This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] computer infected, log looks clean

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Problem started about a week ago, out of the blue. I'm not on my computer all the time and other people use it, so I'm guessing somebody pressed OK on something they shouldn't have. HJT log appears clean, NOD32 founds many many infections, adaware and spybot both just came up with cookies. Here are some logs.

HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:08:46 AM, on 7/26/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Administrator\Desktop\spyware\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: solution Class - {99C6D1BB-7555-474C-91DA-D8FB62A9CC75} - C:\WINDOWS\system32\b2E2c4OA.dll (file missing)
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4A27027D-9371-47B2-A07A-1B5CC3A6F3B3}: NameServer = 192.168.1.1
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

–
End of file - 2674 bytes

NOD32:

Time Module Object Name Threat Action User Information
7/26/2008 11:07:44 AM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\crdVS3lu.exe. The file was moved to quarantine. You may close this window.
7/26/2008 11:07:43 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\crdVS3lu.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/26/2008 8:34:23 AM AMON file C:\WINDOWS\SYSTEM32\B2E2C4OA.DLL Win32/Agent.NZP trojan deleted SKODA\Administrator Event occurred when attempting to access the file.
7/26/2008 8:30:00 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2KJRbO83.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/26/2008 8:29:59 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mAnjIJrc.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/26/2008 8:29:58 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\T836IK78.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/26/2008 1:23:04 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ow32sqay.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/26/2008 0:20:44 AM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/26/2008 0:20:42 AM AMON file C:\WINDOWS\SYSTEM32\B2E2C4OA.DLL Win32/Agent.NZP trojan SKODA\Administrator Event occurred when attempting to access the file.
7/26/2008 0:19:42 AM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/26/2008 0:19:15 AM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/26/2008 0:18:30 AM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/26/2008 0:18:20 AM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/26/2008 0:18:11 AM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/26/2008 0:17:14 AM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/26/2008 0:16:06 AM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/26/2008 0:14:16 AM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/26/2008 0:14:11 AM AMON file C:\WINDOWS\SYSTEM32\B2E2C4OA.DLL Win32/Agent.NZP trojan SKODA\Administrator Event occurred when attempting to access the file.
7/26/2008 0:13:40 AM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/26/2008 0:12:15 AM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/26/2008 0:11:30 AM AMON file C:\WINDOWS\SYSTEM32\B2E2C4OA.DLL Win32/Agent.NZP trojan SKODA\Administrator Event occurred when attempting to access the file.
7/26/2008 0:10:41 AM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/26/2008 0:08:35 AM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/26/2008 0:08:26 AM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/26/2008 0:08:12 AM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/26/2008 0:08:03 AM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/25/2008 23:26:57 PM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/25/2008 23:25:55 PM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/25/2008 23:25:12 PM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/25/2008 23:25:01 PM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/25/2008 23:24:57 PM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/25/2008 23:24:48 PM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/25/2008 23:24:01 PM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/25/2008 23:22:45 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\dhlt7G40.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/25/2008 23:22:07 PM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/25/2008 23:21:11 PM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/25/2008 23:20:47 PM AMON file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/25/2008 23:20:03 PM AMON file C:\WINDOWS\SYSTEM32\B2E2C4OA.DLL Win32/Agent.NZP trojan SKODA\Administrator Event occurred at an attempt to access the file by the application: C:\Program Files\Internet Explorer\iexplore.exe.
7/25/2008 23:18:52 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\OXL5TT4t.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/25/2008 23:18:49 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\gp6FKy4U.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/25/2008 18:56:50 PM Kernel file C:\WINDOWS\system32\b2E2c4OA.dll Win32/Agent.NZP trojan Alert was generated during the system startup file check.
7/25/2008 18:56:46 PM Kernel file c:\windows\system32\b2e2c4oa.dll Win32/Agent.NZP trojan Alert was generated during the system startup file check.
7/25/2008 18:41:44 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\pDSDcxqr.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/25/2008 18:41:41 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\X2NXH0Vd.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/25/2008 18:41:40 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\x3r3O8Dc.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/25/2008 8:31:47 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\J06fPcGL.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/25/2008 8:31:47 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\62pY5JK0.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/25/2008 8:31:46 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\8x5X2Voa.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/25/2008 8:31:41 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\41Tib363.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
7/25/2008 1:45:18 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\n420Hx5W.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/24/2008 22:13:27 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\PuifMX81.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/24/2008 20:12:37 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\P0s0uaCy.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Mozilla Firefox\firefox.exe. The file was moved to quarantine. You may close this window.
7/24/2008 19:33:41 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\8INN4swm.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/24/2008 18:16:37 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\TrdsGkxm.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/24/2008 18:16:37 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1I3kneg5.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/24/2008 18:16:36 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AXD2ufN7.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/24/2008 11:33:05 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Ql60me7H.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/24/2008 11:33:05 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2i28TX6G.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/24/2008 11:33:04 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\qdv071f3.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/24/2008 11:33:04 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1t08h08Q.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/24/2008 11:33:00 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WJWVH78P.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Eset\nod32kui.exe. The file was moved to quarantine. You may close this window.
7/24/2008 0:48:59 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2bXlI557.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/23/2008 23:50:32 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\qxReWv0Q.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/23/2008 23:49:56 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\lBQxkPuU.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/23/2008 18:20:19 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7M6MTDx3.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/23/2008 18:20:18 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Q7AEcx05.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/23/2008 13:53:21 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\61U6h3ka.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/23/2008 13:15:45 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\5o1I42sR.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/23/2008 13:15:44 PM AMON file C:\WINDOWS\system32\7MeM5Doa.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\JcaGHswS.exe. The file was moved to quarantine. You may close this window.
7/23/2008 13:15:44 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1HIeinjY.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/23/2008 13:15:42 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fJkxNNu1.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/23/2008 13:15:40 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\8A5p5Hu3.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/23/2008 1:20:27 AM AMON file C:\WINDOWS\system32\7MeM5Doa.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\TiDL3H5t.exe. The file was moved to quarantine. You may close this window.
7/22/2008 23:37:33 PM AMON file C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\NLW8TWP0\news[1].htm HTML/TrojanClicker.Agent.A trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/22/2008 23:37:28 PM IMON file http://www.thenewsvault.com/cgi/news.pl?t=128 HTML/TrojanClicker.Agent.A trojan SKODA\Administrator
7/22/2008 23:15:12 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\N1FCIVTW.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/22/2008 21:14:57 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\42ctppCV.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/22/2008 19:15:30 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\6B75EsEP.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\WINDOWS\system32\mmc.exe. The file was moved to quarantine. You may close this window.
7/22/2008 18:27:05 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\481UPyLc.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/22/2008 18:27:04 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\k2a50G0n.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/22/2008 18:27:03 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2m0N2AWm.exe probably a variant of Win32/Genetik trojan quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/22/2008 11:32:28 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\qd5fK17l.exe probably unknown NewHeur_PE virus quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/22/2008 11:32:27 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2fcY712W.exe probably unknown NewHeur_PE virus quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/22/2008 11:32:27 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\qu4Q0v1v.exe probably unknown NewHeur_PE virus quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/22/2008 11:32:24 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\XLJIe60c.exe probably unknown NewHeur_PE virus quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/22/2008 11:32:19 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\wIgaLj05.exe probably unknown NewHeur_PE virus quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/22/2008 0:57:28 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\8BlKt2cL.exe probably unknown NewHeur_PE virus quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/21/2008 22:56:59 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\i8M3y1G2.exe probably unknown NewHeur_PE virus quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/21/2008 20:55:36 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hucMFN8f.exe probably unknown NewHeur_PE virus quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/21/2008 18:55:41 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\v18sQm73.exe probably unknown NewHeur_PE virus quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: D:\Program Files\Azureus\Azureus.exe. The file was moved to quarantine. You may close this window.
7/21/2008 16:24:09 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\rw45d08o.exe probably unknown NewHeur_PE virus quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/21/2008 15:36:30 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\b43P1aOH.exe probably unknown NewHeur_PE virus quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Eset\nod32kui.exe. The file was moved to quarantine. You may close this window.
7/21/2008 15:31:03 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\7LS674na.exe probably unknown NewHeur_PE virus quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: D:\Program Files\Azureus\Azureus.exe. The file was moved to quarantine. You may close this window.
7/21/2008 10:04:41 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Ym60np06.exe probably unknown NewHeur_PE virus quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Eset\nod32kui.exe. The file was moved to quarantine. You may close this window.
7/21/2008 8:22:43 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\CTd6XH0v.exe probably unknown NewHeur_PE virus quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/21/2008 8:22:42 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\23gS2I0u.exe probably unknown NewHeur_PE virus quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/21/2008 8:22:37 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\d7B6l4lG.exe probably unknown NewHeur_PE virus quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/21/2008 1:52:06 AM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\JcfE8csf.exe probably unknown NewHeur_PE virus quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
7/20/2008 23:51:56 PM AMON file C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Spl3cayK.exe probably unknown NewHeur_PE virus quarantined - deleted SKODA\Administrator Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
7/13/2008 22:33:23 PM IMON file http://21centmedia.com/ot/a.php/1216008793….exe?affid=5919 a variant of Win32/TrojanDownloader.Firu trojan SKODA\Administrator

Wondering if maybe a format is in order finally, but would like to avoid that if possible.

Thanks for the help!
Hello Dave

Welcome to the Whatthetech Malware Removal Forum Sorry for the delay in responding but with the amount of people posting with infected computers there are not enough hours in the day


Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

O2 - BHO: solution Class - {99C6D1BB-7555-474C-91DA-D8FB62A9CC75} - C:\WINDOWS\system32\b2E2c4OA.dll (file missing)




Please download ATF Cleaner by Atribune to your desktop.
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up





Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– Don't forget to do this
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply along with a New Hijackthis log.
Hi Ken, thanks for the help. Here are the new logs:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:09:45 PM, on 7/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Documents and Settings\Administrator\Desktop\spyware\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4A27027D-9371-47B2-A07A-1B5CC3A6F3B3}: NameServer = 192.168.1.1
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

–
End of file - 2507 bytes

—————————————————–

Malwarebytes' Anti-Malware 1.23
Database version: 1008
Windows 5.1.2600 Service Pack 2

8:07:55 PM 7/30/2008
mbam-log-7-30-2008 (20-07-55).txt

Scan type: Quick Scan
Objects scanned: 42757
Time elapsed: 6 minute(s), 2 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\mrdt.log (Malware.Trace) -> Quarantined and deleted successfully.

——————————————————–

Thanks again.
Hi Dave,

Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt to your post. in your reply
Hi Ken, here are the logs from DSS.exe, thanks again for the help!

Deckard's System Scanner v20071014.68
Run by [removed] on 2008-08-01 12:06:25
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

System Restore is disabled; attempting to re-enable…success.


– Last 1 Restore Point(s) –
1: 2008-08-01 10:06:30 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.



– HijackThis (run as Administrator.exe) —————————————

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:08:16 PM, on 8/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Documents and Settings\Administrator\Desktop\dss.exe
C:\DOCUME~1\ADMINI~1\Desktop\spyware\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: solution Class - {99C6D1BB-7555-474C-91DA-D8FB62A9CC75} - C:\WINDOWS\system32\b2E2c4OA.dll
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4A27027D-9371-47B2-A07A-1B5CC3A6F3B3}: NameServer = 192.168.1.1
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

–
End of file - 2614 bytes

– HijackThis Fixed Entries (C:\DOCUME~1\ADMINI~1\Desktop\spyware\backups\) —-

backup-20070915-144113-201 O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
backup-20070915-144113-543 O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
backup-20070915-144113-688 O2 - BHO: WebAssist - {85589B5D-D53D-4237-A677-46B82EA275F3} - C:\WINDOWS\system32\ofD8pA7E.dll
backup-20070915-144129-531 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
backup-20071004-081048-786 O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - d:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
backup-20071004-081048-807 O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - d:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
backup-20071007-194117-471 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
backup-20071124-160406-416 O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
backup-20071124-160406-833 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
backup-20071124-160406-950 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
backup-20071124-160407-369 O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
backup-20071124-160407-379 O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
backup-20071124-160407-524 O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
backup-20071124-160407-598 O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
backup-20080106-170659-154 O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
backup-20080228-154059-926 O2 - BHO: Gamburg provider - {0CA10898-7F98-4709-A479-B8134AB3D9F3} - bnsock.dll (file missing)
backup-20080309-120232-533 O4 - HKLM\..\Run: [JulaPan] JulaPan.Exe
backup-20080730-195825-586 O2 - BHO: solution Class - {99C6D1BB-7555-474C-91DA-D8FB62A9CC75} - C:\WINDOWS\system32\b2E2c4OA.dll

– File Associations ———————————————————–

.js - JSFile - DefaultIcon - "D:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe",2
.reg - regfile - shell\open\command - regedit.exe "%1" %*
.scr - AutoCADScriptFile - shell\open\command - "C:\WINDOWS\system32\notepad.exe" "%1"


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R0 giveio - c:\windows\system32\giveio.sys
R0 prohlp02 (StarForce Protection Helper Driver v2) - c:\windows\system32\drivers\prohlp02.sys
Hello,

A few questionable entries on your Deckard log.

Please download ATF Cleaner by Atribune to your desktop.
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up




Download ComboFix from Here or Here to your Desktop.

In the event you already have Combofix, this is a new version that I need you to download.
It must be saved directly to your desktop.



1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan.
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again afterwards before connecting to the net


2. Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • IF you have not already done so Combofix will disconnect your machine from the Internet when it starts.
  • If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

3. Now double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze.
Hi Ken, here are the logs, thanks!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:46:14 AM, on 8/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
D:\Program Files\Winamp\winamp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Desktop\spyware\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {FC523D5A-F5C8-48FF-B35B-E008E8F4F9B9} - (no file)
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4A27027D-9371-47B2-A07A-1B5CC3A6F3B3}: NameServer = 192.168.1.1
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

–
End of file - 3058 bytes

———————————————–

ComboFix 08-08-03.03 - Administrator 2008-08-04 10:38:32.23 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1544 [GMT 2:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Administrator\Application Data\macromedia\Flash Player\#SharedObjects\ABPAQKYQ\interclick.com
C:\Documents and Settings\Administrator\Application Data\macromedia\Flash Player\#SharedObjects\ABPAQKYQ\interclick.com\ud.sol
C:\Documents and Settings\Administrator\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Administrator\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\kmd.exe
C:\WINDOWS\system32\b2E2c4OA.dll
C:\WINDOWS\system32\bxvymtcc.ini

.
((((((((((((((((((((((((( Files Created from 2008-07-04 to 2008-08-04 )))))))))))))))))))))))))))))))
.

2008-08-01 12:06 . 2008-08-01 12:06 d——– C:\Deckard
2008-07-30 20:01 . 2008-07-23 20:09 38,472 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-30 20:01 . 2008-07-23 20:09 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-07-28 01:17 . 2008-07-28 01:16 35,842 –a—— C:\WINDOWS\system32\7MeM5Doa.exe
2008-07-23 09:37 . 2008-07-23 09:37 0 –a—— C:\WINDOWS\system32\7MeM5Doa.exe.a_a
2008-07-20 23:33 . 2008-07-20 23:32 29,760 –a—— C:\WINDOWS\system32\3tWBhKcG.exe
2008-07-20 23:33 . 2008-07-20 23:33 0 –a—— C:\WINDOWS\system32\3tWBhKcG.exe.a_a
2008-07-20 11:38 . 2008-07-01 22:38 d-a—— C:\xampplite
2008-07-13 22:34 . 2008-07-13 22:34 0 –a—— C:\jfidoj.exe
2008-07-12 14:14 . 2008-07-12 14:14 d——– C:\WINDOWS\system32\E177E04D548C4006A465EEB92D3DE021
2008-07-12 14:14 . 2008-07-12 14:14 d——– C:\Documents and Settings\All Users\Application Data\Ipswitch
2008-07-12 14:14 . 2008-07-12 14:14 d——– C:\Documents and Settings\Administrator\Application Data\Ipswitch
2008-07-12 14:14 . 2006-07-25 07:42 606,293 –a—— C:\WINDOWS\system32\wbocx.ocx
2008-07-12 14:14 . 2006-07-25 07:42 50,688 –a—— C:\WINDOWS\system32\wbhelp2.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-04 08:36 ——— d—–w C:\Documents and Settings\Administrator\Application Data\bibble
2008-07-23 16:19 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Azureus
2008-07-19 13:13 ——— d—–w C:\Program Files\PartyGaming
2008-07-12 12:14 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-06-23 19:28 ——— d—–w C:\Program Files\Canon
2008-06-23 19:04 ——— d—–w C:\Documents and Settings\Administrator\Application Data\ZoomBrowser EX
2008-06-23 19:01 ——— d—–w C:\Program Files\Common Files\Canon
2008-06-23 18:47 ——— d—–w C:\Program Files\Common Files\Bibble Labs
2008-06-23 18:41 ——— d—–w C:\Program Files\Google
2008-04-15 06:40 68,088 —-a-w C:\Documents and Settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT
.

——- Sigcheck ——-

2007-11-24 16:23 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\system32\svchost.exe

2002-12-31 14:00 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\system32\user32.dll

2002-12-31 14:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\ws2_32.dll

2002-12-31 14:00 359936 63fdfea54eb53de2d863ee454937ce1e C:\WINDOWS\system32\drivers\tcpip.sys

2002-12-31 14:00 502784 b66dbc40d428fe1293041d621d836ac8 C:\WINDOWS\system32\winlogon.exe

2002-12-31 14:00 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\drivers\ndis.sys

2002-12-31 14:00 2056832 d8aba3eab509627e707a3b14f00fbb6b C:\WINDOWS\system32\ntkrnlpa.exe

2002-12-31 14:00 2179456 28187802b7c368c0d3aef7d4c382aabb C:\WINDOWS\system32\ntoskrnl.exe

2002-12-31 14:00 1032192 98d45efddd1a67f90353be8d28ed72db C:\WINDOWS\explorer.exe

2002-12-31 14:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\system32\services.exe

2002-12-31 14:00 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\system32\lsass.exe

2002-12-31 14:00 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\system32\ctfmon.exe

2005-06-11 02:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2002-12-31 14:00 57856 7435b108b935e42ea92ca94f59c8e717 C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
2005-06-11 01:53 57856 da81ec57acd4cdc3d4c51cf3d409af9f C:\WINDOWS\system32\spoolsv.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-11-24 16:39 949376]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.i263"= i263_32.drv
"msacm.imc"= imc32.acm
"vidc.hfyu"= huffyuv.dll
"msacm.divxa32"= DivXa32.acm
"msacm.l3codec"= l3codecp.acm

[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Adobe Gamma Loader.exe]
path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Adobe Gamma Loader.exe
backup=C:\WINDOWS\pss\Adobe Gamma Loader.exeStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^HDD temperature.lnk]
path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\HDD temperature.lnk
backup=C:\WINDOWS\pss\HDD temperature.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Synchronizer.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=C:\WINDOWS\pss\AutoCAD Startup Accelerator.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=C:\WINDOWS\pss\BTTray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^m-trip Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\m-trip Launcher.lnk
backup=C:\WINDOWS\pss\m-trip Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^msn_0802_upd181826.exe]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\msn_0802_upd181826.exe
backup=C:\WINDOWS\pss\msn_0802_upd181826.exeCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Suitcase 11.0.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Suitcase 11.0.lnk
backup=C:\WINDOWS\pss\Suitcase 11.0.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2002-12-31 14:00 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
–a—— 2005-12-10 16:57 133016 d:\Program Files\DAEMON Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RaidTool]
–a—— 2005-06-20 19:53 1056768 C:\Program Files\VIA\RAID\raid_tool.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs—- 2008-01-28 12:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-07-12 04:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JulaPan]
–a—— 2005-07-05 17:27 425984 C:\WINDOWS\system32\JulaPan.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
–a—— 2007-01-23 15:44 101136 C:\WINDOWS\KHALMNPR.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
–a—— 2007-01-23 15:44 101136 C:\WINDOWS\KHALMNPR.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2005-01-10 04:36 77824 C:\WINDOWS\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PDSched"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"D:\\Program Files\\Next Limit\\Maxwell\\mxcl.exe"=

R3 ipgd;IC Plus IP1000 Family Gigabit Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\ipgdnd51.sys [2005-01-11 10:47]
S3 JULA_01;Service for Juli@ 1;C:\WINDOWS\system32\drivers\JulaWdm.sys [2005-07-05 17:27]
S3 JULA_AA;Service for Juli@ Audio Driver (EWDM);C:\WINDOWS\system32\drivers\Jula.sys [2005-07-05 17:27]
S3 MA_CMIDI;%EVOL_USB.SvcDesc%;C:\WINDOWS\system32\drivers\ma_cmidi.sys []
.
Contents of the 'Scheduled Tasks' folder

2008-08-03 C:\WINDOWS\Tasks\At20.job
- C:\WINDOWS\system32\3tWBhKcG.exe [2008-07-20 23:32]

2008-08-03 C:\WINDOWS\Tasks\At34.job
- Y:\ []
.
- - - - ORPHANS REMOVED - - - -

ShellExecuteHooks-{E8E715FE-B057-44BC-94A1-B46F9401DF30} - (no file)
MSConfigStartUp-ABIT uGuru - d:\Program Files\ABIT\ABIT uGuru\uGuru.exe
MSConfigStartUp-Acrobat Assistant 7 - D:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
MSConfigStartUp-Acrobat Assistant 8 - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
MSConfigStartUp-Adobe Photo Downloader - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
MSConfigStartUp-ATIPTA - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
MSConfigStartUp-DAEMON Tools-1033 - D:\Program Files\D-Tools\daemon.exe
MSConfigStartUp-gcasServ - C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
MSConfigStartUp-GuruClock - d:\Program Files\ABIT\ABIT uGuru\GuruClock.exe
MSConfigStartUp-H2O - C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
MSConfigStartUp-HDDHealth - d:\Program Files\HDD Health\hddhealth.exe
MSConfigStartUp-PCSuiteTrayApplication - D:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
MSConfigStartUp-StartCCC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
MSConfigStartUp-updateMgr - D:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
MSConfigStartUp-Microsoft Windows System Kernel - kernel32.exe


.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ehyctlaq.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.google.com


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-04 10:40:30
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


**************************************************************************
.
Completion time: 2008-08-04 10:42:57
ComboFix-quarantined-files.txt 2008-08-04 08:41:55

Pre-Run: 9,912,066,048 bytes free
Post-Run: 9,966,178,304 bytes free

192
Looks good Dave,

How is your system behaving now?

ATF Cleaner <– Yours to keep, run it now and then to clean out the clutter.

Malwarebytes
<– Yours to keep also, check for updates and run a scan now and then.

Combofix Is not a general cleaning tool, just run it with supervision or you can bork your system

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.


    • [external image: Posted Image]

  • When shown the disclaimer, Select "2"

The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.
Hi Ken, The system is running better, but there are still some issues. I'm getting popup notifications on quite a few sites where I never used to get them. I'm also having a problem where if I'm watching a video full screen, sometimes it will just jump out of fullscreen mode as if there was some windows notice or something, but there's no notice on the screen. It's the same as when I got the nod32 notification, but now the window just minimizes… Thanks, Dave
Hello,

Lets make sure there is nothing wrong with these

You need to enable windows to show all files and folders, instructions Here

Go to VirusTotal and submit these files for analysis, just use the Browse Feature and then Submit , you will get a report back, post the report into this thread for me to see.

C:\WINDOWS\system32\7MeM5Doa.exe
C:\WINDOWS\system32\3tWBhKcG.exe


Please run this free online virus scanner from ESET
  • Note: You will need to use Internet explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is ticked, and the option Scan unwanted applications is checked
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic
Here are the two reports for the files:

http://www.virustotal.com/analisis/fd67bcf…bf213db24cb6a0f

http://www.virustotal.com/analisis/4f2b404…a68c009e837fbdc

the second file also has a 'double' : 3tWBhKcG.exe.a_a

and here is the log from ESET

# version=4
# OnlineScanner.ocx=[removed]
# OnlineScannerDLLA.dll=1, 0, 0, 51
# OnlineScannerDLLW.dll=1, 0, 0, 51
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3333 (20080806)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=9518d810262c0e4f893c3d69952798a6
# end=finished
# remove_checked=true
# unwanted_checked=true
# utc_time=2008-08-06 06:04:17
# local_time=2008-08-06 08:04:17 (+0100, Central Europe Daylight Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 2
# scanned=405754
# found=4
# scan_time=3357
# nod_component=NOD32MOD_WINNT_ENGLISH_BASE Build:0x11081627 (NOD32 For Windows NT/2000/XP/2003/Vista/x64 - Base)
# nod_component=NOD32MOD_WINNT_ENGLISH_INET Build:0x11081627 (NOD32 For Windows NT/2000/XP/2003/Vista/x64 - Internet support)
# nod_component=NOD32MOD_WINNT_ENGLISH_STANDARD Build:0x11081627 (NOD32 for Windows NT/2000/XP/2003/Vista/x64 - Standard component)
C:\Documents and Settings\Administrator\Desktop\spyware\backups\backup-20080730-195825-586.dll probably a variant of Win32/TrojanClicker.Agent.NEB trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\WINDOWS\pss\msn_0802_upd181826.exeCommon Startup probably a variant of Win32/TrojanDownloader.Delf trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\WINDOWS\system32\3tWBhKcG.exe a variant of Win32/TrojanDownloader.Firu trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\WINDOWS\system32\7MeM5Doa.exe a variant of Win32/TrojanClicker.Agent.NEB trojan (unable to clean - deleted) 00000000000000000000000000000000
Hi Dave,

There bad, lets make sure there gone.

Please download OTMoveIt by OldTimer.

  • Save it to your desktop.
  • Please double-click OTMoveIt.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\7MeM5Doa.exe
    C:\WINDOWS\system32\3tWBhKcG.exe

  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply.
  • Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Let me see the OTMoveIt log and a new HJT log and let me know if your still having issues
Hi again Ken, OTmoveit said the files don't exist:

File/Folder C:\WINDOWS\system32\7MeM5Doa.exe not found.
File/Folder C:\WINDOWS\system32\3tWBhKcG.exe not found.

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08062008_202812
—————–

Here is the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:30:18 PM, on 8/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\CF6293.exe
C:\WINDOWS\explorer.exe
D:\Program Files\HeavenlyOpportunity\HeavenlyOpportunity.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Desktop\spyware\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {FC523D5A-F5C8-48FF-B35B-E008E8F4F9B9} - (no file)
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/OnlineScanner.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4A27027D-9371-47B2-A07A-1B5CC3A6F3B3}: NameServer = 192.168.1.1
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

–
End of file - 2887 bytes


I will work for a bit on the PC and see if there are still any issues.

Thanks,
Dave
Dave,

You have two new entries on your HJT log that where not on it before.

D:\Program Files\HeavenlyOpportunity\HeavenlyOpportunity.exe <— Did you just install this. Please do not install anymore software until we're done as it gets confusing when new programs show up on your log.

This one won't Google so I have no idea what it is, run it through VirusTotal and post back with the report.
C:\WINDOWS\system32\CF6293.exe


Remove this one with HJT
O2 - BHO: (no name) - {FC523D5A-F5C8-48FF-B35B-E008E8F4F9B9} - (no file)

Post the VT log and a New HJT log please
Hi Ken,

the file looks clean, here is the log:

http://www.virustotal.com/analisis/4b71851…714e5a2dbff4960

———

Heavenly Opportunity is just an astronomy program I have, it should be clean, I don't know why I left it running when scanning with HJT. Here is also the new HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:46:21 PM, on 8/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
D:\Program Files\Azureus\Azureus.exe
C:\Documents and Settings\Administrator\Desktop\spyware\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/OnlineScanner.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4A27027D-9371-47B2-A07A-1B5CC3A6F3B3}: NameServer = 192.168.1.1
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

–
End of file - 2709 bytes

Thanks again, sorry for the delay in replying.
Dave

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI