This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Virus disabled firewall

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I although thought i removed the virus, i did not. The virus completely disabled the firewall on my computer and i cannot run it even on the administrator account. the settings are greyed out as shown in the picture below:
[external image: Posted Image]

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:27:14, on 2008/11/09
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Ora920\bin\omtsreco.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre1.6.0_02\bin\jucheck.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by City of Mississauga
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [\\joe-270c81fc86e\EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P48 "\\joe-270c81fc86e\EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] %*WINSYSDIR%\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] %*WINSYSDIR%\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .NPSSView: C:\Program Files\Seagate Software\Viewers\ActiveXViewer\NPssView.dll
O14 - IERESET.INF: START_PAGE_URL=http://intranet.city.mississauga.on.ca
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6531D99C-0D0E-4293-B3CB-A3E1D0D41847} (AhnASP Control) - http://aspglobal.ahnlab.com/asp/cab/AhnASP.cab
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - file://C:\WINDOWS\msxml4.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = civic.mississauga.ca
O17 - HKLM\Software\..\Telephony: DomainName = civic.mississauga.ca
O17 - HKLM\System\CCS\Services\Tcpip\..\{38F5ABEF-43B0-420F-9382-22F7CB1FB6AE}: Domain = civic.mississauga.ca
O17 - HKLM\System\CCS\Services\Tcpip\..\{38F5ABEF-43B0-420F-9382-22F7CB1FB6AE}: NameServer = 142.240.1.20
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = civic.mississauga.ca
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = civic.mississauga.ca,city.mississauga.on.ca,mississauga.ca
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = civic.mississauga.ca
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = civic.mississauga.ca,city.mississauga.on.ca,mississauga.ca
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = civic.mississauga.ca
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = civic.mississauga.ca,city.mississauga.on.ca,mississauga.ca
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = civic.mississauga.ca,city.mississauga.on.ca,mississauga.ca
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - c:\Ora920\bin\omtsreco.exe
O23 - Service: OracleOra816ClientCache - Unknown owner - c:\Ora816\BIN\ONRSD.EXE
O23 - Service: OracleOra920ClientCache - Unknown owner - c:\Ora920\BIN\ONRSD.EXE
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

–
End of file - 8839 bytes
Run - ATF Cleaner instructions here.

—————-


Then download Malwarebytes' Anti-Malware to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform FULL SCAN, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad. Please save it to a convenient location and post it here. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
Right, i will and as for the malware bytes..i already have it as shown in the picture…ran a scan…didn't find anything…first time it did, and it was rogue.antivirus Antivirus2009, it removed it, i then ran spybot S&D and it finished removing it. Now it detects nothing, repeatedly, I will follow the set instructions and get back to you.
Malwarebytes' Anti-Malware 1.30 Database version: 1390 Windows 5.1.2600 Service Pack 2 2008/11/12 5:25:56 PM mbam-log-2008-11-12 (17-25-56).txt Scan type: Full Scan (C:\|) Objects scanned: 120160 Time elapsed: 31 minute(s), 0 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Download ComboFix from Here or Here to your Desktop.

In the event you already have Combofix, this is a new version that I need you to download.
It must be saved directly to your desktop.



1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan.
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again afterwards before connecting to the net


2. Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • IF you have not already done so Combofix will disconnect your machine from the Internet when it starts.
  • If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

3. Now double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review


Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:05:52, on 2008/11/13
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Ora920\bin\omtsreco.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.6.0_02\bin\jucheck.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [\\joe-270c81fc86e\EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P48 "\\joe-270c81fc86e\EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .NPSSView: C:\Program Files\Seagate Software\Viewers\ActiveXViewer\NPssView.dll
O14 - IERESET.INF: START_PAGE_URL=http://intranet.city.mississauga.on.ca
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6531D99C-0D0E-4293-B3CB-A3E1D0D41847} (AhnASP Control) - http://aspglobal.ahnlab.com/asp/cab/AhnASP.cab
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - file://C:\WINDOWS\msxml4.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = civic.mississauga.ca
O17 - HKLM\Software\..\Telephony: DomainName = civic.mississauga.ca
O17 - HKLM\System\CCS\Services\Tcpip\..\{38F5ABEF-43B0-420F-9382-22F7CB1FB6AE}: Domain = civic.mississauga.ca
O17 - HKLM\System\CCS\Services\Tcpip\..\{38F5ABEF-43B0-420F-9382-22F7CB1FB6AE}: NameServer = 142.240.1.20
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = civic.mississauga.ca
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = civic.mississauga.ca,city.mississauga.on.ca,mississauga.ca
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = civic.mississauga.ca
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = civic.mississauga.ca,city.mississauga.on.ca,mississauga.ca
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = civic.mississauga.ca
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = civic.mississauga.ca,city.mississauga.on.ca,mississauga.ca
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = civic.mississauga.ca,city.mississauga.on.ca,mississauga.ca
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - c:\Ora920\bin\omtsreco.exe
O23 - Service: OracleOra816ClientCache - Unknown owner - c:\Ora816\BIN\ONRSD.EXE
O23 - Service: OracleOra920ClientCache - Unknown owner - c:\Ora920\BIN\ONRSD.EXE
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

–
End of file - 8529 bytes





ComboFix 08-11-12.01 - Administrator 2008-11-13 16:00:14.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.559 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\administrator\Application Data\inst.exe
c:\documents and settings\administrator\Local Settings\Temporary Internet Files\eled._dl
c:\documents and settings\administrator\Local Settings\Temporary Internet Files\owanoku.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\program files\INSTALL.LOG
c:\windows\IE4 Error Log.txt

—– BITS: Possible infected sites —–

hxxp://M2003-102VM.civic.mississauga.ca:80
.
((((((((((((((((((((((((( Files Created from 2008-10-13 to 2008-11-13 )))))))))))))))))))))))))))))))
.

2008-11-10 17:24 . 2001-08-23 07:00 68,608 –a–c— c:\windows\system32\dllcache\plugin.ocx
2008-11-10 17:03 . 2001-08-23 07:00 4,224 –a–c— c:\windows\system32\dllcache\beep.sys
2008-11-09 23:20 . 2008-11-09 23:21 d——– c:\program files\ERUNT
2008-11-09 23:09 . 2008-11-09 23:25 d——– c:\windows\BDOSCAN8
2008-11-09 21:54 . 2008-11-09 21:54 d——– c:\program files\Common Files\AhnLab
2008-11-09 21:54 . 2008-11-07 05:25 1,531,520 –a—— c:\windows\system32\drivers\v3engine.sys
2008-11-09 21:17 . 2008-11-09 21:17 77,921 –a—— c:\windows\system32\v3w32se2.dll
2008-11-08 21:29 . 2008-11-08 21:29 d——– c:\program files\Alwil Software
2008-11-08 21:29 . 2003-03-18 17:20 1,060,864 –a—— c:\windows\system32\MFC71.dll
2008-11-08 20:47 . 2008-11-08 23:15 2,860 –a—— c:\windows\system32\tmp.reg
2008-11-08 20:04 . 2008-11-08 20:59 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-08 20:04 . 2008-11-08 20:04 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-08 20:04 . 2008-11-08 20:04 d——– c:\documents and settings\administrator\Application Data\Malwarebytes
2008-11-08 20:04 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-08 20:04 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-08 20:03 . 2008-11-08 20:03 d——– c:\program files\Trend Micro
2008-11-08 19:57 . 2006-08-18 15:35 d——– c:\documents and settings\Anthony\Application Data\Intel
2008-11-08 19:57 . 2008-11-08 19:57 d——– c:\documents and settings\Anthony
2008-11-07 23:06 . 2008-11-07 23:06 118 –a—— c:\windows\system32\MRT.INI
2008-11-07 22:54 . 2008-06-13 08:10 272,128 ——— c:\windows\system32\drivers\bthport.sys
2008-11-07 22:54 . 2008-06-13 08:10 272,128 –a–c— c:\windows\system32\dllcache\bthport.sys
2008-11-07 20:39 . 2008-11-08 21:00 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-07 20:05 . 2008-11-08 20:45 d——– c:\program files\Windows Defender
2008-11-07 18:47 . 2008-11-07 18:47 19,542 –a—— c:\windows\system32\puwokekavu.dll
2008-11-07 18:47 . 2008-11-07 18:47 18,789 –a—— c:\documents and settings\All Users\Application Data\ahonocog.exe
2008-11-07 18:47 . 2008-11-07 18:47 18,473 –a—— c:\windows\dicilajimi.scr
2008-11-07 18:47 . 2008-11-07 18:47 18,289 –a—— c:\documents and settings\All Users\Application Data\zusafuj.bat
2008-11-07 18:47 . 2008-11-07 18:47 17,148 –a—— c:\windows\evyly.db
2008-11-07 18:47 . 2008-11-07 18:47 16,698 –a—— c:\windows\system32\unaqahujuk.vbs
2008-11-07 18:47 . 2008-11-07 18:47 16,202 –a—— c:\windows\xosomifez.pif
2008-11-07 18:47 . 2008-11-07 18:47 16,004 –a—— c:\documents and settings\administrator\Application Data\ubin.dll
2008-11-07 18:47 . 2008-11-07 18:47 14,321 –a—— c:\windows\aqajijuq.dll
2008-11-07 18:47 . 2008-11-07 18:47 13,098 –a—— c:\windows\yvolyhi.ban
2008-11-07 18:47 . 2008-11-07 18:47 12,571 –a—— c:\windows\pyvemilami.ban
2008-11-07 18:47 . 2008-11-07 18:47 11,029 –a—— c:\windows\okopap.db
2008-11-07 17:56 . 2008-11-08 21:31 d——– c:\program files\Spybot - Search & Destroy
2008-11-07 17:56 . 2008-11-08 21:32 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-07 17:12 . 2008-11-08 22:12 d——– C:\quarantine
2008-11-07 17:11 . 2008-11-07 18:09 527 –a—— c:\windows\system32\TDSSosvd.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-31 02:56 ——— d—–w c:\program files\Click'N Design 3D (V5)
2008-10-27 20:57 ——— d—–w c:\documents and settings\administrator\Application Data\Vso
2008-09-15 11:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-08-20 05:33 667,648 —-a-w c:\windows\system32\wininet.dll
2008-08-14 09:55 2,142,720 —-a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 09:18 2,020,864 —-a-w c:\windows\system32\ntkrnlpa.exe
2008-07-15 02:51 0 -c–a-w c:\documents and settings\administrator\jagex_runescape_preferences.dat
2008-07-09 21:11 47,360 -c–a-w c:\documents and settings\administrator\Application Data\pcouffin.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-07-03 802816]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-07-02 700416]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2006-04-06 49152]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 132496]
"\\joe-270c81fc86e\EPSON Stylus Photo R200 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE" [2003-07-07 99840]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 c:\windows\stsystra.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="c:\windows\Installer\TSClientMsiTrans\tscuinst.vbs" [2006-11-07 12451]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-22 734872]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\0\0]
"Script"=Pushprinters.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\1\0]
"Script"=addgroups.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-352275106-811158669-1221738049-11649\Scripts\Logon\0\0]
"Script"=CityWide_Login_Script.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-352275106-811158669-1221738049-15733\Scripts\Logon\0\0]
"Script"=CityWide_Login_Script.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-352275106-811158669-1221738049-1807\Scripts\Logon\0\0]
"Script"=CityWide_Login_Script.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-352275106-811158669-1221738049-2300\Scripts\Logon\0\0]
"Script"=CityWide_Login_Script.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-352275106-811158669-1221738049-2850\Scripts\Logon\0\0]
"Script"=CityWide_Login_Script.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-352275106-811158669-1221738049-7539\Scripts\Logon\0\0]
"Script"=CityWide_Login_Script.vbs

[HKLM\~\startupfolder\C:^Documents and Settings^administrator^Start Menu^Programs^Startup^naldesk.lnk]
path=c:\documents and settings\administrator\Start Menu\Programs\Startup\naldesk.lnk
backup=c:\windows\pss\naldesk.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Naldesk.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Naldesk.lnk
backup=c:\windows\pss\Naldesk.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Bonjour Service"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 CcmExec;SMS Agent Host;c:\windows\system32\CCM\CcmExec.exe [2007-04-13 590712]
S3 OracleOra816ClientCache;OracleOra816ClientCache;c:\ora816\BIN\ONRSD.EXE [2000-01-25 408568]
S3 OracleOra920ClientCache;OracleOra920ClientCache;c:\ora920\BIN\ONRSD.EXE [2002-04-26 242328]
S3 prepdrvr;SMS Process Event Driver;c:\windows\system32\CCM\prepdrv.sys [2007-04-13 23416]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d121fd42-f65f-11d6-8e94-806d6172696f}]
\Shell\AutoRun\command - D:\Setup.exe

*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder

2008-11-13 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - ORPHANS REMOVED - - - -

HKU-Default-Run-CTFMON.EXE - %*WINSYSDIR%\CTFMON.EXE


.
——- Supplementary Scan ——-
.
R1 -: HKCU-Internet Settings,ProxyOverride = ;*.local
O8 -: &Search
O8 -: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O17 -: HKLM\CCS\Interface\{38F5ABEF-43B0-420F-9382-22F7CB1FB6AE}: NameServer = 142.240.1.20

O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-13 16:02:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-11-13 16:02:54
ComboFix-quarantined-files.txt 2008-11-13 21:02:42

Pre-Run: 67,280,175,104 bytes free
Post-Run: 67,264,847,872 bytes free

164

I work at the city of mississauga so i don't think the site it found is bad, although i may be mistaken.
Open notepad and copy/paste the text in the codebox below into it:

File::
c:\windows\system32\puwokekavu.dll
c:\documents and settings\All Users\Application Data\ahonocog.exe
c:\documents and settings\administrator\Application Data\ubin.dll
c:\windows\aqajijuq.dll

Save this as Save this as "CFScript"


[external image: Posted Image]

Referring to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.
Well, before i blindly go following instructions, i want to know exactly what that does, its not that i don't trust you, i just want to get a better understanding of what i am doing XD
ComboFix 08-11-12.02 - Administrator 2008-11-14 11:54:54.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.590 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\administrator\Desktop\CFScript.txt
* Created a new restore point

FILE ::
c:\documents and settings\administrator\Application Data\ubin.dll
c:\documents and settings\All Users\Application Data\ahonocog.exe
c:\windows\aqajijuq.dll
c:\windows\system32\puwokekavu.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\administrator\Application Data\ubin.dll
c:\documents and settings\All Users\Application Data\ahonocog.exe
c:\windows\aqajijuq.dll
c:\windows\system32\puwokekavu.dll

.
((((((((((((((((((((((((( Files Created from 2008-10-14 to 2008-11-14 )))))))))))))))))))))))))))))))
.

2008-11-10 17:24 . 2001-08-23 07:00 68,608 –a–c— c:\windows\system32\dllcache\plugin.ocx
2008-11-10 17:03 . 2001-08-23 07:00 4,224 –a–c— c:\windows\system32\dllcache\beep.sys
2008-11-09 23:20 . 2008-11-09 23:21 d——– c:\program files\ERUNT
2008-11-09 23:09 . 2008-11-09 23:25 d——– c:\windows\BDOSCAN8
2008-11-09 21:54 . 2008-11-09 21:54 d——– c:\program files\Common Files\AhnLab
2008-11-09 21:54 . 2008-11-07 05:25 1,531,520 –a—— c:\windows\system32\drivers\v3engine.sys
2008-11-09 21:17 . 2008-11-09 21:17 77,921 –a—— c:\windows\system32\v3w32se2.dll
2008-11-08 21:29 . 2008-11-08 21:29 d——– c:\program files\Alwil Software
2008-11-08 21:29 . 2003-03-18 17:20 1,060,864 –a—— c:\windows\system32\MFC71.dll
2008-11-08 20:47 . 2008-11-08 23:15 2,860 –a—— c:\windows\system32\tmp.reg
2008-11-08 20:04 . 2008-11-08 20:59 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-08 20:04 . 2008-11-08 20:04 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-08 20:04 . 2008-11-08 20:04 d——– c:\documents and settings\administrator\Application Data\Malwarebytes
2008-11-08 20:04 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-08 20:04 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-08 20:03 . 2008-11-08 20:03 d——– c:\program files\Trend Micro
2008-11-08 19:57 . 2006-08-18 15:35 d——– c:\documents and settings\Anthony\Application Data\Intel
2008-11-08 19:57 . 2008-11-08 19:57 d——– c:\documents and settings\Anthony
2008-11-07 23:06 . 2008-11-07 23:06 118 –a—— c:\windows\system32\MRT.INI
2008-11-07 22:54 . 2008-06-13 08:10 272,128 ——— c:\windows\system32\drivers\bthport.sys
2008-11-07 22:54 . 2008-06-13 08:10 272,128 –a–c— c:\windows\system32\dllcache\bthport.sys
2008-11-07 20:39 . 2008-11-08 21:00 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-07 20:05 . 2008-11-08 20:45 d——– c:\program files\Windows Defender
2008-11-07 18:47 . 2008-11-07 18:47 18,473 –a—— c:\windows\dicilajimi.scr
2008-11-07 18:47 . 2008-11-07 18:47 18,289 –a—— c:\documents and settings\All Users\Application Data\zusafuj.bat
2008-11-07 18:47 . 2008-11-07 18:47 17,148 –a—— c:\windows\evyly.db
2008-11-07 18:47 . 2008-11-07 18:47 16,698 –a—— c:\windows\system32\unaqahujuk.vbs
2008-11-07 18:47 . 2008-11-07 18:47 16,202 –a—— c:\windows\xosomifez.pif
2008-11-07 18:47 . 2008-11-07 18:47 13,098 –a—— c:\windows\yvolyhi.ban
2008-11-07 18:47 . 2008-11-07 18:47 12,571 –a—— c:\windows\pyvemilami.ban
2008-11-07 18:47 . 2008-11-07 18:47 11,029 –a—— c:\windows\okopap.db
2008-11-07 17:56 . 2008-11-08 21:31 d——– c:\program files\Spybot - Search & Destroy
2008-11-07 17:56 . 2008-11-08 21:32 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-07 17:12 . 2008-11-08 22:12 d——– C:\quarantine
2008-11-07 17:11 . 2008-11-07 18:09 527 –a—— c:\windows\system32\TDSSosvd.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-31 02:56 ——— d—–w c:\program files\Click'N Design 3D (V5)
2008-10-27 20:57 ——— d—–w c:\documents and settings\administrator\Application Data\Vso
2008-09-15 11:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-08-20 05:33 667,648 —-a-w c:\windows\system32\wininet.dll
2008-08-14 09:55 2,142,720 —-a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 09:18 2,020,864 —-a-w c:\windows\system32\ntkrnlpa.exe
2008-07-15 02:51 0 -c–a-w c:\documents and settings\administrator\jagex_runescape_preferences.dat
2008-07-09 21:11 47,360 -c–a-w c:\documents and settings\administrator\Application Data\pcouffin.sys
.

((((((((((((((((((((((((((((( snapshot@2008-11-13_16.02.22.67 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-19 15:43:08 1,163,960 —-a-w c:\windows\system32\aswBoot.exe
+ 2008-11-12 16:57:30 1,235,696 —-a-w c:\windows\system32\aswBoot.exe
- 2008-07-19 15:30:53 94,392 —-a-w c:\windows\system32\AvastSS.scr
+ 2008-11-12 16:51:11 97,480 —-a-w c:\windows\system32\AvastSS.scr
- 2008-07-19 15:32:15 26,944 —-a-w c:\windows\system32\drivers\aavmker4.sys
+ 2008-11-12 16:51:35 26,944 —-a-w c:\windows\system32\drivers\aavmker4.sys
- 2008-07-19 15:37:42 20,560 —-a-w c:\windows\system32\drivers\aswFsBlk.sys
+ 2008-11-12 16:53:27 20,560 —-a-w c:\windows\system32\drivers\aswFsBlk.sys
- 2008-01-17 17:34:01 93,264 —-a-w c:\windows\system32\drivers\aswmon.sys
+ 2008-11-12 16:54:27 93,296 —-a-w c:\windows\system32\drivers\aswmon.sys
- 2008-07-19 15:37:21 94,416 —-a-w c:\windows\system32\drivers\aswmon2.sys
+ 2008-11-12 16:54:19 94,032 —-a-w c:\windows\system32\drivers\aswmon2.sys
- 2008-07-19 15:33:42 23,152 —-a-w c:\windows\system32\drivers\aswRdr.sys
+ 2008-11-12 16:52:28 23,152 —-a-w c:\windows\system32\drivers\aswRdr.sys
- 2008-07-19 15:35:18 78,416 —-a-w c:\windows\system32\drivers\aswSP.sys
+ 2008-11-12 16:53:38 110,160 —-a-w c:\windows\system32\drivers\aswSP.sys
- 2008-07-19 15:32:36 42,912 —-a-w c:\windows\system32\drivers\aswTdi.sys
+ 2008-11-12 16:52:37 50,656 —-a-w c:\windows\system32\drivers\aswTdi.sys
- 2008-11-13 20:59:08 76,990 —-a-w c:\windows\system32\perfc009.dat
+ 2008-11-14 16:50:37 78,926 —-a-w c:\windows\system32\perfc009.dat
- 2008-11-13 20:59:08 428,776 —-a-w c:\windows\system32\perfh009.dat
+ 2008-11-14 16:50:37 431,812 —-a-w c:\windows\system32\perfh009.dat
+ 2008-11-14 16:46:16 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_754.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-07-03 802816]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-07-02 700416]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2006-04-06 49152]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 132496]
"\\joe-270c81fc86e\EPSON Stylus Photo R200 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE" [2003-07-07 99840]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-12 81000]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 c:\windows\stsystra.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="c:\windows\Installer\TSClientMsiTrans\tscuinst.vbs" [2006-11-07 12451]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-22 734872]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\0\0]
"Script"=Pushprinters.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\1\0]
"Script"=addgroups.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-352275106-811158669-1221738049-11649\Scripts\Logon\0\0]
"Script"=CityWide_Login_Script.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-352275106-811158669-1221738049-15733\Scripts\Logon\0\0]
"Script"=CityWide_Login_Script.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-352275106-811158669-1221738049-1807\Scripts\Logon\0\0]
"Script"=CityWide_Login_Script.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-352275106-811158669-1221738049-2300\Scripts\Logon\0\0]
"Script"=CityWide_Login_Script.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-352275106-811158669-1221738049-2850\Scripts\Logon\0\0]
"Script"=CityWide_Login_Script.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-352275106-811158669-1221738049-7539\Scripts\Logon\0\0]
"Script"=CityWide_Login_Script.vbs

[HKLM\~\startupfolder\C:^Documents and Settings^administrator^Start Menu^Programs^Startup^naldesk.lnk]
path=c:\documents and settings\administrator\Start Menu\Programs\Startup\naldesk.lnk
backup=c:\windows\pss\naldesk.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Naldesk.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Naldesk.lnk
backup=c:\windows\pss\Naldesk.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Bonjour Service"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-11-12 110160]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-11-12 20560]
R2 CcmExec;SMS Agent Host;c:\windows\system32\CCM\CcmExec.exe [2007-04-13 590712]
S3 OracleOra816ClientCache;OracleOra816ClientCache;c:\ora816\BIN\ONRSD.EXE [2000-01-25 408568]
S3 OracleOra920ClientCache;OracleOra920ClientCache;c:\ora920\BIN\ONRSD.EXE [2002-04-26 242328]
S3 prepdrvr;SMS Process Event Driver;c:\windows\system32\CCM\prepdrv.sys [2007-04-13 23416]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d121fd42-f65f-11d6-8e94-806d6172696f}]
\Shell\AutoRun\command - D:\Setup.exe
.
Contents of the 'Scheduled Tasks' folder

2008-11-14 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-14 11:56:40
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-11-14 11:57:26
ComboFix-quarantined-files.txt 2008-11-14 16:57:18
ComboFix2.txt 2008-11-13 21:02:56

Pre-Run: 67,229,814,784 bytes free
Post-Run: 67,220,156,416 bytes free

174
__________________________________________

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:01:40, on 2008/11/14
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Ora920\bin\omtsreco.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.6.0_02\bin\jucheck.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [\\joe-270c81fc86e\EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P48 "\\joe-270c81fc86e\EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .NPSSView: C:\Program Files\Seagate Software\Viewers\ActiveXViewer\NPssView.dll
O14 - IERESET.INF: START_PAGE_URL=http://intranet.city.mississauga.on.ca
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6531D99C-0D0E-4293-B3CB-A3E1D0D41847} (AhnASP Control) - http://aspglobal.ahnlab.com/asp/cab/AhnASP.cab
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - file://C:\WINDOWS\msxml4.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = civic.mississauga.ca
O17 - HKLM\Software\..\Telephony: DomainName = civic.mississauga.ca
O17 - HKLM\System\CCS\Services\Tcpip\..\{38F5ABEF-43B0-420F-9382-22F7CB1FB6AE}: Domain = civic.mississauga.ca
O17 - HKLM\System\CCS\Services\Tcpip\..\{38F5ABEF-43B0-420F-9382-22F7CB1FB6AE}: NameServer = 142.240.1.20
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = civic.mississauga.ca
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = civic.mississauga.ca,city.mississauga.on.ca,mississauga.ca
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = civic.mississauga.ca
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = civic.mississauga.ca,city.mississauga.on.ca,mississauga.ca
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = civic.mississauga.ca
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = civic.mississauga.ca,city.mississauga.on.ca,mississauga.ca
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = civic.mississauga.ca,city.mississauga.on.ca,mississauga.ca
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - c:\Ora920\bin\omtsreco.exe
O23 - Service: OracleOra816ClientCache - Unknown owner - c:\Ora816\BIN\ONRSD.EXE
O23 - Service: OracleOra920ClientCache - Unknown owner - c:\Ora920\BIN\ONRSD.EXE
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

–
End of file - 8531 bytes
Be sure to keep SunJava, updated the new version is 6.0 update 10
In Add/Remove programs click on these and press *remove* if listed:
J2SE Runtime Environment 5.0 - 97.99Mb
J2SE Runtime Environment 5.0 Update 2 - 143.00Mb
J2SE Runtime Environment 5.0 Update 4 - 144.00Mb
J2SE Runtime Environment 5.0 Update 5- 151.00Mb
Java 2 Runtime Environment, SE v1.4.2_04 - 130.00Mb
Or any other outdated J2SE
It is important to remove older versions as these are the ones with the holes in them.

Download Newest >>>> http://www.java.com/en/download/index.jsp
Once installed you can test to see that it is in fact installed >>>>
Sun Java Test
Unfortunately i cannot update my java because the banks we connect to have specific requirements in order for us (accountants) to connect to them. If i were to update my java i would be unable to connect to them. Thank you for your help. Is there anything else i should do, or is my system clean?
I love it when banks can't get a secure network going.
Took my bank 6 months to update there online banking site.
After I went down there and spent a afternoon showing them how to bypass their security.

Well your good to go.
Let's do a little cleanup.
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the /U, it needs to be there.

[external image: Posted Image]
Hey, thanks a lot mate i really appreciate it everything works except for the "Do not allow exceptions" as it is still greyed out, but this is a registry setting and i know regedit enough to know what to do. Thank you once again.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI