This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Baseline

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My free version keeps encountering a virus threat and prompts me to heal. When looking in the vault it says 'Generic Trojan' - Computer has been slow lately ..

Here is my HijackThis:

——————————————————–

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:08:09 AM, on 6/19/2008
Platform: Windows XP SP3, v.3244 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.3244)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Ativa\USB AWGUA54\Wireless Utility\Ativawcui.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Symantec\LiveUpdate\ALUNOTIFY.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: {f89f0e87-02d2-c67b-3e44-2c3a0dcf4b19} - {91b4fcd0-a3c2-44e3-b76c-2d2078e0f98f} - C:\WINDOWS\system32\yjywnvhf.dll (file missing)
O2 - BHO: (no name) - {BD3C6F7C-6C8D-48F6-AC52-5E4071AEB257} - C:\WINDOWS\system32\yaywwUMe.dll (file missing)
O2 - BHO: (no name) - {E9D4ECD2-EBA0-4B02-A032-014673318E08} - C:\WINDOWS\system32\ssqRHAtu.dll (file missing)
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [547760fc] rundll32.exe "C:\WINDOWS\system32\wghrafao.dll",b
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [BM57445360] Rundll32.exe "C:\WINDOWS\system32\iorwveuq.dll",s
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [Symantec NetDriver Warning] C:\PROGRA~1\SYMNET~1\SNDWarn.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Symantec NetDriver Warning] C:\PROGRA~1\SYMNET~1\SNDWarn.exe (User 'Default user')
O4 - Global Startup: Ativa Wireless USB Utility.lnk = C:\Program Files\Ativa\USB AWGUA54\Wireless Utility\Ativawcui.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: yaywwUMe - yaywwUMe.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 7311 bytes


Please help!


Thanks,

Ken
My free version keeps encountering a virus threat and prompts me to heal. When looking in the vault it says 'Generic Trojan' - Computer has been slow lately ..

Here is my HijackThis:

——————————————————–

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:08:09 AM, on 6/19/2008
Platform: Windows XP SP3, v.3244 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.3244)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Ativa\USB AWGUA54\Wireless Utility\Ativawcui.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Symantec\LiveUpdate\ALUNOTIFY.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: {f89f0e87-02d2-c67b-3e44-2c3a0dcf4b19} - {91b4fcd0-a3c2-44e3-b76c-2d2078e0f98f} - C:\WINDOWS\system32\yjywnvhf.dll (file missing)
O2 - BHO: (no name) - {BD3C6F7C-6C8D-48F6-AC52-5E4071AEB257} - C:\WINDOWS\system32\yaywwUMe.dll (file missing)
O2 - BHO: (no name) - {E9D4ECD2-EBA0-4B02-A032-014673318E08} - C:\WINDOWS\system32\ssqRHAtu.dll (file missing)
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [547760fc] rundll32.exe "C:\WINDOWS\system32\wghrafao.dll",b
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [BM57445360] Rundll32.exe "C:\WINDOWS\system32\iorwveuq.dll",s
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [Symantec NetDriver Warning] C:\PROGRA~1\SYMNET~1\SNDWarn.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Symantec NetDriver Warning] C:\PROGRA~1\SYMNET~1\SNDWarn.exe (User 'Default user')
O4 - Global Startup: Ativa Wireless USB Utility.lnk = C:\Program Files\Ativa\USB AWGUA54\Wireless Utility\Ativawcui.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: yaywwUMe - yaywwUMe.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 7311 bytes


Please help!


Thanks,

Ken
My free version keeps encountering a virus threat and prompts me to heal. When looking in the vault it says 'Generic Trojan' - Computer has been slow lately ..

Here is my HijackThis:

——————————————————–

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:08:09 AM, on 6/19/2008
Platform: Windows XP SP3, v.3244 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.3244)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Ativa\USB AWGUA54\Wireless Utility\Ativawcui.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Symantec\LiveUpdate\ALUNOTIFY.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: {f89f0e87-02d2-c67b-3e44-2c3a0dcf4b19} - {91b4fcd0-a3c2-44e3-b76c-2d2078e0f98f} - C:\WINDOWS\system32\yjywnvhf.dll (file missing)
O2 - BHO: (no name) - {BD3C6F7C-6C8D-48F6-AC52-5E4071AEB257} - C:\WINDOWS\system32\yaywwUMe.dll (file missing)
O2 - BHO: (no name) - {E9D4ECD2-EBA0-4B02-A032-014673318E08} - C:\WINDOWS\system32\ssqRHAtu.dll (file missing)
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [547760fc] rundll32.exe "C:\WINDOWS\system32\wghrafao.dll",b
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [BM57445360] Rundll32.exe "C:\WINDOWS\system32\iorwveuq.dll",s
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [Symantec NetDriver Warning] C:\PROGRA~1\SYMNET~1\SNDWarn.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Symantec NetDriver Warning] C:\PROGRA~1\SYMNET~1\SNDWarn.exe (User 'Default user')
O4 - Global Startup: Ativa Wireless USB Utility.lnk = C:\Program Files\Ativa\USB AWGUA54\Wireless Utility\Ativawcui.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: yaywwUMe - yaywwUMe.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 7311 bytes


Please help!


Thanks,

Ken
kwpask

Reply to this thread only by using the Add Reply button and do not start any New Topics The forum is very busy and we will get to you when we can.
Hello,

Welcome to the forum

Your infected with the Vundo Trojan, lets do this

Do this first…Important


Disable the TeaTimer, you can re enable it when were done if you wish

  • Run Spybot-S&D in Advanced Mode.
  • If it is not already set to do this Go to the Mode menu select "Advanced Mode"
  • On the left hand side, Click on Tools
  • Then click on the Resident Icon in the List
  • Uncheck "Resident TeaTimer" and OK any prompts.
  • Restart your computer.<–You need to do this for it to take effect


Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

O2 - BHO: {f89f0e87-02d2-c67b-3e44-2c3a0dcf4b19} - {91b4fcd0-a3c2-44e3-b76c-2d2078e0f98f} - C:\WINDOWS\system32\yjywnvhf.dll (file missing)
O2 - BHO: (no name) - {BD3C6F7C-6C8D-48F6-AC52-5E4071AEB257} - C:\WINDOWS\system32\yaywwUMe.dll (file missing)
O2 - BHO: (no name) - {E9D4ECD2-EBA0-4B02-A032-014673318E08} - C:\WINDOWS\system32\ssqRHAtu.dll (file missing)

O4 - HKLM\..\Run: [547760fc] rundll32.exe "C:\WINDOWS\system32\wghrafao.dll",b
O4 - HKLM\..\Run: [BM57445360] Rundll32.exe "C:\WINDOWS\system32\iorwveuq.dll",s

O20 - Winlogon Notify: yaywwUMe - yaywwUMe.dll (file missing)




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.<– Don't forget this
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply along with a Hijackthis log.


Post the Malwarebytes log and a New HJT log please
kwpask,.

Let me explain the way the forums work, we are all linked together helping one another with information about new threats and so fourth, we are all just a small band of volunteers trying to help as many people as we can in our spare time cleaning malware off there systems, you posted here for help also, we do not have the manpower and time to have more than one person helping you with the same problem, instead of wasting my time I could be helping someone else who is seriously infected,

http://www.techsupportforum.com/security-c…ojan-virus.html

These are your options and they make no difference to me what you decide, if you want to continue here than you have to inform the other forum that your being helped here so they can close your thread, if you want to continue with them, then you have to let me know so I can close this thread. Let me know what you decide. If I don't hear back from you in the next 24 hours with your decision I will close this thread.

Ken
I was unaware that the two forums were linked and apparently I upset the other forum to the point where they closed my forum before giving me any help. I was desperate to understand the problems with my computer, not sabotage your thread. I appreciate the hard work and dedication individuals like you provide helping in spare time and would never try to take advantage. I was just leveraging what appeared to be two different forums for two different sets of advice.
Again, I am really sorry and I apologize to anyone I inconvienenced. I would really appreciate your help in this matter if you are still willing to help me out. Thanks, Ken
here is the malware log:

Malwarebytes' Anti-Malware 1.18
Database version: 887

9:00:40 PM 6/24/2008
mbam-log-6-24-2008 (21-00-40).txt

Scan type: Quick Scan
Objects scanned: 44781
Time elapsed: 13 minute(s), 29 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\WR (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{bd3c6f7c-6c8d-48f6-ac52-5e4071aeb257} (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.







——————————————–
Here is the HijackThis log



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:02:37 PM, on 6/24/2008
Platform: Windows XP SP3, v.3244 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.3244)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Ativa\USB AWGUA54\Wireless Utility\Ativawcui.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKUS\S-1-5-18\..\Run: [Symantec NetDriver Warning] C:\PROGRA~1\SYMNET~1\SNDWarn.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Symantec NetDriver Warning] C:\PROGRA~1\SYMNET~1\SNDWarn.exe (User 'Default user')
O4 - Global Startup: Ativa Wireless USB Utility.lnk = C:\Program Files\Ativa\USB AWGUA54\Wireless Utility\Ativawcui.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

–
End of file - 6628 bytes






Thanks again for your ongoing help!



-Ken
Hello,

Just wanted you to understand about posting in the forums, the amount of people posting with infected computers is at epidemic proportions, all the forums linked together get 1000s of new log each day to fix and we are just a small army of volunteers.

Lets run this tool to make sure we are getting it all.

Download ComboFix from Here or Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post the Combofix log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
Thanks again… here is the Combofix log:



ComboFix 08-06-20.4 - Administrator 2008-06-25 8:13:13.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.197 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aslqdvmo.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\utAHRqss.ini
C:\WINDOWS\system32\utAHRqss.ini2
C:\WINDOWS\system32\wnvdxtad.ini
C:\WINDOWS\system32\yiayaibq.ini

.
((((((((((((((((((((((((( Files Created from 2008-05-25 to 2008-06-25 )))))))))))))))))))))))))))))))
.

2008-06-24 16:43 . 2008-06-24 16:43 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-06-24 16:43 . 2008-06-24 16:43 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-24 16:43 . 2008-06-24 16:43 d——– C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-06-24 16:43 . 2008-06-19 17:55 34,296 –a—— C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-24 16:43 . 2008-06-19 17:55 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-06-23 22:21 . 2008-06-23 22:21 dr-h—– C:\MSOCache
2008-06-23 21:44 . 2008-06-23 21:44 d——– C:\Deckard
2008-06-21 14:26 . 2008-06-21 14:31 d——– C:\Documents and Settings\Administrator\Application Data\ZoomBrowser EX
2008-06-21 14:23 . 2007-10-31 00:32 159,232 –a—— C:\WINDOWS\system32\ptpusd.dll
2008-06-21 14:23 . 2007-10-30 19:00 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2008-06-21 14:23 . 2007-10-30 19:00 15,104 –a–c— C:\WINDOWS\system32\dllcache\usbscan.sys
2008-06-21 14:23 . 2001-08-17 22:36 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2008-06-21 14:18 . 2008-06-21 14:26 d——– C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-06-21 14:17 . 2008-06-21 14:21 d——– C:\Program Files\Canon
2008-06-21 14:15 . 2008-06-21 14:15 d——– C:\Program Files\Common Files\Canon
2008-06-17 21:02 . 2008-06-17 21:02 d——– C:\Documents and Settings\Administrator\Application Data\Media Player Classic
2008-06-17 21:01 . 2008-06-17 21:01 d——– C:\Program Files\Essentials Codec Pack
2008-06-17 17:03 . 2007-10-31 01:32 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2008-06-15 14:31 . 2008-06-15 14:32 d——– C:\Documents and Settings\Administrator\Application Data\Move Networks
2008-06-15 11:57 . 2008-06-15 11:56 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-06-15 11:56 . 2008-06-15 11:57 d——– C:\Documents and Settings\Administrator\.housecall6.6
2008-06-15 11:55 . 2008-06-15 11:55 d——– C:\WINDOWS\Sun
2008-06-15 11:54 . 2008-03-25 02:37 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-06-15 11:53 . 2008-06-15 11:53 d——– C:\Program Files\Trend Micro
2008-06-15 11:50 . 2008-06-15 11:54 d——– C:\Program Files\Java
2008-06-15 11:49 . 2008-06-15 11:49 d——– C:\Program Files\Common Files\Java
2008-06-15 11:30 . 2008-06-24 08:48 d——– C:\WINDOWS\system32\drivers\Avg
2008-06-15 11:30 . 2008-06-15 11:30 d——– C:\Program Files\AVG
2008-06-15 11:30 . 2008-06-15 11:30 96,520 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2008-06-15 11:30 . 2008-06-15 11:30 75,272 –a—— C:\WINDOWS\system32\drivers\avgtdix.sys
2008-06-15 11:30 . 2008-06-15 11:30 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll
2008-06-15 10:49 . 2008-06-15 10:49 d——– C:\Documents and Settings\Administrator\Application Data\AVGTOOLBAR
2008-06-15 03:10 . 2008-06-15 10:44 d——– C:\WINDOWS\SxsCaPendDel
2008-06-12 17:02 . 2008-06-12 17:03 d——– C:\Program Files\Spybot - Search & Destroy
2008-06-12 17:02 . 2008-06-12 21:34 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-12 08:24 . 2008-06-20 06:24 d–h—– C:\$AVG8.VAULT$
2008-06-12 08:08 . 2008-06-15 11:30 d——– C:\Documents and Settings\All Users\Application Data\avg8
2008-06-11 17:56 . 2008-06-19 18:01 2,362 —hs—- C:\WINDOWS\system32\oafarhgw.ini
2008-06-11 12:29 . 2008-06-11 12:29 d——– C:\Program Files\AOD
2008-06-11 12:29 . 2008-06-11 12:29 d——– C:\Program Files\AIM
2008-06-11 12:29 . 2008-06-11 12:29 d——– C:\Documents and Settings\Administrator\Application Data\Aim
2008-06-11 12:29 . 2004-02-25 13:05 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2008-06-10 22:17 . 2008-06-10 22:17 d——– C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-06-10 22:15 . 2008-06-10 22:16 d——– C:\Program Files\iTunes
2008-06-10 22:15 . 2008-06-10 22:15 d——– C:\Program Files\iPod
2008-06-10 22:12 . 2008-06-10 22:14 d——– C:\Program Files\QuickTime
2008-06-10 22:12 . 2008-06-10 22:15 d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-06-10 22:11 . 2008-06-10 22:11 d——– C:\Program Files\Apple Software Update
2008-06-10 22:10 . 2008-06-10 22:10 d—-c— C:\WINDOWS\system32\DRVSTORE
2008-06-10 22:09 . 2008-06-10 22:09 d——– C:\Program Files\Common Files\Apple
2008-06-10 22:09 . 2008-06-10 22:09 d——– C:\Documents and Settings\All Users\Application Data\Apple
2008-06-10 22:07 . 2008-06-19 19:19 d——– C:\Program Files\Viewpoint
2008-06-10 22:07 . 2008-06-19 19:19 d——– C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-06-10 22:06 . 2008-06-10 22:57 d——– C:\Program Files\Common Files\AOL
2008-06-10 22:06 . 2008-06-10 22:06 d——– C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-06-10 22:06 . 2008-06-10 22:06 d——– C:\Documents and Settings\All Users\Application Data\AOL
2008-06-10 22:06 . 2008-06-10 22:07 377 –ah—– C:\IPH.PH
2008-06-10 17:32 . 2008-06-10 17:32 d——– C:\Program Files\DivXCodec
2008-06-10 17:29 . 2008-06-10 17:29 d——– C:\Program Files\Xvid
2008-06-10 17:29 . 2008-04-27 10:33 765,952 –a—— C:\WINDOWS\system32\xvidcore.dll
2008-06-10 17:29 . 2008-04-27 10:35 180,224 –a—— C:\WINDOWS\system32\xvidvfw.dll
2008-06-10 17:29 . 2007-06-28 18:55 77,824 –a—— C:\WINDOWS\system32\xvid.ax
2008-06-09 17:51 . 2008-06-12 17:53 48 –a—— C:\WINDOWS\BM57445360.xml
2008-06-09 17:19 . 2008-06-09 17:19 d——– C:\Program Files\Ativa
2008-06-09 17:19 . 2006-07-07 16:23 408,064 -ra—— C:\WINDOWS\system32\drivers\ODWGU.sys
2008-06-09 17:18 . 2008-06-09 17:18 d——– C:\WINDOWS\Downloaded Installations
2008-06-09 01:02 . 2008-06-10 14:27 69 –a—— C:\WINDOWS\NeroDigital.ini
2008-06-09 01:01 . 2007-10-30 18:47 32,128 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys
2008-06-09 01:01 . 2007-10-30 18:47 32,128 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-06-09 01:01 . 2007-10-31 00:31 21,504 –a—— C:\WINDOWS\system32\hidserv.dll
2008-06-09 01:01 . 2007-10-31 00:31 21,504 –a–c— C:\WINDOWS\system32\dllcache\hidserv.dll
2008-06-09 01:01 . 2007-10-30 18:40 14,592 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys
2008-06-09 01:01 . 2007-10-30 18:40 14,592 –a–c— C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-06-09 01:01 . 2001-08-17 13:48 12,160 –a—— C:\WINDOWS\system32\drivers\mouhid.sys
2008-06-09 01:01 . 2001-08-17 13:48 12,160 –a–c— C:\WINDOWS\system32\dllcache\mouhid.sys
2008-06-09 01:01 . 2007-10-30 18:47 10,368 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2008-06-09 01:01 . 2007-10-30 18:47 10,368 –a–c— C:\WINDOWS\system32\dllcache\hidusb.sys
2008-06-08 21:25 . 2008-06-08 21:25 0 –a—— C:\WINDOWS\system32\MSWINSCK.OCX
2008-06-08 21:22 . 2008-06-09 01:03 d——– C:\Documents and Settings\Administrator\Application Data\Ahead
2008-06-08 21:20 . 2008-06-08 21:20 d——– C:\Documents and Settings\All Users\Application Data\Ahead
2008-06-08 21:09 . 2008-06-08 21:09 d——– C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-06-08 20:57 . 2008-03-30 09:05 1,488,688 –a—— C:\WINDOWS\system32\legitcheckcontrol.dll.bak
2008-06-08 20:57 . 2008-03-30 09:06 332,672 –a—— C:\WINDOWS\system32\wgatray.exe.bak
2008-06-08 20:57 . 2008-03-30 09:06 200,064 –a—— C:\WINDOWS\system32\wgalogon.dll.bak
2008-06-08 20:56 . 2001-08-17 13:57 16,128 –a—— C:\WINDOWS\system32\drivers\MODEMCSA.sys
2008-06-08 20:56 . 2001-08-17 13:57 16,128 –a–c— C:\WINDOWS\system32\dllcache\modemcsa.sys
2008-06-08 20:55 . 2005-05-06 14:42 1,339,776 –a—— C:\WINDOWS\system32\drivers\IntelC51.sys
2008-06-08 20:55 . 2006-03-01 20:30 618,880 –a—— C:\WINDOWS\system32\drivers\IntelC52.sys
2008-06-08 20:55 . 2005-05-06 14:39 172,032 –a—— C:\WINDOWS\system32\intelmoh.dll
2008-06-08 20:55 . 2005-05-06 14:39 49,152 –a—— C:\WINDOWS\system32\mhwt.dll
2008-06-08 20:55 . 2005-05-06 14:40 47,360 –a—— C:\WINDOWS\system32\drivers\IntelC53.sys
2008-06-08 20:55 . 2005-05-06 14:40 36,880 –a—— C:\WINDOWS\system32\drivers\mohfilt.sys
2008-06-08 20:55 . 2005-05-06 14:39 33,792 –a—— C:\WINDOWS\system32\IntelCci.dll
2008-06-08 20:54 . 2008-06-08 20:54 d——– C:\dell
2008-06-08 20:44 . 2008-06-08 20:44 d——– C:\Program Files\SymNetDrv
2008-05-27 10:50 . 2008-05-27 10:50 90,112 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2008-05-27 10:50 . 2008-05-27 10:50 57,344 –a—— C:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-09 21:20 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-06-09 21:18 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-06-09 00:54 ——— d—–w C:\Program Files\Intel
2008-06-09 00:53 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-06-08 23:40 ——— d—–w C:\Program Files\Symantec
2008-06-08 23:40 ——— d—–w C:\Program Files\Norton Internet Security
2008-06-08 23:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-06-08 23:39 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Symantec
2008-06-08 23:35 ——— d—–w C:\Program Files\Analog Devices
2008-06-08 23:24 ——— d—–w C:\Program Files\microsoft frontpage
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="C:\Program Files\AIM\aim.exe" [2006-08-01 15:35 67112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-06-02 11:13 267048]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-06-15 11:30 1177368]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"Media Codec Update Service"="C:\Program Files\Essentials Codec Pack\update.exe" [2007-04-08 12:44 303104]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Symantec NetDriver Warning"="C:\PROGRA~1\SYMNET~1\SNDWarn.exe" [2004-10-29 08:52 218232]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2003-08-13 18:38 54472]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Ativa Wireless USB Utility.lnk - C:\Program Files\Ativa\USB AWGUA54\Wireless Utility\Ativawcui.exe [2006-08-29 13:28:34 1556480]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, credssp.dll, msnsspc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
–a—— 2004-12-22 17:45 71280 C:\Program Files\Common Files\Symantec Shared\ccApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
–a—— 2003-04-07 03:07 114688 C:\WINDOWS\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
–a—— 2003-04-07 03:19 155648 C:\WINDOWS\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2007-10-31 00:32 1695232 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu1044.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\URLLSTCK.exe]
–a—— 2003-10-22 12:42 70840 C:\Program Files\Norton Internet Security\UrlLstCk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Updates]
c:\windows\system\Update.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-06-15 11:30]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-06-15 11:30]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-06-15 11:30]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-06-15 11:30]
R3 ODWGU(Ativa);Ativa Wireless G USB Network Adapter(Ativa);C:\WINDOWS\system32\DRIVERS\ODWGU.sys [2006-07-07 16:23]

.
Contents of the 'Scheduled Tasks' folder
"2008-06-21 01:18:36 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/task:
"2008-06-25 12:16:50 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-25 08:17:11
Windows 5.1.2600 Service Pack 3, v.3244 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE
C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Symantec Shared\CCPROXY.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVAPSVC.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVSCAN.EXE
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-06-25 8:20:37 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-25 12:20:27

Pre-Run: 36,790,853,632 bytes free
Post-Run: 36,932,579,328 bytes free

224



———————————————-
HijackThis Log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:24:19 AM, on 6/25/2008
Platform: Windows XP SP3, v.3244 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.3244)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Ativa\USB AWGUA54\Wireless Utility\Ativawcui.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKUS\S-1-5-18\..\Run: [Symantec NetDriver Warning] C:\PROGRA~1\SYMNET~1\SNDWarn.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Symantec NetDriver Warning] C:\PROGRA~1\SYMNET~1\SNDWarn.exe (User 'Default user')
O4 - Global Startup: Ativa Wireless USB Utility.lnk = C:\Program Files\Ativa\USB AWGUA54\Wireless Utility\Ativawcui.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

–
End of file - 7019 bytes
Hi,

Open Notepad ( this will only work in Notepad ), go to Start> All Programs> Assessories> Notepad and copy all the text inside the Code box by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above File::

File::
C:\WINDOWS\system32\oafarhgw.ini
C:\WINDOWS\mrofinu1044.exe

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.




You need to enable windows to show all files and folders, instructions Here

Go to VirusTotal and submit this file for analysis, just use the browse feature and then submit , you will get a report back, post the report into this thread for me to see.

c:\windows\system\Update.exe




Post the New Combofix log, the report from VirusTotal and a new HJT log. How are things running now by the way??
Ken -

Things are running a lot smoother so far. Computer still feels like it is loading a little slower than usual, but a lot better.

Here is the Virus Total Report:





Antivirus Version Last Update Result
AhnLab-V3 2008.6.26.0 2008.06.25 -
AntiVir 7.8.0.59 2008.06.25 -
Authentium 5.1.0.4 2008.06.25 -
Avast 4.8.1195.0 2008.06.25 -
AVG 7.5.0.516 2008.06.25 -
BitDefender 7.2 2008.06.25 -
CAT-QuickHeal 9.50 2008.06.25 -
ClamAV 0.93.1 2008.06.25 -
DrWeb 4.44.0.09170 2008.06.25 -
eSafe 7.0.17.0 2008.06.25 -
eTrust-Vet 31.6.5904 2008.06.25 -
Ewido 4.0 2008.06.25 -
F-Prot 4.4.4.56 2008.06.25 -
F-Secure 7.60.13501.0 2008.06.24 -
Fortinet 3.14.0.0 2008.06.25 -
GData 2.0.7306.1023 2008.06.25 -
Ikarus T3.1.1.26.0 2008.06.25 -
Kaspersky 7.0.0.125 2008.06.25 -
McAfee 5325 2008.06.25 -
Microsoft 1.3604 2008.06.25 -
NOD32v2 3218 2008.06.25 -
Norman 5.80.02 2008.06.25 -
Panda 9.0.0.4 2008.06.25 -
Prevx1 V2 2008.06.25 -
Rising 20.50.22.00 2008.06.25 -
Sophos 4.30.0 2008.06.25 -
Sunbelt 3.0.1153.1 2008.06.15 -
Symantec 10 2008.06.25 -
TheHacker 6.2.92.361 2008.06.25 -
TrendMicro 8.700.0.1004 2008.06.25 -
VBA32 3.12.6.8 2008.06.25 -
VirusBuster 4.5.11.0 2008.06.23 -
Webwasher-Gateway 6.6.2 2008.06.25 -
Additional information
File size: 15542 bytes
MD5…: 606946341b6de4a9cd63f8706b02e039
SHA1..: 0b06dc25e1a3e77921c16d454b554cc4c46a0cb4
SHA256: 9041081d78cda2a4cfa1cc8cb11e30c92f3695e8d9b99c5c8daf8bd501e4d7a8
SHA512: 60a981cd78be68fb26f63c47e30c113385b82352d646f9b8c8bac7b59c806a66
a738b50b9b2cf75a60837087360be4771c30b552646503cc3b9adbd2587b1d7c
PEiD..: -
PEInfo: -



—————————————————–
Combox Fix Report



ComboFix 08-06-20.4 - Administrator 2008-06-25 14:29:39.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.260 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\mrofinu1044.exe
C:\WINDOWS\system32\oafarhgw.ini
.

((((((((((((((((((((((((( Files Created from 2008-05-25 to 2008-06-25 )))))))))))))))))))))))))))))))
.

2008-06-24 16:43 . 2008-06-24 16:43 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-06-24 16:43 . 2008-06-24 16:43 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-24 16:43 . 2008-06-24 16:43 d——– C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-06-24 16:43 . 2008-06-19 17:55 34,296 –a—— C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-24 16:43 . 2008-06-19 17:55 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-06-23 22:21 . 2008-06-23 22:21 dr-h—– C:\MSOCache
2008-06-23 21:44 . 2008-06-23 21:44 d——– C:\Deckard
2008-06-21 14:26 . 2008-06-21 14:31 d——– C:\Documents and Settings\Administrator\Application Data\ZoomBrowser EX
2008-06-21 14:23 . 2007-10-31 00:32 159,232 –a—— C:\WINDOWS\system32\ptpusd.dll
2008-06-21 14:23 . 2007-10-30 19:00 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2008-06-21 14:23 . 2007-10-30 19:00 15,104 –a–c— C:\WINDOWS\system32\dllcache\usbscan.sys
2008-06-21 14:23 . 2001-08-17 22:36 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2008-06-21 14:18 . 2008-06-21 14:26 d——– C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-06-21 14:17 . 2008-06-21 14:21 d——– C:\Program Files\Canon
2008-06-21 14:15 . 2008-06-21 14:15 d——– C:\Program Files\Common Files\Canon
2008-06-17 21:02 . 2008-06-17 21:02 d——– C:\Documents and Settings\Administrator\Application Data\Media Player Classic
2008-06-17 21:01 . 2008-06-17 21:01 d——– C:\Program Files\Essentials Codec Pack
2008-06-17 17:03 . 2007-10-31 01:32 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2008-06-15 14:31 . 2008-06-15 14:32 d——– C:\Documents and Settings\Administrator\Application Data\Move Networks
2008-06-15 11:57 . 2008-06-15 11:56 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-06-15 11:56 . 2008-06-15 11:57 d——– C:\Documents and Settings\Administrator\.housecall6.6
2008-06-15 11:55 . 2008-06-15 11:55 d——– C:\WINDOWS\Sun
2008-06-15 11:54 . 2008-03-25 02:37 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-06-15 11:53 . 2008-06-15 11:53 d——– C:\Program Files\Trend Micro
2008-06-15 11:50 . 2008-06-15 11:54 d——– C:\Program Files\Java
2008-06-15 11:49 . 2008-06-15 11:49 d——– C:\Program Files\Common Files\Java
2008-06-15 11:30 . 2008-06-25 08:59 d——– C:\WINDOWS\system32\drivers\Avg
2008-06-15 11:30 . 2008-06-15 11:30 d——– C:\Program Files\AVG
2008-06-15 11:30 . 2008-06-15 11:30 96,520 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2008-06-15 11:30 . 2008-06-15 11:30 75,272 –a—— C:\WINDOWS\system32\drivers\avgtdix.sys
2008-06-15 11:30 . 2008-06-15 11:30 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll
2008-06-15 10:49 . 2008-06-15 10:49 d——– C:\Documents and Settings\Administrator\Application Data\AVGTOOLBAR
2008-06-15 03:10 . 2008-06-15 10:44 d——– C:\WINDOWS\SxsCaPendDel
2008-06-12 17:02 . 2008-06-12 17:03 d——– C:\Program Files\Spybot - Search & Destroy
2008-06-12 17:02 . 2008-06-12 21:34 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-12 08:24 . 2008-06-20 06:24 d–h—– C:\$AVG8.VAULT$
2008-06-12 08:08 . 2008-06-15 11:30 d——– C:\Documents and Settings\All Users\Application Data\avg8
2008-06-11 12:29 . 2008-06-11 12:29 d——– C:\Program Files\AOD
2008-06-11 12:29 . 2008-06-11 12:29 d——– C:\Program Files\AIM
2008-06-11 12:29 . 2008-06-11 12:29 d——– C:\Documents and Settings\Administrator\Application Data\Aim
2008-06-11 12:29 . 2004-02-25 13:05 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2008-06-10 22:17 . 2008-06-10 22:17 d——– C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-06-10 22:15 . 2008-06-10 22:16 d——– C:\Program Files\iTunes
2008-06-10 22:15 . 2008-06-10 22:15 d——– C:\Program Files\iPod
2008-06-10 22:12 . 2008-06-10 22:14 d——– C:\Program Files\QuickTime
2008-06-10 22:12 . 2008-06-10 22:15 d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-06-10 22:11 . 2008-06-10 22:11 d——– C:\Program Files\Apple Software Update
2008-06-10 22:10 . 2008-06-10 22:10 d—-c— C:\WINDOWS\system32\DRVSTORE
2008-06-10 22:09 . 2008-06-10 22:09 d——– C:\Program Files\Common Files\Apple
2008-06-10 22:09 . 2008-06-10 22:09 d——– C:\Documents and Settings\All Users\Application Data\Apple
2008-06-10 22:07 . 2008-06-19 19:19 d——– C:\Program Files\Viewpoint
2008-06-10 22:07 . 2008-06-19 19:19 d——– C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-06-10 22:06 . 2008-06-10 22:57 d——– C:\Program Files\Common Files\AOL
2008-06-10 22:06 . 2008-06-10 22:06 d——– C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-06-10 22:06 . 2008-06-10 22:06 d——– C:\Documents and Settings\All Users\Application Data\AOL
2008-06-10 22:06 . 2008-06-10 22:07 377 –ah—– C:\IPH.PH
2008-06-10 17:32 . 2008-06-10 17:32 d——– C:\Program Files\DivXCodec
2008-06-10 17:29 . 2008-06-10 17:29 d——– C:\Program Files\Xvid
2008-06-10 17:29 . 2008-04-27 10:33 765,952 –a—— C:\WINDOWS\system32\xvidcore.dll
2008-06-10 17:29 . 2008-04-27 10:35 180,224 –a—— C:\WINDOWS\system32\xvidvfw.dll
2008-06-10 17:29 . 2007-06-28 18:55 77,824 –a—— C:\WINDOWS\system32\xvid.ax
2008-06-09 17:51 . 2008-06-12 17:53 48 –a—— C:\WINDOWS\BM57445360.xml
2008-06-09 17:19 . 2008-06-09 17:19 d——– C:\Program Files\Ativa
2008-06-09 17:19 . 2006-07-07 16:23 408,064 -ra—— C:\WINDOWS\system32\drivers\ODWGU.sys
2008-06-09 17:18 . 2008-06-09 17:18 d——– C:\WINDOWS\Downloaded Installations
2008-06-09 01:02 . 2008-06-10 14:27 69 –a—— C:\WINDOWS\NeroDigital.ini
2008-06-09 01:01 . 2007-10-30 18:47 32,128 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys
2008-06-09 01:01 . 2007-10-30 18:47 32,128 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-06-09 01:01 . 2007-10-31 00:31 21,504 –a—— C:\WINDOWS\system32\hidserv.dll
2008-06-09 01:01 . 2007-10-31 00:31 21,504 –a–c— C:\WINDOWS\system32\dllcache\hidserv.dll
2008-06-09 01:01 . 2007-10-30 18:40 14,592 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys
2008-06-09 01:01 . 2007-10-30 18:40 14,592 –a–c— C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-06-09 01:01 . 2001-08-17 13:48 12,160 –a—— C:\WINDOWS\system32\drivers\mouhid.sys
2008-06-09 01:01 . 2001-08-17 13:48 12,160 –a–c— C:\WINDOWS\system32\dllcache\mouhid.sys
2008-06-09 01:01 . 2007-10-30 18:47 10,368 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2008-06-09 01:01 . 2007-10-30 18:47 10,368 –a–c— C:\WINDOWS\system32\dllcache\hidusb.sys
2008-06-08 21:25 . 2008-06-08 21:25 0 –a—— C:\WINDOWS\system32\MSWINSCK.OCX
2008-06-08 21:22 . 2008-06-09 01:03 d——– C:\Documents and Settings\Administrator\Application Data\Ahead
2008-06-08 21:20 . 2008-06-08 21:20 d——– C:\Documents and Settings\All Users\Application Data\Ahead
2008-06-08 21:09 . 2008-06-08 21:09 d——– C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-06-08 20:57 . 2008-03-30 09:05 1,488,688 –a—— C:\WINDOWS\system32\legitcheckcontrol.dll.bak
2008-06-08 20:57 . 2008-03-30 09:06 332,672 –a—— C:\WINDOWS\system32\wgatray.exe.bak
2008-06-08 20:57 . 2008-03-30 09:06 200,064 –a—— C:\WINDOWS\system32\wgalogon.dll.bak
2008-06-08 20:56 . 2001-08-17 13:57 16,128 –a—— C:\WINDOWS\system32\drivers\MODEMCSA.sys
2008-06-08 20:56 . 2001-08-17 13:57 16,128 –a–c— C:\WINDOWS\system32\dllcache\modemcsa.sys
2008-06-08 20:55 . 2005-05-06 14:42 1,339,776 –a—— C:\WINDOWS\system32\drivers\IntelC51.sys
2008-06-08 20:55 . 2006-03-01 20:30 618,880 –a—— C:\WINDOWS\system32\drivers\IntelC52.sys
2008-06-08 20:55 . 2005-05-06 14:39 172,032 –a—— C:\WINDOWS\system32\intelmoh.dll
2008-06-08 20:55 . 2005-05-06 14:39 49,152 –a—— C:\WINDOWS\system32\mhwt.dll
2008-06-08 20:55 . 2005-05-06 14:40 47,360 –a—— C:\WINDOWS\system32\drivers\IntelC53.sys
2008-06-08 20:55 . 2005-05-06 14:40 36,880 –a—— C:\WINDOWS\system32\drivers\mohfilt.sys
2008-06-08 20:55 . 2005-05-06 14:39 33,792 –a—— C:\WINDOWS\system32\IntelCci.dll
2008-06-08 20:54 . 2008-06-08 20:54 d——– C:\dell
2008-06-08 20:44 . 2008-06-08 20:44 d——– C:\Program Files\SymNetDrv
2008-05-27 10:50 . 2008-05-27 10:50 90,112 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2008-05-27 10:50 . 2008-05-27 10:50 57,344 –a—— C:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-09 21:20 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-06-09 21:18 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-06-09 00:54 ——— d—–w C:\Program Files\Intel
2008-06-09 00:53 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-06-08 23:40 ——— d—–w C:\Program Files\Symantec
2008-06-08 23:40 ——— d—–w C:\Program Files\Norton Internet Security
2008-06-08 23:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-06-08 23:39 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Symantec
2008-06-08 23:35 ——— d—–w C:\Program Files\Analog Devices
2008-06-08 23:24 ——— d—–w C:\Program Files\microsoft frontpage
.

((((((((((((((((((((((((((((( snapshot@2008-06-25_ 8.19.56.92 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-25 12:16:38 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-25 18:23:18 2,048 –s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="C:\Program Files\AIM\aim.exe" [2006-08-01 15:35 67112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-06-02 11:13 267048]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-06-15 11:30 1177368]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"Media Codec Update Service"="C:\Program Files\Essentials Codec Pack\update.exe" [2007-04-08 12:44 303104]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Symantec NetDriver Warning"="C:\PROGRA~1\SYMNET~1\SNDWarn.exe" [2004-10-29 08:52 218232]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2003-08-13 18:38 54472]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Ativa Wireless USB Utility.lnk - C:\Program Files\Ativa\USB AWGUA54\Wireless Utility\Ativawcui.exe [2006-08-29 13:28:34 1556480]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, credssp.dll, msnsspc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
–a—— 2004-12-22 17:45 71280 C:\Program Files\Common Files\Symantec Shared\ccApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
–a—— 2003-04-07 03:07 114688 C:\WINDOWS\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
–a—— 2003-04-07 03:19 155648 C:\WINDOWS\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2007-10-31 00:32 1695232 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\URLLSTCK.exe]
–a—— 2003-10-22 12:42 70840 C:\Program Files\Norton Internet Security\UrlLstCk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Updates]
c:\windows\system\Update.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-06-15 11:30]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-06-15 11:30]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-06-15 11:30]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-06-15 11:30]
R3 ODWGU(Ativa);Ativa Wireless G USB Network Adapter(Ativa);C:\WINDOWS\system32\DRIVERS\ODWGU.sys [2006-07-07 16:23]

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-06-21 01:18:36 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/task:
"2008-06-25 18:23:27 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-25 14:31:18
Windows 5.1.2600 Service Pack 3, v.3244 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-25 14:32:55
ComboFix-quarantined-files.txt 2008-06-25 18:32:47
ComboFix2.txt 2008-06-25 18:08:09
ComboFix3.txt 2008-06-25 12:20:38

Pre-Run: 36,885,028,864 bytes free
Post-Run: 36,878,192,640 bytes free

205





—————————————-
Hijack This





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:47:44 PM, on 6/25/2008
Platform: Windows XP SP3, v.3244 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.3244)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKUS\S-1-5-18\..\Run: [Symantec NetDriver Warning] C:\PROGRA~1\SYMNET~1\SNDWarn.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Symantec NetDriver Warning] C:\PROGRA~1\SYMNET~1\SNDWarn.exe (User 'Default user')
O4 - Global Startup: Ativa Wireless USB Utility.lnk = C:\Program Files\Ativa\USB AWGUA54\Wireless Utility\Ativawcui.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

–
End of file - 6914 bytes











Thanks!
Ken P
Open Notepad ( This will only work with Notepad ) Go to Start> All Programs> Assessories> Notepad and copy all the text inside the Code box by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above File::

File::
c:\windows\system\Update.exe

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Updates]

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI