This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Malware (url.adtrgt) issue / HJT log included

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am using Windows XP, and my laptop (Dell Inspiron) was running fine until this morning where a popup kept appearing everytime I opened a webpage. I use Firefox as my browser, and the popups were appearing in Firefox, as well. The popup was blank and the address started with "url.adtrgt."

I have done some research online regarding this particular malware issue, and I have gone to My Computer > Tools > Folder Options > View > uncheck both hide extensions for known file types & hide protected operating system files. I have also downloaded ATF Cleaner and selected all the options and emptied all the contents.

I then downloaded ComboFix and followed the instructions ComboFix came up with. My computer was beeping and a screen appeared saying that I had Symantec AntiVirus running, but I cannot figure out how to disable Symantec. I proceeded with ComboFix anyway and I have saved my ComboFix log.

I am by no means a tech genius, so I would really appreciate some help.

The following is my HJT log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:23:39 PM, on 1/8/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv42.exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Messenger\msmsgs.exe
D:\spyware\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\spyware\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://register.resnet.stonybrook.edu/wpad.dat
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1\SDHelper.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "D:\spyware\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\SPYBOT~1\SDHelper.dll (file missing)
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\SPYBOT~1\SDHelper.dll (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O20 - AppInit_DLLs: aaphyy.dll bssuqa.dll
O20 - Winlogon Notify: !SASWinLogon - D:\spyware\SASWINLO.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Unknown owner - C:\Program Files\Symantec AntiVirus\DefWatch.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - Unknown owner - C:\Program Files\Symantec AntiVirus\SavRoam.exe (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Unknown owner - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WUSB54Gv42SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

–
End of file - 6623 bytes
I don't recommend running tools that you aren't familiar with as the consequences can sometimes be unexpected. In particular running ComboFix with real-time anti-virus protection active can make it unpredictable and you would have been better aborting the run if you were unable to disable Symantec's protection. CF should have created a log when it ran that I would like to see - it should be a text file in the root of your main drive - C:\Combofix.txt.
Noviciate - Thank you for your reply. I ran CF again just now and I noticed that the two logs are different. The older log from this afternoon is first and the log from now is second.


ComboFix 09-01-08.01 - Zena 2009-01-08 15:46:17.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.767.587 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Outdated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Zena.ZENA-2CE3E9C195\Application Data\NI.GSCNS
c:\documents and settings\Zena.ZENA-2CE3E9C195\Application Data\NI.GSCNS\dl.ini
c:\documents and settings\Zena.ZENA-2CE3E9C195\Application Data\NI.GSCNS\settings.ini
c:\recycler\ADAPT_Installer.exe
c:\temp\DIV55
c:\temp\DIV55\xDb.log
c:\windows\system32\bin
c:\windows\system32\bssuqa.dll
c:\windows\system32\DcbdNnpo.ini
c:\windows\system32\DcbdNnpo.ini2
c:\windows\system32\drivers\seneka.sys
c:\windows\system32\drivers\senekalvrdlxwb.sys
c:\windows\system32\HNUuvyxx.ini
c:\windows\system32\HNUuvyxx.ini2
c:\windows\system32\ieofvlhn.dll
c:\windows\system32\ki3
c:\windows\system32\ki3\shdoclc.dll
c:\windows\system32\senekagkvrswwy.dll
c:\windows\system32\senekaimryiayp.dll
c:\windows\system32\ucuxioqy.dll
c:\windows\system32\uv9
c:\windows\system32\VC
c:\windows\system32\yqoixucu.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_SENEKA


((((((((((((((((((((((((( Files Created from 2008-12-08 to 2009-01-08 )))))))))))))))))))))))))))))))
.

2009-01-08 13:22 . 2009-01-08 13:22 73,216 –a—— c:\windows\system32\ffkuz.dll
2008-12-30 03:12 . 2009-01-08 13:37 54,156 –ah—– c:\windows\QTFont.qfn
2008-12-30 03:12 . 2008-12-30 03:12 1,409 –a—— c:\windows\QTFont.for
2008-12-28 02:57 . 2008-12-28 02:57 d——– c:\documents and settings\All Users\Application Data\Last.fm

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-28 07:57 ——— d—–w c:\program files\iTunes
2008-12-05 22:09 ——— d—–w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-05 22:03 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-12-05 22:03 ——— d—–w c:\documents and settings\Zena.ZENA-2CE3E9C195\Application Data\SUPERAntiSpyware.com
2008-12-05 21:21 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-05 20:24 ——— d—–w c:\program files\Java
2008-12-05 15:07 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-18 10:32 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-08-25 02:59 1,745,106 —-a-w c:\documents and settings\Zena.ZENA-2CE3E9C195\xrt_collect.zip
2008-12-21 23:47 67,688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2008-12-21 23:47 54,368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-21 23:47 34,944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2008-12-21 23:47 46,712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-12-21 23:47 172,136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="c:\program files\AIM\aim.exe" [2005-08-05 67160]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"PopUpStopperFreeEdition"="d:\spyware\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe" [2003-04-29 524288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmaTel StacMon"="c:\program files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe" [2004-04-29 90169]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-01-08 4866048]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-10-04 48752]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-08-11 282624]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-05-08 185896]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-06-14 278528]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 c:\windows\BCMSMMSG.exe]
"nwiz"="nwiz.exe" [2004-01-08 c:\windows\system32\nwiz.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-05-13 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-01-08 13:49 356352 d:\spyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=aaphyy.dll bssuqa.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= DivXa32.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 SASDIFSV;SASDIFSV;d:\spyware\sasdifsv.sys [2008-11-17 8944]
R4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-11 24652]
R4 WUSB54Gv42SVC;WUSB54Gv42SVC;c:\program files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe [2008-09-19 53307]
S1 SASKUTIL;SASKUTIL;\??\d:\saskutil.sys –> d:\SASKUTIL.sys [?]
S3 PhTVTune;Cap7134 TVTuner;c:\windows\system32\drivers\PhTVTune.sys [2006-09-15 53536]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys –> c:\windows\system32\DRIVERS\wg111v2.sys [?]
S3 SASENUM;SASENUM;\??\d:\sasenum.sys –> d:\SASENUM.SYS [?]
S3 SavRoam;SAVRoam;"c:\program files\Symantec AntiVirus\SavRoam.exe" –> c:\program files\Symantec AntiVirus\SavRoam.exe [?]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e0a2b742-bafe-11db-9020-000f1f208d76}]
\Shell\AutoRun\command - Installer.exe
.
- - - - ORPHANS REMOVED - - - -

BHO-{b1d1ec14-90a7-4ace-abb7-9a907f8806e6} - c:\windows\system32\bssuqa.dll
BHO-{EEF52DCA-29FD-4CFB-A793-59C4C4E8CB1E} - (no file)
HKCU-Run-SpybotSD TeaTimer - d:\spybot - search & destroy\TeaTimer.exe
HKCU-Run-SUPERAntiSpyware - D:\SUPERAntiSpyware.exe
HKLM-Run-vptray - c:\progra~1\SYMANT~1\VPTray.exe
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - D:\SASSEH.DLL


.
——- Supplementary Scan ——-
.
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
FF - ProfilePath - c:\documents and settings\Zena.ZENA-2CE3E9C195\Application Data\Mozilla\Firefox\Profiles\6ygmzspj.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-08 15:52:14
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(676)
d:\spyware\SASWINLO.DLL
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv42.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2009-01-08 15:56:44 - machine was rebooted [Zena]
ComboFix-quarantined-files.txt 2009-01-08 20:56:18

Pre-Run: 306,868,224 bytes free
Post-Run: 236,974,080 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

163 — E O F — 2009-01-04 23:04:16

________________________________________________________________________ (the start of the second log is following)

ComboFix 09-01-08.02 - Zena 2009-01-08 23:58:34.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.767.494 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Outdated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\windows media player\mplayer2.exe

.
((((((((((((((((((((((((( Files Created from 2008-12-09 to 2009-01-09 )))))))))))))))))))))))))))))))
.

2009-01-08 13:22 . 2009-01-08 13:22 73,216 –a—— c:\windows\system32\ffkuz.dll
2008-12-30 03:12 . 2009-01-08 13:37 54,156 –ah—– c:\windows\QTFont.qfn
2008-12-30 03:12 . 2008-12-30 03:12 1,409 –a—— c:\windows\QTFont.for
2008-12-28 02:57 . 2008-12-28 02:57 d——– c:\documents and settings\All Users\Application Data\Last.fm

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-08 21:52 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-28 07:57 ——— d—–w c:\program files\iTunes
2008-12-05 22:09 ——— d—–w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-05 22:03 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-12-05 22:03 ——— d—–w c:\documents and settings\Zena.ZENA-2CE3E9C195\Application Data\SUPERAntiSpyware.com
2008-12-05 20:24 ——— d—–w c:\program files\Java
2008-12-05 15:07 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-18 10:32 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-10-23 13:01 283,648 —-a-w c:\windows\system32\gdi32.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 10:37 659,456 —-a-w c:\windows\system32\wininet.dll
2008-08-25 02:59 1,745,106 —-a-w c:\documents and settings\Zena.ZENA-2CE3E9C195\xrt_collect.zip
2008-12-21 23:47 67,688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2008-12-21 23:47 54,368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-21 23:47 34,944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2008-12-21 23:47 46,712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-12-21 23:47 172,136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="c:\program files\AIM\aim.exe" [2005-08-05 67160]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"PopUpStopperFreeEdition"="d:\spyware\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe" [2003-04-29 524288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmaTel StacMon"="c:\program files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe" [2004-04-29 90169]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-01-08 4866048]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-10-04 48752]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-08-11 282624]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-05-08 185896]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-06-14 278528]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 c:\windows\BCMSMMSG.exe]
"nwiz"="nwiz.exe" [2004-01-08 c:\windows\system32\nwiz.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-05-13 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-01-08 13:49 356352 d:\spyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=aaphyy.dll bssuqa.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= DivXa32.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 SASDIFSV;SASDIFSV;d:\spyware\sasdifsv.sys [2008-11-17 8944]
R4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-11 24652]
R4 WUSB54Gv42SVC;WUSB54Gv42SVC;c:\program files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe [2008-09-19 53307]
S1 SASKUTIL;SASKUTIL;\??\d:\saskutil.sys –> d:\SASKUTIL.sys [?]
S3 PhTVTune;Cap7134 TVTuner;c:\windows\system32\drivers\PhTVTune.sys [2006-09-15 53536]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys –> c:\windows\system32\DRIVERS\wg111v2.sys [?]
S3 SASENUM;SASENUM;\??\d:\sasenum.sys –> d:\SASENUM.SYS [?]
S3 SavRoam;SAVRoam;"c:\program files\Symantec AntiVirus\SavRoam.exe" –> c:\program files\Symantec AntiVirus\SavRoam.exe [?]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e0a2b742-bafe-11db-9020-000f1f208d76}]
\Shell\AutoRun\command - Installer.exe
.
.
——- Supplementary Scan ——-
.
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
FF - ProfilePath - c:\documents and settings\Zena.ZENA-2CE3E9C195\Application Data\Mozilla\Firefox\Profiles\6ygmzspj.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-09 00:01:12
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(856)
d:\spyware\SASWINLO.DLL
.
Completion time: 2009-01-09 0:04:03
ComboFix-quarantined-files.txt 2009-01-09 05:03:19
ComboFix2.txt 2009-01-08 20:56:46

Pre-Run: 238,587,904 bytes free
Post-Run: 227,459,072 bytes free

123 — E O F — 2009-01-04 23:04:16
According to the little balloon that pops up from Windows Security Alerts when I start my computer, Symantec is out of date. I have found where Symantec is on my computer, but the files within the Symantec folder are either empty or Windows cannot open the particular file. Symantec doesn't appear under my list of programs via Start > Programs and it doesn't appear on my list of Add/Remove Programs in the Control Panel.
According to the little balloon, this only appeared yesterday (same day my computer started acting up). I have no way of checking because neither Symantec or LiveUpdate open to the actual program itself, since the folder doesn't contain anything.
Have you run ComboFix prior to the nasty pop-ups appearing? Did the warning about Symantec appear before or after you ran CF to deal with the pop-ups? I can see two folders that relate to Symantec: C:\Program Files\Common Files\Symantec Shared and C:\Program Files\Symantec AntiVirus. Are these folders empty?
I did not run CF prior to the popups. I downloaded and ran CF after the popups appeared. I cannot remember exactly, but I am pretty sure that the Symantec error appeared before I ran CF. Again, the Symantec error message was shown via Window Security Alerts. I do not see a Symantec AntiVirus folder under C:\Program Files. C:\Program Files\Symantec exists, though. That folder has only 4 files, which are S32EVNT1.DLL, SYMEVENT.INF, SYMEVENT.CAT, and SYMEVENT.SYS. C:\Program Files\Common Files\Symantec Shared does have a whole bunch of files, though. I should note that I haven't seen the popups for a day, but my computer is running considerably slower. I am aware that spyware/malware/viruses run deep, so it is highly possible that my computer is still infected. I do appreciate your help so far.
Run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
Here it is: Ad-Aware 2007 Ad-aware 6 Professional Adobe Download Manager 2.0 (Remove Only) Adobe Flash Player ActiveX Adobe Flash Player Plugin Adobe Photoshop 7.0 Adobe Reader 7.0.7 Adobe Shockwave Player 11 Advanced X Video Converter AOL Instant Messenger AVerTV BCM V.92 56K Modem Broadcom 440x 10/100 Integrated Controller Cole2k Media - Codec Pack (Standard) DC++ 0.699 Dell ResourceCD DivX DivX Player DivX Web Player ESPN RunTime Google Toolbar for Internet Explorer HijackThis 2.0.2 Hotfix for Windows XP (KB952287) iPod for Windows 2006-06-28 iTunes J2SE Runtime Environment 5.0 Update 11 J2SE Runtime Environment 5.0 Update 6 Jasc Paint Shop Photo Album Java™ 6 Update 11 Java™ 6 Update 3 Java™ 6 Update 5 Java™ 6 Update 7 Last.fm 1.5.2.38918 Linksys Wireless-G USB Network Adapter Microsoft Office 2000 Professional Microsoft Silverlight Mozilla Firefox (3.0.5) MSN NVIDIA Windows 2000/XP Display Drivers Office Key 8.3 Demo OpenOffice.org Installer 1.0 Pop-Up Stopper Free Edition QuickTime RealPlayer ScanToWeb Security Update for Windows Media Player (KB952069) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB944338-v2) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950749) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953838) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956390) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958215) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB960714) Shockwave SigmaTel AC97 Audio Drivers Sonic RecordNow! Spybot - Search & Destroy SpywareBlaster 4.1 SUPERAntiSpyware Free Edition Symantec AntiVirus Update for Windows XP (KB951072-v2) Update for Windows XP (KB955839) Viewpoint Manager (Remove Only) Viewpoint Media Player Windows Genuine Advantage v1.3.0254.0
You need a new anti-virus program before we continue - an out-of-date AV is no use to you. Feel free to buy one, upgrade Symantec or choose one of these three versions:

AVG Free Edition: Available here.
avast! 4 Home Edition: Available here
AntiVir PersonalEdition Classic :Available here

I use both AVG and AntiVir on different PCs and both require very little in the way of user intervention, if you can't be bothered mucking around with them. AntiVir seems to be better thought of at the moment, but it does display a pop-up when updating offering you the chance to upgrade to a paid-for version. Personally I feel this is a fair price to pay for a free AV, but if you don't like the idea of closing one window a day, AVG may be the better option, although it is heavier on system resources.

Unless you go with the Symantec upgrade, you need to download the AV installation file to your Desktop and then log off from the internet. While you are free to try out any number of programs, only install one anti-virus at a time as conflictions can result from two or more running together - not good.
Open Add/Remove Programs and uninstall Symantec AntiVirus.
Once you've done that, you need to reboot your PC to finish the process.
Install the new AV and then update it and run a full system scan and let it delete whatever it finds.
Then let me have a new HJT log and tell me what the PC is up to now.
I have no idea what happened with my Symantec, but I will go ahead and download one of the free AVs you recommended for the meantime. Is Symantec the superior AV, thus worth the price? I do not have extensive knowledge on this issue. Thank you for your help so far! edit: I forgot to add that I ran Spybot S&D earlier today to see if it would catch whatever was possibly slowing up my computer and it found 1 entry for MediaPlex and 1 entry for Smitfraud-C. I used Spybot's 'fix the problem' option and it supposedly deleted these 2 malware issues. If there is something else I should do to make sure these issues are deleted, please let me know.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI