This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Vista Antivirus 2008, spyware removal program pop-ups

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi again! i was unable to download that link, and the virus still redirects me away from whatthetech.com. (i also tried in safe mode but no luck). i was only able to open up SmitfraudFIX i think because it was a file… wasn't it? :) any other ideas? thanks so much!
Hi,

You need to go to known clean computer and download this program to a Flash Drive and then transfer it to the infected computer, install it and run it. Print this out from a good computer so you can follow the instructions. There really is no way around this, your going to have to get this program onto the infected computer and run it. Run it in Safemode, install it in safemode if need be. Believe me, after you run Malwarebytes you will see a big improvement , but there will still be more to do.




To Enter Safemode
  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode
  • Then press the Enter Key on your Keyboard
Tutorial if you need it How to boot into Safemode





Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.<– Don't forget this
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply along with a New Hijackthis log.
okie dokie, ken. so i got a flash drive and uploaded the malwarebytes program onto it. i tried to open it on my computer and i saw the drive and the file there, but when i clicked it didn't work. i then when back to a safe computer and extracted all the files from malwarebytes onto the flash drive. when i clicked on the main program from there on a safe computer, it opened and went to that scran screen. but when i tried to open that from my laptop, i couldn't get anything to happen. it box popped up saying, "run-time error "0"" and then "run-time error "440"". i'm stuck!
Are you able to download this program to the flash drive and run it


Download the HostsXpert 4.2.0.0. - Hosts File Manager.
  • Unzip HostsXpert 4.2.0.0 - Hosts File Manager to a convenient folder such as C:\HostsXpert
  • Click HostsXpert.exe to Run HostsXpert - Hosts File Manager from its new home
  • Click "Make Hosts Writable?" in the upper right corner (If available).
  • Click Restore Microsoft's Hosts file and then click OK.
  • Click the X to exit the program.
  • Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.


"run-time error "440"". <— This can be a windows issue, you can read about it here
http://www.computerhope.com/issues/ch000380.htm


I am going to ask someone else to take a peak here, it seems that your redirected away from whatever URL you enter yet when we transfer a program to the infected computer it won't run.
See if you can download this from a known clean computer to your flash drive

Download ComboFix from Here to your Thumb drive

Then transfer it to your infected computer to the desktop and double click it to run
Try these before Combofix

First do this one.

Internet Explorer is needed to run this program properly.
Download: DelDomains and save it to the desktop.
  • Close all open windows and your browser
  • Right Click DelDomains.inf and select > Install
  • Reboot your computer



Try downloading this one in Safemode with Network support, use Firefox if you can, the tool needs to be run from Safemode

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
hi ken! thanks for all your patience with me on this! :)

so, i did DelDomains successfully.

then, i tried to do SDFix, and before it could scan the first time, it made me reboot my computer to get rid of a worm. then, when i rebooted after that long scanning process, a black box quickly popped up (literally for maybe one second) that said, "SDFix could not remove file" something something. it was so quick, i couldn't read it! i tried running the whole process again, but i still missed the box.

below is the "report" that popped up on the SDFix file on a notepad. do you need anything else?

thank you!

SDFix: Version 1.220
Run by [removed] on Fri 09/05/2008 at 07:18 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: E:\SDFix
Checking Services :
Name :
clbdriver
lanmandrv
WINIQ53
clbdriver
Path :
\??\globalroot\systemroot\system32\drivers\clbdriver.sys
clbdriver - Deleted
lanmandrv - Deleted
WINIQ53 - Deleted
clbdriver - Deleted

Restoring Default Security Values
Restoring Default Hosts File
Sorry,

I forgot you did not install it yet. Lets see if you can now.

Download Trendmicros Hijackthis to your desktop.
  • Double click it to install
  • Follow the prompts and by default it will install in C:\Program Files\Trendmicro\Hijackthis\Highjackthis.exe
  • Open HJT Scan and Save a Log File, it will open in Notepad
  • Go to Format and make sure Wordwrap is Unchecked
  • Go to Edit> Select All…..Edit > Copy and Paste the new log into this thread by using the Post Reply and not start a New Thread.
DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
Hi Ken! Hope this is what you need. Thanks!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:20: VIRUS ALERT!, on 9/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Nikon\Wireless Camera Setup Utility\NkPtpEnum.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\rundll32.exe
c:\program files\aim6\anotify.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [DLBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [\SUE24.exe] C:\Windows\SUE24.exe
O4 - HKLM\..\Run: [\SUE25.exe] C:\Windows\SUE25.exe
O4 - HKLM\..\Run: [\SUE26.exe] C:\Windows\SUE26.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SDFix] E:\SDFix\RunThis.bat /second
O4 - HKLM\..\Run: [64fd8baf] rundll32.exe "C:\WINDOWS\system32\wcpwirrg.dll",b
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Antivirus] C:\Program Files\VAV\vav.exe
O4 - HKCU\..\Run: [\SUE24.exe] C:\Windows\SUE24.exe
O4 - HKCU\..\Run: [\SUE25.exe] C:\Windows\SUE25.exe
O4 - HKCU\..\Run: [\SUE26.exe] C:\Windows\SUE26.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Office Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…90/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,23/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/Facebo…Uploader4_5.cab
O20 - AppInit_DLLs: qfkmrr.dll axuekq.dll tvhzcr.dll srhrui.dll yhcyuj.dll vpykfg.dll lxncvj.dll jadshn.dll bvheex.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: NkPtpEnumP2 - Nikon Corporation - C:\Program Files\Nikon\Wireless Camera Setup Utility\NkPtpEnum.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
–
End of file - 8476 bytes
We're making some progress, this garbage is getting harder to remove each day.

Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

O4 - HKLM\..\Run: [SDFix] E:\SDFix\RunThis.bat /second
O4 - HKLM\..\Run: [64fd8baf] rundll32.exe "C:\WINDOWS\system32\wcpwirrg.dll",b
O4 - HKCU\..\Run: [Antivirus] C:\Program Files\VAV\vav.exe

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

O20 - AppInit_DLLs: qfkmrr.dll axuekq.dll tvhzcr.dll srhrui.dll yhcyuj.dll vpykfg.dll lxncvj.dll jadshn.dll bvheex.dll







Download ComboFix from Here or Here to your Desktop.

In the event you already have Combofix, this is a new version that I need you to download.
It must be saved directly to your desktop.



1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan.
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again afterwards before connecting to the net
2. Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • IF you have not already done so Combofix will disconnect your machine from the Internet when it starts.
  • If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
3. Now double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review
grr… i KNOW! but i do feel like my computer is so much better! the clock doesn't say VIRUS ALERT next to it anymore (though it's still in military time that i can't seem to get rid of), AND, i can access this site from my computer, which i hadn't been able to do. YAY!

below is my latest hijackthis log.
THANK YOU!

ComboFix 08-09-05.12 - Jessica 2008-09-09 19:46:45.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.581 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\a
C:\Documents and Settings\TEMP\Cookies\[removed][1].txt
C:\Documents and Settings\TEMP\Cookies\[removed][3].txt
C:\Documents and Settings\TEMP\Cookies\jessica@revsci[2].txt
C:\Program Files\SpyShredder
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\setup.dll
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\sys1.exe
C:\WINDOWS\Sys6.exe
C:\WINDOWS\Sys7.exe
C:\WINDOWS\Sys8.exe
C:\WINDOWS\system32\_000008_.tmp.dll
C:\WINDOWS\system32\aukvarwt.ini
C:\WINDOWS\system32\awkvofgk.ini
C:\WINDOWS\system32\axuekq.dll
C:\WINDOWS\system32\bvheex.dll
C:\WINDOWS\system32\clbdll.dll
C:\WINDOWS\system32\clbinit.dll
C:\WINDOWS\system32\derxsl.dll
C:\WINDOWS\system32\dhkgmvyh.ini
C:\WINDOWS\system32\dnoeqkex.ini
C:\WINDOWS\system32\drivers\clbdriver.sys
C:\WINDOWS\system32\ewuadako.ini
C:\WINDOWS\system32\fqansrqx.dll
C:\WINDOWS\system32\gchegfsf.dll
C:\WINDOWS\system32\grriwpcw.ini
C:\WINDOWS\system32\hhrfiysu.ini
C:\WINDOWS\system32\ihkmp.bak1
C:\WINDOWS\system32\ihkmp.bak2
C:\WINDOWS\system32\jadshn.dll
C:\WINDOWS\system32\jpripmca.dll
C:\WINDOWS\system32\jqtmdhov.ini
C:\WINDOWS\system32\jrkdfm.dll
C:\WINDOWS\system32\kkmbkh.dll
C:\WINDOWS\system32\lanmandrv.sys
C:\WINDOWS\system32\lxncvj.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mfkkeqcj.dll
C:\WINDOWS\system32\mlJDwWPG.dll
C:\WINDOWS\system32\mrtxpatu.ini
C:\WINDOWS\system32\nfswlnmr.dll
C:\WINDOWS\system32\nhetjxuq.ini
C:\WINDOWS\system32\npAJPXbc.ini
C:\WINDOWS\system32\npAJPXbc.ini2
C:\WINDOWS\system32\npmrhgld.dll
C:\WINDOWS\system32\ofiqyfqt.ini
C:\WINDOWS\system32\pbpkaupj.dll
C:\WINDOWS\system32\pmkhi.dll
C:\WINDOWS\system32\qfkmrr.dll
C:\WINDOWS\system32\qqevhsjr.dll
C:\WINDOWS\system32\qyogcywo.ini
C:\WINDOWS\system32\rraibtoy.dll
C:\WINDOWS\system32\slktuebg.ini
C:\WINDOWS\system32\srhrui.dll
C:\WINDOWS\system32\tacyiofe.dll
C:\WINDOWS\system32\tjevlusy.ini
C:\WINDOWS\system32\tvhzcr.dll
C:\WINDOWS\system32\tzslcn.dll
C:\WINDOWS\system32\udhuxeuo.dll
C:\WINDOWS\system32\vpykfg.dll
C:\WINDOWS\system32\wcpwirrg.dll
C:\WINDOWS\system32\wqyrai.dll
C:\WINDOWS\system32\xgchswpk.dll
C:\WINDOWS\system32\xhlvowff.ini
C:\WINDOWS\system32\xiihucaw.ini
C:\WINDOWS\system32\xltriggj.dll
C:\WINDOWS\system32\yewbxwjr.ini
C:\WINDOWS\system32\yfhirloa.dll
C:\WINDOWS\system32\yhcyuj.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_CLBDRIVER
——-\Legacy_LANMANDRV
——-\Service_clbdriver


((((((((((((((((((((((((( Files Created from 2008-08-09 to 2008-09-09 )))))))))))))))))))))))))))))))
.

2008-09-08 22:20 . 2008-09-08 22:20 d——– C:\Program Files\Trend Micro
2008-09-02 22:17 . 2008-09-02 22:17 d——– C:\WINDOWS\ERUNT
2008-09-02 20:52 . 2008-09-02 20:52 34,304 –a—— C:\WINDOWS\system32\drivers\531lsf.exe
2008-09-02 20:28 . 2008-09-02 20:28 34,304 –a—— C:\WINDOWS\system32\drivers\187lsf.exe
2008-09-01 21:39 . 2008-09-01 21:39 124,544 –a—— C:\WINDOWS\system32\ueweeedd.dll
2008-09-01 21:39 . 2008-09-01 21:39 124,544 –a—— C:\WINDOWS\system32\blrhxo.dll
2008-08-29 02:33 . 2008-08-29 02:33 34,304 –a—— C:\WINDOWS\system32\drivers\281lsf.exe
2008-08-27 00:35 . 2008-08-27 00:35 34,304 –a—— C:\WINDOWS\system32\drivers\203lsf.exe
2008-08-27 00:08 . 2008-08-27 00:08 34,304 –a—— C:\WINDOWS\system32\drivers\718lsf.exe
2008-08-26 22:52 . 2008-08-26 22:52 34,304 –a—— C:\WINDOWS\system32\drivers\546lsf.exe
2008-08-26 07:43 . 2008-08-26 07:43 34,304 –a—— C:\WINDOWS\system32\drivers\437lsf.exe
2008-08-25 23:46 . 2008-08-25 23:46 34,304 –a—— C:\WINDOWS\system32\drivers\906lsf.exe
2008-08-24 03:09 . 2008-08-24 03:09 34,304 –a—— C:\WINDOWS\system32\drivers\468lsf.exe
2008-08-23 19:35 . 2008-08-23 19:35 d——– C:\Program Files\Bonjour
2008-08-23 19:17 . 2008-09-01 21:45 34,304 –a—— C:\WINDOWS\system32\drivers\640lsf.exe
2008-08-23 12:13 . 2008-08-23 12:13 34,304 –a—— C:\WINDOWS\system32\drivers\750lsf.exe
2008-08-23 02:58 . 2008-08-23 02:58 34,304 –a—— C:\WINDOWS\system32\drivers\828lsf.exe
2008-08-22 22:27 . 2008-08-22 22:27 34,304 –a—— C:\WINDOWS\system32\drivers\953lsf.exe
2008-08-20 00:02 . 2008-08-20 00:02 34,304 –a—— C:\WINDOWS\system32\drivers\31lsf.exe
2008-08-18 22:55 . 2008-09-02 20:19 34,304 –a—— C:\WINDOWS\system32\drivers\156lsf.exe
2008-08-18 00:06 . 2008-08-18 00:06 34,304 –a—— C:\WINDOWS\system32\drivers\812lsf.exe
2008-08-17 23:32 . 2008-08-17 23:32 34,304 –a—— C:\WINDOWS\system32\drivers\62lsf.exe
2008-08-17 23:18 . 2008-08-17 23:18 3,434 –a—— C:\WINDOWS\system32\tmp.reg
2008-08-17 23:16 . 2008-08-17 23:16 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-08-17 23:16 . 2008-08-17 23:16 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-08-17 23:16 . 2008-08-17 23:16 86,528 –a—— C:\WINDOWS\system32\VACFix.exe
2008-08-17 23:16 . 2008-08-17 23:16 82,944 –a—— C:\WINDOWS\system32\IEDFix.exe
2008-08-17 23:16 . 2008-08-17 23:16 82,432 –a—— C:\WINDOWS\system32\IEDFix.C.exe
2008-08-17 23:16 . 2008-08-17 23:16 82,432 –a—— C:\WINDOWS\system32\404Fix.exe
2008-08-17 23:16 . 2008-08-17 23:16 53,248 –a—— C:\WINDOWS\system32\Process.exe
2008-08-17 23:16 . 2008-08-17 23:16 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-08-17 23:16 . 2008-08-17 23:16 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2008-08-17 23:00 . 2005-05-02 22:35 d——– C:\Documents and Settings\Administrator.JESSICAELKER.000\Application Data\Sonic
2008-08-17 23:00 . 2005-05-02 22:22 d——– C:\Documents and Settings\Administrator.JESSICAELKER.000\Application Data\Jasc Software Inc
2008-08-17 23:00 . 2008-08-17 23:01 d——– C:\Documents and Settings\Administrator.JESSICAELKER.000\Application Data\Intel
2008-08-17 23:00 . 2005-05-02 22:21 d–h—– C:\Documents and Settings\Administrator.JESSICAELKER.000\Application Data\Gtek
2008-08-17 23:00 . 2008-08-17 23:15 d——– C:\Documents and Settings\Administrator.JESSICAELKER.000
2008-08-14 00:49 . 2005-05-02 22:35 d——– C:\Documents and Settings\Administrator.JESSICAELKER\Application Data\Sonic
2008-08-14 00:49 . 2008-08-14 00:51 d——– C:\Documents and Settings\Administrator.JESSICAELKER\Application Data\Intel
2008-08-14 00:49 . 2008-08-14 00:53 d——– C:\Documents and Settings\Administrator.JESSICAELKER\Application Data\Gtek
2008-08-14 00:49 . 2008-08-14 00:53 d—s—- C:\Documents and Settings\Administrator.JESSICAELKER
2008-08-14 00:06 . 2005-05-02 22:35 d——– C:\Documents and Settings\Administrator\Application Data\Sonic
2008-08-14 00:06 . 2008-08-14 00:08 d——– C:\Documents and Settings\Administrator\Application Data\Intel
2008-08-14 00:06 . 2008-08-14 00:54 d——– C:\Documents and Settings\Administrator\Application Data\Gtek
2008-08-14 00:06 . 2008-08-14 00:54 d—s—- C:\Documents and Settings\Administrator

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-03 00:49 31,616 —-a-w C:\WINDOWS\system32\drivers\Winiq53.sys
2008-08-24 07:05 ——— d—–w C:\Program Files\Apple Software Update
2008-08-23 23:42 ——— d—–w C:\Program Files\iTunes
2008-08-23 23:41 ——— d—–w C:\Program Files\iPod
2008-07-30 12:00 ——— d—–w C:\Documents and Settings\TEMP\Application Data\Amazon
2008-07-25 05:14 ——— d—–w C:\Program Files\EvilLyrics
2008-07-12 01:34 ——— d—–w C:\Program Files\QuickTime
2006-12-25 21:39 20 —h–w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
2005-05-16 06:28 802 —-a-w C:\Documents and Settings\Jessica\Application Data\wklnhst.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E515E5AB-F9FD-4DA0-BF9D-D5C6E4252087}]
2008-07-30 08:03 323840 –a—— C:\WINDOWS\system32\cbXPJApn.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" [2004-07-19 306688]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 50736]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-21 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-12-03 344064]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"DLBTCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll" [2004-11-09 69632]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"WD Button Manager"="WDBtnMgr.exe" [2007-09-04 C:\WINDOWS\system32\WDBtnMgr.exe]

C:\Documents and Settings\Jessica\Start Menu\Programs\Startup\
PictureProject In Touch.lnk - C:\Program Files\Nikon\PictureProject In Touch\PictureProjectInTouch.exe [2005-03-21 8384512]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
NkbMonitor.exe.lnk - C:\Program Files\Nikon\PictureProject\NkbMonitor.exe [2006-07-16 118784]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 16:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winiq53.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
–a—— 2004-09-13 17:33 155648 C:\Program Files\Apoint\Apoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell Photo AIO Printer 922]
–a—— 2004-11-10 20:36 290816 C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
–a—— 2004-07-19 08:51 306688 C:\Program Files\Dell Support\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
——— 2004-10-12 17:54 57344 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-07-30 10:47 289064 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 12:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QBReminderFlash]
–a—— 2004-11-11 11:26 26112 C:\Program Files\Intuit\QuickBooks 2005\Atom\QBReminder.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2005-05-02 22:29 26112 C:\Program Files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2003-11-19 18:48 32881 C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
–a—— 2004-01-07 02:01 110592 C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R2 NkPtpEnumP2;NkPtpEnumP2;C:\Program Files\Nikon\Wireless Camera Setup Utility\NkPtpEnum.exe [2005-06-17 24064]
R3 VBus;Virtual Bus;C:\WINDOWS\system32\DRIVERS\NkVBus.sys [2005-06-17 17664]
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

BHO-{8d3bc7bc-0893-4f40-8c71-53beff05deb1} - C:\WINDOWS\system32\kkmbkh.dll
HKCU-Run-\SUE24.exe - C:\Windows\SUE24.exe
HKCU-Run-\SUE25.exe - C:\Windows\SUE25.exe
HKCU-Run-\SUE26.exe - C:\Windows\SUE26.exe
HKLM-Run-\SUE24.exe - C:\Windows\SUE24.exe
HKLM-Run-\SUE25.exe - C:\Windows\SUE25.exe
HKLM-Run-\SUE26.exe - C:\Windows\SUE26.exe
MSConfigStartUp-AIM - C:\PROGRA~1\AIM\aim.exe
MSConfigStartUp-Dell QuickSet - C:\Program Files\Dell\QuickSet\quickset.exe
MSConfigStartUp-mmtask - C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
MSConfigStartUp-MMTray - C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
MSConfigStartUp-PCMService - C:\Program Files\Dell\Media Experience\PCMService.exe
MSConfigStartUp-Weather - C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE


.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com/
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: E&xport to Microsoft Office Excel - C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-09 19:55:55
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-09-09 20:01:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-10 00:01:17

Pre-Run: 23,201,792,000 bytes free
Post-Run: 23,807,610,880 bytes free

280 — E O F — 2008-07-25 04:54:44

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI