This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] browser corrupted ?

44 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I guess that I will uninstall Adobe reader. It is an older version 6 , and I have heard warnings that older versions could be compromised , but the latest version (9?) , is almost twice as big on the drive as the old version , and I avoid "bloatted" programs since ZoneAlarm firewall got bloatted like that and ZA made it uncompatable with CA Antivirus , that's why I don't have a firewall . Anyway , back to the original problem , the browser problem . Is the browser the whole problem , is that why I have trouble navigating to folders and drives on the infected Acer , can I download and install a new browser like Firefox , by downloading the installer to my laptop and transfering the installer by the thumb drive ? Can I uninstall IE7 from XP Home ? (I see that Microsoft is beginning to play the "uninstallable" game ) .
Uninstall Internet Explorer 7 to return to Internet Explorer 6 on Windows XP Click "Start," and then click "Control Panel." Click "Add or Remove Programs." Check "Show Updates" at the top of the dialog box. Scroll down the list and highlight the version of Internet Explorer 7 that you are running, and then click "Change/Remove."
Thanks for your reply . I have uninstalled IE7 by your instructions , after the computer restarted , I tried clicking on the My Computer icon , it still takes about 2 minutes for the icons to appear , in Windows explorer when you click on the my computer icon in the left window , nothing happens for about 2 minutes , but when the tree of dirves finally appears , I can access them instantly , and all the other icons in the left window work OK . Anyway , I think all the problems are still there . Also although I said that my e-mail was still working , apparently it only worked for about half a day after the malware started , and now I can't downlad or send any e-mail , except with this laptop which I am still using . However , I did some google searching with the laptop for browser fixes and alternatives , and I found a version of Firefox which is supposed to work from a thumbdrive , so I downloaded it to the laptop , installed it on the thumbdrive I've been using , plugged it into he infected computer , and I can actually ACCESS THE INTERNET on the infected computer with the firefox browser . Which probably is a sign that I should switch totally to Firefox . Well I just tried to download save a file on the infected computer that I found with the Firefox browser , and it still won't let me change the "save to" folder , the process freezes and I have to close it with the unresponsive program box . so even with Firefox as a browser , something is still wrong with the OS . By the way , this is Wednesday and I am going to be at my computer all day and into the evening , I am frevently hopeing we can get it fixed today . The computer we are trying to fix is my busines computer , and I need it every day . And one more thing concerning the portable firefox I was using . I could get to the WhatTheTech forumpage with it on the infected computer , but t wouldn't let me log in there with my nick and password , even though they work to log in with the laptop . It asks me to register , but if I do it will tell me I am already registered , and I will be in an endless loop .
Do you still have Combofix? Run a new scan.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
Oh no , just as I am plugging in the thumbdrive to transfer the combo log , I remember I did'nt disable the protective programs . I'll post the log anyway , but let me know if I will have to re-do it


ComboFix 08-11-04.02 - vp^ 2008-11-05 12:35:33.8 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.373 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-10-05 to 2008-11-05 )))))))))))))))))))))))))))))))
.

2008-11-05 12:08 . 2008-11-05 12:08 388,608 –a—— c:\windows\system32\CF23014.exe.vir
2008-11-05 09:07 . 2008-11-05 09:07 d——– c:\windows\LastGood
2008-11-05 08:48 . 2006-11-07 21:01 66,048 –a—— c:\windows\ieResetIcons.exe
2008-11-05 08:48 . 2008-11-05 08:48 230 –a—— c:\windows\system32\spupdsvc.inf
2008-11-01 15:38 . 2008-11-01 15:38 d——– c:\program files\ERUNT
2008-11-01 15:30 . 2008-11-01 15:30 d——– c:\program files\Trend Micro
2008-11-01 13:31 . 2008-11-03 01:30 1,374 –a—— c:\windows\imsins.BAK
2008-10-16 10:36 . 2008-10-31 18:53 54,156 –ah—– c:\windows\QTFont.qfn
2008-10-16 10:36 . 2008-10-16 10:36 1,409 –a—— c:\windows\QTFont.for
2008-10-11 19:35 . 2008-10-11 19:35 d——– c:\documents and settings\vp^\Application Data\Ulead Systems
2008-10-11 19:33 . 2008-10-11 19:33 d——– c:\program files\Ulead Systems
2008-10-11 19:33 . 2008-10-11 19:33 d——– c:\documents and settings\All Users\Application Data\Ulead Systems
2008-10-11 19:32 . 2008-10-11 19:32 d——– c:\windows\Noslip
2008-10-11 19:29 . 2008-10-11 19:29 11,014,144 –a—— c:\program files\UGA5TBYB_E_USG.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-02 01:49 5,527 —-a-w c:\program files\hijackthis11-1.log
2008-11-02 01:48 5,527 —-a-w c:\program files\hijackthis.log
2008-10-30 02:54 27,991 —-a-w c:\program files\081029_2140.caf.txt
2008-10-15 17:57 332,800 —-a-w c:\windows\system32\dllcache\netapi32.dll
2008-10-03 18:41 6,066,176 ——w c:\windows\system32\dllcache\ieframe.dll
2008-09-15 12:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-09-15 12:57 1,846,016 —-a-w c:\windows\system32\dllcache\win32k.sys
2008-08-29 20:58 3,297,268 —-a-w c:\windows\system32\via_chipset_AC_97_sound_driver.ZIP
2008-08-28 11:04 333,056 —-a-w c:\windows\system32\dllcache\srv.sys
2008-08-26 08:24 63,488 ——w c:\windows\system32\dllcache\icardie.dll
2008-08-26 08:24 52,224 ——w c:\windows\system32\dllcache\msfeedsbs.dll
2008-08-26 08:24 459,264 ——w c:\windows\system32\dllcache\msfeeds.dll
2008-08-26 08:24 383,488 ——w c:\windows\system32\dllcache\ieapfltr.dll
2008-08-26 08:24 267,776 ——w c:\windows\system32\dllcache\iertutil.dll
2008-08-25 09:38 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
2008-08-14 11:00 2,180,352 —-a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 11:00 2,180,352 —-a-w c:\windows\system32\dllcache\ntoskrnl.exe
2008-08-14 10:58 2,136,064 —-a-w c:\windows\system32\dllcache\ntkrnlmp.exe
2008-08-14 10:51 138,368 —-a-w c:\windows\system32\dllcache\afd.sys
2008-08-14 10:22 2,057,728 —-a-w c:\windows\system32\ntkrnlpa.exe
2008-08-14 10:22 2,057,728 —-a-w c:\windows\system32\dllcache\ntkrnlpa.exe
2008-08-14 10:22 2,015,744 —-a-w c:\windows\system32\dllcache\ntkrpamp.exe
2008-06-23 03:32 2,703 —-a-w c:\program files\080622_2214.caf
2008-06-22 04:25 21,853 —-a-w c:\program files\080621_2313.caf
2008-06-21 14:58 2,370 —-a-w c:\program files\080621_0947.caf
2008-06-19 10:12 6,922 —-a-w c:\program files\080618_2322.caf
2008-06-18 14:59 4,128 —-a-w c:\program files\080618_0941.caf
2008-06-16 02:49 6,988 —-a-w c:\program files\080615_2136.caf
2008-06-14 16:50 63,189 —-a-w c:\program files\080614_1134.caf
2008-06-14 13:52 11,984 —-a-w c:\program files\080614_0838.caf
2008-06-13 05:04 12,918 —-a-w c:\program files\080612_2324.caf
2008-06-12 14:28 9,446 —-a-w c:\program files\080612_0906.caf
2008-06-12 03:20 2,451 —-a-w c:\program files\080611_2159.caf
2008-06-11 21:03 4,137 —-a-w c:\program files\080611_1502.caf
2008-06-10 18:05 146,371 —-a-w c:\program files\080610_1246.caf
2008-06-10 02:01 246,692 —-a-w c:\program files\080609_2041.caf
2008-06-08 22:37 83,908 —-a-w c:\program files\080608_1718.caf
2008-06-08 21:38 14,359 —-a-w c:\program files\080608_1618.caf
2008-06-08 16:00 16,728 —-a-w c:\program files\080608_1032.caf
2008-06-07 10:49 58,616 —-a-w c:\program files\080603_1143.caf
2008-06-05 03:02 2,762 —-a-w c:\program files\080604_2136.caf
2008-06-01 03:54 38,227 —-a-w c:\program files\080531_2238.caf
2008-05-31 18:49 4,420 —-a-w c:\program files\080531_1135.caf
2008-05-29 17:55 9,909 —-a-w c:\program files\080529_1238.caf
2008-05-29 01:43 50,096 —-a-w c:\program files\080528_2027.caf
2008-05-27 03:10 18,081 —-a-w c:\program files\080526_2159.caf
2008-05-26 21:58 6,012 —-a-w c:\program files\080523_2230.caf
2008-05-25 14:29 2,542 —-a-w c:\program files\080525_0908.caf
2008-05-24 18:18 28,705 —-a-w c:\program files\080524_0704.caf
2008-05-23 00:28 1,466 —-a-w c:\program files\080522_0027.caf
2008-05-21 23:50 1,621 —-a-w c:\program files\080521_1839.caf
2008-05-20 02:47 7,332 —-a-w c:\program files\080519_2120.caf
2008-05-18 00:08 7,055 —-a-w c:\program files\080517_1849.caf
2008-05-17 00:46 5,301 —-a-w c:\program files\080516_1931.caf
2008-05-16 19:56 8,950 —-a-w c:\program files\080516_1444.caf
2008-05-16 04:06 15,902 —-a-w c:\program files\080515_2246.caf
2008-05-15 13:44 18,879 —-a-w c:\program files\080515_0821.caf
2008-05-15 04:31 109,935 —-a-w c:\program files\080514_2312.caf
2008-05-15 03:23 1,506 —-a-w c:\program files\080514_2206.caf
2008-05-14 19:17 1,908 —-a-w c:\program files\080514_1403.caf
2008-05-12 23:05 84,946 —-a-w c:\program files\080512_1732.caf
2008-05-11 05:52 4,402 —-a-w c:\program files\080511_0040.caf
2008-05-10 05:17 100,894 —-a-w c:\program files\080509_2357.caf
2008-05-10 02:07 26,592 —-a-w c:\program files\080509_14061.caf
2008-05-08 03:15 53,533 —-a-w c:\program files\080507_2155.caf
2008-05-06 14:33 65,496 —-a-w c:\program files\080506_0910.caf
2008-05-05 19:27 2,059 —-a-w c:\program files\080505_1409.caf
2008-05-04 13:06 9,118 —-a-w c:\program files\080504_0747.caf
2008-05-03 00:21 991 —-a-w c:\program files\080502_1852.caf
2008-05-02 13:33 515 —-a-w c:\program files\080502_0811.caf
2008-05-01 18:42 1,703 —-a-w c:\program files\080501_1328.caf
2008-05-01 15:03 93,623 —-a-w c:\program files\080430_2221.caf
2008-04-29 19:57 1,062 —-a-w c:\program files\080429_1340.caf
2008-04-29 19:32 4,710 —-a-w c:\program files\080428_0914.caf
2008-04-29 05:12 41,995 —-a-w c:\program files\080428_2355.caf
2008-04-27 17:29 2,741 —-a-w c:\program files\080427_1214.caf
2008-04-27 17:06 3,113 —-a-w c:\program files\My-Disc32.caf
2008-04-27 17:01 3,117 —-a-w c:\program files\080427_0729.caf
2008-04-26 20:58 960 —-a-w c:\program files\080426_1528.caf
2008-04-26 14:27 359 —-a-w c:\program files\080426_0910.caf
2008-04-25 22:28 1,177 —-a-w c:\program files\080425_1712.caf
2008-04-25 14:18 3,834 —-a-w c:\program files\080425_0855.caf
2008-04-24 21:36 5,702 —-a-w c:\program files\080424_1614.caf
2008-04-24 16:29 2,080 —-a-w c:\program files\080424_1114.caf
2008-04-22 16:34 83,652 —-a-w c:\program files\080422_1115.caf
2008-04-22 12:42 1,631 —-a-w c:\program files\080422_0720.caf
2008-04-20 20:12 16,869 —-a-w c:\program files\080420_1500.caf
2008-04-19 17:45 53,404 —-a-w c:\program files\080419_1234.caf
2008-04-19 15:05 60,632 —-a-w c:\program files\080418_2136.caf
2008-04-17 20:17 2,854 —-a-w c:\program files\080417_1503.caf
2008-04-16 21:08 5,840 —-a-w c:\program files\080416_1551.caf
2008-04-16 16:38 7,058 —-a-w c:\program files\080415_0809.caf
2008-04-13 04:37 115,642 —-a-w c:\program files\080412_2313.caf
2008-04-12 23:52 2,704 —-a-w c:\program files\080412_1728.caf
2008-04-11 21:09 14,853 —-a-w c:\program files\080411_1543.caf
2008-04-11 18:59 3,318 —-a-w c:\program files\080411_1326.caf
2008-04-11 13:35 3,022 —-a-w c:\program files\080410_0842.caf
2008-04-10 02:36 3,400 —-a-w c:\program files\080409_2121.caf
2008-04-08 13:28 1,056 —-a-w c:\program files\080408_0812.caf
2008-04-07 05:10 1,349 —-a-w c:\program files\080406_2358.caf
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eRecoveryService"="c:\program files\Acer\eRecovery\Monitor.exe" [2005-06-20 352256]
"!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2007-09-28 177416]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2007-04-30 230928]
"SoundMan"="SOUNDMAN.EXE" [2005-06-08 c:\windows\SOUNDMAN.EXE]
"VTTimer"="VTTimer.exe" [2005-05-13 c:\windows\system32\VTTimer.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.avis"= ff_acm.acm

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Easy Video Joiner Help.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Easy Video Joiner Help.lnk
backup=c:\windows\pss\Easy Video Joiner Help.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Easy Video Joiner on the Web.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Easy Video Joiner on the Web.lnk
backup=c:\windows\pss\Easy Video Joiner on the Web.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Easy Video Joiner.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Easy Video Joiner.lnk
backup=c:\windows\pss\Easy Video Joiner.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Uninstall Easy Video Joiner.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Uninstall Easy Video Joiner.lnk
backup=c:\windows\pss\Uninstall Easy Video Joiner.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Verizon Online Help & Support.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Verizon Online Help & Support.lnk
backup=c:\windows\pss\Verizon Online Help & Support.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Verizon Support Service.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Verizon Support Service.lnk
backup=c:\windows\pss\Verizon Support Service.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^vp^^Start Menu^Programs^Startup^Kremlin Sentry.lnk]
path=c:\documents and settings\vp^\Start Menu\Programs\Startup\Kremlin Sentry.lnk
backup=c:\windows\pss\Kremlin Sentry.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AspireService]
–a—— 2005-06-04 12:40 110592 c:\program files\acer\Acer eMode Management\AspireService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX3800 Series]
–a—— 2005-02-07 15:00 98304 c:\windows\system32\spool\drivers\w32x86\3\E_FATIACA.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaSync]
–a—— 2005-06-01 14:25 421888 c:\program files\acer\Acer eConsole\MediaSync.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2004-10-13 09:24 1694208 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
——— 2005-09-16 16:41 1961984 c:\program files\Ahead\Nero BackItUp\NBJ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
–a—— 2004-07-15 01:07 32768 c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Free Download Manager\\fdmwi.exe"=
"c:\\Program Files\\Westell\\Diagnostic Icon\\DGNIcon.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=

R2 int15.sys;int15.sys;c:\program files\acer\eRecovery\int15.sys [2005-01-13 69632]
S3 {DEF85C80-216A-43ab-AF70-1665EDBE2780};{DEF85C80-216A-43ab-AF70-1665EDBE2780};c:\windows\TEMP\11B.tmp [ ]
.
Contents of the 'Scheduled Tasks' folder

2008-11-05 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = about:blank
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://cgi.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=2.0&bm=bz_welcome
O8 -: Download all with Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
O8 -: Download selected with Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
O8 -: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
O8 -: Download with Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm

O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

O16 -: vzTCPConfig
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-05 12:41:09
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}]
"ImagePath"="\??\c:\windows\TEMP\11B.tmp"
.
Completion time: 2008-11-05 12:44:03
ComboFix-quarantined-files.txt 2008-11-05 17:43:36

Pre-Run: 3,933,667,328 bytes free
Post-Run: 3,926,360,064 bytes free

226 — E O F — 2008-11-05 14:10:48
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\windows\system32\CF23014.exe.vir
c:\windows\TEMP\11B.tmp

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Here are the latest logs

ComboFix 08-11-04.02 - vp^ 2008-11-05 14:03:33.9 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.314 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\vp^\Desktop\CFScript.txt
* Created a new restore point

FILE ::
c:\windows\system32\CF23014.exe.vir
c:\windows\TEMP\11B.tmp
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\CF23014.exe.vir

.
((((((((((((((((((((((((( Files Created from 2008-10-05 to 2008-11-05 )))))))))))))))))))))))))))))))
.

2008-11-05 13:58 . 2008-11-05 13:58 388,608 –a—— c:\windows\system32\CF11848.exe.vir
2008-11-05 09:07 . 2008-11-05 09:07 d——– c:\windows\LastGood
2008-11-05 08:48 . 2006-11-07 21:01 66,048 –a—— c:\windows\ieResetIcons.exe
2008-11-05 08:48 . 2008-11-05 08:48 230 –a—— c:\windows\system32\spupdsvc.inf
2008-11-01 15:38 . 2008-11-01 15:38 d——– c:\program files\ERUNT
2008-11-01 15:30 . 2008-11-01 15:30 d——– c:\program files\Trend Micro
2008-11-01 13:31 . 2008-11-03 01:30 1,374 –a—— c:\windows\imsins.BAK
2008-10-16 10:36 . 2008-10-31 18:53 54,156 –ah—– c:\windows\QTFont.qfn
2008-10-16 10:36 . 2008-10-16 10:36 1,409 –a—— c:\windows\QTFont.for
2008-10-11 19:35 . 2008-10-11 19:35 d——– c:\documents and settings\vp^\Application Data\Ulead Systems
2008-10-11 19:33 . 2008-10-11 19:33 d——– c:\program files\Ulead Systems
2008-10-11 19:33 . 2008-10-11 19:33 d——– c:\documents and settings\All Users\Application Data\Ulead Systems
2008-10-11 19:32 . 2008-10-11 19:32 d——– c:\windows\Noslip
2008-10-11 19:29 . 2008-10-11 19:29 11,014,144 –a—— c:\program files\UGA5TBYB_E_USG.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-02 01:49 5,527 —-a-w c:\program files\hijackthis11-1.log
2008-11-02 01:48 5,527 —-a-w c:\program files\hijackthis.log
2008-10-30 02:54 27,991 —-a-w c:\program files\081029_2140.caf.txt
2008-10-15 17:57 332,800 —-a-w c:\windows\system32\dllcache\netapi32.dll
2008-10-03 18:41 6,066,176 ——w c:\windows\system32\dllcache\ieframe.dll
2008-09-15 12:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-09-15 12:57 1,846,016 —-a-w c:\windows\system32\dllcache\win32k.sys
2008-08-29 20:58 3,297,268 —-a-w c:\windows\system32\via_chipset_AC_97_sound_driver.ZIP
2008-08-28 11:04 333,056 —-a-w c:\windows\system32\dllcache\srv.sys
2008-08-26 08:24 63,488 ——w c:\windows\system32\dllcache\icardie.dll
2008-08-26 08:24 52,224 ——w c:\windows\system32\dllcache\msfeedsbs.dll
2008-08-26 08:24 459,264 ——w c:\windows\system32\dllcache\msfeeds.dll
2008-08-26 08:24 383,488 ——w c:\windows\system32\dllcache\ieapfltr.dll
2008-08-26 08:24 267,776 ——w c:\windows\system32\dllcache\iertutil.dll
2008-08-25 09:38 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
2008-08-14 11:00 2,180,352 —-a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 11:00 2,180,352 —-a-w c:\windows\system32\dllcache\ntoskrnl.exe
2008-08-14 10:58 2,136,064 —-a-w c:\windows\system32\dllcache\ntkrnlmp.exe
2008-08-14 10:51 138,368 —-a-w c:\windows\system32\dllcache\afd.sys
2008-08-14 10:22 2,057,728 —-a-w c:\windows\system32\ntkrnlpa.exe
2008-08-14 10:22 2,057,728 —-a-w c:\windows\system32\dllcache\ntkrnlpa.exe
2008-08-14 10:22 2,015,744 —-a-w c:\windows\system32\dllcache\ntkrpamp.exe
2008-06-23 03:32 2,703 —-a-w c:\program files\080622_2214.caf
2008-06-22 04:25 21,853 —-a-w c:\program files\080621_2313.caf
2008-06-21 14:58 2,370 —-a-w c:\program files\080621_0947.caf
2008-06-19 10:12 6,922 —-a-w c:\program files\080618_2322.caf
2008-06-18 14:59 4,128 —-a-w c:\program files\080618_0941.caf
2008-06-16 02:49 6,988 —-a-w c:\program files\080615_2136.caf
2008-06-14 16:50 63,189 —-a-w c:\program files\080614_1134.caf
2008-06-14 13:52 11,984 —-a-w c:\program files\080614_0838.caf
2008-06-13 05:04 12,918 —-a-w c:\program files\080612_2324.caf
2008-06-12 14:28 9,446 —-a-w c:\program files\080612_0906.caf
2008-06-12 03:20 2,451 —-a-w c:\program files\080611_2159.caf
2008-06-11 21:03 4,137 —-a-w c:\program files\080611_1502.caf
2008-06-10 18:05 146,371 —-a-w c:\program files\080610_1246.caf
2008-06-10 02:01 246,692 —-a-w c:\program files\080609_2041.caf
2008-06-08 22:37 83,908 —-a-w c:\program files\080608_1718.caf
2008-06-08 21:38 14,359 —-a-w c:\program files\080608_1618.caf
2008-06-08 16:00 16,728 —-a-w c:\program files\080608_1032.caf
2008-06-07 10:49 58,616 —-a-w c:\program files\080603_1143.caf
2008-06-05 03:02 2,762 —-a-w c:\program files\080604_2136.caf
2008-06-01 03:54 38,227 —-a-w c:\program files\080531_2238.caf
2008-05-31 18:49 4,420 —-a-w c:\program files\080531_1135.caf
2008-05-29 17:55 9,909 —-a-w c:\program files\080529_1238.caf
2008-05-29 01:43 50,096 —-a-w c:\program files\080528_2027.caf
2008-05-27 03:10 18,081 —-a-w c:\program files\080526_2159.caf
2008-05-26 21:58 6,012 —-a-w c:\program files\080523_2230.caf
2008-05-25 14:29 2,542 —-a-w c:\program files\080525_0908.caf
2008-05-24 18:18 28,705 —-a-w c:\program files\080524_0704.caf
2008-05-23 00:28 1,466 —-a-w c:\program files\080522_0027.caf
2008-05-21 23:50 1,621 —-a-w c:\program files\080521_1839.caf
2008-05-20 02:47 7,332 —-a-w c:\program files\080519_2120.caf
2008-05-18 00:08 7,055 —-a-w c:\program files\080517_1849.caf
2008-05-17 00:46 5,301 —-a-w c:\program files\080516_1931.caf
2008-05-16 19:56 8,950 —-a-w c:\program files\080516_1444.caf
2008-05-16 04:06 15,902 —-a-w c:\program files\080515_2246.caf
2008-05-15 13:44 18,879 —-a-w c:\program files\080515_0821.caf
2008-05-15 04:31 109,935 —-a-w c:\program files\080514_2312.caf
2008-05-15 03:23 1,506 —-a-w c:\program files\080514_2206.caf
2008-05-14 19:17 1,908 —-a-w c:\program files\080514_1403.caf
2008-05-12 23:05 84,946 —-a-w c:\program files\080512_1732.caf
2008-05-11 05:52 4,402 —-a-w c:\program files\080511_0040.caf
2008-05-10 05:17 100,894 —-a-w c:\program files\080509_2357.caf
2008-05-10 02:07 26,592 —-a-w c:\program files\080509_14061.caf
2008-05-08 03:15 53,533 —-a-w c:\program files\080507_2155.caf
2008-05-06 14:33 65,496 —-a-w c:\program files\080506_0910.caf
2008-05-05 19:27 2,059 —-a-w c:\program files\080505_1409.caf
2008-05-04 13:06 9,118 —-a-w c:\program files\080504_0747.caf
2008-05-03 00:21 991 —-a-w c:\program files\080502_1852.caf
2008-05-02 13:33 515 —-a-w c:\program files\080502_0811.caf
2008-05-01 18:42 1,703 —-a-w c:\program files\080501_1328.caf
2008-05-01 15:03 93,623 —-a-w c:\program files\080430_2221.caf
2008-04-29 19:57 1,062 —-a-w c:\program files\080429_1340.caf
2008-04-29 19:32 4,710 —-a-w c:\program files\080428_0914.caf
2008-04-29 05:12 41,995 —-a-w c:\program files\080428_2355.caf
2008-04-27 17:29 2,741 —-a-w c:\program files\080427_1214.caf
2008-04-27 17:06 3,113 —-a-w c:\program files\My-Disc32.caf
2008-04-27 17:01 3,117 —-a-w c:\program files\080427_0729.caf
2008-04-26 20:58 960 —-a-w c:\program files\080426_1528.caf
2008-04-26 14:27 359 —-a-w c:\program files\080426_0910.caf
2008-04-25 22:28 1,177 —-a-w c:\program files\080425_1712.caf
2008-04-25 14:18 3,834 —-a-w c:\program files\080425_0855.caf
2008-04-24 21:36 5,702 —-a-w c:\program files\080424_1614.caf
2008-04-24 16:29 2,080 —-a-w c:\program files\080424_1114.caf
2008-04-22 16:34 83,652 —-a-w c:\program files\080422_1115.caf
2008-04-22 12:42 1,631 —-a-w c:\program files\080422_0720.caf
2008-04-20 20:12 16,869 —-a-w c:\program files\080420_1500.caf
2008-04-19 17:45 53,404 —-a-w c:\program files\080419_1234.caf
2008-04-19 15:05 60,632 —-a-w c:\program files\080418_2136.caf
2008-04-17 20:17 2,854 —-a-w c:\program files\080417_1503.caf
2008-04-16 21:08 5,840 —-a-w c:\program files\080416_1551.caf
2008-04-16 16:38 7,058 —-a-w c:\program files\080415_0809.caf
2008-04-13 04:37 115,642 —-a-w c:\program files\080412_2313.caf
2008-04-12 23:52 2,704 —-a-w c:\program files\080412_1728.caf
2008-04-11 21:09 14,853 —-a-w c:\program files\080411_1543.caf
2008-04-11 18:59 3,318 —-a-w c:\program files\080411_1326.caf
2008-04-11 13:35 3,022 —-a-w c:\program files\080410_0842.caf
2008-04-10 02:36 3,400 —-a-w c:\program files\080409_2121.caf
2008-04-08 13:28 1,056 —-a-w c:\program files\080408_0812.caf
2008-04-07 05:10 1,349 —-a-w c:\program files\080406_2358.caf
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eRecoveryService"="c:\program files\Acer\eRecovery\Monitor.exe" [2005-06-20 352256]
"!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2007-09-28 177416]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2007-04-30 230928]
"SoundMan"="SOUNDMAN.EXE" [2005-06-08 c:\windows\SOUNDMAN.EXE]
"VTTimer"="VTTimer.exe" [2005-05-13 c:\windows\system32\VTTimer.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.avis"= ff_acm.acm

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Easy Video Joiner Help.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Easy Video Joiner Help.lnk
backup=c:\windows\pss\Easy Video Joiner Help.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Easy Video Joiner on the Web.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Easy Video Joiner on the Web.lnk
backup=c:\windows\pss\Easy Video Joiner on the Web.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Easy Video Joiner.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Easy Video Joiner.lnk
backup=c:\windows\pss\Easy Video Joiner.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Uninstall Easy Video Joiner.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Uninstall Easy Video Joiner.lnk
backup=c:\windows\pss\Uninstall Easy Video Joiner.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Verizon Online Help & Support.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Verizon Online Help & Support.lnk
backup=c:\windows\pss\Verizon Online Help & Support.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Verizon Support Service.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Verizon Support Service.lnk
backup=c:\windows\pss\Verizon Support Service.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^vp^^Start Menu^Programs^Startup^Kremlin Sentry.lnk]
path=c:\documents and settings\vp^\Start Menu\Programs\Startup\Kremlin Sentry.lnk
backup=c:\windows\pss\Kremlin Sentry.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AspireService]
–a—— 2005-06-04 12:40 110592 c:\program files\acer\Acer eMode Management\AspireService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX3800 Series]
–a—— 2005-02-07 15:00 98304 c:\windows\system32\spool\drivers\w32x86\3\E_FATIACA.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaSync]
–a—— 2005-06-01 14:25 421888 c:\program files\acer\Acer eConsole\MediaSync.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2004-10-13 09:24 1694208 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
——— 2005-09-16 16:41 1961984 c:\program files\Ahead\Nero BackItUp\NBJ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
–a—— 2004-07-15 01:07 32768 c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Free Download Manager\\fdmwi.exe"=
"c:\\Program Files\\Westell\\Diagnostic Icon\\DGNIcon.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=

R2 int15.sys;int15.sys;c:\program files\acer\eRecovery\int15.sys [2005-01-13 69632]
S3 {DEF85C80-216A-43ab-AF70-1665EDBE2780};{DEF85C80-216A-43ab-AF70-1665EDBE2780};c:\windows\TEMP\11B.tmp [ ]
.
Contents of the 'Scheduled Tasks' folder

2008-11-05 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-05 14:09:38
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}]
"ImagePath"="\??\c:\windows\TEMP\11B.tmp"
.
Completion time: 2008-11-05 14:12:14
ComboFix-quarantined-files.txt 2008-11-05 19:12:00
ComboFix2.txt 2008-11-05 17:44:08

Pre-Run: 3,875,340,288 bytes free
Post-Run: 3,859,677,184 bytes free

222 — E O F — 2008-11-05 14:10:48



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:16, on 2008-11-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\acer\Acer eConsole\MediaServerService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\Acer\eRecovery\Monitor.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://cgi.verizon.net/bookmarks/bmredir.a…p;bm=bz_welcome
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: vzTCPConfig -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1158766737609
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1163900908375
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} -
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\acer\Acer eConsole\MediaServerService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

–
End of file - 6069 bytes
Stilling t seems to have all the problems including difficulty with My Computer , browser window freezes if trying to access a web page .
sorry for delay , search had to go thru 140 gig I searched for any file containing .exe.vir as part of its name 2 instances found CF11848.exe.vir location C:\WINDOWS\system32 CF23014.exe.vir.vir location C:\Qobox\Quarantine\C\WINDOWS\system32
While I was waiting for your reply it occured to me that since I could use the infected computer with the portable firefox , perhaps I could get an update to AdAware with it . And that's exactly what happened , I was able to update to today and did a quick scan . it found 7 instances of malware , I will post just the header and bottom of the log : Ad-Aware Build Log File Created on: 2008-11-05 19:18:22 Using Definitions File: C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\core.aawdef Computer name: ACER Name of user performing scan: SYSTEM System information =========================== Number of processors: 1 Processor type: AMD Sempron™ Processor 3300+ Memory Available: 27% Total Physical Memory: 737656832 Bytes Available Physical Memory: 198004736 Bytes Total Page File Size: 1804316672 Bytes Available On Page File: 1106231296 Bytes Total Virtual Memory: 2147352576 Bytes Available Virtual Memory: 1755107328 Bytes OS: Microsoft Windows XP Service Pack 2 (Build 2600) Ad-Aware Settings =========================== Skipping files larger than 1048576 kB Ignoring infections with lower TAI than: 3 Extended Ad-Aware Settings =========================== Unloading known modules during scan Ignoring spanned files when scanning cab archives Scanning registry for all users Using permanent archive caching Reanalyzing results after scanning before displaying results Trying to unload modules prior to removal Let Windows remove files currently in use at next reboot Removing quarantined objects after restore Logging Ad-Aware events Blocking Pop-Ups aggressively Deactivating Ad-Watch during scans Writeprotecting system files after repairs Including Ad-Aware command line parameters in log file Include info about ignored objects in log file Including basic settings in log file Including advanced settings in log file Including user and computer name in log file Include reference summary in log file Creating log file for removal operations Including module info in log file Include Alternate Data Stream details in log file Create and save WebUpdate log file Databaseinfo =========================== Version number: 137 Build Number: 0 Build Date and Time: 2008/11/05 02:18:45 Scan Statistics =========================== Method: Smart Scan tracking cookies………………………..: On Scan ADS filestreams…………………………: Off Item Scanned: 150445 Infections Detected: 10 Infections Ignored: 0 Scan detailed statistics =========================== Type Critical Total Process Scan….: 0 0 Registry Scan…: 7 7 Registry PE Scan: 0 0 Hosts File Scan.: 0 0 File Scan…….: 0 0 Folder Scan…..: 0 0 LSP Scan……..: 0 0 ADS Scan……..: 0 0 Cookie Scan…..: 0 0 File Hash Scan..: 0 0 Infections Found =========================== Family Id: 941 Name: Win32.Trojan.Agent Category: Malware TAI:10 Item Id: 300054460 Value: Root: HKLM Path: system\controlset003\services\{def85c80-216a-43ab-af70-1665edbe2780} Item Id: 300030980 Value: Root: HKLM Path: software\microsoft\windows nt\currentversion\appcompatflags\layers Value: c:\windows\explorer.exe Item Id: 300051765 Value: Root: HKLM Path: software\microsoft\windows\currentversion\policies\explorer\run Family Id: 2130 Name: Win32.Backdoor.Sinowal Category: Malware TAI:10 Item Id: 300052650 Value: Root: HKLM Path: system\controlset001\enum\root\legacy_{def85c80-216a-43ab-af70-1665edbe2780} Item Id: 300052651 Value: Root: HKLM Path: system\controlset001\services\{def85c80-216a-43ab-af70-1665edbe2780} Item Id: 300052652 Value: Root: HKLM Path: system\currentcontrolset\enum\root\legacy_{def85c80-216a-43ab-af70-1665edbe2780} Item Id: 300052653 Value: Root: HKLM Path: system\currentcontrolset\services\{def85c80-216a-43ab-af70-1665edbe2780} Family Id: 9999 Name: MRU Object Category: MRU Object TAI:0 Item Id: 1 Value: MRU Path: C:\Documents and Settings\vp^\Recent Count: 296 Item Id: 2 Value: MRU Registry Key: S-1-5-21-1871259199-1857639920-1093324118-1006\Software\Microsoft\Search Assistant\ACMru\5603 Count: 5 Item Id: 3 Value: MRU Registry Key: S-1-5-21-1871259199-1857639920-1093324118-1006\Software\Microsoft\Internet Explorer\TypedURLs Count: 25 End of Scan Section =========================== Cleaned Infections =========================== MRU Path: C:\Documents and Settings\vp^\Recent Count: 296, Belonging to MRU Object MRU Registry Key: S-1-5-21-1871259199-1857639920-1093324118-1006\Software\Microsoft\Search Assistant\ACMru\5603 Count: 5, Belonging to MRU Object MRU Registry Key: S-1-5-21-1871259199-1857639920-1093324118-1006\Software\Microsoft\Internet Explorer\TypedURLs Count: 25, Belonging to MRU Object End of Cleaned Infections =========================== Cleaned Infections =========================== Root: HKLM Path: system\controlset003\services\{def85c80-216a-43ab-af70-1665edbe2780}, Belonging to Win32.Trojan.Agent Root: HKLM Path: software\microsoft\windows nt\currentversion\appcompatflags\layers Value: c:\windows\explorer.exe, Belonging to Win32.Trojan.Agent Root: HKLM Path: software\microsoft\windows\currentversion\policies\explorer\run, Belonging to Win32.Trojan.Agent Root: HKLM Path: system\controlset001\enum\root\legacy_{def85c80-216a-43ab-af70-1665edbe2780}, Belonging to Win32.Backdoor.Sinowal Root: HKLM Path: system\controlset001\services\{def85c80-216a-43ab-af70-1665edbe2780}, Belonging to Win32.Backdoor.Sinowal Root: HKLM Path: system\currentcontrolset\enum\root\legacy_{def85c80-216a-43ab-af70-1665edbe2780}, Belonging to Win32.Backdoor.Sinowal End of Cleaned Infections ===========================
Adaware is showing it cleaned a backdoor, so don't forget, if I don't remember to tell you, when you're clean, you need to change ALL passwords.


Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\windows\system32\CF11848.exe.vir

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Let me know when you want to quit for the night , we can continue tomorrow , I will be at the computer all day .

Here are the logs :

ComboFix 08-11-04.02 - vp^ 2008-11-05 21:39:41.10 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.402 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\vp^\Desktop\CFScript.txt
* Created a new restore point

FILE ::
c:\windows\system32\CF11848.exe.vir
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\CF11848.exe.vir

.
((((((((((((((((((((((((( Files Created from 2008-10-06 to 2008-11-06 )))))))))))))))))))))))))))))))
.

2008-11-05 09:07 . 2008-11-05 09:07 d——– c:\windows\LastGood
2008-11-05 08:48 . 2006-11-07 21:01 66,048 –a—— c:\windows\ieResetIcons.exe
2008-11-05 08:48 . 2008-11-05 08:48 230 –a—— c:\windows\system32\spupdsvc.inf
2008-11-01 15:38 . 2008-11-01 15:38 d——– c:\program files\ERUNT
2008-11-01 15:30 . 2008-11-01 15:30 d——– c:\program files\Trend Micro
2008-11-01 13:31 . 2008-11-03 01:30 1,374 –a—— c:\windows\imsins.BAK
2008-10-16 10:36 . 2008-10-31 18:53 54,156 –ah—– c:\windows\QTFont.qfn
2008-10-16 10:36 . 2008-10-16 10:36 1,409 –a—— c:\windows\QTFont.for
2008-10-11 19:35 . 2008-10-11 19:35 d——– c:\documents and settings\vp^\Application Data\Ulead Systems
2008-10-11 19:33 . 2008-10-11 19:33 d——– c:\program files\Ulead Systems
2008-10-11 19:33 . 2008-10-11 19:33 d——– c:\documents and settings\All Users\Application Data\Ulead Systems
2008-10-11 19:32 . 2008-10-11 19:32 d——– c:\windows\Noslip
2008-10-11 19:29 . 2008-10-11 19:29 11,014,144 –a—— c:\program files\UGA5TBYB_E_USG.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-02 01:49 5,527 —-a-w c:\program files\hijackthis11-1.log
2008-11-02 01:48 5,527 —-a-w c:\program files\hijackthis.log
2008-10-30 02:54 27,991 —-a-w c:\program files\081029_2140.caf.txt
2008-10-15 17:57 332,800 —-a-w c:\windows\system32\dllcache\netapi32.dll
2008-10-03 18:41 6,066,176 ——w c:\windows\system32\dllcache\ieframe.dll
2008-09-15 12:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-09-15 12:57 1,846,016 —-a-w c:\windows\system32\dllcache\win32k.sys
2008-08-29 20:58 3,297,268 —-a-w c:\windows\system32\via_chipset_AC_97_sound_driver.ZIP
2008-08-28 11:04 333,056 —-a-w c:\windows\system32\dllcache\srv.sys
2008-08-26 08:24 63,488 ——w c:\windows\system32\dllcache\icardie.dll
2008-08-26 08:24 52,224 ——w c:\windows\system32\dllcache\msfeedsbs.dll
2008-08-26 08:24 459,264 ——w c:\windows\system32\dllcache\msfeeds.dll
2008-08-26 08:24 383,488 ——w c:\windows\system32\dllcache\ieapfltr.dll
2008-08-26 08:24 267,776 ——w c:\windows\system32\dllcache\iertutil.dll
2008-08-25 09:38 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
2008-08-14 11:00 2,180,352 —-a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 11:00 2,180,352 —-a-w c:\windows\system32\dllcache\ntoskrnl.exe
2008-08-14 10:58 2,136,064 —-a-w c:\windows\system32\dllcache\ntkrnlmp.exe
2008-08-14 10:51 138,368 —-a-w c:\windows\system32\dllcache\afd.sys
2008-08-14 10:22 2,057,728 —-a-w c:\windows\system32\ntkrnlpa.exe
2008-08-14 10:22 2,057,728 —-a-w c:\windows\system32\dllcache\ntkrnlpa.exe
2008-08-14 10:22 2,015,744 —-a-w c:\windows\system32\dllcache\ntkrpamp.exe
2008-06-23 03:32 2,703 —-a-w c:\program files\080622_2214.caf
2008-06-22 04:25 21,853 —-a-w c:\program files\080621_2313.caf
2008-06-21 14:58 2,370 —-a-w c:\program files\080621_0947.caf
2008-06-19 10:12 6,922 —-a-w c:\program files\080618_2322.caf
2008-06-18 14:59 4,128 —-a-w c:\program files\080618_0941.caf
2008-06-16 02:49 6,988 —-a-w c:\program files\080615_2136.caf
2008-06-14 16:50 63,189 —-a-w c:\program files\080614_1134.caf
2008-06-14 13:52 11,984 —-a-w c:\program files\080614_0838.caf
2008-06-13 05:04 12,918 —-a-w c:\program files\080612_2324.caf
2008-06-12 14:28 9,446 —-a-w c:\program files\080612_0906.caf
2008-06-12 03:20 2,451 —-a-w c:\program files\080611_2159.caf
2008-06-11 21:03 4,137 —-a-w c:\program files\080611_1502.caf
2008-06-10 18:05 146,371 —-a-w c:\program files\080610_1246.caf
2008-06-10 02:01 246,692 —-a-w c:\program files\080609_2041.caf
2008-06-08 22:37 83,908 —-a-w c:\program files\080608_1718.caf
2008-06-08 21:38 14,359 —-a-w c:\program files\080608_1618.caf
2008-06-08 16:00 16,728 —-a-w c:\program files\080608_1032.caf
2008-06-07 10:49 58,616 —-a-w c:\program files\080603_1143.caf
2008-06-05 03:02 2,762 —-a-w c:\program files\080604_2136.caf
2008-06-01 03:54 38,227 —-a-w c:\program files\080531_2238.caf
2008-05-31 18:49 4,420 —-a-w c:\program files\080531_1135.caf
2008-05-29 17:55 9,909 —-a-w c:\program files\080529_1238.caf
2008-05-29 01:43 50,096 —-a-w c:\program files\080528_2027.caf
2008-05-27 03:10 18,081 —-a-w c:\program files\080526_2159.caf
2008-05-26 21:58 6,012 —-a-w c:\program files\080523_2230.caf
2008-05-25 14:29 2,542 —-a-w c:\program files\080525_0908.caf
2008-05-24 18:18 28,705 —-a-w c:\program files\080524_0704.caf
2008-05-23 00:28 1,466 —-a-w c:\program files\080522_0027.caf
2008-05-21 23:50 1,621 —-a-w c:\program files\080521_1839.caf
2008-05-20 02:47 7,332 —-a-w c:\program files\080519_2120.caf
2008-05-18 00:08 7,055 —-a-w c:\program files\080517_1849.caf
2008-05-17 00:46 5,301 —-a-w c:\program files\080516_1931.caf
2008-05-16 19:56 8,950 —-a-w c:\program files\080516_1444.caf
2008-05-16 04:06 15,902 —-a-w c:\program files\080515_2246.caf
2008-05-15 13:44 18,879 —-a-w c:\program files\080515_0821.caf
2008-05-15 04:31 109,935 —-a-w c:\program files\080514_2312.caf
2008-05-15 03:23 1,506 —-a-w c:\program files\080514_2206.caf
2008-05-14 19:17 1,908 —-a-w c:\program files\080514_1403.caf
2008-05-12 23:05 84,946 —-a-w c:\program files\080512_1732.caf
2008-05-11 05:52 4,402 —-a-w c:\program files\080511_0040.caf
2008-05-10 05:17 100,894 —-a-w c:\program files\080509_2357.caf
2008-05-10 02:07 26,592 —-a-w c:\program files\080509_14061.caf
2008-05-08 03:15 53,533 —-a-w c:\program files\080507_2155.caf
2008-05-06 14:33 65,496 —-a-w c:\program files\080506_0910.caf
2008-05-05 19:27 2,059 —-a-w c:\program files\080505_1409.caf
2008-05-04 13:06 9,118 —-a-w c:\program files\080504_0747.caf
2008-05-03 00:21 991 —-a-w c:\program files\080502_1852.caf
2008-05-02 13:33 515 —-a-w c:\program files\080502_0811.caf
2008-05-01 18:42 1,703 —-a-w c:\program files\080501_1328.caf
2008-05-01 15:03 93,623 —-a-w c:\program files\080430_2221.caf
2008-04-29 19:57 1,062 —-a-w c:\program files\080429_1340.caf
2008-04-29 19:32 4,710 —-a-w c:\program files\080428_0914.caf
2008-04-29 05:12 41,995 —-a-w c:\program files\080428_2355.caf
2008-04-27 17:29 2,741 —-a-w c:\program files\080427_1214.caf
2008-04-27 17:06 3,113 —-a-w c:\program files\My-Disc32.caf
2008-04-27 17:01 3,117 —-a-w c:\program files\080427_0729.caf
2008-04-26 20:58 960 —-a-w c:\program files\080426_1528.caf
2008-04-26 14:27 359 —-a-w c:\program files\080426_0910.caf
2008-04-25 22:28 1,177 —-a-w c:\program files\080425_1712.caf
2008-04-25 14:18 3,834 —-a-w c:\program files\080425_0855.caf
2008-04-24 21:36 5,702 —-a-w c:\program files\080424_1614.caf
2008-04-24 16:29 2,080 —-a-w c:\program files\080424_1114.caf
2008-04-22 16:34 83,652 —-a-w c:\program files\080422_1115.caf
2008-04-22 12:42 1,631 —-a-w c:\program files\080422_0720.caf
2008-04-20 20:12 16,869 —-a-w c:\program files\080420_1500.caf
2008-04-19 17:45 53,404 —-a-w c:\program files\080419_1234.caf
2008-04-19 15:05 60,632 —-a-w c:\program files\080418_2136.caf
2008-04-17 20:17 2,854 —-a-w c:\program files\080417_1503.caf
2008-04-16 21:08 5,840 —-a-w c:\program files\080416_1551.caf
2008-04-16 16:38 7,058 —-a-w c:\program files\080415_0809.caf
2008-04-13 04:37 115,642 —-a-w c:\program files\080412_2313.caf
2008-04-12 23:52 2,704 —-a-w c:\program files\080412_1728.caf
2008-04-11 21:09 14,853 —-a-w c:\program files\080411_1543.caf
2008-04-11 18:59 3,318 —-a-w c:\program files\080411_1326.caf
2008-04-11 13:35 3,022 —-a-w c:\program files\080410_0842.caf
2008-04-10 02:36 3,400 —-a-w c:\program files\080409_2121.caf
2008-04-08 13:28 1,056 —-a-w c:\program files\080408_0812.caf
2008-04-07 05:10 1,349 —-a-w c:\program files\080406_2358.caf
.

((((((((((((((((((((((((((((( snapshot@2008-11-05_12.41.57.64 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-11-06 00:12:46 16,384 —-a-w c:\windows\Temp\Perflib_Perfdata_144.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eRecoveryService"="c:\program files\Acer\eRecovery\Monitor.exe" [2005-06-20 352256]
"!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2007-09-28 177416]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2007-04-30 230928]
"SoundMan"="SOUNDMAN.EXE" [2005-06-08 c:\windows\SOUNDMAN.EXE]
"VTTimer"="VTTimer.exe" [2005-05-13 c:\windows\system32\VTTimer.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.avis"= ff_acm.acm

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Easy Video Joiner Help.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Easy Video Joiner Help.lnk
backup=c:\windows\pss\Easy Video Joiner Help.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Easy Video Joiner on the Web.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Easy Video Joiner on the Web.lnk
backup=c:\windows\pss\Easy Video Joiner on the Web.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Easy Video Joiner.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Easy Video Joiner.lnk
backup=c:\windows\pss\Easy Video Joiner.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Uninstall Easy Video Joiner.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Uninstall Easy Video Joiner.lnk
backup=c:\windows\pss\Uninstall Easy Video Joiner.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Verizon Online Help & Support.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Verizon Online Help & Support.lnk
backup=c:\windows\pss\Verizon Online Help & Support.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Verizon Support Service.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Verizon Support Service.lnk
backup=c:\windows\pss\Verizon Support Service.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^vp^^Start Menu^Programs^Startup^Kremlin Sentry.lnk]
path=c:\documents and settings\vp^\Start Menu\Programs\Startup\Kremlin Sentry.lnk
backup=c:\windows\pss\Kremlin Sentry.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AspireService]
–a—— 2005-06-04 12:40 110592 c:\program files\acer\Acer eMode Management\AspireService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX3800 Series]
–a—— 2005-02-07 15:00 98304 c:\windows\system32\spool\drivers\w32x86\3\E_FATIACA.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaSync]
–a—— 2005-06-01 14:25 421888 c:\program files\acer\Acer eConsole\MediaSync.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2004-10-13 09:24 1694208 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
——— 2005-09-16 16:41 1961984 c:\program files\Ahead\Nero BackItUp\NBJ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
–a—— 2004-07-15 01:07 32768 c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Free Download Manager\\fdmwi.exe"=
"c:\\Program Files\\Westell\\Diagnostic Icon\\DGNIcon.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=

R2 int15.sys;int15.sys;c:\program files\acer\eRecovery\int15.sys [2005-01-13 69632]
.
Contents of the 'Scheduled Tasks' folder

2008-11-05 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-05 21:46:14
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-11-05 21:48:44
ComboFix-quarantined-files.txt 2008-11-06 02:48:28
ComboFix2.txt 2008-11-05 17:44:08

Pre-Run: 3,810,099,200 bytes free
Post-Run: 3,796,828,160 bytes free

221 — E O F — 2008-11-05 14:10:48



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:49, on 2008-11-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\acer\Acer eConsole\MediaServerService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\Acer\eRecovery\Monitor.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://cgi.verizon.net/bookmarks/bmredir.a…p;bm=bz_welcome
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: vzTCPConfig -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1158766737609
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1163900908375
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} -
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\acer\Acer eConsole\MediaServerService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

–
End of file - 6102 bytes
Good job :thumbup:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]


    Here's my usual all clean post

    Log looks good :D


    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
      • From within Internet Explorer click on the Tools menu and then click on Options.
      • Click once on the Security tab
      • Click once on the Internet icon so it becomes highlighted.
      • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:
    Note: I no longer suggest Zone Alarm

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
  • Winpatrol

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein

Also: "How to prevent malware"
I guess I forgot to say that the OS is still not right , the My Computer icon still takes too long to open , and I can not access any internet pages except thru the portable firefox on the thumbdrive . Still the way it was on my first post . I'll check back tomorrow morning .

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI