This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Help removing Downloader.Mislead.App

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Delete these emails from outlook express

They are infected

[From [removed]][Date Wed, 30 Aug 2006 20:01:36 GMT]
[From [removed]][Date Thu, 31 Aug 2006 20:07:29 GMT]
[From [removed]][Date Wed, 30 Aug 2006 20:11:03 GMT]


Open up Hijackthis
Click on do a system scan only.
Place a checkmark next to these lines(if still present)

O20 - Winlogon Notify: rceqtxib - rceqtxib.dll (file missing)

Then close all windows except Hijackthis and click Fix Checked



please delete Combofix from your Desktop, also delete the QooBox Folder from youer C drive, along with any combofix logs text documents

Now please download a new copy of Combofix, this will sort out the issues your are having.


Download from one of the three below listed places and place it at your DESKTOP

Link 1
Link 2
Link 3


Please connect your all your external hard drive/flash drive before running all scans


Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan.
They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".

  • Now please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File:: 
    C:\WINDOWS\system32\rceqtxib.dll
    C:\WINDOWS\Fonts\RandFont.dll
    G:\Programs\Nero-8.2.8.0_eng_trial.exe"
    G:\Windows OneCare Backup\CHAOTIC-KEVIN\2008\Files\Part 20.ZIP
    G:\Windows OneCare Backup\CHAOTIC-KEVIN\2008\Files\Part 25.ZIP
    G:\Windows OneCare Backup\CHAOTIC-KEVIN\2008\Files\Part 28.ZIP
    
    Folder::
    C:\Program Files\NoAdware5.0
    C:\WINDOWS\SxsCaPendDel
    C:\WINDOWS\system32\5e8d0349.exe
    
    DirLook::
    C:\WINDOWS\system32\bits 
    
    Registry:: 
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rceqtxib]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\5e8d0349]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dccc2d8f-3bac-11db-9060-0013026c7717}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eb7acf81-9fad-11dc-9109-0013026c7717}]

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.


    [external image: Posted Image]


  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.


Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Note: Combofix should not be used without supervision




Please post

Combofix Log
and a new HJT Log
Thanks again, here are the new logs:

Combofix log:

ComboFix 08-04-13.1 - Kevin 2008-04-13 14:11:23.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.363 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Kevin\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\WINDOWS\Fonts\RandFont.dll
C:\WINDOWS\system32\rceqtxib.dll
G:\Programs\Nero-8.2.8.0_eng_trial.exe"
G:\Windows OneCare Backup\CHAOTIC-KEVIN\2008\Files\Part 20.ZIP
G:\Windows OneCare Backup\CHAOTIC-KEVIN\2008\Files\Part 25.ZIP
G:\Windows OneCare Backup\CHAOTIC-KEVIN\2008\Files\Part 28.ZIP
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

G:\Programs\Nero-8.2.8.0_eng_trial.exe
G:\Windows OneCare Backup\CHAOTIC-KEVIN\2008\Files\Part 20.ZIP
G:\Windows OneCare Backup\CHAOTIC-KEVIN\2008\Files\Part 25.ZIP
G:\Windows OneCare Backup\CHAOTIC-KEVIN\2008\Files\Part 28.ZIP

.
((((((((((((((((((((((((( Files Created from 2008-03-13 to 2008-04-13 )))))))))))))))))))))))))))))))
.

2008-04-12 14:11 . 2008-04-12 14:11 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-04-12 14:11 . 2008-04-12 14:11 d——– C:\WINDOWS\LastGood
2008-04-12 14:11 . 2008-04-12 14:11 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-12 13:41 . 2008-04-12 13:41 d——– C:\WINDOWS\ERUNT
2008-04-12 13:39 . 2008-04-12 13:57 d——– C:\SDFix
2008-04-06 17:54 . 2008-04-06 17:54 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-04-06 17:54 . 2008-04-06 17:54 d——– C:\Documents and Settings\Kevin\Application Data\Malwarebytes
2008-04-06 17:54 . 2008-04-06 17:54 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-06 17:49 . 2008-04-06 17:49 d——– C:\Program Files\CCleaner
2008-04-06 14:52 . 2008-04-06 14:52 5,202 –a—— C:\WINDOWS\system32\tmp.reg
2008-04-06 14:48 . 2008-04-06 14:48 d——– C:\Program Files\Trend Micro
2008-03-30 15:40 . 2008-03-30 15:34 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-03-30 15:34 . 2008-03-30 15:43 d——– C:\Documents and Settings\Kevin\.housecall6.6
2008-03-30 08:04 . 2007-11-27 22:56 116,416 –a—— C:\WINDOWS\system32\drivers\msfwhlpr.sys
2008-03-30 08:04 . 2007-11-27 22:56 91,328 –a—— C:\WINDOWS\system32\drivers\msfwdrv.sys
2008-03-30 08:03 . 2008-03-30 08:03 d——– C:\WINDOWS\system32\bits
2008-03-30 08:03 . 2007-03-29 06:56 409,600 ——— C:\WINDOWS\system32\dllcache\qmgr.dll
2008-03-30 08:03 . 2007-07-06 15:09 70,928 –a—— C:\WINDOWS\system32\drivers\MpFilter.sys
2008-03-30 08:03 . 2007-03-29 06:56 18,944 ——— C:\WINDOWS\system32\dllcache\qmgrprxy.dll
2008-03-30 08:03 . 2007-03-29 06:56 8,192 ——— C:\WINDOWS\system32\dllcache\bitsprx2.dll
2008-03-30 08:03 . 2007-03-29 06:56 7,168 ——— C:\WINDOWS\system32\dllcache\bitsprx4.dll
2008-03-30 08:03 . 2007-03-29 06:56 7,168 ——— C:\WINDOWS\system32\dllcache\bitsprx3.dll
2008-03-30 08:03 . 2007-03-29 06:56 7,168 ——— C:\WINDOWS\system32\bitsprx4.dll
2008-03-30 07:52 . 2008-04-13 13:25 d——– C:\Program Files\Microsoft Windows OneCare Live
2008-03-25 19:47 . 2008-03-30 08:23 d–h—– C:\WINDOWS\system32\.5e8d0349
2008-03-21 13:04 . 2008-03-21 13:05 d–hs—- C:\Documents and Settings\LocalService\Temporary Internet Files
2008-03-21 13:04 . 2008-03-21 13:04 d–hs—- C:\Documents and Settings\LocalService\History
2008-03-16 08:50 . 2008-03-16 08:50 d——– C:\Program Files\Active Data Recovery Software

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-12 01:29 ——— d—–w C:\Program Files\Java
2008-04-06 23:45 ——— d—–w C:\Program Files\WildTangent
2008-03-30 23:14 15,360 —-a-w C:\WINDOWS\TASKMAN.EXE
2008-03-30 23:14 15,360 —-a-w C:\WINDOWS\system32\dllcache\taskman.exe
2008-03-30 23:07 ——— d—–w C:\Program Files\Common Files\Adobe
2008-03-30 13:51 ——— d—–w C:\Program Files\Symantec
2008-03-30 13:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-21 18:20 ——— d—–w C:\Documents and Settings\Kevin\Application Data\U3
2008-03-19 09:47 1,845,248 —-a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ——w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-18 17:41 ——— d—–w C:\Program Files\MagicISO
2008-03-12 02:17 ——— d—–w C:\Program Files\CFPAS_SEPFC_2007
2008-03-03 00:45 ——— d—–w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-03-02 00:36 3,591,680 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-02-29 08:55 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-02-29 08:55 625,664 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-02-22 10:00 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-20 06:51 282,624 —-a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ——w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:32 45,568 —-a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:32 45,568 ——w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:32 148,992 ——w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-02-15 05:44 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
2006-09-18 22:25 247 -c–a-w C:\Program Files\setuplog.txt
2006-09-19 17:53 22 -csha-w C:\WINDOWS\SMINST\HPCD.sys
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\WINDOWS\system32\bits —-

2007-03-29 06:56 409600 ——— C:\WINDOWS\system32\bits\qmgr.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Location Finder"="C:\Program Files\Microsoft Location Finder\LocationFinder.exe" [2005-08-24 18:25 101080]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-14 19:45 68856]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2006-05-08 06:17 81920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-02-14 20:49 454656]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-04-15 12:26 86016]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-02 23:02 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 23:46 761948]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2006-04-11 22:54 102400]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 00:11 49152]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-03-07 14:38 131072]
"BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [2002-09-10 21:26 368706]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-10-05 22:11 866584]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 23:32 53248]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-15 03:17 1838592]
"NWEReboot"="" []
"IRIS_S2P"="C:\Program Files\Samsung\Samsung CLX-3160 Series\SPanel\PSU\Scan2pc.exe" [2006-12-07 05:02 253952]
"Samsung PanelMgr"="C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe" [2007-08-17 00:17 524288]
"NSCSysTrayUI"="C:\Program Files\Samsung\NetworkScan\NSCSysTrayUI.exe" [2006-09-14 19:16 270336]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 16:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 04:22 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"OneCareUI"="C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" [2008-01-22 19:43 67112]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-15 12:26 7561216]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 01:01 437160]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Photosmart Premier Fast Start.lnk - C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe [2005-09-24 11:39:30 73728]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Samsung\\NetworkScan\\NSCSysTrayUI.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Active Data Recovery Software\\Active UNDELETE\\UndeleteAgent.exe"=

S2 SSPORT;SSPORT;C:\WINDOWS\system32\Drivers\SSPORT.sys []
S4 5e8d0349;Microsoft DDE+ server;C:\WINDOWS\system32\.5e8d0349\5e8d0349.exe []

.
Contents of the 'Scheduled Tasks' folder
"2008-04-13 01:53:09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-13 14:14:21
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-04-13 14:14:49
ComboFix-quarantined-files.txt 2008-04-13 20:14:44
Pre-Run: 44,803,686,400 bytes free
Post-Run: 44,475,707,392 bytes free
.
2008-04-10 01:56:32 — E O F —


new HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:18:22, on 13/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Samsung\Samsung CLX-3160 Series\SPanel\PSU\Scan2pc.exe
C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe
C:\Program Files\Samsung\NetworkScan\NSCSysTrayUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Microsoft Location Finder\LocationFinder.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4nb.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://register.hp.com/servlet/WebReg.serv…&prodOS=011
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [IRIS_S2P] C:\Program Files\Samsung\Samsung CLX-3160 Series\SPanel\PSU\Scan2pc.exe
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe /autorun
O4 - HKLM\..\Run: [NSCSysTrayUI] "C:\Program Files\Samsung\NetworkScan\NSCSysTrayUI.exe" /HIDEUI
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [Microsoft Location Finder] "C:\Program Files\Microsoft Location Finder\LocationFinder.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200707…ex/qtplugin.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h20278.www2.hp.com/HPISWeb/Customer…DataManager.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase8300.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1157327505906
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

–
End of file - 9866 bytes
Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan.
They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".

  • Now please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    Folder::
    C:\WINDOWS\system32\5e8d0349

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.


    [external image: Posted Image]


  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.


Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Note: Combofix should not be used without supervision




Please run CCleaner on all user acoounts before online scan, this cuts down on scanning time and log size

Double click CCleaner icon on desktop
Click on Run Cleaner
Confirm to delete

Now close CCleaner



Go here to run an online scannner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked, and the option Scan unwanted applications is checked
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
    Copy and paste that log as a reply to this topic, along with a new HijackThis log & a description of any remaining problems

Copy and paste the report in your next post.Note: It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and to speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware application you use.



Please post back

Combofix Log
Eset online-scanner Log
A Fresh HijackThis log & a description of any remaining problems
Thanks again. Here are the log files.

Combofix Log:

ComboFix 08-04-13.1 - Kevin 2008-04-13 17:51:15.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.474 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Kevin\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-03-13 to 2008-04-13 )))))))))))))))))))))))))))))))
.

2008-04-12 14:11 . 2008-04-12 14:11 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-04-12 14:11 . 2008-04-12 14:11 d——– C:\WINDOWS\LastGood
2008-04-12 14:11 . 2008-04-12 14:11 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-12 13:41 . 2008-04-12 13:41 d——– C:\WINDOWS\ERUNT
2008-04-12 13:39 . 2008-04-12 13:57 d——– C:\SDFix
2008-04-12 13:25 . 2008-04-12 12:05 1,442,600 –a—— C:\SDFix.exe
2008-04-06 17:54 . 2008-04-06 17:54 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-04-06 17:54 . 2008-04-06 17:54 d——– C:\Documents and Settings\Kevin\Application Data\Malwarebytes
2008-04-06 17:54 . 2008-04-06 17:54 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-06 17:49 . 2008-04-06 17:49 d——– C:\Program Files\CCleaner
2008-04-06 14:52 . 2008-04-06 14:52 5,202 –a—— C:\WINDOWS\system32\tmp.reg
2008-04-06 14:48 . 2008-04-06 14:48 d——– C:\Program Files\Trend Micro
2008-03-30 15:40 . 2008-03-30 15:34 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-03-30 15:34 . 2008-03-30 15:43 d——– C:\Documents and Settings\Kevin\.housecall6.6
2008-03-30 08:04 . 2007-11-27 22:56 116,416 –a—— C:\WINDOWS\system32\drivers\msfwhlpr.sys
2008-03-30 08:04 . 2007-11-27 22:56 91,328 –a—— C:\WINDOWS\system32\drivers\msfwdrv.sys
2008-03-30 08:03 . 2008-03-30 08:03 d——– C:\WINDOWS\system32\bits
2008-03-30 08:03 . 2007-03-29 06:56 409,600 ——— C:\WINDOWS\system32\dllcache\qmgr.dll
2008-03-30 08:03 . 2007-07-06 15:09 70,928 –a—— C:\WINDOWS\system32\drivers\MpFilter.sys
2008-03-30 08:03 . 2007-03-29 06:56 18,944 ——— C:\WINDOWS\system32\dllcache\qmgrprxy.dll
2008-03-30 08:03 . 2007-03-29 06:56 8,192 ——— C:\WINDOWS\system32\dllcache\bitsprx2.dll
2008-03-30 08:03 . 2007-03-29 06:56 7,168 ——— C:\WINDOWS\system32\dllcache\bitsprx4.dll
2008-03-30 08:03 . 2007-03-29 06:56 7,168 ——— C:\WINDOWS\system32\dllcache\bitsprx3.dll
2008-03-30 08:03 . 2007-03-29 06:56 7,168 ——— C:\WINDOWS\system32\bitsprx4.dll
2008-03-30 07:52 . 2008-04-13 13:25 d——– C:\Program Files\Microsoft Windows OneCare Live
2008-03-25 19:47 . 2008-03-30 08:23 d–h—– C:\WINDOWS\system32\.5e8d0349
2008-03-21 13:04 . 2008-03-21 13:05 d–hs—- C:\Documents and Settings\LocalService\Temporary Internet Files
2008-03-21 13:04 . 2008-03-21 13:04 d–hs—- C:\Documents and Settings\LocalService\History
2008-03-16 08:50 . 2008-03-16 08:50 d——– C:\Program Files\Active Data Recovery Software

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-12 01:29 ——— d—–w C:\Program Files\Java
2008-04-06 23:45 ——— d—–w C:\Program Files\WildTangent
2008-03-30 23:14 15,360 —-a-w C:\WINDOWS\TASKMAN.EXE
2008-03-30 23:14 15,360 —-a-w C:\WINDOWS\system32\dllcache\taskman.exe
2008-03-30 23:07 ——— d—–w C:\Program Files\Common Files\Adobe
2008-03-30 13:51 ——— d—–w C:\Program Files\Symantec
2008-03-30 13:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-21 18:20 ——— d—–w C:\Documents and Settings\Kevin\Application Data\U3
2008-03-19 09:47 1,845,248 —-a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ——w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-18 17:41 ——— d—–w C:\Program Files\MagicISO
2008-03-12 02:17 ——— d—–w C:\Program Files\CFPAS_SEPFC_2007
2008-03-03 00:45 ——— d—–w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-03-02 00:36 3,591,680 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-02-29 08:55 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-02-29 08:55 625,664 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-02-22 10:00 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-20 06:51 282,624 —-a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ——w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:32 45,568 —-a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:32 45,568 ——w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:32 148,992 ——w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-02-15 05:44 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
2006-09-18 22:25 247 -c–a-w C:\Program Files\setuplog.txt
2006-09-19 17:53 22 -csha-w C:\WINDOWS\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Location Finder"="C:\Program Files\Microsoft Location Finder\LocationFinder.exe" [2005-08-24 18:25 101080]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-14 19:45 68856]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2006-05-08 06:17 81920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-02-14 20:49 454656]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-04-15 12:26 86016]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-02 23:02 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 23:46 761948]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2006-04-11 22:54 102400]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 00:11 49152]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-03-07 14:38 131072]
"BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [2002-09-10 21:26 368706]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-10-05 22:11 866584]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 23:32 53248]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-15 03:17 1838592]
"NWEReboot"="" []
"IRIS_S2P"="C:\Program Files\Samsung\Samsung CLX-3160 Series\SPanel\PSU\Scan2pc.exe" [2006-12-07 05:02 253952]
"Samsung PanelMgr"="C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe" [2007-08-17 00:17 524288]
"NSCSysTrayUI"="C:\Program Files\Samsung\NetworkScan\NSCSysTrayUI.exe" [2006-09-14 19:16 270336]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 16:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 04:22 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"OneCareUI"="C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" [2008-01-22 19:43 67112]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-15 12:26 7561216]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 01:01 437160]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Photosmart Premier Fast Start.lnk - C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe [2005-09-24 11:39:30 73728]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Samsung\\NetworkScan\\NSCSysTrayUI.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Active Data Recovery Software\\Active UNDELETE\\UndeleteAgent.exe"=

S2 SSPORT;SSPORT;C:\WINDOWS\system32\Drivers\SSPORT.sys []
S4 5e8d0349;Microsoft DDE+ server;C:\WINDOWS\system32\.5e8d0349\5e8d0349.exe []

.
Contents of the 'Scheduled Tasks' folder
"2008-04-13 01:53:09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-13 17:52:29
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-04-13 17:52:55
ComboFix-quarantined-files.txt 2008-04-13 23:52:50
ComboFix2.txt 2008-04-13 20:14:50
Pre-Run: 44,471,865,344 bytes free
Post-Run: 44,453,212,160 bytes free
.
2008-04-10 01:56:32 — E O F —


Eset onlinr-scanner Log:

# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3021 (20080412)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.064 (20070717)
# EOSSerial=14efc9c97ab19c47b67634afa8cd3990
# end=finished
# remove_checked=false
# unwanted_checked=true
# utc_time=2008-04-14 12:55:21
# local_time=2008-04-13 06:55:21 (-0700, Mountain Daylight Time)
# country="Canada"
# osver=5.1.2600 NT Service Pack 2
# scanned=420854
# found=0
# scan_time=3269

New HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:01:49, on 13/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Samsung\Samsung CLX-3160 Series\SPanel\PSU\Scan2pc.exe
C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe
C:\Program Files\Samsung\NetworkScan\NSCSysTrayUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Microsoft Location Finder\LocationFinder.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4nb.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://register.hp.com/servlet/WebReg.serv…&prodOS=011
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [IRIS_S2P] C:\Program Files\Samsung\Samsung CLX-3160 Series\SPanel\PSU\Scan2pc.exe
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe /autorun
O4 - HKLM\..\Run: [NSCSysTrayUI] "C:\Program Files\Samsung\NetworkScan\NSCSysTrayUI.exe" /HIDEUI
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [Microsoft Location Finder] "C:\Program Files\Microsoft Location Finder\LocationFinder.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200707…ex/qtplugin.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h20278.www2.hp.com/HPISWeb/Customer…DataManager.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase8300.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1157327505906
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

–
End of file - 9991 bytes


And by the way, we have had no further problems. There have been no pop ups, no false security programs and warnings, and no unexpected reboots. Thanks!
Hi Again


Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan.
They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".

  • Now please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    Folder::
    C:\WINDOWS\system32\.5e8d0349

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.


    [external image: Posted Image]


  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.


Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Note: Combofix should not be used without supervision





Please post back

Combofix Log
A Fresh HijackThis log
Hi, will do as requested when I return home again on Friday. I work away from home during the week. Thanks for the assistance.
Sorry, I apologize for not getting back to you sooner but I did not have Internet access. Both my husband Mayand I are away at the moment on courses and tasks for our jobs. I will be back 17 May and will have another look at my husband's laptop. I will let you know then how things are going. I hope that is okay. Thank you for all the assistance you have given us so far.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI