This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan issue, Trojan horse SHeur2.MR (another user)

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello all,

I was inspired to make this post by another thread started by a user that seemed to be having a problem with the same trojan. Please see thread: http://forums.whatthetech.com/Trojan_issue_t96719.html

My symptoms are somewhat different than what are explained in that thread. I experienced some weirdness in my web browser while looking at both newegg.com and some other sites. The task bar at the bottom of the screen disappeared, such that I could not click on anything after I closed the internet explorer window. So I did a hard reboot on my computer. Once it restarted, I had the following problems:

1. When I use internet explorer, every so often it brings up a new advertising window without my asking it to (once every few minutes). This appears to be advertising malware.

2. There is a red shield in the bottom of my system tray, telling me that windows automatic update is turned off. When I try to clik it to turn it on, it gives me an error message saying that the Security Center cannot turn it on, and that I need to turn it on from the System panel. When I go to that panel in the system information, it appears that automatic updates are turned on, but this does nothing to the red shield in the system tray.

3. My system restores have either been deleted or masked. In system restore, the only one listed is right after the problem started, but I know I had system restores from before that.

Like the user in the above thread, I ran AVG antivirus, which showed that I was infected by SHeur2.MR (from gadcom.exe) as well as it finding "a registry key with reference to infected file C:\Documents and Settings\….gadcom.exe." AVG said it healed the infection. I also ran Ad-Aware 2007, which found some other malware under a different name (which I unfortunately did not write down), which was also removed by Ad-Aware. Despite both of these, the above symptoms persisted.

Per what was recommended by Rorschach112 in the thread I mentioned, I followed the same instructions there and ran SDFix and Lop S&D; the way that he described. I give the log files below. The problem still seems to exist, even though SDFix removed some sort of infection.

After these first two steps, Rorschach's instructions seem to get specific to the other user, and somewhat more complicated. What I am hoping is that someone can look at my log files and provide me with some specific advice to how to fix this problem on my computer.

I apologize if I am posting this in the wrong forum. I would really appreciate any help anyone can give. My email is [removed], if you need to talk to me directly.

Thank you,
Hunter

SDFix Log File:

SDFix: Version 1.240
Run by [removed] on Sat 11/08/2008 at 09:43 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File
Resetting SecurityProviders Value

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\system32\pmnkICUo.dll - Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk - Deleted
C:\WINDOWS\system32\msansspc.dll - Deleted



Folder C:\Documents and Settings\user\Application Data\gadcom - Removed


Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-08 21:51:27
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Disabled:Logitech Desktop Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\BF2.exe"="C:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\BF2.exe:*:Enabled:Battlefield 2"
"C:\\Program Files\\Turbine\\The Lord of the Rings Online\\lotroclient.exe"="C:\\Program Files\\Turbine\\The Lord of the Rings Online\\lotroclient.exe:*:Enabled:lotroclient.exe"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"C:\\Program Files\\Unreal Tournament 3 Demo\\Binaries\\UT3Demo.exe"="C:\\Program Files\\Unreal Tournament 3 Demo\\Binaries\\UT3Demo.exe:*:Enabled:Unreal Tournament 3 Demo"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Microsoft Office\\Office10\\WINWORD.EXE"="C:\\Program Files\\Microsoft Office\\Office10\\WINWORD.EXE:*:Enabled:Microsoft Word"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Program Files\\Capcom\\Bionic Commando Rearmed\\bcr.exe"="C:\\Program Files\\Capcom\\Bionic Commando Rearmed\\bcr.exe:*:Enabled:Bionic Commando Rearmed"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Tue 13 Sep 2005 1,847,296 …HR — "C:\Program Files\Microsoft Works Suite 2006\Setup\LAUNCHER.EXE"
Sat 25 Jun 2005 62,464 …HR — "C:\Program Files\Microsoft Works Suite 2006\Setup\MNYINSTA.DLL"
Fri 22 Apr 2005 95,232 …HR — "C:\Program Files\Microsoft Works Suite 2006\Setup\RMVSUITE.EXE"
Thu 18 Aug 2005 36,864 …HR — "C:\Program Files\Microsoft Works Suite 2006\Setup\SETUPLNG.DLL"
Wed 5 Jan 2005 20,480 …HR — "C:\Program Files\Microsoft Works Suite 2006\Setup\UNREGWTR.EXE"
Mon 27 Oct 2008 8,089 …HR — "C:\Documents and Settings\user\Application Data\SecuROM\UserData\securom_v7_01.bak"
Thu 16 Feb 2006 396,288 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL0200.tmp"
Fri 24 Feb 2006 72,192 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL0665.tmp"
Fri 24 Feb 2006 72,704 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL0771.tmp"
Thu 16 Feb 2006 50,688 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL0775.tmp"
Thu 16 Feb 2006 396,800 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL0889.tmp"
Thu 16 Feb 2006 391,168 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL1048.tmp"
Thu 16 Feb 2006 395,776 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL1753.tmp"
Thu 16 Feb 2006 392,192 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL2173.tmp"
Wed 22 Feb 2006 98,816 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL2613.tmp"
Thu 16 Feb 2006 390,656 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL3756.tmp"
Mon 28 Aug 2006 151,552 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Jessica's Dissertation\~WRL3828.tmp"
Thu 8 Jan 2004 45,568 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL0003.tmp"
Fri 9 Jan 2004 60,416 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL0568.tmp"
Fri 9 Jan 2004 75,776 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL1269.tmp"
Fri 9 Jan 2004 50,688 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL1298.tmp"
Fri 9 Jan 2004 53,760 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL1387.tmp"
Fri 9 Jan 2004 61,440 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL1598.tmp"
Fri 9 Jan 2004 63,488 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL2156.tmp"
Fri 9 Jan 2004 47,616 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL2312.tmp"
Fri 9 Jan 2004 62,976 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL2581.tmp"
Fri 9 Jan 2004 46,080 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL2860.tmp"
Fri 9 Jan 2004 60,416 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL3216.tmp"
Fri 9 Jan 2004 49,664 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL3517.tmp"
Fri 9 Jan 2004 56,320 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Third Year Paper\~WRL4058.tmp"
Wed 26 Feb 2003 35,840 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Clinical\Begay v. begay\~WRL0003.tmp"
Thu 27 Feb 2003 39,424 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Clinical\Begay v. begay\~WRL0125.tmp"
Thu 27 Feb 2003 36,352 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Clinical\Begay v. begay\~WRL1768.tmp"
Thu 27 Feb 2003 40,448 A..H. — "C:\Documents and Settings\user\Desktop\Backups\Hunter's Backup\Clinical\Begay v. begay\~WRL2058.tmp"

Finished!


Lop S&D; Report:


——————–\\ Lop S&D; 4.2.4-9c XP/Vista

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel® Core™2 CPU 6600 @ 2.40GHz )
BIOS : Default System BIOS
USER : user ( Administrator )
BOOT : Normal boot
Antivirus : AVG Anti-Virus Free 8.0 (Not Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:298 Go (Free:182 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
E:\ (USB)
F:\ (USB)

"C:\Lop SD" ( MAJ : 01-11-2008|16:30 )
Option : [1] ( Sat 11/08/2008|21:58 )

——————–\\ Listing folders in APPLIC~1

[12/27/2006|03:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Creative
[06/26/2008|09:14] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Microsoft

[02/18/2007|11:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[08/02/2006|06:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Ahead
[02/15/2008|08:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple
[02/15/2008|08:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[10/17/2007|05:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ ATI
[06/27/2008|06:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ avg8
[10/03/2008|09:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ BCR
[12/27/2006|03:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Creative
[10/29/2006|08:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ HP
[11/08/2008|08:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Lavasoft
[09/10/2007|05:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[06/10/2007|12:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Pure Networks
[12/30/2007|06:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SimCity Societies
[11/08/2008|09:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TEMP
[12/16/2006|01:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[07/04/2007|05:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ WinZip

[08/02/2006|04:44] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft

[12/01/2007|04:50] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft

[12/01/2007|04:50] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft

[11/04/2006|08:57] C:\DOCUME~1\user\APPLIC~1\ ACV
[02/25/2007|10:11] C:\DOCUME~1\user\APPLIC~1\ Adobe
[05/19/2008|08:11] C:\DOCUME~1\user\APPLIC~1\ AdobeUM
[02/15/2008|08:24] C:\DOCUME~1\user\APPLIC~1\ Apple Computer
[10/17/2007|05:35] C:\DOCUME~1\user\APPLIC~1\ ATI
[11/05/2006|10:50] C:\DOCUME~1\user\APPLIC~1\ atitray
[12/10/2007|09:31] C:\DOCUME~1\user\APPLIC~1\ Bioshock
[12/27/2006|04:02] C:\DOCUME~1\user\APPLIC~1\ Creative
[05/10/2008|04:14] C:\DOCUME~1\user\APPLIC~1\ Help
[12/04/2006|01:04] C:\DOCUME~1\user\APPLIC~1\ HP
[11/01/2006|10:31] C:\DOCUME~1\user\APPLIC~1\ ICAClient
[08/02/2006|05:01] C:\DOCUME~1\user\APPLIC~1\ Identities
[12/07/2007|09:06] C:\DOCUME~1\user\APPLIC~1\ Image Zone Express
[11/08/2007|06:39] C:\DOCUME~1\user\APPLIC~1\ InstallShield
[10/22/2007|05:48] C:\DOCUME~1\user\APPLIC~1\ InstallShield Installation Information
[10/29/2006|09:16] C:\DOCUME~1\user\APPLIC~1\ Logitech
[10/29/2006|07:32] C:\DOCUME~1\user\APPLIC~1\ Macromedia
[12/01/2007|04:50] C:\DOCUME~1\user\APPLIC~1\ Microsoft
[05/09/2008|07:05] C:\DOCUME~1\user\APPLIC~1\ Move Networks
[10/29/2006|08:59] C:\DOCUME~1\user\APPLIC~1\ Musicmatch
[06/26/2008|07:38] C:\DOCUME~1\user\APPLIC~1\ rhcnd6j0e38p
[05/12/2007|03:37] C:\DOCUME~1\user\APPLIC~1\ SecuROM
[12/27/2006|04:03] C:\DOCUME~1\user\APPLIC~1\ Smart Recorder
[01/18/2007|11:14] C:\DOCUME~1\user\APPLIC~1\ Sun
[04/14/2007|04:49] C:\DOCUME~1\user\APPLIC~1\ Turbine
[11/08/2008|09:50] C:\DOCUME~1\user\APPLIC~1\ WinRAR

——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[05/08/2008 06:07 AM][–a——] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[11/08/2008 09:48 PM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[07/27/2006 07:00 AM][-r-h—–] C:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in C:\Program Files

[11/08/2007|06:39] C:\Program Files\ 2K Games
[06/26/2008|09:02] C:\Program Files\ Ace Utilities
[08/02/2006|04:59] C:\Program Files\ Adobe
[10/03/2008|09:40] C:\Program Files\ AGEIA Technologies
[08/02/2006|06:15] C:\Program Files\ Ahead
[02/15/2008|08:23] C:\Program Files\ Apple Software Update
[11/08/2008|08:10] C:\Program Files\ a-squared Free
[10/17/2007|05:32] C:\Program Files\ ATI Technologies
[06/27/2008|06:39] C:\Program Files\ AVG
[09/23/2007|03:53] C:\Program Files\ Bethesda Softworks
[12/17/2007|09:09] C:\Program Files\ Black Isle
[02/15/2008|08:24] C:\Program Files\ Bonjour
[11/05/2006|05:40] C:\Program Files\ Cacheman
[11/05/2006|05:48] C:\Program Files\ CachemanXP
[10/03/2008|09:40] C:\Program Files\ Capcom
[11/01/2006|10:28] C:\Program Files\ Citrix
[02/15/2008|08:22] C:\Program Files\ Common Files
[08/02/2006|04:42] C:\Program Files\ ComPlus Applications
[11/26/2006|03:48] C:\Program Files\ cpu-z-138
[12/27/2006|03:49] C:\Program Files\ Creative
[06/10/2007|01:59] C:\Program Files\ DIFX
[05/15/2007|08:29] C:\Program Files\ Double Dragon
[11/01/2008|04:20] C:\Program Files\ EA GAMES
[12/30/2007|06:13] C:\Program Files\ Electronic Arts
[10/29/2006|07:33] C:\Program Files\ Encarta
[10/29/2006|04:02] C:\Program Files\ Futuremark
[05/15/2007|05:46] C:\Program Files\ Golden Axe
[12/01/2007|04:50] C:\Program Files\ Grisoft
[06/28/2008|02:54] C:\Program Files\ Guild Wars
[10/29/2006|08:41] C:\Program Files\ Hewlett-Packard
[10/29/2006|08:43] C:\Program Files\ HP
[10/03/2008|10:06] C:\Program Files\ InstallShield Installation Information
[05/09/2008|10:47] C:\Program Files\ Intel
[08/02/2006|05:56] C:\Program Files\ Intel Audio Studio
[10/16/2008|12:06] C:\Program Files\ Internet Explorer
[08/02/2006|05:00] C:\Program Files\ InterVideo
[02/15/2008|08:24] C:\Program Files\ iPod
[02/15/2008|08:24] C:\Program Files\ iTunes
[07/14/2007|04:31] C:\Program Files\ Jade Empire
[01/18/2007|11:14] C:\Program Files\ Java
[12/01/2007|05:00] C:\Program Files\ Lavasoft
[10/03/2008|10:07] C:\Program Files\ Logitech
[06/11/2007|07:53] C:\Program Files\ LucasArts
[09/16/2008|07:58] C:\Program Files\ Messenger
[10/29/2006|07:30] C:\Program Files\ Microsoft ActiveSync
[10/29/2006|07:32] C:\Program Files\ Microsoft Digital Image 2006
[08/02/2006|04:48] C:\Program Files\ microsoft frontpage
[10/29/2006|09:28] C:\Program Files\ Microsoft Location Finder
[06/02/2007|01:33] C:\Program Files\ microsoft money 2006
[08/31/2008|08:51] C:\Program Files\ Microsoft Office
[10/29/2006|07:34] C:\Program Files\ Microsoft Streets and Trips Essentials
[10/29/2006|07:30] C:\Program Files\ Microsoft Works
[10/29/2006|07:00] C:\Program Files\ Microsoft Works Suite 2006
[09/16/2008|07:57] C:\Program Files\ Movie Maker
[01/20/2007|04:10] C:\Program Files\ MP3Gain
[08/31/2008|08:51] C:\Program Files\ MSECache
[08/02/2006|04:41] C:\Program Files\ MSN
[08/02/2006|04:41] C:\Program Files\ MSN Gaming Zone
[08/02/2006|05:37] C:\Program Files\ MSXML 4.0
[10/29/2006|08:59] C:\Program Files\ MUSICMATCH
[09/16/2008|07:56] C:\Program Files\ NetMeeting
[08/02/2006|05:01] C:\Program Files\ NTRU Cryptosystems
[08/02/2006|04:41] C:\Program Files\ Online Services
[05/21/2008|07:16] C:\Program Files\ OpenAL
[08/24/2008|10:24] C:\Program Files\ Orban
[09/16/2008|07:55] C:\Program Files\ Outlook Express
[05/21/2008|07:12] C:\Program Files\ Paradox Interactive
[05/15/2008|08:37] C:\Program Files\ Prime95
[05/10/2008|01:50] C:\Program Files\ Prime95 - 2d Copy
[06/10/2007|12:31] C:\Program Files\ Pure Networks
[02/15/2008|08:23] C:\Program Files\ QuickTime
[11/08/2007|07:35] C:\Program Files\ Ray Adams
[06/22/2008|03:47] C:\Program Files\ Rockstar Games
[12/01/2007|05:11] C:\Program Files\ RootkitRevealer
[12/27/2006|04:11] C:\Program Files\ Sierra
[08/02/2006|05:56] C:\Program Files\ SigmaTel
[07/07/2008|10:05] C:\Program Files\ SpeedFan
[10/03/2008|09:15] C:\Program Files\ Steam
[08/02/2006|05:01] C:\Program Files\ STMicroelectronics
[05/21/2008|08:18] C:\Program Files\ The Witcher
[04/14/2007|04:36] C:\Program Files\ Turbine
[08/02/2006|05:01] C:\Program Files\ Uninstall Information
[10/22/2007|05:47] C:\Program Files\ Unreal Tournament 3 Demo
[08/02/2006|05:01] C:\Program Files\ Wave Systems Corp
[09/16/2008|07:55] C:\Program Files\ Windows Media Player
[09/16/2008|07:55] C:\Program Files\ Windows NT
[08/02/2006|04:43] C:\Program Files\ WindowsUpdate
[10/31/2006|09:24] C:\Program Files\ WinRAR
[07/04/2007|05:36] C:\Program Files\ WinZip
[08/02/2006|04:48] C:\Program Files\ xerox

——————–\\ Listing Folders in C:\Program Files\Common Files

[02/18/2007|11:32] C:\Program Files\Common Files\ Adobe
[08/02/2006|06:11] C:\Program Files\Common Files\ Ahead
[02/15/2008|08:22] C:\Program Files\Common Files\ Apple
[10/29/2006|07:29] C:\Program Files\Common Files\ Designer
[10/29/2006|08:41] C:\Program Files\Common Files\ Hewlett-Packard
[10/29/2006|08:43] C:\Program Files\Common Files\ HP
[08/02/2006|05:00] C:\Program Files\Common Files\ InstallShield
[01/18/2007|11:13] C:\Program Files\Common Files\ Java
[08/02/2006|06:14] C:\Program Files\Common Files\ LightScribe
[10/03/2008|10:07] C:\Program Files\Common Files\ Logitech
[08/31/2008|08:51] C:\Program Files\Common Files\ Microsoft Shared
[08/02/2006|04:42] C:\Program Files\Common Files\ MSSoap
[08/02/2006|06:13] C:\Program Files\Common Files\ Nero
[08/02/2006|09:36] C:\Program Files\Common Files\ ODBC
[06/10/2007|01:59] C:\Program Files\Common Files\ Pure Networks Shared
[08/02/2006|04:42] C:\Program Files\Common Files\ Services
[08/02/2006|09:36] C:\Program Files\Common Files\ SpeechEngines
[09/16/2008|07:55] C:\Program Files\Common Files\ System
[10/03/2008|09:41] C:\Program Files\Common Files\ Wise Installation Wizard

——————–\\ Process

( 42 Processes )

… OK !

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

C:\DOCUME~1\user\Cookies\user@advertising[1].txt
C:\DOCUME~1\user\Cookies\[removed][1].txt

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-08 21:59:28
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections

C:\WINDOWS\system32\TBJjkUtv.ini
C:\WINDOWS\system32\TBJjkUtv.ini2
C:\WINDOWS\system32\vtUkjJBT.dll
==> VUNDO <==

——————–\\ Cracks & Keygens ..

C:\DOCUME~1\user\Desktop\Backups\Hunter's Backup\GTA San Andreas Other Files\data\Decision\Craig\crack1.ped


[F:688][D:76]-> C:\DOCUME~1\user\LOCALS~1\Temp
[F:131][D:0]-> C:\DOCUME~1\user\Cookies
[F:2718][D:5]-> C:\DOCUME~1\user\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Sat 11/08/2008|22:00 - Option : [1]

——————–\\ Scan completed at 22:00:03
Download VundoFix.exe to your desktop.

* Double-click VundoFix.exe to run it.
* When VundoFix re-opens, click the Scan for Vundo button.
* Once it's done scanning, click the Remove Vundo button.
* You will receive a prompt asking if you want to remove the files, click YES
* Once you click yes, your desktop will go blank as it starts removing Vundo.
* When completed, it will prompt that it will reboot your computer, click OK.

Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the
Scan for Vundo button.
" when VundoFix appears at reboot.

Post the contents of C:\vundofix.txt
Hello, I used VundoFix as suggested by little eagle above. The program ran, but it said that it did not locate any files. Therefore I was unable to complete the steps after the "Scan for Vundo" step. There was therefore not much in the vundofix.txt file. Its contents are posted below: VundoFix V7.0.6 Scan started at 1:50:31 PM 11/9/2008 Listing files found while scanning…. No infected files were found. Beginning removal… [End of Log] In addition to the symptoms mentioned in my first post, I have the following two additional symptoms: 4. I cannot manually start the windows update process. When I go to the Microsoft website and click on starting the update, it gives me an error and tells me to start the automatic updates service. I then go to Run:services.msc, and clieck on the "Properties" tab of the "Automatic Updates" service, per the instructions. When I try to start the service, however, it gives me an error with the information: "Error 1058: The service cannot be started, either becuase it is disabled or because it has no enabled devices associated with it." 5. The virus appears to be messing with my power settings. When I put the computer into standby or hibernation modes, the computer will enter the modes, but every few minutes it will turn back on. It will stay on for a few minutes (not visibly doing anything), and then re-enter hibernation mode, for example. Finally, I remembered the name of the Malware that Ad-Aware 2007 said it had found and removed. It was Virtumonde. Thanks for the advice, but it does not appear that VundoFix dealt with the problem. I am happy to try something else. Thank you, Hunter
Download ComboFix from Here or Here to your Desktop.

In the event you already have Combofix, this is a new version that I need you to download.
It must be saved directly to your desktop.



1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan.
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again afterwards before connecting to the net


2. Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • IF you have not already done so Combofix will disconnect your machine from the Internet when it starts.
  • If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

3. Now double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review


Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze.
Hello,

I followed the instructions as to ComboFix, which ran and said that it removed some files (shown in the log below).

For what it is worth, after running combofix, at least some of the symptoms I describe above have gone away. I no longer see the window popups. The red shield in the system tray has gone away, and I have confirmed that the Windows Automatic Updates now work (and the service related to them is started). Combofix successfully created a new restore point in system restore.

I have not yet confirmed that the power settings are back to normal, but hopefully they should be.

Anyway, please find below the ComboFix.txt log (first), and the new HijackThis log (second). Please let me know if I need to do anything else.

Thanks,
Hunter

[ComboFix.txt Log]

ComboFix 08-11-09.01 - user 2008-11-09 18:38:14.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2606 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\user\Application Data\rhcnd6j0e38p
c:\documents and settings\user\Local Settings\Temporary Internet Files\fbk.sts
c:\windows\system32\byXpQJyV.dll
c:\windows\system32\duqgqlth.dll
c:\windows\system32\ebvamwws.ini
c:\windows\system32\emkxrg.dll
c:\windows\system32\isggigsm.dll
c:\windows\system32\mlzeik.dll
c:\windows\system32\swwmavbe.dll
c:\windows\system32\TBJjkUtv.ini
c:\windows\system32\TBJjkUtv.ini2
c:\windows\system32\vtUkjJBT.dll
c:\windows\system32\wxosnhjd.ini
c:\windows\wiaserviv.log

.
((((((((((((((((((((((((( Files Created from 2008-10-09 to 2008-11-09 )))))))))))))))))))))))))))))))
.

2008-11-09 13:50 . 2008-11-09 13:50 d——– C:\VundoFix Backups
2008-11-08 21:57 . 2008-11-08 22:00 d——– C:\Lop SD
2008-11-08 21:56 . 2008-11-09 13:47 d——– C:\Nov. 8 virus fix
2008-11-08 21:41 . 2008-11-08 21:41 578,560 –a–c— c:\windows\system32\dllcache\user32.dll
2008-11-08 21:38 . 2008-11-08 21:38 d——– c:\windows\ERUNT
2008-11-08 21:33 . 2008-11-08 21:53 d——– C:\SDFix
2008-11-08 20:22 . 2008-11-08 20:22 d——– c:\windows\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP
2008-10-26 17:40 . 2001-08-17 21:36 8,704 –a—— c:\windows\system32\kbdjpn.dll
2008-10-26 17:40 . 2001-08-17 21:36 8,704 –a–c— c:\windows\system32\dllcache\kbdjpn.dll
2008-10-26 17:40 . 2001-08-17 21:36 8,192 –a—— c:\windows\system32\kbdkor.dll
2008-10-26 17:40 . 2001-08-17 21:36 8,192 –a–c— c:\windows\system32\dllcache\kbdkor.dll
2008-10-26 17:40 . 2008-04-13 19:09 6,144 –a—— c:\windows\system32\kbd106.dll
2008-10-26 17:40 . 2001-08-17 13:55 6,144 –a—— c:\windows\system32\kbd101c.dll
2008-10-26 17:40 . 2001-08-17 13:55 6,144 –a—— c:\windows\system32\kbd101b.dll
2008-10-26 17:40 . 2008-04-13 19:09 6,144 –a–c— c:\windows\system32\dllcache\kbd106.dll
2008-10-26 17:40 . 2001-08-17 13:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101c.dll
2008-10-26 17:40 . 2001-08-17 13:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101b.dll
2008-10-26 17:40 . 2001-08-17 13:55 5,632 –a—— c:\windows\system32\kbd103.dll
2008-10-26 17:40 . 2001-08-17 13:55 5,632 –a–c— c:\windows\system32\dllcache\kbd103.dll
2008-10-23 12:24 . 2008-10-15 11:34 337,408 —–c— c:\windows\system32\dllcache\netapi32.dll
2008-10-15 15:22 . 2008-08-14 05:11 2,189,184 —–c— c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-15 15:22 . 2008-08-14 05:09 2,145,280 —–c— c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-15 15:22 . 2008-08-14 04:33 2,066,048 —–c— c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-15 15:22 . 2008-08-14 04:33 2,023,936 —–c— c:\windows\system32\dllcache\ntkrpamp.exe
2008-10-15 15:22 . 2008-09-15 07:12 1,846,400 —–c— c:\windows\system32\dllcache\win32k.sys
2008-10-15 15:22 . 2008-09-08 05:41 333,824 —–c— c:\windows\system32\dllcache\srv.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-09 02:10 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-09 01:22 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-09 01:10 ——— d—–w c:\program files\a-squared Free
2008-11-02 20:57 24,100 —-a-w c:\documents and settings\user\Application Data\wklnhst.dat
2008-11-01 21:20 ——— d—–w c:\program files\EA GAMES
2008-10-03 15:07 ——— d—–w c:\program files\Logitech
2008-10-03 15:07 ——— d—–w c:\program files\Common Files\Logitech
2008-10-03 15:06 ——— d–h–w c:\program files\InstallShield Installation Information
2008-10-03 14:44 ——— d—–w c:\documents and settings\All Users\Application Data\BCR
2008-10-03 14:41 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-10-03 14:40 ——— d—–w c:\program files\Capcom
2008-10-03 14:40 ——— d—–w c:\program files\AGEIA Technologies
2008-10-03 14:15 ——— d—–w c:\program files\Steam
2006-11-26 19:08 57,504 —-a-w c:\documents and settings\user\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"AtiTrayTools"="c:\program files\Ray Adams\ATI Tray Tools\atitray.exe" [2007-05-22 521128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTDVDDET"="c:\program files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 49152]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-01-31 385024]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2008-04-04 88584]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-07-23 c:\windows\KHALMNPR.Exe]
"CTHelper"="CTHELPER.EXE" [2005-10-29 c:\windows\CTHELPER.EXE]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll emkxrg.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup

[HKLM\~\startupfolder\C:^DOCUME~1^ALLUSE~1^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^DOCUME~1^ALLUSE~1^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^DOCUME~1^ALLUSE~1^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKLM\~\startupfolder\C:^DOCUME~1^ALLUSE~1^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lphcjd6j0e38p

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
–a—— 2008-09-29 12:35 1234712 c:\progra~1\AVG\AVG8\avgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2006-02-19 05:41 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelAudioStudio]
–a—— 2005-10-27 18:17 8740864 c:\program files\Intel Audio Studio\IntelAudioStudio.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-02-04 14:18 267048 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
–a—— 2006-10-29 20:59 32768 c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Location Finder]
–a—— 2006-05-15 18:24 101136 c:\program files\Microsoft Location Finder\LocationFinder.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
–a—— 2005-07-19 13:05 53248 c:\program files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 12:50 155648 c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nmapp]
–a—— 2006-10-31 23:04 321088 c:\program files\Pure Networks\Network Magic\nmapp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-01-31 23:13 385024 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RCSystem]
——— 2005-11-04 18:07 49152 c:\program files\Creative\Shared Files\Module Loader\DLLML.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
–a—— 2006-11-10 11:35 90112 c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
–a—— 2008-10-03 09:12 1271032 c:\program files\Steam\Steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2006-11-09 15:07 49263 c:\program files\Java\jre1.5.0_10\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra—— 2006-03-30 16:45 313472 c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
——— 2000-05-11 01:00 90112 c:\windows\Updreg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VolPanel]
——— 2005-10-14 11:01 122880 c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTxfiHlp]
–a—— 2005-10-29 06:31 18944 c:\windows\system32\CTXFIHLP.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Avg7Alrt"=2 (0x2)
"AVGEMS"=2 (0x2)
"nmservice"=2 (0x2)
"nmraapache"=3 (0x3)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\BF2.exe"=
"c:\\Program Files\\Turbine\\The Lord of the Rings Online\\lotroclient.exe"=
"c:\\Program Files\\Unreal Tournament 3 Demo\\Binaries\\UT3Demo.exe"=
"c:\\Program Files\\Microsoft Office\\Office10\\WINWORD.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Capcom\\Bionic Commando Rearmed\\bcr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service

R0 stmtpm;STM TPM Service;c:\windows\system32\DRIVERS\stm_tpm.sys [2005-05-02 21664]
R1 atitray;atitray;c:\program files\Ray Adams\ATI Tray Tools\atitray.sys [2007-05-22 18088]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-08-29 97928]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-08-29 231704]
R3 ha20x2k;Creative 20X HAL Driver;c:\windows\system32\drivers\ha20x2k.sys [2005-10-29 1095680]
S3 ldiskl;ldiskl;c:\docume~1\user\LOCALS~1\Temp\ldiskl.sys [ ]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a5068329-221d-11db-859a-806d6172696f}]
\Shell\AutoRun\command - D:\EISetup.exe
.
Contents of the 'Scheduled Tasks' folder

2008-05-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
.
- - - - ORPHANS REMOVED - - - -

BHO-{07ccb796-5267-412e-98c0-9f7277730f9e} - c:\windows\system32\emkxrg.dll
BHO-{5D495646-CBDD-4CBB-80C6-F9FBEDF28C56} - c:\windows\system32\vtUkjJBT.dll
HKLM-Run-7071ca77 - c:\windows\system32\swwmavbe.dll
MSConfigStartUp-AVG7_CC - c:\progra~1\Grisoft\AVG7\avgcc.exe
MSConfigStartUp-SMrhcnd6j0e38p - c:\program files\rhcnd6j0e38p\rhcnd6j0e38p.exe
MSConfigStartUp-SigmatelSysTrayApp - sttray.exe


.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com/
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O18 -: Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-09 18:43:30
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\a-squared Free\a2service.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\wdfmgr.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\CTXFISPI.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-11-09 18:46:11 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-09 23:46:08

Pre-Run: 197,011,218,432 bytes free
Post-Run: 197,274,439,680 bytes free

235 — E O F — 2008-10-23 22:19:24


[New HijackThis log]


Logfile of HijackThis v1.99.1
Scan saved at 6:54:16 PM, on 11/9/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Logitech\Gaming Software\LWEMon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AtiTrayTools] "C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1226256047171
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) - http://javadl-esd.sun.com/update/1.5.0/jin…ows-i586-jc.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: bw+0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {5C0EC233-8697-4FF6-A0A2-B290757A10B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\puresp3.dll
O20 - AppInit_DLLs: avgrsstx.dll emkxrg.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: DataSvr - Unknown owner - C:\Program Files\Wave Systems Corp\Common\DataServer.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: NTRU Hybrid TSS v1.05 TCSD (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v1.05\bin\tcsd_win32.exe
Lets see what is left over.

Run this online scan from ESET

You will need to use Internet explorer for this scan!
  • First, accept the Terms of Use
  • Click: Start
  • When asked, allow the ActiveX control to install
  • Click: Start
  • Make sure the options:
    Remove found threats, and Scan unwanted applications
    are both checked!
  • Click: Scan

When the scan finishes, use Notepad to open the ESET report.
It will be located here C:\Program Files\EsetOnlineScanner\log.txt
Hello little eagle, I ran the online scan from ESET, and it scanned the computer and said that no threats were found. Please see the log below. Is there anything else I should do? Thanks, Hunter [ESET log] # version=4 # OnlineScanner.ocx=1.0.0.56 # OnlineScannerDLLA.dll=1, 0, 0, 51 # OnlineScannerDLLW.dll=1, 0, 0, 51 # OnlineScannerUninstaller.exe=1, 0, 0, 49 # vers_standard_module=3597 (20081108) # vers_arch_module=1.064 (20080214) # vers_adv_heur_module=1.066 (20070917) # EOSSerial=17a7df5de95e7c40a34852a43d5569fe # end=finished # remove_checked=true # unwanted_checked=true # utc_time=2008-11-10 04:07:58 # local_time=2008-11-09 11:07:58 (-0500, Eastern Standard Time) # country="United States" # osver=5.1.2600 NT Service Pack 3 # scanned=287103 # found=0 # scan_time=1768
emkxrg.dll

I would like to see a copy of the file in bold.
Using Windows Explorer, locate the file you want to zip.
Right click on the file and select Send To and Compressed (zipped) Folder.
This makes a copy it does not delete it.
Please zip the file and upload it here
Or email it here

Please include a link to this thread.
Dear little eagle, I sent you an email with the emkxrg.dll file attached as a compressed zip file. Please let me know if you did not receive it, or need anything else. Thank you, Hunter
Well looks like you anti-virus found and deleted it. I'd like to see an Uninstall List. Please open up HijackThis. Click on Open the Misc Tools section button Click on Open Uninstall Manager Click on Save A notepad document will open with a list of your installed programs. Please copy that into your reply.
Hi little eagle, Here is the content of the text file that the uninstall manager of Hijack This generated: 3DMark06 Ace Utilities Ad-Aware 2007 Adobe Flash Player 10 ActiveX Adobe Reader 7.0.9 AGEIA PhysX v7.11.13 Apple Mobile Device Support Apple Software Update a-squared Free 3.0 ATI - Software Uninstall Utility ATI Catalyst Control Center ATI Display Driver AVG Free 8.0 Baldur's Gate II - Shadows of Amn Collectors CD Baldur's Gate™ II - Throne of Bhaal ™ Battlefield 2™ Demo Bejeweled 2 Deluxe 1.1 Bejeweled Deluxe 1.87 Bionic Commando Rearmed BioShock Bonjour Cacheman 5.50 Citrix ICA Client Creative Media Toolbox Creative MediaSource Creative System Information Double Dragon ESET Online Scanner FEAR SP Demo Free Games Offer, Desktop Shortcut Golden Axe GTA San Andreas Guild Wars Hijackthis 1.99.1 HijackThis 1.99.1 Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows XP (KB952287) HP Imaging Device Functions 7.0 HP Photosmart and Deskjet 7.0.A HP Photosmart Essential HP Software Update HP Solution Center 7.0 Intel Audio Studio 2.0 Intel® Desktop Control Center Intel® PRO Network Connections InterVideo WinDVD iTunes J2SE Runtime Environment 5.0 Update 10 Jade Empire Logitech Desktop Messenger Logitech Gaming Software 5.02 Logitech SetPoint Macromedia Shockwave Player Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 1.1 SP1 with KB886903 Hotfix Microsoft .NET Framework 2.0 Service Pack 1 Microsoft Digital Image Standard 2006 Microsoft Encarta Encyclopedia Standard 2006 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Location Finder Microsoft Money 2006 Microsoft National Language Support Downlevel APIs Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Streets & Trips 2006 Microsoft Visual C++ 2005 Redistributable Microsoft Word 2002 Microsoft Works Microsoft Works Suite 2006 Setup Launcher Microsoft Works Suite Add-in for Microsoft Word Morrowind MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 Parser and SDK Musicmatch® Jukebox Nero Suite Network Magic NTRU Hybrid TSS v1.05 Oblivion Oblivion - BTmod 2.20 Oblivion mod manager 0.9.10 OCR Software by I.R.I.S 7.0 OpenAL Orban/Coding Technologies AAC/aacPlus Player Plugin™ 1.0 Penumbra Black Plague QuickTime Ray Adams ATI Tray Tools Sam and Max - Season One - Episode 104 - Abe Lincoln Must Die! Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows XP (KB913433) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB958644) SigmaTel Audio SimCity™ Societies Sound Blaster X-Fi SpeedFan (remove only) Star Wars®: Knights of the Old Republic ™ Steam STMicroelectronics TPM Software Package TES Construction Set The Lord of the Rings Online™: Shadows of Angmar™ v06.11.30.134 The Sims 2 The Sims 2 Pets The Witcher Unreal Tournament 3 Demo Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Windows Driver Package - Pure Networks, Inc. Network Magic Device Discovery Driver (02/08/2007 4.1.7039.0) Windows Driver Package - Pure Networks, Inc. Network Magic Wireless Driver (02/08/2007 4.1.7039.0) Windows Media Format Runtime Windows Media Player 10 Windows XP Service Pack 3 WinRAR archiver WinZip 11.1 Please let me know if you need anything else. Hunter
J2SE Runtime Environment 5.0 Update 10 Needs to be removed.

Be sure to keep SunJava, updated the new version is 6.0 update 7

It is important to remove older versions as these are the ones with the holes in them.

Download Newest >>>> http://www.java.com/en/download/index.jsp
Once installed you can test to see that it is in fact installed >>>>
Sun Java Test



Let's do a little cleanup.
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the /U, it needs to be there.

[external image: Posted Image]
Hi little eagle, To update the SunJava runtime, do I first need to remove the old version (presumably through Add/Remove Programs)? Or can I simply download the most recent version and install that? I.e. will installing the new version automatically remove the older version? Thank you, Hunter
Hi little eagle, Two issues: 1. I installed the most recent version of SunJava, version 6, update 10. I confirmed that this is what is installed through the link you gave me. However, the J2SE Runtime Environment 5.0 Update 10 is still listed as on the computer (both in Add/Remove Programs and in the Hijack This install manager). Should I remove J2SE Runtime Environment 5.0 Update 10, say trhough add/remove programs? 2. When I tried typing in ComboFix /u into the the Run box, it says that it cannot find the file. There is a C:\ComboFix folder, but there is nothing in it. Should I point the Run box to where I have the ComboFix.exe file that I downloaded? If so, how do I make the /u part work? Thanks, Hunter

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI