This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Removal request for Trojan Generic11, Downloader.Fraud

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, Each time I open windows, AVG gives me another shield alert on a new Trojan found. I am also being rediredted to many sites. My computer is almost at a stop. I can not get into my e-mail. Also having a hard time getting and staying here. I have read the notice for help by djchuckle77 and the advice given to him by mschroe919. Per this person's advice I have created a new stand alone file for HJT on my C drive. I have made sure my hidden filesand folders could be read and downloaded ATF Cleaner by Atribune. I ran that program and cleaned. Next, I downloaded Malwarebytes' Anti-Malware, did a full scan. Removed selected, and saved Log file rebooted and ran HJT and saved that log. Here are the name of some of the Trojan's and also the Malwarebytes' Log and the HJT log. Also when I rebooted the computer I had an "error loading" message Windows/system32/niddwybk.dll could not be found. Your help getting rid of this would be greatly appreciated.

Trojan Horse Generic11.OFO
Trojan Horse Generic11.GSA
Trojan Horse Downloader.FraudLoad.N
Trojan Horse Generic11. MCO
Trojan Horse Generic11.MCO
Trojan Horse Generic11.MCO
Trojan Horse Generic11.OFO
Trojan Horse Generic11.PBB

Malwarebytes' Anti-Malware 1.25
Database version: 1102
Windows 5.1.2600 Service Pack 2

5:13:19 PM 8/31/2008
mbam-log-08-31-2008 (17-13-19).txt

Scan type: Full Scan (A:\|C:\|D:\|E:\|)
Objects scanned: 103526
Time elapsed: 51 minute(s), 2 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 3
Registry Keys Infected: 26
Registry Values Infected: 2
Registry Data Items Infected: 9
Folders Infected: 0
Files Infected: 22

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\usodtema.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\lkiduj.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\bhwpdn.dll (Trojan.Vundo.H) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c85bd9f1-5b95-46da-9f39-979db6b58484} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\khfccdaw (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c85bd9f1-5b95-46da-9f39-979db6b58484} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fb3d4c48-c9c7-4235-aedc-77f7f494fde6} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{fb3d4c48-c9c7-4235-aedc-77f7f494fde6} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/downloaded program files/popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\seekmotoolbar.seekmotoolband (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\seekmotoolbar.seekmotoolband.1 (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\seekmotoolbar.seekmotoolband (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\seekmotoolbar.seekmotoolband.1 (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\2056af03 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bm23659c9f (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.26 85.255.112.104 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{d89dd58d-7da6-423b-8f90-919df5595948}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed],[removed] -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{f8acfc27-0215-4c8d-b3ed-c4e6619fdaec}\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.26,85.255.112.104 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.26 85.255.112.104 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{d89dd58d-7da6-423b-8f90-919df5595948}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed],[removed] -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{f8acfc27-0215-4c8d-b3ed-c4e6619fdaec}\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.26,85.255.112.104 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.26 85.255.112.104 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{d89dd58d-7da6-423b-8f90-919df5595948}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed],[removed] -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{f8acfc27-0215-4c8d-b3ed-c4e6619fdaec}\NameServer (Trojan.DNSChanger) -> Data: 85.255.116.26,85.255.112.104 -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\khfccdaw.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bhwpdn.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\usodtema.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\ametdosu.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{68A81065-9D19-4B3D-8350-9A65931F89CE}\RP958\A0103041.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{68A81065-9D19-4B3D-8350-9A65931F89CE}\RP959\A0104142.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{68A81065-9D19-4B3D-8350-9A65931F89CE}\RP959\A0104154.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{68A81065-9D19-4B3D-8350-9A65931F89CE}\RP959\A0104155.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{68A81065-9D19-4B3D-8350-9A65931F89CE}\RP959\A0104156.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{68A81065-9D19-4B3D-8350-9A65931F89CE}\RP959\A0104141.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{68A81065-9D19-4B3D-8350-9A65931F89CE}\RP971\A0108957.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cnamlxfg.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lkiduj.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\papgkdyp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\niddwybk.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\pac.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\pskt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM23659c9f.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM23659c9f.txt (Trojan.Vundo) -> Quarantined and deleted successfully.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:25:26, on 8/31/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\HJT\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {5ED7D3DE-6DBE-4516-8712-436325722327} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: (no name) - {CDFF31F6-206F-41A8-AD85-95ADDF00C36E} - C:\WINDOWS\system32\pmnklLda.dll (file missing)
O3 - Toolbar: (no name) - {53E0B6E8-A51D-448B-B692-40B67B285543} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LXCICATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCItime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/dow…llerControl.cab
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt4_x.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143847610390
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab53083.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHos…ronGameHost.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/cnma/default/ct.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
O20 - AppInit_DLLs: lkiduj.dll zrllfp.dll
O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: lxci_device - - C:\WINDOWS\system32\lxcicoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)

–
End of file - 8099 bytes
Hi montanablondie2001,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.


A. Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

B. Now we must disable some of your security programs so that they do not interfere with the running of our tools:

AVG
Please open the AVG Control Center program -> double-click on the "AVG Resident Shield" component (looks like this: [external image: Posted Image]) -> deselect the "Turn on AVG Resident Shield" checkmark and save the setting.
When you need to enable the AVG Resident Shield, ( I will let you know when) just open the AVG Control Center program -> double-click on the "AVG Resident Shield" component -> select the "Turn on AVG Resident Shield" checkmark and save the setting.


C.Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • DO NOT USE your computer for any other purpose while ComboFix is running.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
I appreciate your help so much ty! I had a problem with Combofix and when restarting the computer I had to restart in safe mode I hope this did not effect my logs. Here is the combo log and the new HJT log. Also AVG was shut off and stayed off but on the log file for Combo I thought it said it was on.

ComboFix 08-08-30.03 - Holly Harris 2008-08-31 20:16:00.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.323 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Holly Harris\Application Data\macromedia\Flash Player\#SharedObjects\KRMTNGVS\bin.clearspring.com
C:\Documents and Settings\Holly Harris\Application Data\macromedia\Flash Player\#SharedObjects\KRMTNGVS\bin.clearspring.com\clearspring.sol
C:\Documents and Settings\Holly Harris\Application Data\macromedia\Flash Player\#SharedObjects\KRMTNGVS\interclick.com
C:\Documents and Settings\Holly Harris\Application Data\macromedia\Flash Player\#SharedObjects\KRMTNGVS\interclick.com\ud.sol
C:\Documents and Settings\Holly Harris\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com
C:\Documents and Settings\Holly Harris\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol
C:\Documents and Settings\Holly Harris\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Holly Harris\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\WINDOWS\system32\adLlknmp.ini
C:\WINDOWS\system32\adLlknmp.ini2
C:\WINDOWS\system32\hwqukjjk.dll
C:\WINDOWS\system32\jkhpijbk.dll
C:\WINDOWS\system32\jvyvyovn.dll
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\pgwpyorh.dll
C:\WINDOWS\system32\sndnus.dll
C:\WINDOWS\system32\vweothwc.dll
C:\WINDOWS\system32\yxehfsaa.dll
C:\WINDOWS\system32\zrllfp.dll

.
((((((((((((((((((((((((( Files Created from 2008-08-01 to 2008-09-01 )))))))))))))))))))))))))))))))
.

2008-08-29 18:11 . 2008-08-29 18:11 d——– C:\Documents and Settings\Holly Harris\Application Data\Malwarebytes
2008-08-29 18:10 . 2008-08-31 17:12 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-29 18:10 . 2008-08-29 18:10 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-29 18:10 . 2008-08-17 15:01 38,472 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-29 18:10 . 2008-08-17 15:01 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-08-29 17:31 . 2008-08-31 17:25 d—-c— C:\HJT
2008-08-29 13:25 . 2008-08-29 13:25 d——– C:\Program Files\VS Revo Group
2008-08-29 11:18 . 2008-08-29 11:35 1,316 –a—— C:\WINDOWS\system32\tmp.reg
2008-08-29 11:17 . 2007-09-06 00:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-08-29 11:17 . 2006-04-27 17:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-08-29 11:17 . 2008-08-26 20:19 88,576 –a—— C:\WINDOWS\system32\AntiXPVSTFix.exe
2008-08-29 11:17 . 2008-08-27 15:17 87,040 –a—— C:\WINDOWS\system32\VACFix.exe
2008-08-29 11:17 . 2008-05-18 21:40 82,944 –a—— C:\WINDOWS\system32\IEDFix.exe
2008-08-29 11:17 . 2008-08-28 22:36 82,432 –a—— C:\WINDOWS\system32\IEDFix.C.exe
2008-08-29 11:17 . 2008-08-18 12:19 82,432 –a—— C:\WINDOWS\system32\404Fix.exe
2008-08-29 11:17 . 2003-06-05 21:13 53,248 –a—— C:\WINDOWS\system32\Process.exe
2008-08-29 11:17 . 2004-07-31 18:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-08-29 11:17 . 2007-10-04 00:36 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2008-08-28 00:42 . 2008-08-28 00:42 d——– C:\Program Files\Abexo
2008-08-27 16:18 . 2008-08-27 16:19 d——– C:\WINDOWS\system32\eMaxt02
2008-08-27 16:18 . 2008-08-27 16:18 d——– C:\Temp\bbc2
2008-08-21 21:50 . 2008-08-21 21:50 d——– C:\Program Files\MP3 Decoder
2008-08-21 15:47 . 2008-08-21 15:47 d——– C:\Program Files\LimeWire
2008-08-21 15:47 . 2008-08-27 18:34 d——– C:\Documents and Settings\Holly Harris\Application Data\LimeWire
2008-08-18 21:07 . 2008-08-29 13:46 d——– C:\WINDOWS\system32\scripting
2008-08-18 21:07 . 2008-08-29 13:46 d——– C:\WINDOWS\system32\en
2008-08-18 21:07 . 2008-08-29 13:45 d——– C:\WINDOWS\l2schemas
2008-08-18 20:52 . 2007-10-25 21:34 8,460,288 –a—— C:\WINDOWS\system32\dllcache\shell32.dll
2008-08-18 20:51 . 2007-02-28 03:10 2,180,352 –a—— C:\WINDOWS\system32\ntoskrnl.exe
2008-08-18 20:51 . 2007-02-28 03:10 2,180,352 –a—— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-08-18 20:51 . 2007-02-28 02:38 2,057,600 –a—— C:\WINDOWS\system32\ntkrnlpa.exe
2008-08-18 20:51 . 2007-02-28 02:38 2,057,600 –a—— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-08-18 20:51 . 2004-08-03 23:10 19,328 –a—— C:\WINDOWS\system32\drivers\wstcodec.sys
2008-08-18 20:51 . 2004-08-03 23:10 19,328 –a—— C:\WINDOWS\system32\dllcache\wstcodec.sys
2008-08-18 20:51 . 2001-03-02 18:52 15,360 –a—— C:\WINDOWS\system32\asfsipc.dll
2008-08-18 15:04 . 2006-12-28 13:01 19,569 –a—— C:\WINDOWS\005912_.tmp
2008-08-15 13:36 . 2008-08-15 13:37 686 –a—— C:\WINDOWS\WorldTimeClock.ini
2008-08-12 17:20 . 2008-05-01 08:30 331,776 –a—— C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-12 13:56 . 2008-08-12 13:56 d—-c— C:\New Folder
2008-08-03 21:02 . 2008-08-03 21:02 d——– C:\Documents and Settings\Holly Harris\Saved Games
2008-08-03 20:59 . 2008-08-03 20:59 d——– C:\Documents and Settings\Holly Harris\Application Data\iWin
2008-08-03 20:59 . 2008-08-04 00:45 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-03 20:58 . 2008-08-04 16:16 d——– C:\Program Files\Gamesville
2008-08-03 20:58 . 2008-08-03 20:58 d——– C:\Program Files\GamesBar
2008-08-03 20:58 . 2008-08-03 20:58 d——– C:\Program Files\Common Files\Oberon Media

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-31 19:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-31 19:03 ——— d—–w C:\Documents and Settings\Holly Harris\Application Data\AVG7
2008-08-30 16:58 ——— d—–w C:\Program Files\Lx_cats
2008-08-22 02:19 ——— d—–w C:\Program Files\Winamp
2008-08-21 21:39 ——— d—–w C:\Program Files\Morpheus Ultra
2008-08-12 19:34 ——— d—–w C:\Documents and Settings\Holly Harris\Application Data\Winamp
2008-07-31 01:01 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-07-18 20:58 ——— d—–w C:\Program Files\Java
2008-07-14 20:39 ——— d—–w C:\Documents and Settings\Holly Harris\Application Data\Ludia
2008-07-10 23:54 ——— d—–w C:\Program Files\Freeze.com
2008-07-10 01:16 ——— d—–w C:\Program Files\ReflexiveArcade
2007-09-25 20:10 6,221,304 —-a-w C:\Program Files\winamp535_full_emusic-7plus.exe
2007-02-26 05:18 2,792,389 —-a-w C:\Program Files\VBJB-Script_Installer.zip
2006-11-02 23:28 1,951,432 —-a-w C:\Program Files\ppviewer.exe
2006-10-31 04:20 49 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb1478.dat
2006-10-07 00:37 334 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb1942.dat
2006-10-07 00:37 13,046 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb8467.dat
2006-10-07 00:37 0 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb6500.dat
2006-10-06 15:16 9,216 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb6731.dat
2006-10-06 15:16 177,152 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb41.dat
2006-10-06 15:16 0 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb9216.dat
2006-10-06 15:13 0 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb9169.dat
2006-10-06 15:13 0 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb6334.dat
2006-10-06 15:13 0 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb5724.dat
2006-10-06 15:13 0 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb5447.dat
2006-06-15 10:48 6,580,784 ——w C:\Documents and Settings\All Users\MorpheusUltra521.exe
2006-04-01 02:37 16,781,440 ——w C:\Program Files\jre-1_5_0_06-windows-i586-p.exe
2006-03-18 20:04 2,815,270 —-a-w C:\Program Files\VBJB-Script setup_1.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 19:05 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-10-06 13:16 5058560]
"LXCICATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCItime.dll" [2006-02-24 15:05 73728]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-14 09:56 579584]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-04-29 14:03 180269]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-04 22:09 219136]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-02-01 14:32 8699904]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
2007-02-22 22:04 9216 C:\WINDOWS\system32\avgwlntf.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=lkiduj.dll zrllfp.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.SP54"= SP5X_32.DLL
"VIDC.SP55"= SP5X_32.DLL
"VIDC.SP56"= SP5X_32.DLL
"VIDC.SP57"= SP5X_32.DLL
"VIDC.SP58"= SP5X_32.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Holly Harris^Start Menu^Programs^Startup^BitTorrent.lnk]
path=C:\Documents and Settings\Holly Harris\Start Menu\Programs\Startup\BitTorrent.lnk
backup=C:\WINDOWS\pss\BitTorrent.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Holly Harris^Start Menu^Programs^Startup^MyAdultExplorer.lnk]
path=C:\Documents and Settings\Holly Harris\Start Menu\Programs\Startup\MyAdultExplorer.lnk
backup=C:\WINDOWS\pss\MyAdultExplorer.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
–a—— 2008-04-14 09:56 579584 C:\PROGRA~1\Grisoft\AVG7\avgcc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-04 01:56 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzPrint]
–a—— 2005-08-01 06:05 94208 C:\Program Files\Lexmark 7300 Series\ezprint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMS]
–a—— 2001-09-24 07:39 98304 C:\Program Files\Common Files\Logitech\QCDriver\LVComS.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxcimon.exe]
–a—— 2005-09-30 08:47 200704 C:\Program Files\Lexmark 7300 Series\lxcimon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 10:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
–a—— 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
–a—— 2008-02-01 14:32 8699904 C:\Program Files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2003-10-06 13:16 5058560 C:\WINDOWS\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2003-10-06 13:16 49152 C:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-04-19 20:26 155648 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2006-12-15 02:23 75520 C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2006-04-29 14:03 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
——— 2006-10-18 19:05 204288 C:\Program Files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2006-11-30 20:49 4662776 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
–a—— 2003-08-29 03:59 122880 C:\WINDOWS\BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2003-10-06 13:16 741376 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" -hide
"OneCareUI"="C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Morpheus Ultra\\Morpheus.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=

S2 Ca533av;Icatch(IV) Video Camera Device;C:\WINDOWS\system32\Drivers\Ca533av.sys [2002-10-21 11:37]
S3 CIF USB CAMERA Service;CIF USB CAMERA;C:\WINDOWS\system32\DRIVERS\pfc027.sys [2003-10-15 23:58]
S3 lxci_device;lxci_device;C:\WINDOWS\system32\lxcicoms.exe [2005-10-24 06:33]
S3 tbcspud;Santa Cruz Driver;C:\WINDOWS\system32\drivers\tbcspud.sys [2002-04-03 10:51]
S3 tbcwdm;Santa Cruz WDM Driver;C:\WINDOWS\system32\drivers\tbcwdm.sys [2002-04-03 10:51]
S3 USBCamera;Icatch(IV) Still Camera Device;C:\WINDOWS\system32\Drivers\Bulk533.sys [2002-07-25 11:19]
.
Contents of the 'Scheduled Tasks' folder

2008-08-31 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-04-03 16:12]
.
- - - - ORPHANS REMOVED - - - -

BHO-{CDFF31F6-206F-41A8-AD85-95ADDF00C36E} - C:\WINDOWS\system32\pmnklLda.dll
WebBrowser-{6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
ShellExecuteHooks-{C85BD9F1-5B95-46DA-9F39-979DB6B58484} - (no file)
Notify-dimsntfy - (no file)
MSConfigStartUp-AdaptecDirectCD - C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
MSConfigStartUp-Adobe Photo Downloader - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
MSConfigStartUp-CaISSDT - C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe
MSConfigStartUp-eTrustPPAP - C:\Program Files\CA\eTrust Internet Security Suite\eTrust PestPatrol Anti-Spyware\PPActiveDetection.exe
MSConfigStartUp-PC Booster - C:\Program Files\inKline Global\PC Booster\pcbooster.exe
MSConfigStartUp-REGSHAVE - C:\Program Files\REGSHAVE\REGSHAVE.EXE
MSConfigStartUp-seekmo - c:\program files\seekmo\seekmo.exe
MSConfigStartUp-SpySweeper - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
MSConfigStartUp-Symantec NetDriver Monitor - C:\PROGRA~1\SYMNET~1\SNDMon.exe


.
——- Supplementary Scan ——-
.
O8 -: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 -: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 -: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 -: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm

O16 -: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
C:\WINDOWS\Downloaded Program Files\OSDED4D.OSD
C:\WINDOWS\Downloaded Program Files\InstallerControl.dll

O16 -: DirectAnimation Java Classes - file://C:\WINDOWS\Java\classes\dajava.cab
C:\WINDOWS\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd

O16 -: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} - hxxp://games.myspace.com/Gameshell/GameHost/1.0/OberonGameHost.cab
C:\WINDOWS\Downloaded Program Files\OberonGameHost_dbg.inf
C:\WINDOWS\Downloaded Program Files\OberonGameHost.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-31 20:49:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
.
**************************************************************************
.
Completion time: 2008-08-31 20:54:35 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-01 02:54:25

Pre-Run: 74,027,241,472 bytes free
Post-Run: 74,510,516,224 bytes free

265 — E O F — 2008-08-13 06:32:05

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:07, on 2008-08-31
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LXCICATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCItime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/dow…llerControl.cab
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt4_x.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143847610390
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab53083.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHos…ronGameHost.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/cnma/default/ct.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
O20 - AppInit_DLLs: lkiduj.dll zrllfp.dll
O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: lxci_device - - C:\WINDOWS\system32\lxcicoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)

–
End of file - 7542 bytes
montanablondie2001,

We have noticed that most people seeking help from us are coming with infections contracted from the use of P2P programs.

Because of this, we felt we needed to change our policy on the use of P2P file sharing programs.

You have the following P-2-P program(s) installed
Limewire and Morpheus Ultra

This is how you uninstall it/them:

  • Click Start
  • Go to Control Panel
  • Go to Add/Remove Programs
  • Find and click Remove for the following (if present):

Limewire
Morpheus Ultra


Please respond back when you have these uninstalled and we will continue with your fix. :thumbup:
Tomk, Limewire and Morpheus have both been uninstalled, a disk clean and a reboot done for the uninstall to be complete. Thank you for informing me of this problem. I am ready to resume with your help.
montanablondie2001,

Disable your protection programs as we did before.


Next

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    KILLALL::
    
    File::
    C:\WINDOWS\005912_.tmp
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=-
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

In your next reply please provide:
  • ComboFix.txt
  • Kaspersky report
  • New HijackThis log taken after everything else completed
Tomk, thank you for the new instructions… I have hit a snag. Thought it wise to ask you first before I did anything. I opened HJT and checked the 4 files you asked me too and hit "Fix". and then closed out HJT when it was done. I opened "Notepad" and c/p the info you gave me and created that as CFScript.txt in All files and placed on Desktop. When I went to drag and drop that into ComboFix.exe I could not find the shortcut for it. It was not on my desktop as it was before. I went to "Start" and programs to see if it was there so I could create another desktop and it was not, but I did see that there are traces of Morpheus that should have been gone when I did the uninstall as you asked. Do I try to uninstall the reminants of Morpheus and then DL ComboFix again and then proceed with the rest of your instructions? I am not sure what I should do. Thank you for being so patient with me.
montanablondie2001, Your doing great. No worries. :thumbup: Don't worry about morpheus. We'll clean it up later. Download Combofix to your desktop again and then drag the script into it.
Tomk,

I am either having a really blonde moment or very tired…. I DL ComboFix a second time and tried to drage the CFScript.txt file into it. When I did it asked me if I wanted to run the program and I clicked yes. Then I got a message. This was it.

327882R2FWJFW\hidec.exe
Windows Cannot access the specified device, path or file. You may not have the appropriate permissions to access the item.


I clicked it off and then ComboFix started to run….I let it just in case. This is the log file from it but not sure if it exactly what you need. I am waiting to hear from you about this before I go to Kaspersky Website.

ComboFix 08-08-30.03 - Holly Harris 2008-08-31 23:12:20.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.190 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-08-01 to 2008-09-01 )))))))))))))))))))))))))))))))
.

2008-08-29 18:11 . 2008-08-29 18:11 d——– C:\Documents and Settings\Holly Harris\Application Data\Malwarebytes
2008-08-29 18:10 . 2008-08-31 17:12 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-29 18:10 . 2008-08-29 18:10 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-29 18:10 . 2008-08-17 15:01 38,472 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-29 18:10 . 2008-08-17 15:01 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-08-29 17:31 . 2008-08-31 22:29 d—-c— C:\HJT
2008-08-29 13:25 . 2008-08-29 13:25 d——– C:\Program Files\VS Revo Group
2008-08-29 11:18 . 2008-08-29 11:35 1,316 –a—— C:\WINDOWS\system32\tmp.reg
2008-08-29 11:17 . 2007-09-06 00:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-08-29 11:17 . 2006-04-27 17:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-08-29 11:17 . 2008-08-26 20:19 88,576 –a—— C:\WINDOWS\system32\AntiXPVSTFix.exe
2008-08-29 11:17 . 2008-08-27 15:17 87,040 –a—— C:\WINDOWS\system32\VACFix.exe
2008-08-29 11:17 . 2008-05-18 21:40 82,944 –a—— C:\WINDOWS\system32\IEDFix.exe
2008-08-29 11:17 . 2008-08-28 22:36 82,432 –a—— C:\WINDOWS\system32\IEDFix.C.exe
2008-08-29 11:17 . 2008-08-18 12:19 82,432 –a—— C:\WINDOWS\system32\404Fix.exe
2008-08-29 11:17 . 2003-06-05 21:13 53,248 –a—— C:\WINDOWS\system32\Process.exe
2008-08-29 11:17 . 2004-07-31 18:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-08-29 11:17 . 2007-10-04 00:36 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2008-08-28 00:42 . 2008-08-28 00:42 d——– C:\Program Files\Abexo
2008-08-27 16:18 . 2008-08-27 16:19 d——– C:\WINDOWS\system32\eMaxt02
2008-08-27 16:18 . 2008-08-27 16:18 d——– C:\Temp\bbc2
2008-08-21 21:50 . 2008-08-21 21:50 d——– C:\Program Files\MP3 Decoder
2008-08-21 15:47 . 2008-08-27 18:34 d——– C:\Documents and Settings\Holly Harris\Application Data\LimeWire
2008-08-18 21:07 . 2008-08-29 13:46 d——– C:\WINDOWS\system32\scripting
2008-08-18 21:07 . 2008-08-29 13:46 d——– C:\WINDOWS\system32\en
2008-08-18 21:07 . 2008-08-29 13:45 d——– C:\WINDOWS\l2schemas
2008-08-18 20:52 . 2007-10-25 21:34 8,460,288 –a—— C:\WINDOWS\system32\dllcache\shell32.dll
2008-08-18 20:51 . 2007-02-28 03:10 2,180,352 –a—— C:\WINDOWS\system32\ntoskrnl.exe
2008-08-18 20:51 . 2007-02-28 03:10 2,180,352 –a—— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-08-18 20:51 . 2007-02-28 02:38 2,057,600 –a—— C:\WINDOWS\system32\ntkrnlpa.exe
2008-08-18 20:51 . 2007-02-28 02:38 2,057,600 –a—— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-08-18 20:51 . 2004-08-03 23:10 19,328 –a—— C:\WINDOWS\system32\drivers\wstcodec.sys
2008-08-18 20:51 . 2004-08-03 23:10 19,328 –a—— C:\WINDOWS\system32\dllcache\wstcodec.sys
2008-08-18 20:51 . 2001-03-02 18:52 15,360 –a—— C:\WINDOWS\system32\asfsipc.dll
2008-08-18 15:04 . 2006-12-28 13:01 19,569 –a—— C:\WINDOWS\005912_.tmp
2008-08-15 13:36 . 2008-08-15 13:37 686 –a—— C:\WINDOWS\WorldTimeClock.ini
2008-08-12 17:20 . 2008-05-01 08:30 331,776 –a—— C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-12 13:56 . 2008-08-12 13:56 d—-c— C:\New Folder
2008-08-03 21:02 . 2008-08-03 21:02 d——– C:\Documents and Settings\Holly Harris\Saved Games
2008-08-03 20:59 . 2008-08-03 20:59 d——– C:\Documents and Settings\Holly Harris\Application Data\iWin
2008-08-03 20:59 . 2008-08-04 00:45 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-03 20:58 . 2008-08-04 16:16 d——– C:\Program Files\Gamesville
2008-08-03 20:58 . 2008-08-03 20:58 d——– C:\Program Files\GamesBar
2008-08-03 20:58 . 2008-08-03 20:58 d——– C:\Program Files\Common Files\Oberon Media

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-01 04:21 ——— d—–w C:\Program Files\Lx_cats
2008-09-01 03:55 ——— d—–w C:\Program Files\Morpheus Ultra
2008-08-31 19:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-31 19:03 ——— d—–w C:\Documents and Settings\Holly Harris\Application Data\AVG7
2008-08-22 02:19 ——— d—–w C:\Program Files\Winamp
2008-08-12 19:34 ——— d—–w C:\Documents and Settings\Holly Harris\Application Data\Winamp
2008-07-31 01:01 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-07-19 04:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 04:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 04:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 04:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 04:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 04:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 04:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 04:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 04:07 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 04:07 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
2008-07-18 20:58 ——— d—–w C:\Program Files\Java
2008-07-14 20:39 ——— d—–w C:\Documents and Settings\Holly Harris\Application Data\Ludia
2008-07-10 23:54 ——— d—–w C:\Program Files\Freeze.com
2008-07-10 01:16 ——— d—–w C:\Program Files\ReflexiveArcade
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\dllcache\es.dll
2008-06-24 16:23 74,240 —-a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:23 74,240 —-a-w C:\WINDOWS\system32\dllcache\mscms.dll
2008-06-23 16:57 826,368 —-a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 —-a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 —-a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 —-a-w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:52 225,920 —-a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-13 13:10 272,128 —-a-w C:\WINDOWS\system32\dllcache\bthport.sys
2007-09-25 20:10 6,221,304 —-a-w C:\Program Files\winamp535_full_emusic-7plus.exe
2007-02-26 05:18 2,792,389 —-a-w C:\Program Files\VBJB-Script_Installer.zip
2006-11-02 23:28 1,951,432 —-a-w C:\Program Files\ppviewer.exe
2006-10-31 04:20 49 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb1478.dat
2006-10-07 00:37 334 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb1942.dat
2006-10-07 00:37 13,046 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb8467.dat
2006-10-07 00:37 0 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb6500.dat
2006-10-06 15:16 9,216 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb6731.dat
2006-10-06 15:16 177,152 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb41.dat
2006-10-06 15:16 0 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb9216.dat
2006-10-06 15:13 0 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb9169.dat
2006-10-06 15:13 0 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb6334.dat
2006-10-06 15:13 0 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb5724.dat
2006-10-06 15:13 0 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb5447.dat
2006-06-15 10:48 6,580,784 ——w C:\Documents and Settings\All Users\MorpheusUltra521.exe
2006-04-01 02:37 16,781,440 ——w C:\Program Files\jre-1_5_0_06-windows-i586-p.exe
2006-03-18 20:04 2,815,270 —-a-w C:\Program Files\VBJB-Script setup_1.exe
.

((((((((((((((((((((((((((((( snapshot@2008-08-31_20.53.56.12 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 19:05 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-10-06 13:16 5058560]
"LXCICATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCItime.dll" [2006-02-24 15:05 73728]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-14 09:56 579584]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-04-29 14:03 180269]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-04 22:09 219136]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-02-01 14:32 8699904]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
2007-02-22 22:04 9216 C:\WINDOWS\system32\avgwlntf.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=lkiduj.dll zrllfp.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.SP54"= SP5X_32.DLL
"VIDC.SP55"= SP5X_32.DLL
"VIDC.SP56"= SP5X_32.DLL
"VIDC.SP57"= SP5X_32.DLL
"VIDC.SP58"= SP5X_32.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Holly Harris^Start Menu^Programs^Startup^BitTorrent.lnk]
path=C:\Documents and Settings\Holly Harris\Start Menu\Programs\Startup\BitTorrent.lnk
backup=C:\WINDOWS\pss\BitTorrent.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Holly Harris^Start Menu^Programs^Startup^MyAdultExplorer.lnk]
path=C:\Documents and Settings\Holly Harris\Start Menu\Programs\Startup\MyAdultExplorer.lnk
backup=C:\WINDOWS\pss\MyAdultExplorer.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
–a—— 2008-04-14 09:56 579584 C:\PROGRA~1\Grisoft\AVG7\avgcc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-04 01:56 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzPrint]
–a—— 2005-08-01 06:05 94208 C:\Program Files\Lexmark 7300 Series\ezprint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMS]
–a—— 2001-09-24 07:39 98304 C:\Program Files\Common Files\Logitech\QCDriver\LVComS.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxcimon.exe]
–a—— 2005-09-30 08:47 200704 C:\Program Files\Lexmark 7300 Series\lxcimon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 10:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
–a—— 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
–a—— 2008-02-01 14:32 8699904 C:\Program Files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2003-10-06 13:16 5058560 C:\WINDOWS\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2003-10-06 13:16 49152 C:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-04-19 20:26 155648 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2006-12-15 02:23 75520 C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2006-04-29 14:03 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
——— 2006-10-18 19:05 204288 C:\Program Files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2006-11-30 20:49 4662776 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
–a—— 2003-08-29 03:59 122880 C:\WINDOWS\BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2003-10-06 13:16 741376 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" -hide
"OneCareUI"="C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=

R3 CIF USB CAMERA Service;CIF USB CAMERA;C:\WINDOWS\system32\DRIVERS\pfc027.sys [2003-10-15 23:58]
R3 lxci_device;lxci_device;C:\WINDOWS\system32\lxcicoms.exe [2005-10-24 06:33]
R3 tbcspud;Santa Cruz Driver;C:\WINDOWS\system32\drivers\tbcspud.sys [2002-04-03 10:51]
R3 tbcwdm;Santa Cruz WDM Driver;C:\WINDOWS\system32\drivers\tbcwdm.sys [2002-04-03 10:51]
S2 Ca533av;Icatch(IV) Video Camera Device;C:\WINDOWS\system32\Drivers\Ca533av.sys [2002-10-21 11:37]
S3 USBCamera;Icatch(IV) Still Camera Device;C:\WINDOWS\system32\Drivers\Bulk533.sys [2002-07-25 11:19]
.
Contents of the 'Scheduled Tasks' folder

2008-08-31 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-04-03 16:12]
.
.
——- Supplementary Scan ——-
.
O8 -: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 -: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 -: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 -: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm

O16 -: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
C:\WINDOWS\Downloaded Program Files\OSDED4D.OSD
C:\WINDOWS\Downloaded Program Files\InstallerControl.dll

O16 -: DirectAnimation Java Classes - file://C:\WINDOWS\Java\classes\dajava.cab
C:\WINDOWS\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-31 23:15:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


**************************************************************************
.
Completion time: 2008-08-31 23:17:40
ComboFix-quarantined-files.txt 2008-09-01 05:16:36
ComboFix2.txt 2008-09-01 02:54:36

Pre-Run: 74,585,939,968 bytes free
Post-Run: 74,585,317,376 bytes free

240 — E O F — 2008-08-13 06:32:05
montanablondie2001, Is AVG resident shield still disabled per instructions in post #2? Make sure that it is. Make the CFScript.txt file again per instructions in post #6 and then drag into the ComboFix icon. After it runs, continue on with the Kaspersky scan. You might want to let it run overnight because it take a couple hours.
Tomk, Siiiighhh, it's me again.I have double checked my AVG to make sure it is off as it is suppose to be. The Icon in the quick bar was off. I went to "Start" "Control Panel" , "Security Center" and it showed the "Firewall" was on and so was the "Virus Protector" "Popup Blocker" is off. I tried to click on the "Firewall to shut it off and it would not let me do anything the same with the "Virus Protector" I then tried back in "Control Panel" and went to "Windows Firewall" , in there it says the firewall is off. I made another copy and went to move the CFScript.txt into ComboFix and once again the same thing is happening. I am getting the same message I got before. What should I do? At this point I am ready to uninstall my AVG and see if that will work. I also noticed there are also limewire remnants as well all of those should be gone. Are those messing me up still? Any Ideas? I would love to at least be able to go to the other site to start my scan. Bless you for having more patience than I. Hopefully you have not gone to bed yet!
Tomk, Thank you once again for your help. It is very late here. I am going to go on to bed, still having the problem with the AVG. Some of it says it is on and some says it is off. I will check back tomorrow. Have a great Labor Day !! I am in the process of moving to Florida and I leave at o'dark thirty Wednesday morning. I would very much like to get this resolved before I go. I will try and log on as soon as possible Monday. Thanks again! :smack:
montanablondie2001, Relax a little. We'll get this. Your firewall shouldn't interfere with us. The only thing we want to shut off in AVG is the resident shield. We aren't trying to shut everything off because you would then be unprotected. Can you drag the script into Combofix and continue? Or does Combofix stop when you get the warning?
Tomk,

Sorry I couldn't get back here sooner. I was having problems with my AVG and it was creating problems. Their help center had me uninstall the program and reinstall. After that was done I was able to drag and drop the CFScript.txt into ComboFix.exe and it ran great no problems. I have that log and am including it. The next step you asked me to do was go to Kaspersky website and perfom an online virus scan. I have tried this twice. yes AVG is turned off and is working properly now, Kaspersky both times has gotten about halfway thru and it is shutting the computer down … the monitor turns blue with a MS Dos message………….. klif.sys …… has created a problem and has created a stop system error message that told if that happens twice I am to reboot in safe mode. the "stop" message was as follows

0x000000DH, 0XF2B13938,0X000000FF, 0X00000001, 0X0804E2E41

here is the ComboFix log, but not sure what to do next with the Kaspersky failure.

ComboFix 08-08-30.03 - Holly Harris 2008-09-01 17:04:16.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.179 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Holly Harris\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\005912_.tmp

.
((((((((((((((((((((((((( Files Created from 2008-08-01 to 2008-09-01 )))))))))))))))))))))))))))))))
.

2008-08-29 18:11 . 2008-08-29 18:11 d——– C:\Documents and Settings\Holly Harris\Application Data\Malwarebytes
2008-08-29 18:10 . 2008-08-31 17:12 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-29 18:10 . 2008-08-29 18:10 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-29 18:10 . 2008-08-17 15:01 38,472 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-29 18:10 . 2008-08-17 15:01 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-08-29 17:31 . 2008-08-31 22:29 d—-c— C:\HJT
2008-08-29 13:25 . 2008-08-29 13:25 d——– C:\Program Files\VS Revo Group
2008-08-29 11:18 . 2008-08-29 11:35 1,316 –a—— C:\WINDOWS\system32\tmp.reg
2008-08-29 11:17 . 2007-09-06 00:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-08-29 11:17 . 2006-04-27 17:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-08-29 11:17 . 2008-08-26 20:19 88,576 –a—— C:\WINDOWS\system32\AntiXPVSTFix.exe
2008-08-29 11:17 . 2008-08-27 15:17 87,040 –a—— C:\WINDOWS\system32\VACFix.exe
2008-08-29 11:17 . 2008-05-18 21:40 82,944 –a—— C:\WINDOWS\system32\IEDFix.exe
2008-08-29 11:17 . 2008-08-28 22:36 82,432 –a—— C:\WINDOWS\system32\IEDFix.C.exe
2008-08-29 11:17 . 2008-08-18 12:19 82,432 –a—— C:\WINDOWS\system32\404Fix.exe
2008-08-29 11:17 . 2003-06-05 21:13 53,248 –a—— C:\WINDOWS\system32\Process.exe
2008-08-29 11:17 . 2004-07-31 18:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-08-29 11:17 . 2007-10-04 00:36 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2008-08-28 00:42 . 2008-08-28 00:42 d——– C:\Program Files\Abexo
2008-08-27 16:18 . 2008-08-27 16:19 d——– C:\WINDOWS\system32\eMaxt02
2008-08-27 16:18 . 2008-08-27 16:18 d——– C:\Temp\bbc2
2008-08-21 21:50 . 2008-08-21 21:50 d——– C:\Program Files\MP3 Decoder
2008-08-21 15:47 . 2008-08-27 18:34 d——– C:\Documents and Settings\Holly Harris\Application Data\LimeWire
2008-08-18 21:07 . 2008-08-29 13:46 d——– C:\WINDOWS\system32\scripting
2008-08-18 21:07 . 2008-08-29 13:46 d——– C:\WINDOWS\system32\en
2008-08-18 21:07 . 2008-08-29 13:45 d——– C:\WINDOWS\l2schemas
2008-08-18 20:52 . 2007-10-25 21:34 8,460,288 –a—— C:\WINDOWS\system32\dllcache\shell32.dll
2008-08-18 20:51 . 2007-02-28 03:10 2,180,352 –a—— C:\WINDOWS\system32\ntoskrnl.exe
2008-08-18 20:51 . 2007-02-28 03:10 2,180,352 –a—— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-08-18 20:51 . 2007-02-28 02:38 2,057,600 –a—— C:\WINDOWS\system32\ntkrnlpa.exe
2008-08-18 20:51 . 2007-02-28 02:38 2,057,600 –a—— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-08-18 20:51 . 2004-08-03 23:10 19,328 –a—— C:\WINDOWS\system32\drivers\wstcodec.sys
2008-08-18 20:51 . 2004-08-03 23:10 19,328 –a—— C:\WINDOWS\system32\dllcache\wstcodec.sys
2008-08-18 20:51 . 2001-03-02 18:52 15,360 –a—— C:\WINDOWS\system32\asfsipc.dll
2008-08-15 13:36 . 2008-08-15 13:37 686 –a—— C:\WINDOWS\WorldTimeClock.ini
2008-08-12 17:20 . 2008-05-01 08:30 331,776 –a—— C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-12 13:56 . 2008-08-12 13:56 d—-c— C:\New Folder
2008-08-03 21:02 . 2008-08-03 21:02 d——– C:\Documents and Settings\Holly Harris\Saved Games
2008-08-03 20:59 . 2008-08-03 20:59 d——– C:\Documents and Settings\Holly Harris\Application Data\iWin
2008-08-03 20:59 . 2008-08-04 00:45 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-03 20:58 . 2008-08-04 16:16 d——– C:\Program Files\Gamesville
2008-08-03 20:58 . 2008-08-03 20:58 d——– C:\Program Files\GamesBar
2008-08-03 20:58 . 2008-08-03 20:58 d——– C:\Program Files\Common Files\Oberon Media

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-01 20:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-09-01 16:07 ——— d—–w C:\Documents and Settings\Holly Harris\Application Data\AVG7
2008-09-01 04:21 ——— d—–w C:\Program Files\Lx_cats
2008-09-01 03:55 ——— d—–w C:\Program Files\Morpheus Ultra
2008-08-22 02:19 ——— d—–w C:\Program Files\Winamp
2008-08-12 19:34 ——— d—–w C:\Documents and Settings\Holly Harris\Application Data\Winamp
2008-07-31 01:01 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-07-18 20:58 ——— d—–w C:\Program Files\Java
2008-07-14 20:39 ——— d—–w C:\Documents and Settings\Holly Harris\Application Data\Ludia
2008-07-10 23:54 ——— d—–w C:\Program Files\Freeze.com
2008-07-10 01:16 ——— d—–w C:\Program Files\ReflexiveArcade
2007-09-25 20:10 6,221,304 —-a-w C:\Program Files\winamp535_full_emusic-7plus.exe
2007-02-26 05:18 2,792,389 —-a-w C:\Program Files\VBJB-Script_Installer.zip
2006-11-02 23:28 1,951,432 —-a-w C:\Program Files\ppviewer.exe
2006-10-31 04:20 49 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb1478.dat
2006-10-07 00:37 334 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb1942.dat
2006-10-07 00:37 13,046 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb8467.dat
2006-10-07 00:37 0 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb6500.dat
2006-10-06 15:16 9,216 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb6731.dat
2006-10-06 15:16 177,152 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb41.dat
2006-10-06 15:16 0 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb9216.dat
2006-10-06 15:13 0 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb9169.dat
2006-10-06 15:13 0 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb6334.dat
2006-10-06 15:13 0 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb5724.dat
2006-10-06 15:13 0 —-a-w C:\Documents and Settings\Holly Harris\Application Data\internaldb5447.dat
2006-06-15 10:48 6,580,784 ——w C:\Documents and Settings\All Users\MorpheusUltra521.exe
2006-04-01 02:37 16,781,440 ——w C:\Program Files\jre-1_5_0_06-windows-i586-p.exe
2006-03-18 20:04 2,815,270 —-a-w C:\Program Files\VBJB-Script setup_1.exe
.

((((((((((((((((((((((((((((( snapshot@2008-08-31_20.53.56.12 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-07-31 01:19:10 271,224 —-a-w C:\WINDOWS\system32\mucltui.dll
+ 2008-07-19 04:07:34 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
- 2007-07-31 01:19:04 207,736 —-a-w C:\WINDOWS\system32\muweb.dll
+ 2008-07-19 04:07:32 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 19:05 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-10-06 13:16 5058560]
"LXCICATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCItime.dll" [2006-02-24 15:05 73728]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-14 09:56 579584]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-04-29 14:03 180269]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-04 22:09 219136]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-02-01 14:32 8699904]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
2007-02-22 22:04 9216 C:\WINDOWS\system32\avgwlntf.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.SP54"= SP5X_32.DLL
"VIDC.SP55"= SP5X_32.DLL
"VIDC.SP56"= SP5X_32.DLL
"VIDC.SP57"= SP5X_32.DLL
"VIDC.SP58"= SP5X_32.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Holly Harris^Start Menu^Programs^Startup^BitTorrent.lnk]
path=C:\Documents and Settings\Holly Harris\Start Menu\Programs\Startup\BitTorrent.lnk
backup=C:\WINDOWS\pss\BitTorrent.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Holly Harris^Start Menu^Programs^Startup^MyAdultExplorer.lnk]
path=C:\Documents and Settings\Holly Harris\Start Menu\Programs\Startup\MyAdultExplorer.lnk
backup=C:\WINDOWS\pss\MyAdultExplorer.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
–a—— 2008-04-14 09:56 579584 C:\PROGRA~1\Grisoft\AVG7\avgcc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-04 01:56 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzPrint]
–a—— 2005-08-01 06:05 94208 C:\Program Files\Lexmark 7300 Series\ezprint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMS]
–a—— 2001-09-24 07:39 98304 C:\Program Files\Common Files\Logitech\QCDriver\LVComS.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxcimon.exe]
–a—— 2005-09-30 08:47 200704 C:\Program Files\Lexmark 7300 Series\lxcimon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 10:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
–a—— 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
–a—— 2008-02-01 14:32 8699904 C:\Program Files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2003-10-06 13:16 5058560 C:\WINDOWS\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2003-10-06 13:16 49152 C:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-04-19 20:26 155648 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2006-12-15 02:23 75520 C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2006-04-29 14:03 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
——— 2006-10-18 19:05 204288 C:\Program Files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2006-11-30 20:49 4662776 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
–a—— 2003-08-29 03:59 122880 C:\WINDOWS\BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2003-10-06 13:16 741376 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" -hide
"OneCareUI"="C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

R3 CIF USB CAMERA Service;CIF USB CAMERA;C:\WINDOWS\system32\DRIVERS\pfc027.sys [2003-10-15 23:58]
R3 tbcspud;Santa Cruz Driver;C:\WINDOWS\system32\drivers\tbcspud.sys [2002-04-03 10:51]
R3 tbcwdm;Santa Cruz WDM Driver;C:\WINDOWS\system32\drivers\tbcwdm.sys [2002-04-03 10:51]
S2 Ca533av;Icatch(IV) Video Camera Device;C:\WINDOWS\system32\Drivers\Ca533av.sys [2002-10-21 11:37]
S3 lxci_device;lxci_device;C:\WINDOWS\system32\lxcicoms.exe [2005-10-24 06:33]
S3 USBCamera;Icatch(IV) Still Camera Device;C:\WINDOWS\system32\Drivers\Bulk533.sys [2002-07-25 11:19]
.
Contents of the 'Scheduled Tasks' folder

2008-08-31 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-04-03 16:12]
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-01 17:09:23
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2008-09-01 17:16:38 - machine was rebooted [Holly Harris]
ComboFix-quarantined-files.txt 2008-09-01 23:16:32
ComboFix2.txt 2008-09-01 05:17:42
ComboFix3.txt 2008-09-01 02:54:36

Pre-Run: 74,514,485,248 bytes free
Post-Run: 74,511,216,640 bytes free

227 — E O F — 2008-09-01 16:09:38
montanablondie2001,

Something weird is happening with Kaspersky lately. About half of the victims that I have worked with in the last couple weeks have been unable to get it to work. Lets try a different scanner.

I need you to run the following scan: Eset Online Scanner

  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI