This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] smacchat.com & related popups

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I use FireFox to browse the web. Always have during this install of windows. Always will. HOWEVER, I get immense amount of popups from places like smacchat.com and other sports/betting/random websites. It's wildly annoying and they only pop-up using IE even though I've got every website BLOCKED in IE except the MS update sites. Any help would be greatly appreciated and rewarded with 10000000000000000 interweb points.

Logfile of HijackThis v1.99.1
Scan saved at 2:22:13 AM, on 7/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AIM Lite\aimlite.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe
C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe
C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C2631CA-8F5E-4AFC-A050-532A8004F17D} - C:\Program Files\MSN\homerys4444.dll
O2 - BHO: (no name) - {717D27D4-6991-42F3-A26C-0039256A5372} - C:\Program Files\MSN\homerys83122.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: 0 - {95BC05B3-56AD-463E-B488-5B98FFF9539D} - C:\Program Files\ComPlus Applications\laxulitam.dll
O2 - BHO: (no name) - {9C5F4207-936C-4B08-A013-A17716F4C9E0} - C:\WINDOWS\System32\ddcyw.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu572.exe 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C88332017491394661A64DB7
C8F0287E55E246220D9E728F9FC17D446BC57D5375FB0FB68AD6
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [laim] "C:\Program Files\AIM Lite\aimlite.exe" -autorun
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
O4 - HKLM\..\Run: [Sprint SmartView] "C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" -a
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {88D8E8B7-A33B-4417-A385-8373484D43ED} (InstallHelper Class) - file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ThereInstallHelper.dll
O16 - DPF: {8B486EF6-6B2A-4A1E-BB0D-236CB2DBB8D2} (There Voice Trainer) - file://c:\Program Files\There\ThereClient\ThereVoiceTrainer.dll
O16 - DPF: {AAF421E6-7914-430A-9981-72B31AFF3BF4} (There Launcher) - file://c:\Program Files\There\ThereClient\ThereLauncher.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{976CD8D4-17D8-4BAF-A1D1-D0425ED6F965}: NameServer = 68.28.186.91 68.28.178.91
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: pmnonml - pmnonml.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - Unknown owner - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe" /n "SprintRcAppSvc (file missing)
Hello bhardman

Welcome to the Whatthetech Malware Removal Forum, sorry about the delay, but the amount of people posting with infected computers is through the roof and sometimes we can't get to logs as fast as we would like to.

Your infected with the Vundo Trojan and a few other things, what I need you to do is to drag Hijackthis to the trash as its outdated and download and install the latest version by Trendmicro and post a new log please.

Download Trendmicros Hijackthis to your desktop.
Double click it to install
Follow the prompts and by default it will install in C:\Program Files\Trendmicro\Hijackthis\Highjackthis.exe
  • Open HJT Scan and Save a Log File, it will open in Notepad
  • Go to Format and make sure Wordwrap is Unchecked
  • Go to Edit> Select All…..Edit > Copy and Paste the new log into this thread by using the Post Reply and not start a New Thread.
DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
Ken, first of all THANK YOU for your help. It is very much appreciated! Secondly, I'm definitely not worried about the delay, I completely understand and I applaud you and the others for your altruism.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:02:23 PM, on 7/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AIM Lite\aimlite.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe
C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe
C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
C:\Program Files\QuickTime\QuicktimePlayer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C2631CA-8F5E-4AFC-A050-532A8004F17D} - C:\Program Files\MSN\homerys4444.dll
O2 - BHO: (no name) - {717D27D4-6991-42F3-A26C-0039256A5372} - C:\Program Files\MSN\homerys83122.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: 0 - {95BC05B3-56AD-463E-B488-5B98FFF9539D} - C:\Program Files\ComPlus Applications\laxulitam.dll
O2 - BHO: (no name) - {9C5F4207-936C-4B08-A013-A17716F4C9E0} - C:\WINDOWS\System32\ddcyw.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu572.exe 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C88332017491394661A64DB7
C8F0287E55E246220D9E728F9FC17D446BC57D5375FB0FB68AD6
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [laim] "C:\Program Files\AIM Lite\aimlite.exe" -autorun
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
O4 - HKLM\..\Run: [Sprint SmartView] "C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" -a
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {88D8E8B7-A33B-4417-A385-8373484D43ED} (InstallHelper Class) - file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ThereInstallHelper.dll
O16 - DPF: {8B486EF6-6B2A-4A1E-BB0D-236CB2DBB8D2} (There Voice Trainer) - file://c:\Program Files\There\ThereClient\ThereVoiceTrainer.dll
O16 - DPF: {AAF421E6-7914-430A-9981-72B31AFF3BF4} (There Launcher) - file://c:\Program Files\There\ThereClient\ThereLauncher.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{976CD8D4-17D8-4BAF-A1D1-D0425ED6F965}: NameServer = 68.28.186.91 68.28.178.91
O20 - Winlogon Notify: pmnonml - pmnonml.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - PCTEL - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe

–
End of file - 6092 bytes
Hi,

Before we attack Vundo, you have a more serious issue, we need to remove the SDBot worm.


This tool needs to be run from Safemode to be effective so download it to your desktop then boot to Safemode to run it

To Enter Safemode

  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode
  • Then press the Enter Key on your Keyboard
Tutorial if you need it How to boot into Safemode


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
Ken, you're the man! Let me ask you something: how did you know that I had those problems based on viewing a few lines about my system? Just curious how your magic works.


SDFix: Version 1.207
Run by [removed] on Sun 07/20/2008 at 06:51 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :

Name :
Network Monitor

Path :
C:\Program Files\Network Monitor\netmon.exe service

Network Monitor - Deleted



Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\PROGRA~1\COMPLU~1\LAXULI~1.DLL - Deleted
C:\autorun.inf - Deleted
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt - Deleted
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt - Deleted
C:\Temp\1cb\syscheck.log - Deleted
C:\Program Files\Temporary\InsiDERInst.exe - Deleted
C:\Program Files\Temporary\kernInst.exe - Deleted
C:\WINDOWS\b122.exe - Deleted
C:\WINDOWS\b153.exe - Deleted
C:\WINDOWS\mrofinu.exe - Deleted
C:\WINDOWS\mrofinu1000106.exe - Deleted
C:\WINDOWS\mrofinu572.exe.tmp - Deleted
C:\Program Files\Network Monitor\netmon.exe - Deleted
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\removalfile.bat - Deleted
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\yazzsnet.exe - Deleted
C:\WINDOWS\system32\atmtd.dll - Deleted
C:\WINDOWS\system32\atmtd.dll._ - Deleted
C:\WINDOWS\system32\pac.txt - Deleted
C:\WINDOWS\tk58.exe - Deleted
C:\WINDOWS\TTC-4444.exe - Deleted
C:\WINDOWS\uninstall_nmon.vbs - Deleted


Could Not Remove C:\WINDOWS\system32\drivers\core.cache.dsk

Folder C:\Program Files\Network Monitor - Removed
Folder C:\Program Files\Temporary - Removed
Folder C:\Program Files\xInsIDE - Removed
Folder C:\Documents and Settings\LocalService\Application Data\NetMon - Removed
Folder C:\Temp\1cb - Removed
Folder C:\Temp\tn3 - Removed


Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-20 18:57:19
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe:*:Disabled:Orb"
"C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM"
"C:\\Program Files\\Autodesk\\Cleaner XL 1.5\\Cleaner XL.exe"="C:\\Program Files\\Autodesk\\Cleaner XL 1.5\\Cleaner XL.exe:*:Enabled:Cleaner XL"
"C:\\Program Files\\mIRC\\mirc.exe"="C:\\Program Files\\mIRC\\mirc.exe:*:Enabled:mIRC"
"C:\\Program Files\\AIM Lite\\aimlite.exe"="C:\\Program Files\\AIM Lite\\aimlite.exe:*:Enabled:aimlite"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

Remaining Files :

C:\WINDOWS\system32\drivers\core.cache.dsk Found

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Mon 14 Jan 2008 204 A.SHR — "C:\BOOT.BAK"
Wed 4 Aug 2004 93,184 A.SH. — "C:\Program Files\Internet Explorer\iexplore.exe"
Wed 13 Oct 2004 1,694,208 ..SH. — "C:\Program Files\Messenger\msmsgs.exe"
Wed 4 Aug 2004 60,416 A.SH. — "C:\Program Files\Outlook Express\msimn.exe"
Tue 2 Aug 2005 187,904 A.SHR — "C:\WINDOWS\IA\asappsrv.dll"
Tue 2 Aug 2005 293,888 A.SHR — "C:\WINDOWS\IA\command.exe"
Mon 14 Jan 2008 8 ..SHR — "C:\WINDOWS\system32\A91B63E39A.sys"
Mon 14 Jan 2008 4,184 A.SH. — "C:\WINDOWS\system32\KGyGaAvL.sys"
Mon 12 Feb 2007 3,096,576 A..H. — "C:\Documents and Settings\Administrator\Application Data\U3\temp\Launchpad Removal.exe"
Fri 20 Jun 2008 6,004 A.SH. — "C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\TempSBE\SBE152A.tmp"

Finished!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:01:52 PM, on 7/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\AIM Lite\aimlite.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe
C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C2631CA-8F5E-4AFC-A050-532A8004F17D} - C:\Program Files\MSN\homerys4444.dll
O2 - BHO: (no name) - {717D27D4-6991-42F3-A26C-0039256A5372} - C:\Program Files\MSN\homerys83122.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: 0 - {95BC05B3-56AD-463E-B488-5B98FFF9539D} - C:\Program Files\ComPlus Applications\laxulitam.dll (file missing)
O2 - BHO: (no name) - {9C5F4207-936C-4B08-A013-A17716F4C9E0} - C:\WINDOWS\System32\ddcyw.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [laim] "C:\Program Files\AIM Lite\aimlite.exe" -autorun
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
O4 - HKLM\..\Run: [Sprint SmartView] "C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" -a
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {88D8E8B7-A33B-4417-A385-8373484D43ED} (InstallHelper Class) - file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ThereInstallHelper.dll
O16 - DPF: {8B486EF6-6B2A-4A1E-BB0D-236CB2DBB8D2} (There Voice Trainer) - file://c:\Program Files\There\ThereClient\ThereVoiceTrainer.dll
O16 - DPF: {AAF421E6-7914-430A-9981-72B31AFF3BF4} (There Launcher) - file://c:\Program Files\There\ThereClient\ThereLauncher.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{976CD8D4-17D8-4BAF-A1D1-D0425ED6F965}: NameServer = 68.28.186.91 68.28.178.91
O20 - Winlogon Notify: pmnonml - pmnonml.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - PCTEL - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe

–
End of file - 5790 bytes
Great, we kicked that one in the butt :thumbup:


Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.<– Don't forget this
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply along with a New Hijackthis log.
Malwarebytes' Anti-Malware 1.22
Database version: 972
Windows 5.1.2600 Service Pack 2

9:07:30 PM 7/20/2008
mbam-log-7-20-2008 (21-07-30).txt

Scan type: Quick Scan
Objects scanned: 38776
Time elapsed: 3 minute(s), 31 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 18
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 18

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{5c2631ca-8f5e-4afc-a050-532a8004f17d} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5c2631ca-8f5e-4afc-a050-532a8004f17d} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{717d27d4-6991-42f3-a26c-0039256a5372} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{717d27d4-6991-42f3-a26c-0039256a5372} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\aldd (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\jkwslist (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\AVSystemCare (Rogue.AVSystemcare) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{98663E21-9CCE-4CF6-863C-911A9523A66F} (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\Administrator\Local Settings\Temp\NI.UGA6P_0001_N122M2210 (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nGpxx01 (Trojan.Downloader) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\crdbbhou.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uohbbdrc.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hxwfkmec.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cemkfwxh.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\usbdd.sys (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\windows (Trojan.Zapchast) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nGpxx01\nGpxx011065.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ets1\ovstadcom2.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nip4\hoftidndll3.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wnis6\enamd83122.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\MSN\homerys4444.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\MSN\homerys83122.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wvurqrs.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BMef7bdf86.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BMef7bdf86.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\iraofkrl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\core.cache.dsk (Rootkit.Agent) -> Delete on reboot.










Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:18:35 PM, on 7/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\AIM Lite\aimlite.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe
C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: 0 - {95BC05B3-56AD-463E-B488-5B98FFF9539D} - C:\Program Files\ComPlus Applications\laxulitam.dll (file missing)
O2 - BHO: (no name) - {9C5F4207-936C-4B08-A013-A17716F4C9E0} - C:\WINDOWS\System32\ddcyw.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [laim] "C:\Program Files\AIM Lite\aimlite.exe" -autorun
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
O4 - HKLM\..\Run: [Sprint SmartView] "C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" -a
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {88D8E8B7-A33B-4417-A385-8373484D43ED} (InstallHelper Class) - file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ThereInstallHelper.dll
O16 - DPF: {8B486EF6-6B2A-4A1E-BB0D-236CB2DBB8D2} (There Voice Trainer) - file://c:\Program Files\There\ThereClient\ThereVoiceTrainer.dll
O16 - DPF: {AAF421E6-7914-430A-9981-72B31AFF3BF4} (There Launcher) - file://c:\Program Files\There\ThereClient\ThereLauncher.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{976CD8D4-17D8-4BAF-A1D1-D0425ED6F965}: NameServer = 68.28.186.91 68.28.178.91
O20 - Winlogon Notify: pmnonml - pmnonml.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - PCTEL - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe

–
End of file - 5508 bytes
Good Morning,

Things are looking better. We can most times tell what your infected with by looking at lines in your HJT log, thats why we need to see it after a program is run so we can see what was removed and what has not,

Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

O2 - BHO: 0 - {95BC05B3-56AD-463E-B488-5B98FFF9539D} - C:\Program Files\ComPlus Applications\laxulitam.dll (file missing)
O2 - BHO: (no name) - {9C5F4207-936C-4B08-A013-A17716F4C9E0} - C:\WINDOWS\System32\ddcyw.dll (file missing)

O20 - Winlogon Notify: pmnonml - pmnonml.dll (file missing)






Please download ATF Cleaner by Atribune to your desktop.
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up





There may be more hiding that we can't see so run this tool please,


Download ComboFix from Here or Here to your Desktop.

In the event you already have Combofix, this is a new version that I need you to download.
It must be saved directly to your desktop.



1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan.
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again afterwards before connecting to the net


2. Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • IF you have not already done so Combofix will disconnect your machine from the Internet when it starts.
  • If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

3. Now double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze.
ComboFix 08-07-21.2 - Administrator 2008-07-24 7:22:23.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.326 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Administrator\Application Data\ASEMBL~1
C:\Documents and Settings\Administrator\Application Data\SKS~1
C:\Documents and Settings\Administrator\Application Data\SSTEM3~1
C:\Program Files\dobe~1
C:\WINDOWS\IA
C:\WINDOWS\IA\asappsrv.dll
C:\WINDOWS\IA\command.exe
C:\WINDOWS\IA\KE.vbs
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\acvtvnxs.dll
C:\WINDOWS\system32\acysvkqf.dll
C:\WINDOWS\system32\agkaflwi.ini
C:\WINDOWS\system32\akxrdkwm.ini
C:\WINDOWS\system32\aoukcbek.dll
C:\WINDOWS\system32\apcxanct.dll
C:\WINDOWS\system32\apdynxlc.ini
C:\WINDOWS\system32\appatc~1
C:\WINDOWS\system32\ayuxecuv.dll
C:\WINDOWS\system32\bfihkhcg.dll
C:\WINDOWS\system32\bgeflkxc.dll
C:\WINDOWS\system32\cfedwvlq.dll
C:\WINDOWS\system32\cholojhe.ini
C:\WINDOWS\system32\chyjscof.ini
C:\WINDOWS\system32\cmveyfjo.dll
C:\WINDOWS\system32\crcovogq.ini
C:\WINDOWS\system32\cuvigvhd.dll
C:\WINDOWS\system32\dgrfgeen.dll
C:\WINDOWS\system32\dhticbvh.dll
C:\WINDOWS\system32\doseuwqu.ini
C:\WINDOWS\system32\dpwuuhjx.ini
C:\WINDOWS\system32\dwiptorb.dll
C:\WINDOWS\system32\ejbqltdq.dll
C:\WINDOWS\system32\fkycisqt.dll
C:\WINDOWS\system32\foswaklq.ini
C:\WINDOWS\system32\fqxiygfy.dll
C:\WINDOWS\system32\guwteqqr.dll
C:\WINDOWS\system32\hefygjlf.ini
C:\WINDOWS\system32\howkqdmf.dll
C:\WINDOWS\system32\hqokdurx.dll
C:\WINDOWS\system32\htmpvukx.dll
C:\WINDOWS\system32\ihdfgxbm.ini
C:\WINDOWS\system32\iheatrsi.dll
C:\WINDOWS\system32\iwuyqpme.dll
C:\WINDOWS\system32\jgaxuiwf.ini
C:\WINDOWS\system32\jjwnrkqt.dll
C:\WINDOWS\system32\jqbixnls.dll
C:\WINDOWS\system32\ljrhedcl.dll
C:\WINDOWS\system32\lxxjrfwx.dll
C:\WINDOWS\system32\lymnupfv.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\meiiujwt.ini
C:\WINDOWS\system32\mroovibw.ini
C:\WINDOWS\system32\mrutqlqj.dll
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\msodtbpv.dll
C:\WINDOWS\system32\mtmsvolk.ini
C:\WINDOWS\system32\mvyvwysn.dll
C:\WINDOWS\system32\mxyoqojs.dll
C:\WINDOWS\system32\myhtywhl.dll
C:\WINDOWS\system32\njvxtojn.dll
C:\WINDOWS\system32\nskrvdov.ini
C:\WINDOWS\system32\ofnjvebt.ini
C:\WINDOWS\system32\oknivxby.dll
C:\WINDOWS\system32\owotjchb.dll
C:\WINDOWS\system32\oysaamjf.ini
C:\WINDOWS\system32\pofhikwg.ini
C:\WINDOWS\system32\ptyykjaq.dll
C:\WINDOWS\system32\pwqijrfp.ini
C:\WINDOWS\system32\pxdunnfy.ini
C:\WINDOWS\system32\qlqklnut.dll
C:\WINDOWS\system32\rauawqre.dll
C:\WINDOWS\system32\rfjwcmev.ini
C:\WINDOWS\system32\rulqeexa.dll
C:\WINDOWS\system32\sedaxtnx.dll
C:\WINDOWS\system32\shaiyfbb.dll
C:\WINDOWS\system32\slbgoydq.ini
C:\WINDOWS\system32\sttvacuk.dll
C:\WINDOWS\system32\synrgufc.dll
C:\WINDOWS\system32\tnjlcweg.dll
C:\WINDOWS\system32\tqsimpyg.ini
C:\WINDOWS\system32\ugnagbke.dll
C:\WINDOWS\system32\uhifmotf.dll
C:\WINDOWS\system32\ukppkhny.dll
C:\WINDOWS\system32\umbktmde.dll
C:\WINDOWS\system32\umsplvhv.dll
C:\WINDOWS\system32\upkjqbic.dll
C:\WINDOWS\system32\utdfklwl.dll
C:\WINDOWS\system32\uuqdwnor.dll
C:\WINDOWS\system32\uxobodin.ini
C:\WINDOWS\system32\vgxgatnj.dll
C:\WINDOWS\system32\vhlqfucg.ini
C:\WINDOWS\system32\viyhyokb.dll
C:\WINDOWS\system32\vunqcujk.dll
C:\WINDOWS\system32\wbghjufk.dll
C:\WINDOWS\system32\wrclmdup.ini
C:\WINDOWS\system32\wrhpxdju.ini
C:\WINDOWS\system32\wycdd.ini
C:\WINDOWS\system32\wycdd.ini2
C:\WINDOWS\system32\xaqrejyn.dll
C:\WINDOWS\system32\xbxrldrc.dll
C:\WINDOWS\system32\xfvxahju.ini
C:\WINDOWS\system32\xqbxmtyq.dll
C:\WINDOWS\system32\yhrmetbn.dll
C:\WINDOWS\system32\yjwatxdu.ini
C:\WINDOWS\system32\yvcroeko.dll
C:\WINDOWS\ymante~1

.
((((((((((((((((((((((((( Files Created from 2008-06-24 to 2008-07-24 )))))))))))))))))))))))))))))))
.

2008-07-20 20:55 . 2008-07-20 20:55 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-07-20 20:55 . 2008-07-20 20:55 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-20 20:55 . 2008-07-20 20:55 d——– C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-07-20 20:55 . 2008-07-20 20:21 38,472 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-20 20:55 . 2008-07-20 20:21 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-07-20 20:33 . 2008-06-13 07:10 272,128 —–c— C:\WINDOWS\system32\dllcache\bthport.sys
2008-07-20 18:47 . 2008-07-20 18:47 d——– C:\WINDOWS\ERUNT
2008-07-20 18:45 . 2008-07-20 18:59 d——– C:\SDFix
2008-07-20 13:01 . 2008-07-20 13:01 d——– C:\Program Files\Trend Micro
2008-07-09 20:01 . 2008-07-09 20:01 0 –ah—– C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-07-09 20:01 . 2008-07-09 20:01 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_motccgpfl_01005.Wdf
2008-07-09 20:01 . 2008-07-09 20:01 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_motccgp_01005.Wdf
2008-07-08 02:44 . 2008-07-08 02:44 d—s—- C:\Documents and Settings\Administrator\UserData
2008-07-06 15:43 . 2008-07-06 15:43 53 –a—— C:\WINDOWS\REGKEYNT.INI
2008-07-06 15:37 . 2008-07-07 17:02 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-06 15:36 . 2008-07-06 16:50 d——– C:\Program Files\NoteBurner
2008-07-06 15:36 . 2007-05-16 11:42 13,440 –a—— C:\WINDOWS\system32\drivers\ntcdrdrv.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-07 02:39 ——— d—–w C:\Documents and Settings\Administrator\Application Data\U3
2008-07-07 02:07 ——— d—–w C:\Documents and Settings\Administrator\Application Data\mIRC
2008-07-06 22:50 ——— d—–w C:\Program Files\mIRC
2008-06-20 10:45 360,320 —-a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 —-a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 —-a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 13:10 272,128 ——w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-07 05:26 ——— d—–w C:\Documents and Settings\Administrator\Application Data\OpenOffice.org2
2008-05-29 19:06 ——— d—–w C:\Program Files\Sprint
2008-05-29 19:06 ——— d—–w C:\Program Files\Sierra Wireless
2008-05-29 19:06 ——— d—–w C:\Program Files\Novatel Wireless
2008-05-29 19:06 ——— d—–w C:\Program Files\Common Files\Research in Motion
2008-05-29 19:06 ——— d—–w C:\Program Files\Common Files\Motorola Shared
2008-05-29 19:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Sprint
2008-05-28 19:29 ——— d—–w C:\Program Files\Hewlett-Packard
2008-05-28 19:28 ——— d–h–w C:\Program Files\Zenographics
2008-05-28 07:03 ——— d—–w C:\Program Files\Opera 9.5 beta
2008-05-24 07:28 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-05-24 07:28 ——— d—–w C:\Program Files\IntelliMover Data Transfer Demo
2008-05-24 07:21 ——— d—–w C:\Program Files\Symantec
2008-05-24 07:20 ——— d—–w C:\Program Files\Microsoft Works
2008-05-24 07:13 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-05-24 07:07 ——— d—–w C:\Program Files\There
2008-01-14 07:58 8 –sh–r C:\WINDOWS\system32\A91B63E39A.sys
2008-01-14 07:58 4,184 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"laim"="C:\Program Files\AIM Lite\aimlite.exe" [2007-06-07 11:11 765952]
"OrderReminder"="C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2005-03-18 17:17 98304]
"Sprint SmartView"="C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" [2008-05-20 10:55 17672]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-05-11 06:29 151597]
"AGRSMMSG"="AGRSMMSG.exe" [2004-02-28 02:07 88364 C:\WINDOWS\AGRSMMSG.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wzto]
C:\WINDOWS\system32\A?pPatch\r?ndll.exe [?]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
–a—— 2004-04-21 21:00 335872 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
–a—— 2003-08-15 01:59 70816 c:\Program Files\Common Files\Symantec Shared\ccApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
–a—— 2004-08-04 01:56 50176 C:\WINDOWS\eHome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
–a—— 1998-05-07 17:04 52736 c:\WINDOWS\system\hpsysdrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2007-12-11 12:10 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MRT]
–a—— 2008-05-09 15:35 16863864 C:\WINDOWS\system32\MRT.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
–a—— 2008-01-07 14:02 495616 C:\Program Files\Winamp Remote\bin\OrbTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-01-10 15:27 385024 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rainlendar2]
–a—— 2007-12-30 04:23 1365504 C:\Program Files\Rainlendar2\Rainlendar2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
–a—— 2004-04-14 14:43 233472 C:\WINDOWS\SMINST\Recguard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
–a—— 2003-12-18 00:31 118784 C:\WINDOWS\CREATOR\Remind_XP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-12-14 03:42 144784 C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2004-05-11 06:29 151597 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
–a—— 2003-08-19 01:01 110592 c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
–a—— 2007-12-20 09:16 37376 C:\Program Files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
–a—— 2004-02-28 02:07 88364 C:\WINDOWS\AGRSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
–a—— 2004-04-26 20:21 57344 C:\WINDOWS\ALCMTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
–a—— 2004-05-03 14:23 2533888 C:\WINDOWS\ALCWZRD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2004-05-03 12:21 67584 C:\WINDOWS\SOUNDMAN.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\AIM Lite\\aimlite.exe"=

R0 ntcdrdrv;ntcdrdrv;C:\WINDOWS\system32\DRIVERS\ntcdrdrv.sys [2007-05-16 11:42]
R3 Nmea;Sprint Connection Manager - emulates the NMEA ports;C:\WINDOWS\system32\DRIVERS\pctnullport.sys [2008-04-18 10:45]
R3 NWADI;NWADI Bus Enumerator;C:\WINDOWS\system32\DRIVERS\NWADIenum.sys [2007-09-06 15:30]
R3 swmsflt;swmsflt;C:\WINDOWS\system32\drivers\swmsflt.sys [2008-04-18 10:45]
S1 usbdd;usbdd;C:\WINDOWS\system32\drivers\usbdd.sys []
S3 motccgp;Motorola USB Composite Device Driver;C:\WINDOWS\system32\DRIVERS\motccgp.sys [2007-02-16 11:35]
S3 motccgpfl;MotCcgpFlService;C:\WINDOWS\system32\DRIVERS\motccgpfl.sys [2007-01-23 19:03]
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys [2007-10-12 16:04]
S3 SprintRcAppSvc;Sprint RcAppSvc;C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe [2008-04-18 11:43]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{464a68a0-c262-11dc-acce-00112f32b4ad}]
\Shell\AutoRun\command - H:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2008-07-19 19:02:03 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- c:\PROGRA~1\NORTON~1\Navw32.exeh/task:
.
- - - - ORPHANS REMOVED - - - -

BHO-{95BC05B3-56AD-463E-B488-5B98FFF9539D} - C:\Program Files\ComPlus Applications\laxulitam.dll
BHO-{9C5F4207-936C-4B08-A013-A17716F4C9E0} - C:\WINDOWS\System32\ddcyw.dll
Notify-pmnonml - pmnonml.dll
MSConfigStartUp-Dot1XCfg - C:\Program Files\Dot1XCfg\Dot1XCfg.exe
MSConfigStartUp-HP Component Manager - C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
MSConfigStartUp-Iaes - C:\DOCUME~1\ADMINI~1\APPLIC~1\YSTEM~1\iexplore.exe
MSConfigStartUp-KBD - C:\HP\KBD\KBD.EXE
MSConfigStartUp-PS2 - C:\WINDOWS\system32\ps2.exe
MSConfigStartUp-Sprint Connection Manager - C:\Program Files\Sprint\Connection Manager\SprintCM.exe
MSConfigStartUp-AutoTBar - AUTOTBAR.EXE


.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
R0 -: HKCU-Main,Default_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
R0 -: HKLM-Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
R0 -: HKLM-Main,Search Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000

O16 -: {88D8E8B7-A33B-4417-A385-8373484D43ED} - file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ThereInstallHelper.dll
C:\WINDOWS\Downloaded Program Files\ThereInstallHelper.dll

O16 -: {8B486EF6-6B2A-4A1E-BB0D-236CB2DBB8D2} - file://c:\Program Files\There\ThereClient\ThereVoiceTrainer.dll
C:\WINDOWS\Downloaded Program Files\ThereVoiceTrainer.dll

O16 -: {AAF421E6-7914-430A-9981-72B31AFF3BF4} - file://c:\Program Files\There\ThereClient\ThereLauncher.dll
C:\WINDOWS\Downloaded Program Files\ThereLauncher.dll


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-24 07:26:10
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-07-24 7:28:39 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-24 13:28:36

Pre-Run: 64,600,612,864 bytes free
Post-Run: 64,471,474,176 bytes free

288 — E O F — 2008-07-23 22:01:03










Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:31:33 AM, on 7/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\AIM Lite\aimlite.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe
C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe
C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [laim] "C:\Program Files\AIM Lite\aimlite.exe" -autorun
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
O4 - HKLM\..\Run: [Sprint SmartView] "C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" -a
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {88D8E8B7-A33B-4417-A385-8373484D43ED} (InstallHelper Class) - file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ThereInstallHelper.dll
O16 - DPF: {8B486EF6-6B2A-4A1E-BB0D-236CB2DBB8D2} (There Voice Trainer) - file://c:\Program Files\There\ThereClient\ThereVoiceTrainer.dll
O16 - DPF: {AAF421E6-7914-430A-9981-72B31AFF3BF4} (There Launcher) - file://c:\Program Files\There\ThereClient\ThereLauncher.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{976CD8D4-17D8-4BAF-A1D1-D0425ED6F965}: NameServer = 68.28.186.91 68.28.178.91
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - PCTEL - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe

–
End of file - 4685 bytes









Also: my C:\ drive icon is a big red X like this: [external image: Posted Image]
Hello,

Open Notepad ( this will only work in Notepad ), go to Start> All Programs> Assessories> Notepad and copy all the text inside the Code box by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above Folder::

Folder::
C:\WINDOWS\system32\A?pPatch
C:\Program Files\Rainlendar2

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wzto]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rainlendar2]

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.



This will fix the RED X

Using your mouse, Highlight and then Right-click> Copy the entire contents of the Code box below, including blank lines:
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\c]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\c\DefaultIcon]

Open a new Notepad document. (Do not use a Word Processor or WordPad). Click "Format" and be certain that Word Wrap is unchecked
Right-click > Paste the Code box contents from above into Notepad.
Click File> Save as… and enter (including quotation marks) as the filename: "RedIcon.REG".
Exit Notepad.

Double click your new file and agree to the registry merge when asked. You can then delete this new file.


Post the New Combofix log and a New HJT log and let me know how things are running now???
ComboFix 08-07-21.2 - Administrator 2008-07-26 1:37:18.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.284 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Rainlendar2
C:\Program Files\Rainlendar2\Changes.txt
C:\Program Files\Rainlendar2\Debug Rainlendar2.lnk
C:\Program Files\Rainlendar2\License.txt
C:\Program Files\Rainlendar2\msvcp71.dll
C:\Program Files\Rainlendar2\msvcr71.dll
C:\Program Files\Rainlendar2\plugins\iCalendarPlugin.dll
C:\Program Files\Rainlendar2\plugins\IniFormatPlugin.dll
C:\Program Files\Rainlendar2\Rainlendar2.exe
C:\Program Files\Rainlendar2\Rainlendar2.htb
C:\Program Files\Rainlendar2\resources\about.xrs
C:\Program Files\Rainlendar2\resources\alarm.wav
C:\Program Files\Rainlendar2\resources\alarm.xrs
C:\Program Files\Rainlendar2\resources\event.xrs
C:\Program Files\Rainlendar2\resources\manager.xrs
C:\Program Files\Rainlendar2\resources\options.xrs
C:\Program Files\Rainlendar2\resources\print.xrs
C:\Program Files\Rainlendar2\resources\resources.zrc
C:\Program Files\Rainlendar2\resources\todo.xrs
C:\Program Files\Rainlendar2\scripts\alarm.lua
C:\Program Files\Rainlendar2\scripts\calendars.lua
C:\Program Files\Rainlendar2\scripts\hotkeys.lua
C:\Program Files\Rainlendar2\scripts\months.lua
C:\Program Files\Rainlendar2\scripts\windows.lua
C:\Program Files\Rainlendar2\skins\Chromophore.r2skin
C:\Program Files\Rainlendar2\skins\Shadow4.r2skin
C:\Program Files\Rainlendar2\uninst.exe
C:\Program Files\Rainlendar2\utils\diff.exe
C:\Program Files\Rainlendar2\utils\ptch.exe
C:\Program Files\Rainlendar2\utils\Readme.txt

.
((((((((((((((((((((((((( Files Created from 2008-06-26 to 2008-07-26 )))))))))))))))))))))))))))))))
.

2008-07-24 08:39 . 2008-07-24 08:39 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-07-24 08:39 . 2008-07-24 08:39 1,409 –a—— C:\WINDOWS\QTFont.for
2008-07-20 20:55 . 2008-07-20 20:55 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-07-20 20:55 . 2008-07-20 20:55 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-20 20:55 . 2008-07-20 20:55 d——– C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-07-20 20:55 . 2008-07-20 20:21 38,472 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-20 20:55 . 2008-07-20 20:21 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-07-20 20:33 . 2008-06-13 07:10 272,128 —–c— C:\WINDOWS\system32\dllcache\bthport.sys
2008-07-20 18:47 . 2008-07-20 18:47 d——– C:\WINDOWS\ERUNT
2008-07-20 18:45 . 2008-07-20 18:59 d——– C:\SDFix
2008-07-20 13:01 . 2008-07-20 13:01 d——– C:\Program Files\Trend Micro
2008-07-09 20:01 . 2008-07-09 20:01 0 –ah—– C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-07-09 20:01 . 2008-07-09 20:01 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_motccgpfl_01005.Wdf
2008-07-09 20:01 . 2008-07-09 20:01 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_motccgp_01005.Wdf
2008-07-08 02:44 . 2008-07-08 02:44 d—s—- C:\Documents and Settings\Administrator\UserData
2008-07-06 15:43 . 2008-07-06 15:43 53 –a—— C:\WINDOWS\REGKEYNT.INI
2008-07-06 15:37 . 2008-07-07 17:02 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-06 15:36 . 2008-07-06 16:50 d——– C:\Program Files\NoteBurner
2008-07-06 15:36 . 2007-05-16 11:42 13,440 –a—— C:\WINDOWS\system32\drivers\ntcdrdrv.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-07 02:39 ——— d—–w C:\Documents and Settings\Administrator\Application Data\U3
2008-07-07 02:07 ——— d—–w C:\Documents and Settings\Administrator\Application Data\mIRC
2008-07-06 22:50 ——— d—–w C:\Program Files\mIRC
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 —-a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 —-a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 —-a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 13:10 272,128 ——w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-07 05:26 ——— d—–w C:\Documents and Settings\Administrator\Application Data\OpenOffice.org2
2008-05-29 19:06 ——— d—–w C:\Program Files\Sprint
2008-05-29 19:06 ——— d—–w C:\Program Files\Sierra Wireless
2008-05-29 19:06 ——— d—–w C:\Program Files\Novatel Wireless
2008-05-29 19:06 ——— d—–w C:\Program Files\Common Files\Research in Motion
2008-05-29 19:06 ——— d—–w C:\Program Files\Common Files\Motorola Shared
2008-05-29 19:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Sprint
2008-05-28 19:29 ——— d—–w C:\Program Files\Hewlett-Packard
2008-05-28 19:28 ——— d–h–w C:\Program Files\Zenographics
2008-05-28 07:03 ——— d—–w C:\Program Files\Opera 9.5 beta
2008-05-07 05:18 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2008-01-14 07:58 8 –sh–r C:\WINDOWS\system32\A91B63E39A.sys
2008-01-14 07:58 4,184 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"laim"="C:\Program Files\AIM Lite\aimlite.exe" [2007-06-07 11:11 765952]
"OrderReminder"="C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2005-03-18 17:17 98304]
"Sprint SmartView"="C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" [2008-05-20 10:55 17672]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-05-11 06:29 151597]
"AGRSMMSG"="AGRSMMSG.exe" [2004-02-28 02:07 88364 C:\WINDOWS\AGRSMMSG.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
–a—— 2004-04-21 21:00 335872 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
–a—— 2003-08-15 01:59 70816 c:\Program Files\Common Files\Symantec Shared\ccApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
–a—— 2004-08-04 01:56 50176 C:\WINDOWS\eHome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
–a—— 1998-05-07 17:04 52736 c:\WINDOWS\system\hpsysdrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2007-12-11 12:10 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MRT]
–a—— 2008-05-09 15:35 16863864 C:\WINDOWS\system32\MRT.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
–a—— 2008-01-07 14:02 495616 C:\Program Files\Winamp Remote\bin\OrbTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-01-10 15:27 385024 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
–a—— 2004-04-14 14:43 233472 C:\WINDOWS\SMINST\Recguard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
–a—— 2003-12-18 00:31 118784 C:\WINDOWS\CREATOR\Remind_XP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-12-14 03:42 144784 C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2004-05-11 06:29 151597 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
–a—— 2003-08-19 01:01 110592 c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
–a—— 2007-12-20 09:16 37376 C:\Program Files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
–a—— 2004-02-28 02:07 88364 C:\WINDOWS\AGRSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
–a—— 2004-04-26 20:21 57344 C:\WINDOWS\ALCMTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
–a—— 2004-05-03 14:23 2533888 C:\WINDOWS\ALCWZRD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2004-05-03 12:21 67584 C:\WINDOWS\SOUNDMAN.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\AIM Lite\\aimlite.exe"=

R0 ntcdrdrv;ntcdrdrv;C:\WINDOWS\system32\DRIVERS\ntcdrdrv.sys [2007-05-16 11:42]
R3 Nmea;Sprint Connection Manager - emulates the NMEA ports;C:\WINDOWS\system32\DRIVERS\pctnullport.sys [2008-04-18 10:45]
R3 NWADI;NWADI Bus Enumerator;C:\WINDOWS\system32\DRIVERS\NWADIenum.sys [2007-09-06 15:30]
R3 swmsflt;swmsflt;C:\WINDOWS\system32\drivers\swmsflt.sys [2008-04-18 10:45]
S1 usbdd;usbdd;C:\WINDOWS\system32\drivers\usbdd.sys []
S3 motccgp;Motorola USB Composite Device Driver;C:\WINDOWS\system32\DRIVERS\motccgp.sys [2007-02-16 11:35]
S3 motccgpfl;MotCcgpFlService;C:\WINDOWS\system32\DRIVERS\motccgpfl.sys [2007-01-23 19:03]
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys [2007-10-12 16:04]
S3 SprintRcAppSvc;Sprint RcAppSvc;C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe [2008-04-18 11:43]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{464a68a0-c262-11dc-acce-00112f32b4ad}]
\Shell\AutoRun\command - H:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2008-07-26 05:52:14 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- c:\PROGRA~1\NORTON~1\Navw32.exeh/task:
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-26 01:38:42
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
Completion time: 2008-07-26 1:39:37
ComboFix-quarantined-files.txt 2008-07-26 07:39:26
ComboFix2.txt 2008-07-24 13:28:40

Pre-Run: 64,752,312,320 bytes free
Post-Run: 64,737,017,856 bytes free

173 — E O F — 2008-07-23 22:01:03









Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:40:12 AM, on 7/26/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\AIM Lite\aimlite.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Winamp\winamp.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe
C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe
C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [laim] "C:\Program Files\AIM Lite\aimlite.exe" -autorun
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
O4 - HKLM\..\Run: [Sprint SmartView] "C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" -a
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {88D8E8B7-A33B-4417-A385-8373484D43ED} (InstallHelper Class) - file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ThereInstallHelper.dll
O16 - DPF: {8B486EF6-6B2A-4A1E-BB0D-236CB2DBB8D2} (There Voice Trainer) - file://c:\Program Files\There\ThereClient\ThereVoiceTrainer.dll
O16 - DPF: {AAF421E6-7914-430A-9981-72B31AFF3BF4} (There Launcher) - file://c:\Program Files\There\ThereClient\ThereLauncher.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - PCTEL - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe

–
End of file - 4619 bytes
















Everything seems to be fine now. Thanks for everything! Though, I know we're not done until you tell me.
Good Morning,

Things are looking good, THERE seems to use quite a bit of system resources so if you don't use it I would uninstall it via the Add Remove programs in the Control Panel.

I also see Norton Anti Virus on your system but it looks like its not running, is it out of date and disabled. I can link you to some free ones if you need one.

The rest of your log looks fine :thumbup:
Hi,

Hijackthis <– You can keep or delete it, lets hope you won't need it in the future, if you do, you can always redownload it

ATF Cleaner <– Yours to keep, run it now and then to clean out the clutter.

Malwarebytes
<– Yours to keep also, check for updates and run a scan now and then.

Combofix Is not a general cleaning tool, just run it with supervision or you can bork your system

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.


    • [external image: Posted Image]

  • When shown the disclaimer, Select "2"

The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.


  • How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • WhattheTech
  • TonyKlein CastleCops
  • Grinler BleepingComputer
  • GeeksTo Go
  • Dslreports


Safe Surfn
Ken

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI