This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] desktop background changed to "Warning: Spyware t

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

aha, here we have a result! the clock is still on 24 hour mode should i reset it and start avast and defender again?

ComboFix 08-04-26.5 - ———— 2008-04-27 13:26:41.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1652 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\bpnvdlwd.ini
C:\WINDOWS\system32\dllcache\spoolsv.exe
C:\WINDOWS\system32\hiijmUvw.ini
C:\WINDOWS\system32\hiijmUvw.ini2
C:\WINDOWS\system32\vlmywpox.ini

.
((((((((((((((((((((((((( Files Created from 2008-03-27 to 2008-04-27 )))))))))))))))))))))))))))))))
.

2008-04-24 21:42 . 2008-04-24 22:15 d——– C:\Program Files\EsetOnlineScanner
2008-04-24 20:50 . 2004-08-04 05:00 28,288 –a–c— C:\WINDOWS\system32\dllcache\xjis.nls
2008-04-24 20:48 . 2004-08-04 05:00 13,463,552 –a–c— C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-04-24 20:47 . 2004-08-04 05:00 2,134,528 –a–c— C:\WINDOWS\system32\dllcache\smtpsnap.dll
2008-04-24 20:45 . 2008-04-24 20:45 749 -rah—– C:\WINDOWS\WindowsShell.Manifest
2008-04-24 20:45 . 2008-04-24 20:45 749 -rah—– C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-04-24 20:45 . 2008-04-24 20:45 749 -rah—– C:\WINDOWS\system32\sapi.cpl.manifest
2008-04-24 20:45 . 2008-04-24 20:45 749 -rah—– C:\WINDOWS\system32\nwc.cpl.manifest
2008-04-24 20:45 . 2008-04-24 20:45 749 -rah—– C:\WINDOWS\system32\ncpa.cpl.manifest
2008-04-24 20:45 . 2008-04-24 20:45 488 -rah—– C:\WINDOWS\system32\logonui.exe.manifest
2008-04-24 20:34 . 2004-08-04 00:56 152,576 –a—— C:\WINDOWS\system32\irftp.exe
2008-04-24 20:34 . 2004-08-04 00:56 27,136 –a—— C:\WINDOWS\system32\irmon.dll
2008-04-24 20:34 . 2004-08-04 00:56 8,192 –a—— C:\WINDOWS\system32\wshirda.dll
2008-04-24 20:29 . 2004-08-04 05:00 1,086,058 -ra—— C:\WINDOWS\SET46.tmp
2008-04-24 20:29 . 2004-08-04 05:00 1,042,903 -ra—— C:\WINDOWS\SET43.tmp
2008-04-24 20:29 . 2004-08-04 05:00 13,753 -ra—— C:\WINDOWS\SET52.tmp
2008-04-24 13:18 . 2008-04-25 23:40 2,145,386,496 –a—— C:\WINDOWS\MEMORY.DMP
2008-04-23 22:55 . 2008-04-23 22:55 d——– C:\Program Files\Common Files\Webroot Shared
2008-04-23 22:55 . 2008-04-23 22:55 d——– C:\Documents and Settings\————\Application Data\Webroot
2008-04-23 22:53 . 2005-04-20 10:34 487,936 –a—— C:\WINDOWS\system32\wwSecure.exe
2008-04-23 22:53 . 2005-04-18 13:49 57,344 –a—— C:\WINDOWS\Unwash6.exe
2008-04-23 19:30 . 2008-04-23 19:30 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-04-23 19:30 . 2008-04-23 19:30 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-22 18:44 . 2008-04-22 18:44 d——– C:\Documents and Settings\————\Application Data\Malwarebytes
2008-04-22 18:43 . 2008-04-22 18:43 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-21 20:08 . 2008-04-21 20:08 1,482 –a—— C:\WINDOWS\system32\qjveiuar.dll
2008-04-21 20:08 . 2008-04-21 20:08 1,482 –a—— C:\WINDOWS\system32\gnifujls.dll
2008-04-21 19:53 . 2004-08-04 05:00 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2008-04-21 19:51 . 2004-08-04 05:00 16,384 –a–c— C:\WINDOWS\system32\dllcache\isignup.exe
2008-04-21 19:07 . 2004-08-04 05:00 1,086,058 -ra—— C:\WINDOWS\SETB9.tmp
2008-04-21 19:07 . 2004-08-04 05:00 1,042,903 -ra—— C:\WINDOWS\SETB6.tmp
2008-04-21 19:07 . 2004-08-04 05:00 13,753 -ra—— C:\WINDOWS\SETC5.tmp
2008-04-13 23:32 . 2008-04-13 23:32 5 –a—— C:\WINDOWS\system32\SndDrv32_d.dlx
2008-04-13 23:32 . 2008-04-13 23:32 5 –ahs—- C:\WINDOWS\system32\AuxDrv32_d.dlx
2008-04-13 23:23 . 2005-08-25 18:19 115,920 –a—— C:\WINDOWS\system32\MSINET.OCX
2008-04-13 22:55 . 2008-04-23 22:55 d——– C:\Program Files\[spyscanner]
2008-04-13 22:55 . 2008-04-13 22:56 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-13 22:53 . 2008-04-13 22:53 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-04-13 17:18 . 2008-04-25 23:43 d——– C:\Program Files\hjtSpyware
2008-04-13 16:55 . 2008-04-22 19:19 d——– C:\Documents and Settings\All Users\Application Data\ktetifmn
2008-04-13 12:14 . 2008-04-13 12:14 d——– C:\WINDOWS\Sun
2008-04-12 22:08 . 2008-04-12 22:08 d——– C:\Documents and Settings\————\Application Data\Amazon
2008-04-12 13:44 . 2008-04-12 13:44 d——– C:\Program Files\NeroInstall.bak
2008-04-12 13:36 . 2008-04-12 13:36 d——– C:\Program Files\Nero
2008-04-12 13:36 . 2008-04-12 13:41 d——– C:\Program Files\Common Files\Nero
2008-04-12 12:54 . 2008-02-28 13:26 1,414,440 –a—— C:\WINDOWS\system32\ShellManager310E2D762.dll
2008-04-08 20:06 . 2008-04-08 20:06 d——– C:\Program Files\iPod
2008-03-28 23:37 . 2008-03-28 23:37 90,112 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2008-03-28 23:37 . 2008-03-28 23:37 57,344 –a—— C:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-15 01:07 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-12 20:36 ——— d—–w C:\Documents and Settings\All Users\Application Data\Nero
2008-04-09 03:06 ——— d—–w C:\Program Files\iTunes
2008-04-09 03:04 ——— d—–w C:\Program Files\QuickTime
2008-03-24 04:17 ——— d—–w C:\Program Files\NoteBurner
2008-03-24 03:39 ——— d—–w C:\Documents and Settings\————\Application Data\drms
2008-03-24 03:31 ——— d—–w C:\Program Files\Java
2008-03-24 03:29 ——— d—–w C:\Program Files\Common Files\Java
2008-03-22 02:05 ——— d—–w C:\Program Files\Family Tree Maker 2006
2008-03-22 02:02 ——— d—–w C:\Documents and Settings\————\Application Data\HP
2008-03-22 02:00 ——— d—–w C:\Documents and Settings\All Users\Application Data\HP
2008-03-22 01:59 ——— d—–w C:\Program Files\HP
2008-03-22 01:59 ——— d—–w C:\Program Files\Hewlett-Packard
2008-03-22 01:59 ——— d—–w C:\Program Files\Common Files\HP
2008-02-29 00:38 972,072 —-a-w C:\WINDOWS\UNNeroMediaHome.exe
2008-02-28 18:39 ——— d—–w C:\Documents and Settings\————\Application Data\U3
2008-02-26 23:14 972,072 —-a-w C:\WINDOWS\UNRecode.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DS Clock"="C:\Program Files\DS Clock\dsclock.exe" [2007-10-07 20:39 450560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 05:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 15:59 385024]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-03-24 16:41 5525504]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 20:20 866584]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 16:38 39264]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 17:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Common Files\\Nero\\Nero Web\\SetupX.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 11:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 11:35]
S0 ntcdrdrv;ntcdrdrv;C:\WINDOWS\system32\DRIVERS\ntcdrdrv.sys []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9a8d16bc-e292-11dc-bf9a-0010c6945ddb}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9a8d16be-e292-11dc-bf9a-0010c6945ddb}]
\Shell\AutoRun\command - H:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2008-04-26 06:46:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-04-27 14:00:53 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-27 13:28:47
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Nero\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\wwSecure.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\Setup\avast.setup
.
**************************************************************************
.
Completion time: 2008-04-27 13:32:28 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-27 20:32:24

Pre-Run: 84,898,156,544 bytes free
Post-Run: 84,893,646,848 bytes free

164 — E O F — 2008-04-27 20:12:07


Logfile of HijackThis v1.99.1
Scan saved at 13:53, on 2008-04-27
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\DS Clock\dsclock.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Nero\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\wwSecure.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\hjtSpyware\hjtSpyware.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [DS Clock] "C:\Program Files\DS Clock\dsclock.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: Washer AutoComplete (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe
bigbonelessjerk,

A. First, we must ensure that your security programs are still disabled.


B. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\WINDOWS\SET46.tmp
C:\WINDOWS\SET43.tmp
C:\WINDOWS\SET52.tmp
C:\WINDOWS\system32\qjveiuar.dll
C:\WINDOWS\system32\gnifujls.dll
C:\WINDOWS\SETB9.tmp
C:\WINDOWS\SETB6.tmp
C:\WINDOWS\SETC5.tmp

DirLook::
C:\Program Files\[spyscanner]
C:\Documents and Settings\All Users\Application Data\ktetifmn

Driver::
ntcdrdrv

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again. Do not use your computer for any other purpose while ComboFix is running.

5. All your monitoring programs (Antivirus/Antispyware, Guards and Shields) will be stopped.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


C. Using Internet Explorer, please do a Kaspersky Online Scan

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will provide a report if your system is infected. It does not provide an option to clean/disinfect. We only require a report from it.

    [external image: Posted Image]

  • Click the Save as Text button to save the file to your desktop and post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan
ComboFix 08-04-26.5 - ———- 2008-04-27 17:52:16.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1690 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\———-\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\SET43.tmp
C:\WINDOWS\SET46.tmp
C:\WINDOWS\SET52.tmp
C:\WINDOWS\SETB6.tmp
C:\WINDOWS\SETB9.tmp
C:\WINDOWS\SETC5.tmp
C:\WINDOWS\system32\gnifujls.dll
C:\WINDOWS\system32\qjveiuar.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\SET43.tmp
C:\WINDOWS\SET46.tmp
C:\WINDOWS\SET52.tmp
C:\WINDOWS\SETB6.tmp
C:\WINDOWS\SETB9.tmp
C:\WINDOWS\SETC5.tmp
C:\WINDOWS\system32\gnifujls.dll
C:\WINDOWS\system32\qjveiuar.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_ntcdrdrv


((((((((((((((((((((((((( Files Created from 2008-03-28 to 2008-04-28 )))))))))))))))))))))))))))))))
.

2008-04-24 21:42 . 2008-04-24 22:15 d——– C:\Program Files\EsetOnlineScanner
2008-04-24 20:50 . 2004-08-04 05:00 28,288 –a–c— C:\WINDOWS\system32\dllcache\xjis.nls
2008-04-24 20:48 . 2004-08-04 05:00 13,463,552 –a–c— C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-04-24 20:47 . 2004-08-04 05:00 2,134,528 –a–c— C:\WINDOWS\system32\dllcache\smtpsnap.dll
2008-04-24 20:45 . 2008-04-24 20:45 749 -rah—– C:\WINDOWS\WindowsShell.Manifest
2008-04-24 20:45 . 2008-04-24 20:45 749 -rah—– C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-04-24 20:45 . 2008-04-24 20:45 749 -rah—– C:\WINDOWS\system32\sapi.cpl.manifest
2008-04-24 20:45 . 2008-04-24 20:45 749 -rah—– C:\WINDOWS\system32\nwc.cpl.manifest
2008-04-24 20:45 . 2008-04-24 20:45 749 -rah—– C:\WINDOWS\system32\ncpa.cpl.manifest
2008-04-24 20:45 . 2008-04-24 20:45 488 -rah—– C:\WINDOWS\system32\logonui.exe.manifest
2008-04-24 20:34 . 2004-08-04 00:56 152,576 –a—— C:\WINDOWS\system32\irftp.exe
2008-04-24 20:34 . 2004-08-04 00:56 27,136 –a—— C:\WINDOWS\system32\irmon.dll
2008-04-24 20:34 . 2004-08-04 00:56 8,192 –a—— C:\WINDOWS\system32\wshirda.dll
2008-04-24 13:18 . 2008-04-25 23:40 2,145,386,496 –a—— C:\WINDOWS\MEMORY.DMP
2008-04-23 22:55 . 2008-04-23 22:55 d——– C:\Program Files\Common Files\Webroot Shared
2008-04-23 22:55 . 2008-04-23 22:55 d——– C:\Documents and Settings\———-\Application Data\Webroot
2008-04-23 22:53 . 2005-04-20 10:34 487,936 –a—— C:\WINDOWS\system32\wwSecure.exe
2008-04-23 22:53 . 2005-04-18 13:49 57,344 –a—— C:\WINDOWS\Unwash6.exe
2008-04-23 19:30 . 2008-04-23 19:30 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-04-23 19:30 . 2008-04-23 19:30 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-22 18:44 . 2008-04-22 18:44 d——– C:\Documents and Settings\———-\Application Data\Malwarebytes
2008-04-22 18:43 . 2008-04-22 18:43 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-21 19:53 . 2004-08-04 05:00 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2008-04-21 19:51 . 2004-08-04 05:00 16,384 –a–c— C:\WINDOWS\system32\dllcache\isignup.exe
2008-04-13 23:32 . 2008-04-13 23:32 5 –a—— C:\WINDOWS\system32\SndDrv32_d.dlx
2008-04-13 23:32 . 2008-04-13 23:32 5 –ahs—- C:\WINDOWS\system32\AuxDrv32_d.dlx
2008-04-13 23:23 . 2005-08-25 18:19 115,920 –a—— C:\WINDOWS\system32\MSINET.OCX
2008-04-13 22:55 . 2008-04-23 22:55 d——– C:\Program Files\[spyscanner]
2008-04-13 22:55 . 2008-04-13 22:56 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-13 22:53 . 2008-04-13 22:53 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-04-13 17:18 . 2008-04-27 13:53 d——– C:\Program Files\hjtSpyware
2008-04-13 16:55 . 2008-04-22 19:19 d——– C:\Documents and Settings\All Users\Application Data\ktetifmn
2008-04-13 12:14 . 2008-04-13 12:14 d——– C:\WINDOWS\Sun
2008-04-12 22:08 . 2008-04-12 22:08 d——– C:\Documents and Settings\———-\Application Data\Amazon
2008-04-12 13:44 . 2008-04-12 13:44 d——– C:\Program Files\NeroInstall.bak
2008-04-12 13:36 . 2008-04-12 13:36 d——– C:\Program Files\Nero
2008-04-12 13:36 . 2008-04-12 13:41 d——– C:\Program Files\Common Files\Nero
2008-04-12 12:54 . 2008-02-28 13:26 1,414,440 –a—— C:\WINDOWS\system32\ShellManager310E2D762.dll
2008-04-08 20:06 . 2008-04-08 20:06 d——– C:\Program Files\iPod
2008-03-28 23:37 . 2008-03-28 23:37 90,112 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2008-03-28 23:37 . 2008-03-28 23:37 57,344 –a—— C:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-15 01:07 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-12 20:36 ——— d—–w C:\Documents and Settings\All Users\Application Data\Nero
2008-04-09 03:06 ——— d—–w C:\Program Files\iTunes
2008-04-09 03:04 ——— d—–w C:\Program Files\QuickTime
2008-03-24 04:17 ——— d—–w C:\Program Files\NoteBurner
2008-03-24 03:39 ——— d—–w C:\Documents and Settings\———-\Application Data\drms
2008-03-24 03:31 ——— d—–w C:\Program Files\Java
2008-03-24 03:29 ——— d—–w C:\Program Files\Common Files\Java
2008-03-22 02:05 ——— d—–w C:\Program Files\Family Tree Maker 2006
2008-03-22 02:02 ——— d—–w C:\Documents and Settings\———-\Application Data\HP
2008-03-22 02:00 ——— d—–w C:\Documents and Settings\All Users\Application Data\HP
2008-03-22 01:59 ——— d—–w C:\Program Files\HP
2008-03-22 01:59 ——— d—–w C:\Program Files\Hewlett-Packard
2008-03-22 01:59 ——— d—–w C:\Program Files\Common Files\HP
2008-02-29 00:38 972,072 —-a-w C:\WINDOWS\UNNeroMediaHome.exe
2008-02-28 18:39 ——— d—–w C:\Documents and Settings\———-\Application Data\U3
2008-02-26 23:14 972,072 —-a-w C:\WINDOWS\UNRecode.exe
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\Documents and Settings\All Users\Application Data\ktetifmn —-


—- Directory of C:\Program Files\[spyscanner] —-

2008-04-23 23:11 277721 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Backups\000EBB\Entries.reg
2008-04-23 23:11 187 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Backups\000EBB\Index.dat
2008-04-23 23:11 0 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Backups\000EBB\Strings.dat
2008-04-23 23:11 0 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Backups\000EBB\Files.dat
2008-04-22 18:43 7131 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\unins000.dat
2008-04-22 18:43 10498 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\unins000.msg
2008-04-22 18:42 688760 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\unins000.exe
2008-04-14 18:07 501 –a—— C:\Program Files\[spyscanner]\SpywareBlaster\sbversion4.txt
2008-04-13 23:35 67 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Data\Windows.dat
2008-04-13 23:35 155188 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Backups\0015A1\Entries.reg
2008-04-13 23:34 180 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Backups\0015A1\Index.dat
2008-04-13 23:34 0 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Backups\0015A1\Strings.dat
2008-04-13 23:34 0 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Backups\0015A1\Files.dat
2008-04-13 23:33 30 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Data\Columns.dat
2008-04-13 23:32 402346 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Data\FileCache.dat
2008-04-13 23:32 30 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Data\Settings.dat
2008-04-13 23:30 442880 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\RegSupremePro.exe
2008-04-13 23:29 72748 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\unins000.exe
2008-04-13 23:29 3464 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\unins000.dat
2008-04-13 23:24 447558 –a—— C:\Program Files\[spyscanner]\SpywareBlaster\sbdatabase.dtb
2008-04-13 23:24 25283 –a—— C:\Program Files\[spyscanner]\SpywareBlaster\sbdatabaseinf.dtb
2008-04-13 23:24 169173 –a—— C:\Program Files\[spyscanner]\SpywareBlaster\rsdatabase.dtb
2008-04-13 23:23 4765 –a—— C:\Program Files\[spyscanner]\SpywareBlaster\unins000.dat
2008-04-13 23:22 691481 –a—— C:\Program Files\[spyscanner]\SpywareBlaster\unins000.exe
2008-04-07 20:17 65144 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\mbam.dll
2008-04-07 20:17 606600 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\comctl32.ocx
2008-04-07 20:17 57464 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\zlib.dll
2008-04-07 20:17 495224 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\vbalsgrid6.ocx
2008-04-07 20:17 44664 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\ssubtmr6.dll
2008-04-07 20:17 380536 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\mbamtrayctrl.exe
2008-04-07 20:17 36472 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\mbamext.dll
2008-04-07 20:17 27048 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\catchme.sys
2008-04-07 20:17 15864 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\mbam.sys
2008-04-07 20:17 1175160 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\mbam.exe
2008-04-07 20:17 102008 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\mbamservice.exe
2008-04-02 15:16 146334 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\Lang\ES.lslang
2008-03-25 16:25 13928 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\Languages\albanian.lng
2008-03-20 12:38 2711376 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\Ad-Aware2007.exe
2008-03-19 17:23 271712 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\upmanager.dll
2008-03-19 17:22 525664 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\Update.dll
2008-03-19 17:08 607576 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\aawservice.exe
2008-03-13 20:09 12672 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\Languages\romanian.lng
2008-03-12 20:45 12529 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\Languages\bulgarian.lng
2008-03-07 23:36 11635 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\Languages\finnish.lng
2008-03-05 17:57 12174 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\Languages\swedish.lng
2008-03-04 21:05 12595 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\Languages\catalan.lng
2008-03-04 21:03 13019 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\Languages\italian.lng
2008-03-04 21:03 12875 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\Languages\spanish.lng
2008-03-04 20:57 13353 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\Languages\french.lng
2008-03-04 20:56 13302 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\Languages\german.lng
2008-03-04 20:56 12255 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\Languages\dutch.lng
2008-03-04 20:56 12245 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\Languages\portugueseBR.lng
2008-03-04 00:28 11205 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\Languages\slovenian.lng
2008-03-03 18:39 12048 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\Languages\hungarian.lng
2008-03-03 15:52 19786 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\mbam.chm
2008-03-03 07:03 12114 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\Languages\serbian.lng
2008-03-02 20:33 11232 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\Languages\english.lng
2008-02-28 23:02 19759 –a—— C:\Program Files\[spyscanner]\SpywareBlaster\sbhelp.chm
2008-02-28 21:58 902696 –a—— C:\Program Files\[spyscanner]\SpywareBlaster\sbautoupdate.exe
2008-02-28 02:18 16545 –a—— C:\Program Files\[spyscanner]\SpywareBlaster\license.txt
2008-02-28 00:26 1320464 –a—— C:\Program Files\[spyscanner]\SpywareBlaster\spywareblaster.exe
2008-02-28 00:04 9944 –a—— C:\Program Files\[spyscanner]\SpywareBlaster\ckdatabase.dtb
2008-02-28 00:04 60 –a—— C:\Program Files\[spyscanner]\SpywareBlaster\sbdatabaseinf2.dtb
2008-02-28 00:04 60 –a—— C:\Program Files\[spyscanner]\SpywareBlaster\sbdatabase2.dtb
2008-02-28 00:04 21697 –a—— C:\Program Files\[spyscanner]\SpywareBlaster\sbinfo.dtb
2008-02-24 23:33 755 –a—— C:\Program Files\[spyscanner]\SpywareBlaster\readme.txt
2008-02-06 13:29 738664 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\CEAPI.dll
2008-02-06 12:36 153176 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\Lang\FR.lslang
2008-02-06 12:34 145298 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\Lang\EN.lslang
2008-01-31 20:45 4046 –a—— C:\Program Files\[spyscanner]\Malwarebytes' Anti-Malware\License.txt
2008-01-24 09:22 2476408 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\Ad-Watch2007.exe
2008-01-23 10:31 662644 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\Skin\Sedona.LGFF
2008-01-22 14:46 548045 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\Skin\Ad-Aware 2007 Pro Default.LGFF
2008-01-18 16:03 2332016 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\ProcessWatch.exe
2008-01-18 14:05 701776 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\lavalicense.dll
2008-01-10 10:39 1623904 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\AAWLic.exe
2008-01-09 10:27 2293112 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\HostFileEditor.exe
2008-01-08 14:40 578904 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\lavamessage.dll
2007-12-14 12:15 1899368 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\lsupdatemanager.exe
2007-09-25 09:00 255336 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\AWCCommunicatorDLL.dll
2007-09-25 09:00 238944 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\CookieBlocker.dll
2007-09-25 09:00 214352 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\AWCoreComm.dll
2007-09-25 09:00 206160 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\AWRegWatchDLL.dll
2007-09-17 15:25 202080 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\AWProcessWatch.dll
2007-09-17 12:02 907096 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\pkarchive85u.dll
2007-08-30 13:19 87392 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\AAWTray.exe
2007-07-11 14:37 274432 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\ProcessWatch.dll
2007-07-11 14:37 2001583 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\Help\Ad-Aware2007manual-EN.chm
2007-07-11 14:37 162304 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\unrar.dll
2007-06-21 09:58 44018 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\Registration\plus_home_office.prg
2007-06-21 09:55 44018 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\Registration\plus_corporate.prg
2007-06-21 09:51 44018 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\Registration\professional_corporate.prg
2007-06-01 17:52 581632 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\Registration\registration_helper.prg
2007-06-01 17:49 44018 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\Registration\professional_12_months.prg
2007-06-01 17:49 44018 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\Registration\plus_24_months.prg
2007-06-01 17:48 44018 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\Registration\plus_12_months.prg
2007-06-01 17:46 44018 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\Registration\plus_36_months.prg
2007-06-01 17:44 44018 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\Registration\professional_24_months.prg
2007-06-01 17:43 44018 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\Registration\professional_36_months.prg
2007-06-01 17:41 44018 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\Registration\professional_18_months.prg
2007-06-01 17:39 44018 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\Registration\plus_18_months.prg
2005-04-20 10:44 894464 –a—— C:\Program Files\[spyscanner]\Windows Washer\wwDisp.exe
2005-04-19 13:09 98304 –a—— C:\Program Files\[spyscanner]\Windows Washer\Languages\English.dll
2005-04-08 11:09 21 –a—— C:\Program Files\[spyscanner]\Windows Washer\Version.ini
2005-04-07 13:45 51200 –a—— C:\Program Files\[spyscanner]\Windows Washer\wwShred.exe
2005-04-07 13:45 51200 –a—— C:\Program Files\[spyscanner]\Windows Washer\WashIdx.exe
2005-04-07 13:45 44032 –a—— C:\Program Files\[spyscanner]\Windows Washer\NscpScan.exe
2005-04-07 13:45 44032 –a—— C:\Program Files\[spyscanner]\Windows Washer\NscpProf.exe
2005-04-07 13:45 37888 –a—— C:\Program Files\[spyscanner]\Windows Washer\SchdWash.exe
2005-04-07 13:45 378071 –a—— C:\Program Files\[spyscanner]\Windows Washer\Documents\Washer6.chm
2005-04-07 13:45 233472 –a—— C:\Program Files\[spyscanner]\Windows Washer\NscpWzrd.dll
2005-04-07 13:45 1474560 –a—— C:\Program Files\[spyscanner]\Windows Washer\Cache.img
2005-04-07 13:45 13795 –a—— C:\Program Files\[spyscanner]\Windows Washer\Documents\License.txt
2004-10-12 12:14 26624 –a—— C:\Program Files\[spyscanner]\Ad-Aware 2007\alert.wav
2004-07-22 17:42 442880 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\RegSupremePro.exe.bak
2004-07-22 17:26 4803 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Languages\English.lng
2004-07-22 17:09 8637 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Documentation\html\about_registry.html
2004-07-20 14:13 6683 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Documentation\html\regcleaner.html
2004-07-20 13:01 30663 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Documentation\images\regedit.jpg
2004-07-20 12:46 10727 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Documentation\images\registry1.jpg
2004-06-02 22:58 8364 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Documentation\html\reg_tools.html
2004-06-01 17:58 13653 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Documentation\License Agreement.txt
2004-05-28 22:26 123 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Data\Default IgnoreList.dat
2004-05-20 17:15 3310 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Data\MetaData4.xbin
2004-05-11 13:24 1872 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Default License.bin
2004-05-11 13:24 1872 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Data\Default License.xbin
2004-05-11 11:31 8115 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Documentation\html\FAQ.html
2004-05-10 16:17 2936 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Documentation\html\backuptool.html
2004-05-10 16:17 2151 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Documentation\index.html
2003-11-14 16:09 33 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Data\MetaData3.xbin
2003-11-14 16:09 30 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Data\MetaData2.xbin
2003-11-14 16:09 115 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Data\MetaData1.xbin
2003-05-24 01:12 1512 –a—— C:\Program Files\[spyscanner]\RegSupreme Pro\Documentation\html\style.css


((((((((((((((((((((((((((((( snapshot@2008-04-27_13.32.14.37 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-27 20:28:29 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-28 00:55:25 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2005-10-21 03:02:28 163,328 —-a-w C:\WINDOWS\ERDNT\subs\ERDNT.EXE
+ 2008-04-28 00:54:48 5,368 —-a-w C:\WINDOWS\SoftwareDistribution\EventCache\{83E0C53E-243D-451C-8138-5FF0805511B8}.bin
- 2008-04-26 20:26:05 71,710 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-04-27 20:33:05 71,710 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2008-04-26 20:26:05 442,192 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-04-27 20:33:05 442,192 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-04-28 00:55:30 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_7c8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DS Clock"="C:\Program Files\DS Clock\dsclock.exe" [2007-10-07 20:39 450560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 05:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 15:59 385024]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-03-24 16:41 5525504]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 20:20 866584]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 16:38 39264]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 17:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Common Files\\Nero\\Nero Web\\SetupX.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 11:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 11:35]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9a8d16bc-e292-11dc-bf9a-0010c6945ddb}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9a8d16be-e292-11dc-bf9a-0010c6945ddb}]
\Shell\AutoRun\command - H:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2008-04-26 06:46:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-04-27 14:00:53 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-27 17:55:44
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Nero\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\wwSecure.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\SoftwareDistribution\Download\c23140ab2b4cffaee396a230df8b1229\update\update.exe
.
**************************************************************************
.
Completion time: 2008-04-27 17:59:53 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-28 00:59:44
ComboFix2.txt 2008-04-27 20:32:28

Pre-Run: 84,625,125,376 bytes free
Post-Run: 84,495,380,480 bytes free

320 — E O F — 2008-04-27 21:45:33


Logfile of HijackThis v1.99.1
Scan saved at 18:32, on 2008-04-27
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Nero\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\wwSecure.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\DS Clock\dsclock.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\hjtSpyware\hjtSpyware.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [DS Clock] "C:\Program Files\DS Clock\dsclock.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PsExec (PSEXESVC) - Unknown owner - C:\WINDOWS\PSEXESVC.EXE (file missing)
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: Washer AutoComplete (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe


——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
2008-04-27 19:57
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 28/04/2008
Kaspersky Anti-Virus database records: 728019
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 33457
Number of viruses found: 1
Number of infected objects: 1
Number of suspicious objects: 0
Duration of the scan process: 00:35:11

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Nero\Nero8\Nero BackItUp\Cache\NeroBackItUpScheduler3.log Object is locked skipped
C:\Documents and Settings\———-\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.21291 Infected: not-virus:Hoax.Win32.Agent.by skipped
C:\Documents and Settings\———-\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\cert8.db Object is locked skipped
C:\Documents and Settings\———-\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\history.dat Object is locked skipped
C:\Documents and Settings\———-\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\key3.db Object is locked skipped
C:\Documents and Settings\———-\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\parent.lock Object is locked skipped
C:\Documents and Settings\———-\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\search.sqlite Object is locked skipped
C:\Documents and Settings\———-\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\———-\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\———-\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db Object is locked skipped
C:\Documents and Settings\———-\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db.shadow Object is locked skipped
C:\Documents and Settings\———-\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\———-\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\———-\Local Settings\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\———-\Local Settings\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\———-\Local Settings\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\———-\Local Settings\Application Data\Mozilla\Firefox\Profiles\7omdhf4a.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\———-\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\———-\Local Settings\History\History.IE5\MSHist012008042720080428\index.dat Object is locked skipped
C:\Documents and Settings\———-\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\———-\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\———-\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\Program Files\Nero\Nero\Nero8\Nero BackItUp\BIU1.txt Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{141E1845-BB88-4E8C-9A42-A67A6CBA36DA}\RP35\change.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edbtmp.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_7e8.dat Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
bigbonelessjerk,

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 6.
  • Scroll down to where it says "The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • In the pull down menu next to Platform select Windows
  • Check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement"
  • Click Continue
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u6-windows-i586-p.exe to install the newest version.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are three options in the window to clear the cache - Leave all 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.

Run this online scan Click HERE to run Panda's ActiveScan

  • You need to use IE to run this scan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report

In your next reply please post:
Panda ActiveScan report
new HijackThis log
got the java stuff done, but im getting an error trying to run the Panda scan. i registered and logged in but now ive tried to run it 5 or 6 times (complete and quick scans) and i keep getting this…
[external image: Posted Image]

heres a hjt log even though Panda didnt work.

Logfile of HijackThis v1.99.1
Scan saved at 23:28, on 2008-04-27
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Nero\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\wwSecure.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\DS Clock\dsclock.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\hjtSpyware\hjtSpyware.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [DS Clock] "C:\Program Files\DS Clock\dsclock.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PsExec (PSEXESVC) - Unknown owner - C:\WINDOWS\PSEXESVC.EXE (file missing)
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: Washer AutoComplete (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe
bigbonelessjerk,

Log looks good :D

I would suggest that you have a go with the tech team at the windows forum here because of the troubles you've had. Be sure to provide a link to this topic for them.

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • [external image: Posted Image]
The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialize and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.


Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
(Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
Without a firewall your computer is succeptible to being hacked and taken over.
I am very serious about this and see it happen almost every day with my clients.
Simply using a Firewall in its default configuration can lower your risk greatly.

For a tutorial on Firewalls and a listing of some available ones see the link below:

Understanding and Using Firewalls

Keep Microsoft Windows Updated - This will ensure your computer has always the latest security updates available installed on your computer. The easiest way to do this is to turn on Automatic Updates. Do this by:
  • From your desktop, right-click on My Computer,
  • click on Properties
  • Select the Automatic Updates tab
  • Click on Automatic
  • Click on Apply button
  • Click on OK to exit.
If there are new updates to install, install them immediately, until there are no more critical updates.

Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware

IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.

Using IE-SPYAD to help block unwanted sites and activities

Winpatrol


Update all these programs regularly - Make sure you update all the programs I have listed regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.


Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein

Please respond back that you understand the above instructions, and we'll close this thread.
understood. thanks very much Tomk. im just having issues with the windows update. it wont install automatically or manually but it keeps telling me that there are multiple updates. is this something that is better asked in the forum you mentioned or can you help me out. other than that im extremely happy to have a healthy computer once again! :D
bigbonelessjerk, I suggest you take this up in the windows software forum. They know way more about this kind of stuff than I do. There is no longer any sign of malware on your computer but I'm nervous about what it might have done to your software. I'd feel better if you checked in with the Tech Team to be sure you're ok. :thumbup: Good luck and be well.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI