This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Hijack Log

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hello

my computer very slaw when open firefox

help me

my Hijack Log

Logfile of HijackThis v1.99.1
Scan saved at 04:54:50 ص, on 03/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system32\kernel32.dlI
C:\WINDOWS\system32\kernel32.dlI
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\System.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe
C:\Program Files\Internet Download Manager\IDMan.exe
D:\original vip\usd\USDownloader135\USDownloader.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\ping.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
D:\windos elmohager adel\hijackthis_199\hijackthis_199\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.emurayden.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ThunderAdvise - {97421D0D-E07F-40DF-8F07-99597B9585AD} - C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll
O4 - HKLM\..\Run: [Vistadrv] C:\Program Files\Vortex Tools\Classes\vortex\vista\VIPhd\vsdrv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 11\Register\registration.exe /title="CorelDRAW Graphics Suite 11" /date=100708 serial=DR11WBL-2154582-AVZ
O4 - HKLM\..\Run: [kernel32] C:\WINDOWS\system32\kernel32.dlI
O4 - HKLM\..\Run: [3PMmUpdate] rundll32 "C:\WINDOWS\Update.dll",Main
O4 - HKLM\..\Run: [HBService32] System.exe
O4 - HKLM\..\Run: [MPKrnl] rundll32 "C:\WINDOWS\MPKrnl.dll",KrnlMsgProc
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [SRS Audio Sandbox] "C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" /hideme
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [USDownloader] "D:\original vip\usd\USDownloader135\USDownloader.exe"
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: تحميل الكل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: تحميل بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: HBmhly.dll,HBZG.dll,HBZHUXIAN.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: msnmsg - {DA191DE0-AA86-4ED0-4B87-293D48B2AE99} - C:\Program Files\Messenger\msgmr.dll
O21 - SSODL: Upnp - {DE01DA19-A6A8-EB80-4D47-248DEB2A9399} - C:\WINDOWS\system32\upnpsrv.dll
O21 - SSODL: ThunderAdvise - {97421D0D-E07F-40DF-8F07-99597B9585AD} - C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe


thank you
Hi elmohager,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://www.bleepingcomputer.com/forums/topic114351.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

ComboFix 08-11-02.02 - Sad Boy 11/02/2008 22:47:44.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.166 [GMT 2:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\AppPatch\AcSpecf.sdb
C:\WINDOWS\MSVB50CHS.dll
C:\WINDOWS\system32\mdhash.dll' C:\WINDOWS\system32\mdhsh.sys
.
—- Previous Run ——-
.
C:\Program Files\Messenger\msgmr.dll
C:\WINDOWS\AppPatch\AcSpecf.dll
C:\WINDOWS\AppPatch\AcSpecf.sdb
C:\WINDOWS\AppPatch\AcXtrnel.sdb
C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll
C:\WINDOWS\Fonts\Framdee.ttf
C:\WINDOWS\MSVB50CHS.dll
C:\WINDOWS\msvrc20.dll
C:\WINDOWS\system32\08223B03.cfg
C:\WINDOWS\system32\08223B03.dll
C:\WINDOWS\system32\122B901E.cfg
C:\WINDOWS\system32\122B901E.dll
C:\WINDOWS\system32\19b5406.sys
C:\WINDOWS\system32\22D75360.cfg
C:\WINDOWS\system32\22D75360.dll
C:\WINDOWS\system32\2EF0D734.cfg
C:\WINDOWS\system32\2EF0D734.dll
C:\WINDOWS\system32\3474A8C2.cfg
C:\WINDOWS\system32\3474A8C2.dll
C:\WINDOWS\system32\43ACDCC5.cfg
C:\WINDOWS\system32\43ACDCC5.dll
C:\WINDOWS\system32\4BF9CBA3.cfg
C:\WINDOWS\system32\4BF9CBA3.dll
C:\WINDOWS\system32\4D023DE9.cfg
C:\WINDOWS\system32\4D023DE9.dll
C:\WINDOWS\system32\5102a80.sys
C:\WINDOWS\system32\58FF3024.cfg
C:\WINDOWS\system32\58FF3024.dll
C:\WINDOWS\system32\66AFCB56.cfg
C:\WINDOWS\system32\66AFCB56.dll
C:\WINDOWS\system32\93DEE065.dll
C:\WINDOWS\system32\9CA963CA.cfg
C:\WINDOWS\system32\9CA963CA.dll
C:\WINDOWS\system32\9F684DE8.cfg
C:\WINDOWS\system32\9F684DE8.dll
C:\WINDOWS\system32\9fd8db.sys
C:\WINDOWS\system32\B3721C07.cfg
C:\WINDOWS\system32\B3721C07.dll
C:\WINDOWS\system32\BA7EDF54.cfg
C:\WINDOWS\system32\BA7EDF54.dll
C:\WINDOWS\system32\ca99d57.sys
C:\WINDOWS\system32\CABA599D.cfg
C:\WINDOWS\system32\CABA599D.dll
C:\WINDOWS\system32\D7C79813.cfg
C:\WINDOWS\system32\D7C79813.dll
C:\WINDOWS\system32\DA63E650.cfg
C:\WINDOWS\system32\DA63E650.dll
C:\WINDOWS\system32\DE02F764.cfg
C:\WINDOWS\system32\DE02F764.dll
C:\WINDOWS\system32\drivers\eth8023.sys
C:\WINDOWS\system32\drivers\HBKernel32.sys
C:\WINDOWS\system32\E0D39066.cfg
C:\WINDOWS\system32\E0D39066.dll
C:\WINDOWS\system32\E3367679.cfg
C:\WINDOWS\system32\E3367679.dll
C:\WINDOWS\system32\E5D39975.dll
C:\WINDOWS\system32\F65BDEC7.cfg
C:\WINDOWS\system32\F65BDEC7.dll
C:\WINDOWS\system32\F8E07BB2.dll
C:\WINDOWS\system32\HBmhly.dll
C:\WINDOWS\system32\HBZG.dll
C:\WINDOWS\system32\HBZHUXIAN.dll
C:\WINDOWS\system32\system.exe
C:\WINDOWS\temp\wmsetup.dll
C:\WINDOWS\Update.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_5102A80
——-\Legacy_CA99D57
——-\Legacy_ETH8023
——-\Service_19b5406
——-\Service_5102a80
——-\Service_9fd8db
——-\Service_ca99d57
——-\Service_eth8023
——-\Service_HBKernel32
——-\Legacy_5102A80
——-\Legacy_CA99D57
——-\Legacy_ETH8023


((((((((((((((((((((((((( Files Created from 2008-10-02 to 2008-11-02 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-02 08:39 ——— d—–w C:\Program Files\Internet Download Manager
2008-10-02 08:39 ——— d—–w C:\Documents and Settings\Sad Boy\Application Data\IDM
2008-10-02 08:39 ——— d—–w C:\Documents and Settings\Sad Boy\Application Data\DMCache
2008-10-02 07:38 20,480 —-a-w C:\WINDOWS\MPKrnl.dll
2008-09-28 22:06 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-09-28 21:19 ——— d—–w C:\Program Files\MagicISO
2008-09-20 10:12 ——— d—–w C:\Program Files\Common Files\Adobe
2008-09-12 04:58 848 –sha-w C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
2008-09-10 06:04 ——— d—–w C:\Program Files\Emurayden PSX Emulator v2.2
2008-09-09 22:05 ——— d—–w C:\Documents and Settings\Sad Boy\Application Data\Ahead
2008-09-09 17:23 ——— d—–w C:\Program Files\SFTech
2008-09-09 17:22 21,504 —-a-w C:\WINDOWS\uninstall.exe
2008-09-08 00:00 ——— d—–w C:\Documents and Settings\Sad Boy\Application Data\Media Player Classic
2008-09-07 15:58 ——— d—–w C:\Documents and Settings\Sad Boy\Application Data\Corel
2008-09-07 15:56 ——— d—–w C:\Program Files\Corel
2008-09-07 15:56 ——— d—–w C:\Program Files\Common Files\Corel
2008-09-07 15:54 ——— d—–w C:\Program Files\CorelDRAW Graphics Suite 11
2008-09-06 19:09 ——— d—–w C:\Documents and Settings\Sad Boy\Application Data\Thinstall
2008-09-06 19:07 ——— d—–w C:\Program Files\PowerISO
2008-09-06 00:34 2,560 —-a-w C:\WINDOWS\system32\bitcometres.dll
2008-09-06 00:33 ——— d—–w C:\Program Files\BitComet
2008-09-06 00:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\SRS Labs
2008-09-06 00:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-09-06 00:25 ——— d—–w C:\Program Files\SRS Labs
2008-09-06 00:24 ——— d—–w C:\Program Files\Winamp
2008-09-06 00:19 ——— d—–w C:\Program Files\Realtek Sound Manager
2008-09-06 00:19 ——— d—–w C:\Program Files\Realtek AC97
2008-09-06 00:19 ——— d—–w C:\Program Files\AvRack
2008-09-06 00:05 0 —-a-w C:\WINDOWS\system32\drivers\SET14.tmp
2008-09-05 23:23 ——— d—–w C:\Program Files\Intel
2008-09-05 23:22 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-05 23:22 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-09-05 23:18 ——— d—–w C:\Program Files\MSXML 6.0
2008-09-05 23:18 ——— d—–w C:\Program Files\MSXML 4.0
2008-09-05 23:16 ——— d—–w C:\Program Files\Windows Media Connect 2
2008-09-05 23:16 ——— d—–w C:\Program Files\UltraISO
2008-09-05 23:16 ——— d—–w C:\Program Files\Common Files\EZB Systems
2008-09-05 23:15 155,995 —-a-w C:\WINDOWS\java\Packages\GUGQTJ5F.ZIP
2008-09-05 23:15 ——— d—–w C:\Program Files\Yahoo!
2008-09-05 23:15 ——— d—–w C:\Program Files\Windows Live
2008-09-05 23:15 ——— d—–w C:\Documents and Settings\Sad Boy\Application Data\Winamp
2008-09-05 23:14 ——— d—–w C:\Program Files\Real Alternative
2008-09-05 23:14 ——— d—–w C:\Program Files\K-Lite Codec Pack
2008-09-05 21:31 ——— d—–w C:\Program Files\Foxit Software
2008-09-05 21:26 ——— d—–w C:\Program Files\Vortex Tools
2008-09-05 21:26 ——— d—–w C:\Program Files\%tmp%
2008-07-02 21:31 3,540,480 —-a-w C:\Program Files\Emurayden v2.2.exe
.

——- Sigcheck ——-

01/27/2008 11:18 AM 2222464 a176424c39e93dd4face8191d568de83 C:\WINDOWS\system32\ntkrnlpa.exe

01/27/2008 11:06 AM 2345216 6c23d899a3c46543bbb7ac1edc1c8b5e C:\WINDOWS\system32\ntoskrnl.exe

01/27/2008 11:04 AM 1524224 e24cd37d23a71dbb9a484a50eb255462 C:\WINDOWS\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 10:00 AM 15360]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [08/30/2007 05:43 PM 4670704]
"SRS Audio Sandbox"="C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" [09/06/2008 02:26 AM 3215360]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [07/14/2008 07:12 PM 2606512]
"USDownloader"="D:\original vip\usd\USDownloader135\USDownloader.exe" [08/11/2008 09:59 PM 531456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Vistadrv"="C:\Program Files\Vortex Tools\Classes\vortex\vista\VIPhd\vsdrv.exe" [07/30/2006 12:37 AM 121089]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [10/08/2004 05:01 AM 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [10/08/2004 04:57 AM 126976]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [03/11/2003 04:24 PM 86016]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [03/15/2008 04:21 AM 233472]
"CorelDRAW Graphics Suite 11b"="C:\Program Files\Corel\Corel Graphics 11\Register\registration.exe" [02/17/2005 03:24 PM 315392]
"MPKrnl"="C:\WINDOWS\MPKrnl.dll" [10/02/2008 09:38 AM 20480]
"SoundMan"="SOUNDMAN.EXE" [12/14/2005 06:06 PM 577536 C:\WINDOWS\soundman.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [08/04/2004 10:00 AM 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"Upnp"= {DE01DA19-A6A8-EB80-4D47-248DEB2A9399} - C:\WINDOWS\system32\upnpsrv.dll [01/27/2008 11:04 AM 20480]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"22143:TCP"= 22143:TCP:BitComet 22143 TCP
"22143:UDP"= 22143:UDP:BitComet 22143 UDP

S1 vcdrom;Virtual CD-ROM Device Driver;C:\Documents and Settings\Sad Boy\Desktop\xcxvxvx [ ]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Emurayden PSX Emulator - (no file)
ShellExecuteHooks-{F8E07BB2-7A19-4057-80F1-E14646E630B4} - F8E07BB2.dll
ShellExecuteHooks-{E5D39975-A103-4A21-9EE9-A638E9DD9EB4} - E5D39975.dll
ShellExecuteHooks-{93DEE065-EC9B-4505-ADD3-19880AD3C38F} - 93DEE065.dll


.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Sad Boy\Application Data\Mozilla\Firefox\Profiles\4m1w7xwe.default\
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-02 22:51:09
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vcdrom]
"ImagePath"="\??\C:\Documents and Settings\Sad Boy\Desktop\xcxvxvx"
.
———————— Other Running Processes ————————
.
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\PROGRAM FILES\YAHOO!\MESSENGER\YMSGR_TRAY.EXE
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 11/02/2008 22:52:18 - machine was rebooted [Sad Boy]
ComboFix-quarantined-files.txt 2008-11-02 20:52:14

Pre-Run: 13,584,465,920 bytes free
Post-Run: 13,551,648,768 bytes free

229


thanks dear
elmohager,

Do you notice any difference yet?

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI