on this alternate account(jhinkids as opposed to mjhin).

-I went through the combofix log from this alternate account, and realized that the log deleted much more than I wanted. Just on the surface: all the documents, pictures, and music got deleted…. So many files got deleted that the computer freezes up when I try to copy and paste the combofix log here. So…. Heres the combofix log…. without all the files it deleted… Also you might want to note that the combofix started in one account(mjhin, my dads) and ended in the alternate account(jhin kids).

-I also couldn't find a combofixlog(2) or #2 or whatever. Only one combofixlog

- I set in motion the system restore, cause while the deletion of favorites is annoying, the loss of the pictures and music is well…. he needs them.



Anyways, Combofixlog:

ComboFix 08-03-21.1 - mjhin 2008-03-21 18:55:31.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.910 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\virus removers\ComboFix.exe
Command switches used :: C:\Documents and Settings\mjhin\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\blank.htm
C:\WINDOWS\SYSTEM32\AK083E209605E394C.lie
C:\WINDOWS\SYSTEM32\ffhkj.ini2
C:\WINDOWS\SYSTEM32\lnnmp.ini2
C:\WINDOWS\SYSTEM32\opqss.ini2
C:\WINDOWS\SYSTEM32\rqstv.ini2
.
TimedOut: progfile.dat

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

(these are the first and last files that were deleted)

C:\Documents and Settings\mjhin\Application Data\Adobe\Acrobat\7.0\AdobeCMapFnt07.lst
…
C:\Documents and Settings\mjhin\UserData\index.dat
C:\WINDOWS\SYSTEM32\AK083E209605E394C.lie
C:\WINDOWS\SYSTEM32\ffhkj.ini2
C:\WINDOWS\SYSTEM32\lnnmp.ini2
C:\WINDOWS\SYSTEM32\opqss.ini2
C:\WINDOWS\SYSTEM32\rqstv.ini2
C:\Documents and Settings\mjhin . . . . failed to delete
C:\Documents and Settings\mjhin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat . . . . failed to delete
C:\Documents and Settings\mjhin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG . . . . failed to delete
C:\Documents and Settings\mjhin\NTUSER.DAT . . . . failed to delete
C:\Documents and Settings\mjhin\ntuser.dat.LOG . . . . failed to delete
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_THREATFIRE
——-\Service_ThreatFire


((((((((((((((((((((((((( Files Created from 2008-02-23 to 2008-03-23 )))))))))))))))))))))))))))))))
.

2008-03-21 21:24 . 2008-03-21 21:24 d——– C:\SlimBrowser
2008-03-21 21:09 . 2008-03-21 21:09 1,342,469 –a—— C:\catchme.zip

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-22 02:09 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-20 17:48 ——— d—–w C:\Program Files\Spyware Doctor
2008-03-19 23:34 ——— d—–w C:\Program Files\Google
2008-03-19 17:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-03-19 17:23 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-03-19 17:14 ——— d—–w C:\Program Files\Broderbund
2008-03-08 04:46 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-03-07 00:14 ——— d—–w C:\Program Files\Norton Security Scan
2008-02-09 03:13 ——— d—–w C:\Program Files\SlimBrowser
2008-02-09 01:20 ——— d—–w C:\Program Files\iTunes
2008-02-09 01:20 ——— d—–w C:\Program Files\iPod
2008-02-09 01:14 ——— d—–w C:\Program Files\QuickTime
2008-02-09 01:06 ——— d—–w C:\Program Files\Common Files\Apple
.

((((((((((((((((((((((((((((( snapshot@2008-03-20_17.59.03.20 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-01-26 16:06:42 155,136 —-a-r C:\WINDOWS\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\accicons.exe
+ 2008-03-22 02:50:18 155,136 —-a-r C:\WINDOWS\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\accicons.exe
- 2005-01-26 16:06:42 22,528 —-a-r C:\WINDOWS\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\bindico.exe
+ 2008-03-22 02:50:18 22,528 —-a-r C:\WINDOWS\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\bindico.exe
- 2005-01-26 16:06:43 73,216 —-a-r C:\WINDOWS\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\fpicon.exe
+ 2008-03-22 02:50:18 73,216 —-a-r C:\WINDOWS\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\fpicon.exe
- 2005-01-26 16:06:42 28,160 —-a-r C:\WINDOWS\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\misc.exe
+ 2008-03-22 02:50:18 28,160 —-a-r C:\WINDOWS\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\misc.exe
- 2005-01-26 16:06:43 104,960 —-a-r C:\WINDOWS\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\outicon.exe
+ 2008-03-22 02:50:18 104,960 —-a-r C:\WINDOWS\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\outicon.exe
- 2005-01-26 16:06:43 11,264 —-a-r C:\WINDOWS\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\PEicons.exe
+ 2008-03-22 02:50:18 11,264 —-a-r C:\WINDOWS\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\PEicons.exe
- 2005-01-26 16:06:42 30,208 —-a-r C:\WINDOWS\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\pptico.exe
+ 2008-03-22 02:50:18 30,208 —-a-r C:\WINDOWS\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\pptico.exe
- 2005-01-26 16:06:42 35,328 —-a-r C:\WINDOWS\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\wordicon.exe
+ 2008-03-22 02:50:18 35,328 —-a-r C:\WINDOWS\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\wordicon.exe
- 2005-01-26 16:06:42 69,120 —-a-r C:\WINDOWS\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\xlicons.exe
+ 2008-03-22 02:50:18 69,120 —-a-r C:\WINDOWS\Installer\{00000409-78E1-11D2-B60F-006097C998E7}\xlicons.exe
+ 2008-03-23 23:31:41 16,384 –sha-w C:\WINDOWS\TEMP\Cookies\index.dat
+ 2008-03-23 23:31:41 16,384 –sha-w C:\WINDOWS\TEMP\History\History.IE5\index.dat
+ 2008-03-23 23:31:41 16,384 –sha-w C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02B2577C-3AF6-4D70-8BDB-3196F2F7998D}]
C:\WINDOWS\system32\pmnnl.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{391B174C-A6B7-C9D7-6743-01F7A0D663D6}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7996F075-3EAA-40D1-B2E3-097A4834D9D8}]
C:\WINDOWS\system32\jkhff.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AcctMgr"="C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe" [2004-08-18 12:41 586896]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-12-22 17:45 71280]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-19 08:59 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-19 08:59 126976]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2006-10-22 14:58 95960]
"StrgSync.exe"="C:\Program Files\StorageSync\StrgSync.exe" [2005-10-07 22:01 3032576]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-12 21:01 185632]
"ThreatFire"="C:\Program Files\ThreatFire\TFTray.exe" [2007-12-13 16:41 1238336]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-04 15:18 267048]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
"QD FastAndSafe"="" []

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2006-07-25 18:03 67264]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56 65588]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^1-Click Answers.lnk]
backup=C:\WINDOWS\pss\1-Click Answers.lnkCommon Startup
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\1-Click Answers.lnk

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MiniMavis.lnk]
backup=C:\WINDOWS\pss\MiniMavis.lnkCommon Startup
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MiniMavis.lnk

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
–a—— 2007-01-01 16:22 3739648 C:\Program Files\Google\Google Talk\googletalk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-02-04 15:18 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra—— 2007-08-23 00:19 23120680 C:\Program Files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2007-09-12 21:01 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2004-08-06 15:33 2502656 C:\Program Files\Yahoo!\Messenger\ypager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPodService"=3 (0x3)
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"avast! Antivirus"=2 (0x2)
"aswUpdSv"=2 (0x2)
"IDriverT"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
"LxrSG20s"=3 (0x3)
"LxrJD31s"=2 (0x2)
"CCALib8"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\SlimBrowser\\sbrowser.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R0 TfFsMon;TfFsMon;C:\WINDOWS\system32\drivers\TfFsMon.sys [2007-12-21 21:52]
R0 TfSysMon;TfSysMon;C:\WINDOWS\system32\drivers\TfSysMon.sys [2007-12-21 21:52]
R2 MIMO XR TM PCI WLService;MIMO XR TM PCI Adapter WLService;C:\Program Files\Airlink101\AWLH5025\WLService.exe [2004-03-29 17:08]
S3 LxrSG20d;LxrSG20d;C:\WINDOWS\system32\Drivers\LxrSG20d.sys [2006-08-13 16:34]
S3 PhilCam8116;Logitech QuickCam Pro 3000 (08B0);C:\WINDOWS\system32\DRIVERS\CamDrO21.sys [2001-08-17 14:05]
S3 PRISM_USB;Dell TrueMobile 1180 Wireless USB Adapter;C:\WINDOWS\system32\DRIVERS\DELUSB_51.sys [2002-08-09 15:46]
S3 TfNetMon;TfNetMon;C:\WINDOWS\system32\drivers\TfNetMon.sys [2007-12-13 16:42]
S3 ZSMC302;VIMICRO USB PC Camera;C:\WINDOWS\system32\Drivers\usbVM31b.sys [2004-09-07 03:11]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-08 17:22:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-29 21:00:00 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2006-02-14 02:30:37 C:\WINDOWS\Tasks\XoftSpy.job"
- C:\Program Files\XoftSpy\XoftSpy.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-23 18:31:23
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\Program Files\Airlink101\AWLH5025\WLanCfgG.exe
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-03-23 18:40:42 - machine was rebooted [jhinkids]
ComboFix-quarantined-files.txt 2008-03-23 23:40:38
ComboFix2.txt 2008-03-20 23:01:35
.
2008-03-14 05:02:24 — E O F —
There may be a little bit of hope for the content of your dad's profilr.

1. First, You were asked to disable your security programs before running ComboFix and based upon your above comments, Symantec was still active, thus not disabled.

2.

I set in motion the system restore, cause while the deletion of favorites is annoying, the loss of the pictures and music is well…. he needs them

.

What did you recover by invoking System Restore?


3. Please do the following to Show Hidden Files:

To enable the viewing of Hidden files follow these steps:

1. Close all programs so that you are at your desktop.
2. Double-click on the My Computer icon.
3. Select the Tools menu and click Folder Options.
4. After the new window appears select the View tab.
5. Put a checkmark in the checkbox labeled Display the contents of system folders.
6. Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
7. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
8. Remove the checkmark from the checkbox labeled Hide protected operating system files.
9. Press the Apply button and then the OK button and shutdown My Computer.
10. Now your computer is configured to show all hidden files.


4. Now using Windows Explorer, (Windows Key + E), using an Admin Account, look for the following of the following Folder under in your father's account:


C:\Documents and Settings\mjhin


5. Also, using the Windows Explorer, check C:\Qoobox for the same folder and please report back.
First off, I'd like to stress that, only my dad's profile doesnt work, the other profiles work fine.

1.How do you completely inactivate symantec? I checked the windows task manager, the apps in the bottom right hand corner of the screen, even msconfig under startup and services. Symaneec was not shown running anywhere

2. Uh, by system restore…. I meant this:

3. We will attempt to restore the different original hines so the result will be an infected machine again but hopefully one that we can continue to work with.

Using Windows Explorer, (Windows Key +E), please locate and :

Double click on C:\WINDOWS\ERDNT\Hiv-backup\erdnt.exe. This should set in motionthe restoration of your original settings prior to the initial run of ComboFix.


3. I can't show hidden files, as every time I try to change the settings, nothing happens. The settings revert back and never change.

EDIT: using the alternate account, I was able to change the settings.

C:\Documents and Settings\mjhin is present, but it is practically empty.

However I checked qoobox, and all the old C:\Documents and Settings\mjhin are there, except in .vir form. If there is someway to revert those files back, then I can just create a new account for my dad, and transfer his old documents and settings(his favorites and my documents are all that matter to him)
Yes, there is an excellent change that we can recover most of the files. Be advised, however, that we will probably also be replacing the infected files back where they were but do not worry, they can be removed later.


I need you to look in the folder C:\Qoobox and tell me under what folder heading all the good file/folders are located. From that information, I will provide you with a replacement routine. If you are unable to do the above, please then try to provide me with a screenshot of the expanded C:\Qoobox folder and perhaps I will be able to establish the folder heading myself but it is much more difficult that way.

The important thing here is to proceed slowly and surely


Trevuren
The files I would like to recover are: -C:\QooBox\Quarantine\C\Documents and Settings\mjhin\Application Data\SlimBrowser ( my dad refuses to switch to firefox, and swears by slimbrowser…. which doesnt make any sense to me, because it is just a skin for IE, but anyways…) -C:\QooBox\Quarantine\C\Documents and Settings\mjhin\Application Data\Microsoft\ -C:\QooBox\Quarantine\C\Documents and Settings\mjhin\My Documents -C:\QooBox\Quarantine\C\Documents and Settings\mjhin\Desktop -C:\QooBox\Quarantine\C\Documents and Settings\mjhin\Favorites -C:\QooBox\Quarantine\C\Documents and Settings\mjhin\NetHood I know it seems like thats basically all of the documents and settings but…. if you can teach me how to restore files, I can go through and restore files one by one. Also, I found the combofix2 that you were talking about, in the qoobox, so…. I attached it if you still want it.

Attachments:

I will be attempting to restore the whole profile, not just chosen items.

Please provide me with the entire list of folders subfolders under the following:

C:\QooBox\Quarantine\C\Documents and Settings\mjhin\



Trevuren
I was just thinking that if I only restored the files that were neccessary, then there would be no reason to revert completely, and have to re-delete the malware. But I don't completely understand the process, so that idea might not work. Its not letting me attach a picture with all the subfolders in C:\QooBox\Quarantine\C\Documents and Settings\mjhin\….. so. here goes The folders: C:\QooBox\Quarantine\C\Documents and Settings\mjhin\Application Data C:\QooBox\Quarantine\C\Documents and Settings\mjhin\Cookies C:\QooBox\Quarantine\C\Documents and Settings\mjhin\Desktop C:\QooBox\Quarantine\C\Documents and Settings\mjhin\Favorites C:\QooBox\Quarantine\C\Documents and Settings\mjhin\Local Settings C:\QooBox\Quarantine\C\Documents and Settings\mjhin\My Documents C:\QooBox\Quarantine\C\Documents and Settings\mjhin\Nethood C:\QooBox\Quarantine\C\Documents and Settings\mjhin\Recent C:\QooBox\Quarantine\C\Documents and Settings\mjhin\Registrations C:\QooBox\Quarantine\C\Documents and Settings\mjhin\SendTo C:\QooBox\Quarantine\C\Documents and Settings\mjhin\Start Menu C:\QooBox\Quarantine\C\Documents and Settings\mjhin\Templates C:\QooBox\Quarantine\C\Documents and Settings\mjhin\UserData The files: C:\QooBox\Quarantine\C\Documents and Settings\mjhin\mit.bat.vir C:\QooBox\Quarantine\C\Documents and Settings\mjhin\ntuser.dat.LOG.vir C:\QooBox\Quarantine\C\Documents and Settings\mjhin\ntuser.dat.vir C:\QooBox\Quarantine\C\Documents and Settings\mjhin\NTUSER.INI.vir C:\QooBox\Quarantine\C\Documents and Settings\mjhin\trace.log.vir
ComboFix.exe must still be on your Desktop as it was when this occurred, Is it?

1. Now create a new folder under C:\ and call it Qoobox1. So you will end up with C:\Qoobox1

2. Now copy/paste the content of C:\Qoobox to C:\Qoobox1. This way, we will have a backup of the information we want to move in case an error occurs and thus have a fallback position.

3. Please advise me when this is all done and the answer to the question posed in Part #1 of this post.. When completed, our next step will be an automated restore of the data using ComboFix and another little program that I will have you download.
When you mean combofix.exe as it was, do you mean that I should find combofix under C:\QooBox\Quarantine\C\Documents and Settings\mjhin\Desktop. There is a combofix.exe.vir inside the Qoobox\Quarantine…… Or do you mean I should find combofix on the current desktop? Because… there is no combofix currently on the desktop. The files are going to take about an hour to copy, so I'll post again when they finish. EDIT: the eta keeps fluctuating between 20 minutes and 60 minutes just fyi. So hopefully under an hour Thanks for all your help, I really appreciate the fast response times, I'm sorry my response times are not as fast.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI