Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 09-18-2006, 07:21 AM   #1 (permalink)
Registered User
 
Join Date: Sep 2006
Posts: 5
OS: XP


Malware Slowing Down Browser

Firefox taking 45 seconds to open and then pauses for so long between websites and opens so slow when I minimize and maximize the window. I have to run explorer now which seems to work fine. I got some sort of virus a week ago and thought I had gotten rid of it completely. I downloaded and followed all the steps to do before making a thread. Here is my hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 9:19:58 AM, on 9/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Prevx1\PXAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Prevx1\PXConsole.exe
C:\Program Files\iTunes\iTunes.exe
C:\PROGRA~1\MOZILL~1\firefox.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\AIM\aim.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Chris\LOCALS~1\Temp\Rar$EX00.016\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com.../fix_homepage/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Enterprise
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

If anyone can help, it would be greatly appreciated! Thanks.
calechko is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 09-19-2006, 11:29 AM   #2 (permalink)
Analyst, Security Team ; TSF Supporter
 
fredmh's Avatar
 
Join Date: May 2006
Location: Phila,Pa
Posts: 2,335
OS: XP


Hello calechko, and welcome to TSF.


I am currently reviewing your log. Please note that this is under the supervision of an expert analyst,
and I will be back with a fix for your problem as soon as possible.

You may wish to Subscribe to this thread (Thread Tools) so that you are notified when you receive a reply.

Please be patient with me during this time.



You are running Hijack This from a temporary directory. It needs to be in a permanent folder. Please go into Windows Explorer,
click on C: then click on File > New > Folder and call it HJT , or another name of your choice. The program creates backup
files that we may need to use later. If the program is in a Temporary folder, files may be deleted by you or automatically if your
system is set to empty temp files.


I believe that you have an infection which is hiding from HJT. Once you have moved HJT to a permanent folder, I need you to rename it.

Please go into the new HJT folder, right click on the executable file (which looks like sticks of dynamite with a detenator} and click on
"rename". When the box appears, type in doom and click enter. This will rename the file to doom.exe. Please then post a new hjt log using the
renamed program.
fredmh is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 09-19-2006, 04:54 PM   #3 (permalink)
Registered User
 
Join Date: Sep 2006
Posts: 5
OS: XP


Here is the new file out of a permanent folder. I renamed the executable file doom.exe.

Thanks for your help.

Logfile of HijackThis v1.99.1
Scan saved at 6:53:09 PM, on 9/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Prevx1\PXAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Prevx1\PXConsole.exe
C:\Program Files\iTunes\iTunes.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\HJT\doom.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com.../fix_homepage/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: (no name) - {73025D84-E868-4E5E-835E-48151C6D9233} - C:\WINDOWS\system32\awtqn.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - (no file)
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Enterprise
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: awtqn - C:\WINDOWS\system32\awtqn.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winpsa32 - C:\WINDOWS\
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
calechko is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 09-19-2006, 05:08 PM   #4 (permalink)
Analyst, Security Team ; TSF Supporter
 
fredmh's Avatar
 
Join Date: May 2006
Location: Phila,Pa
Posts: 2,335
OS: XP


Hello calechko, and welcome to TSF.


I am currently reviewing your log. Please note that this is under the supervision of an expert analyst,
and I will be back with a fix for your problem as soon as possible.

You may wish to Subscribe to this thread (Thread Tools) so that you are notified when you receive a reply.

Please be patient with me during this time.
fredmh is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 09-19-2006, 09:30 PM   #5 (permalink)
Analyst, Security Team ; TSF Supporter
 
fredmh's Avatar
 
Join Date: May 2006
Location: Phila,Pa
Posts: 2,335
OS: XP


Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools,
then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe.


Please read this post completely before begining the fix. If there's anything that you do not understand, kindly ask your questions before proceeding.
Please ensure that there aren't any opened browsers when you are carrying out the procedures below. Save the following instructions in Notepad as this
webpage would not be available when you're carrying out the fix.



IT IS IMPORTANT THAT YOU DON'T MISS A STEP & PERFORM EVERYTHING IN THE RIGHT ORDER.

----------------------------------------

The fixes we will use are specific to your problems and should only be used for this issue on this machine.

Please only use this topic to reply to. Do not start another thread.
If any other issues arise let me know.
The process is not instant. Please continue to review my answers until I tell you your machine is clear.
Please make every effort to reply to my posts in a timely manner. Malware breeds malware and the longer an infection remains on a system, the more
likely additional infections will result.
Absence of symptoms does not mean that everything is clear. So lets do this to the end!


----------------------------------------

DOWNLOADS


ATF CLEANER

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 only


EWIDO

Please download Ewido Anti-Malware
  1. Install Ewido Anti-Malware.
  2. Double-click the icon on Desktop to launch Ewido
  3. On the top of the main screen click Shield
  4. Click the word active to change it to inactive
  5. On the top of the main screen click Update.
  6. Then click on Start Update. The update will start and a progress bar will show the updates being installed.
  7. I also recommend changing the "Update interval" to something more reasonable like 12 hours.

If you are having problems with the updater, you can use this link to manually update Ewido.
When you have finished updating, EXIT Ewido.

----------------------------------------

DISABLE ANTI-SPYWARE APPLICATIONS

Please disable these Anti-Spyware applications, as it may hinder the removal of some entries. They may be re-enabled upon completion of the fix.


Prevx:
  • Right click on the Prevx icon in your system tray at the bottom-right corner of your screen and choose "Show Management Console".
  • On the Management Console click the Protection Level drop-down menu. You will see three levels:
    • Maximum
    • Off
    • User Defined
  • To disable all protection set the level to [b]Off. You will receive a prompt asking "You are about to change your security settings. Do you wish to continue?" Click Yes.
  • Click the X on the upper right hand corner to exit the Management console.

Windows Defender

Please disable your Windows Defender Real-time Protection, as it may hinder the removal of some entries.
  • Open Windows Defender.
  • Click on Tools>Options.
  • Scroll down and uncheck "Use real-time protection (recommended)".
  • After you uncheck this, click on the Save button and close Windows Defender.

----------------------------------------

COMBO FIX


1. Download this file - You MUST save it to your desktop

http://download.bleepingcomputer.com/sUBs/combofix.exe

or

http://www.techsupportforum.com/sectools/combofix.exe





2. 2. Go to <<Start>> then <<Run>> then paste in the single line command then click OK

"%userprofile%\desktop\combofix.exe" /v awtqn


3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

----------------------------------------


SAFE MODE RE-BOOT

Restart your computer and boot into Safe Mode by hitting the F8 key repeatedly until a menu shows up (and choose Safe Mode from the list).
In some systems, this may be the F5 key, so try that if F8 doesn't work. Login on your usual account. Make sure to close any open browsers.

----------------------------------------

FIXES AND DELETIONS


Open HijackThis and click on 'Do a System Scan Only'. Check the following entries (If they still exist, make sure you do not miss any)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - (no file)
O20 - Winlogon Notify: winpsa32 - C:\WINDOWS\


Please remember to close all other windows, including browsers then click Fix checked.

----------------------------------------

RUNNING SCANNERS


ATF CLEANER

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.


If you use Opera browser

Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.


Click Exit on the Main menu to close the program


EWIDO
  • Run Ewido with it's updated definitions: (...it's important that all windows must be closed)
    This scan can take quite a while to run, so be prepared.
  • Click Scanner
  • Click on the Scan tab
  • Click Complete System Scan to begin scanning.
  • When the scan is complete click Recommended Action and change it to Quarantine.
  • Then click Apply all actions.


Once finished, click the Save report button, then click Save Report As and save it to your desktop.

----------------------------------------
SYSTEM RE-BOOT

Reboot into Normal Mode.

----------------------------------------

SMITFRAUD

Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"
and a text file will appear which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

IMPORTANT: Do NOT run option #2 OR any other option until you are directed to do so!

----------------------------------------

ON-LINE SCANS


Perform an online scan with Internet Explorer with Panda ActiveScan

Click on the "Free To Use ActiveScan" located on the top right hand corner
  1. Click Check Now and a "pop up" window will appear. * Please ensure that your pop up blocker doesn't block it *
  2. Enter your e-mail address, country, and state & click Scan Now * The download of the 8 MB Panda's ActiveX control will take place *

Begin the scan by selecting My Computer
  • If it finds any malware, it will offer you a report.
  • Please ignore any entry it finds and the offer to buy the program to remove the entry, as we will address this later.
  • Click on See report then click Save report
* You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
* Turn off the real time scanner of any existing antivirus program while performing the online scan


----------------------------------------

FOLLOW-UP

Please return and post these items:

ComboFix log
SmitFraud log
Ewido scan
Panda scan
A new HJT log run in Normal Mode


Please note: In order to properly see what is on your system, all HJT logs must be run in the normal mode
fredmh is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 09-20-2006, 09:45 PM   #6 (permalink)
Registered User
 
Join Date: Sep 2006
Posts: 5
OS: XP


Ok, I have done all the steps you have asked me to. Here are the logs you asked for.

Chris - 06-09-20 9:30:15.73 Service Pack 2
ComboFix 06.09.20 - Running from: "C:\Documents and Settings\Chris\desktop"
Command switches used :: /v awtqn

(((((((((((((((((((((((((((((((((((((((((((((((( Vundo Log )))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\awtqn.dll
C:\WINDOWS\system32\nqtwa.bak1
C:\WINDOWS\system32\nqtwa.bak2
C:\WINDOWS\system32\nqtwa.ini
C:\WINDOWS\system32\nqtwa.ini2
C:\WINDOWS\system32\nqtwa.tmp


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\components


((((((((((((((((((((((((((((((( Files Created from 2009-19-06 to 2009/20/2006 ))))))))))))))))))))))))))))))))))


No new files created in this timespan


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2012/18/2004 08:32 PM 38229 --------- C:\WINDOWS\system32\drivers\StMp3Rec.sys
2012/17/2004 08:13 PM 145920 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2012/15/2004 11:18 AM 703232 --a------ C:\WINDOWS\system32\drivers\HSF_CNXT.sys
2012/15/2004 11:18 AM 207232 --a------ C:\WINDOWS\system32\drivers\HSFHWICH.sys
2012/15/2004 11:18 AM 1038208 --a------ C:\WINDOWS\system32\drivers\HSF_DP.sys
2011/17/2004 06:17 AM 293120 --a------ C:\WINDOWS\system32\drivers\camcaud.sys
2011/17/2004 06:17 AM 280192 --a------ C:\WINDOWS\system32\drivers\camchal.sys


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"LSBWatcher"="c:\\hp\\drivers\\hplsbwatcher\\lsburnwatcher.exe"
"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Enterprise"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"vptray"="C:\\PROGRA~1\\SYMANT~1\\VPTray.exe"
"PrevxOne"="\"C:\\Program Files\\Prevx1\\PXConsole.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,50,01,00,00,00,00,00,00,40,05,00,00,f8,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~2.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
"backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\MICROS~4\\Office10\\OSA.EXE -b -l"
"item"="Microsoft Office"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^Chris^Start Menu^Programs^Startup^Zeno.lnk]
"backup"="C:\\WINDOWS\\pss\\Zeno.lnkStartup"
"location"="Startup"
"item"="Zeno"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\AIM]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="aim"
"hkey"="HKCU"
"command"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\ATIPTA]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="atiptaxx"
"hkey"="HKLM"
"command"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\BearShare]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="BearShare"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\BearShare\\BearShare.exe\" /pause"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\BrowserUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="lwinlsaw"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\fmuz]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="fmuzm"
"hkey"="HKCU"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\hpWirelessAssistant]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="HP Wireless Assistant"
"hkey"="HKLM"
"command"="C:\\Program Files\\hpq\\HP Wireless Assistant\\HP Wireless Assistant.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\MsnMsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MsnMsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\MSPY2002]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ImScInst"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\IME\\PINTLGNT\\ImScInst.exe /SYNC"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\NaviSearch]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nls"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\PHIME2002A]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TINTSETP"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\PHIME2002ASync]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TINTSETP"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime Alternative\\qttask.exe\" -atboottime"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Screen Calendar]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="scrcal"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Screen Calendar\\scrcal.exe\" -m"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\services32]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mc-110-12-0000187"
"hkey"="HKCU"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Symantec NetDriver Monitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SNDMon"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\SynTPLpr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SynTPLpr"
"hkey"="HKLM"
"command"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\WhenUSave]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Save"
"hkey"="HKLM"
"inimapping"="0"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winpsa32

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job

Completion time: Wed 09/20/2006 9:37:05.65
ComboFix.txt


SmitFraudFix v2.96

Scan done at 22:00:37.57, 06-09-20
Run from C:\Documents and Settings\Chris\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

C:\WINDOWS\system32\ot.ico FOUND !
C:\WINDOWS\system32\ts.ico FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Chris\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Chris\FAVORI~1

C:\DOCUME~1\Chris\FAVORI~1\Antivirus Test Online.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32


»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End


---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 21:48 06-09-20

+ Scan result:



C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WhenUSave -> Adware.SaveNow : Cleaned with backup (quarantined).
:mozilla.86:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.2o7 : Error during cleaning.
:mozilla.26:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Advertising : Error during cleaning.
:mozilla.27:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Advertising : Error during cleaning.
:mozilla.28:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Advertising : Error during cleaning.
:mozilla.29:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Advertising : Error during cleaning.
:mozilla.30:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Advertising : Error during cleaning.
:mozilla.6:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Atdmt : Error during cleaning.
:mozilla.106:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Casalemedia : Error during cleaning.
:mozilla.107:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Casalemedia : Error during cleaning.
:mozilla.46:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Coremetrics : Error during cleaning.
:mozilla.52:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Coremetrics : Error during cleaning.
:mozilla.108:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Cpvfeed : Error during cleaning.
:mozilla.109:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Cpvfeed : Error during cleaning.
:mozilla.110:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Cpvfeed : Error during cleaning.
:mozilla.111:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Cpvfeed : Error during cleaning.
:mozilla.31:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Doubleclick : Error during cleaning.
:mozilla.102:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Fastclick : Error during cleaning.
:mozilla.103:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Fastclick : Error during cleaning.
:mozilla.55:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Pointroll : Error during cleaning.
:mozilla.56:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Pointroll : Error during cleaning.
:mozilla.57:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Pointroll : Error during cleaning.
:mozilla.58:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Pointroll : Error during cleaning.
:mozilla.60:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Questionmarket : Error during cleaning.
:mozilla.61:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Questionmarket : Error during cleaning.
C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{23D49DE9-CCF2-4DA9-9A64-8C4154EAB27F}.txt/{23D49DE9-CCF2-4DA9-9A64-8C4154EAB27F}.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.123:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.124:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.125:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.126:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.12:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.13:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.14:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.15:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.67:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Tribalfusion : Error during cleaning.
:mozilla.68:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Tribalfusion : Error during cleaning.
:mozilla.100:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Yieldmanager : Error during cleaning.
:mozilla.101:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Yieldmanager : Error during cleaning.
:mozilla.16:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Yieldmanager : Error during cleaning.
:mozilla.17:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Yieldmanager : Error during cleaning.
:mozilla.18:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Yieldmanager : Error during cleaning.
:mozilla.19:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Yieldmanager : Error during cleaning.


::Report end



Incident Status Location

Adware:adware/securityerror Not disinfected c:\windows\system32\ot.ico
Adware:adware/savenow Not disinfected Windows Registry
Adware:adware/sqwire Not disinfected Windows Registry
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Chris\Cookies\chris@atwola[1].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Chris\Cookies\chris@casalemedia[2].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Chris\Desktop\SmitfraudFix\SmitfraudFix\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Chris\Desktop\SmitfraudFix.zip[SmitfraudFix/Process.exe]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\8X6VSPIJ\SmitfraudFix[1].zip[SmitfraudFix/Process.exe]
Spyware:Cookie/Atlas DMT Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.atdmt.com/]
Spyware:Cookie/Advertising Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.advertising.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.doubleclick.net/]
Spyware:Cookie/Coremetrics Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][data.coremetrics.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.ads.pointroll.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.questionmarket.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.realmedia.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.tribalfusion.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][ad.yieldmanager.com/]
Spyware:Cookie/FastClick Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.fastclick.net/]
Spyware:Cookie/Casalemedia Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.casalemedia.com/]
Spyware:Cookie/Atwola Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{EB311F4D-F2A3-410F-AF4D-80086B1E1E3D}.txt[{EB311F4D-F2A3-410F-AF4D-80086B1E1E3D}.txt]
Spyware:Cookie/Atwola Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{19D31794-AE2B-4680-8BC8-376B5CD1EEE2}.txt[{19D31794-AE2B-4680-8BC8-376B5CD1EEE2}.txt]
Spyware:Cookie/YieldManager Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt[{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt][ad.yieldmanager.com/]
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe
Logfile of HijackThis v1.99.1
Scan saved at 23:44, on 06-09-20
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\iTunes\iTunes.exe
C:\HJT\doom.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Enterprise
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
calechko is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 09-21-2006, 09:52 AM   #7 (permalink)
Analyst, Security Team ; TSF Supporter
 
fredmh's Avatar
 
Join Date: May 2006
Location: Phila,Pa
Posts: 2,335
OS: XP


Please read this post completely before begining the fix. If there's anything that you do not understand, kindly ask your questions before proceeding.
Please ensure that there aren't any opened browsers when you are carrying out the procedures below. Save the following instructions in Notepad as this
webpage would not be available when you're carrying out the fix.



IT IS IMPORTANT THAT YOU DON'T MISS A STEP & PERFORM EVERYTHING IN THE RIGHT ORDER.

----------------------------------------

Good job. We got the main infection. Just a little bit more to do. Please let me know how your computer's running.

----------------------------------------

SAFE MODE RE-BOOT

Restart your computer and boot into Safe Mode by hitting the F8 key repeatedly until a menu shows up (and choose Safe Mode from the list).
In some systems, this may be the F5 key, so try that if F8 doesn't work. Login on your usual account. Make sure to close any open browsers.

----------------------------------------

SmitFraud - OPTION 2


Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : " Registry cleaning - Do you want to clean the registry?" answer Yes by typing Y and hit Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question " Replace infected file?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: (C:rapport.txt) or partition where your operating system is installed. Please post that log along with all others requested in your next reply.

----------------------------------------

SECURE DESKTOP


Next go to Control Panel click Display>Desktop>Customize Desktop>Web> Now, Uncheck Everything and delete if present:

  • "Security Info"
  • "Warning Message"
  • "Security Desktop"
  • "Warning Homepage"
  • "Desktop Uninstall"


Also make sure the 'Lock desktop items' box is unticked. Click OK, and then Click Apply, then OK.

----------------------------------------
SYSTEM RE-BOOT

Reboot into Normal Mode.

----------------------------------------

SmitFraud - OPTION 3

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #3 - Delete Trusted zone by typing 3 and press Enter
Answer Yes to the question "Restore Trusted Zone ?" by typing Y and hit Enter.



Note, if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford.
For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protectio

----------------------------------------

ON-LINE SCANS



Establish an internet connection & perform an online scan with Internet Explorer at Kaspersky Online Scanner

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure to:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect.
    We only require a report from it.
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply

* Turn off the real time scanner of any existing antivirus program while performing the online scan

----------------------------------------

FOLLOW-UP

Please return and post these items:

ComboFix log
SmitFraud log
Ewido scan
Panda scan
A new HJT log run in Normal Mode


Please note: In order to properly see what is on your system, all HJT logs must be run in the normal mode
fredmh is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 09-21-2006, 05:11 PM   #8 (permalink)
Registered User
 
Join Date: Sep 2006
Posts: 5
OS: XP


here ya go. firefox is working now.
thanks for your help.

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
06-09-21 19:04
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 21/09/2006
Kaspersky Anti-Virus database records: 225382
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 93382
Number of viruses found: 6
Number of infected objects: 34 / 0
Number of suspicious objects: 2
Duration of the scan process: 01:38:29

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\WDLog-08132006-163255.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ExactAdvertisingBargainsBuddy11.zip/adv.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ExactAdvertisingBargainsBuddy11.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2006-09-21_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02600000.VBN/Setup.exe Infected: Worm.Win32.VB.an skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02600000.VBN ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02600000.VBN CryptZ: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02600001.VBN/Setup.exe Infected: Worm.Win32.VB.an skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02600001.VBN ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02600001.VBN CryptZ: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09D00000.VBN Infected: Worm.Win32.VB.an skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09D00001.VBN Infected: Worm.Win32.VB.an skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\10240000.VBN/Setup.exe Infected: Worm.Win32.VB.an skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\10240000.VBN ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\10240000.VBN CryptZ: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\10240001.VBN/Setup.exe Infected: Worm.Win32.VB.an skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\10240001.VBN ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\10240001.VBN CryptZ: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\12D40000.VBN/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\12D40000.VBN ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\12D40000.VBN CryptZ: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\12D40001.VBN/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\12D40001.VBN ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\12D40001.VBN CryptZ: infected - 1 skipped
C:\Documents and Settings\Chris\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Chris\Desktop\SmitfraudFix\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Chris\Desktop\SmitfraudFix.zip/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Chris\Desktop\SmitfraudFix.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Chris\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Chris\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Chris\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Chris\Local Settings\History\History.IE5\MSHist012006092120060922\index.dat Object is locked skipped
C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\8X6VSPIJ\SmitfraudFix[1].zip/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\8X6VSPIJ\SmitfraudFix[1].zip ZIP: infected - 1 skipped
C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Chris\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Chris\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\Hp\hpcoretech\hpcmerr.log Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0111NAV~.TMP Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0140NAV~.TMP Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\tracking.log Object is locked skipped
C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP451\A0036539.exe/WISE0026.BIN/clientax.dll Infected: not-a-virus:AdWare.Win32.180Solutions.ao skipped
C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP451\A0036539.exe/WISE0026.BIN Infected: not-a-virus:AdWare.Win32.180Solutions.ao skipped
C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP451\A0036539.exe WiseSFX: infected - 2 skipped
C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP451\A0036539.exe WiseSFX Dropper: infected - 2 skipped
C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP459\A0036618.exe Infected: Trojan-Downloader.Win32.Zlob.ajx skipped
C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP465\A0036767.exe/WISE0026.BIN/clientax.dll Infected: not-a-virus:AdWare.Win32.180Solutions.ao skipped
C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP465\A0036767.exe/WISE0026.BIN Infected: not-a-virus:AdWare.Win32.180Solutions.ao skipped
C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP465\A0036767.exe WiseSFX: infected - 2 skipped
C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP465\A0036767.exe WiseSFX Dropper: infected - 2 skipped
C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP486\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{5330C6D9-29C7-4AD2-8B5A-DD8A85C993E9}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.


---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 21:48 06-09-20

+ Scan result:



C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WhenUSave -> Adware.SaveNow : Cleaned with backup (quarantined).
:mozilla.86:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.2o7 : Error during cleaning.
:mozilla.26:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Advertising : Error during cleaning.
:mozilla.27:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Advertising : Error during cleaning.
:mozilla.28:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Advertising : Error during cleaning.
:mozilla.29:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Advertising : Error during cleaning.
:mozilla.30:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Advertising : Error during cleaning.
:mozilla.6:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Atdmt : Error during cleaning.
:mozilla.106:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Casalemedia : Error during cleaning.
:mozilla.107:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Casalemedia : Error during cleaning.
:mozilla.46:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Coremetrics : Error during cleaning.
:mozilla.52:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Coremetrics : Error during cleaning.
:mozilla.108:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Cpvfeed : Error during cleaning.
:mozilla.109:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Cpvfeed : Error during cleaning.
:mozilla.110:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Cpvfeed : Error during cleaning.
:mozilla.111:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Cpvfeed : Error during cleaning.
:mozilla.31:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Doubleclick : Error during cleaning.
:mozilla.102:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Fastclick : Error during cleaning.
:mozilla.103:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Fastclick : Error during cleaning.
:mozilla.55:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Pointroll : Error during cleaning.
:mozilla.56:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Pointroll : Error during cleaning.
:mozilla.57:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Pointroll : Error during cleaning.
:mozilla.58:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Pointroll : Error during cleaning.
:mozilla.60:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Questionmarket : Error during cleaning.
:mozilla.61:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Questionmarket : Error during cleaning.
C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{23D49DE9-CCF2-4DA9-9A64-8C4154EAB27F}.txt/{23D49DE9-CCF2-4DA9-9A64-8C4154EAB27F}.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.123:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.124:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.125:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.126:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.12:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.13:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.14:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.15:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.67:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Tribalfusion : Error during cleaning.
:mozilla.68:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Tribalfusion : Error during cleaning.
:mozilla.100:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Yieldmanager : Error during cleaning.
:mozilla.101:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Yieldmanager : Error during cleaning.
:mozilla.16:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Yieldmanager : Error during cleaning.
:mozilla.17:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Yieldmanager : Error during cleaning.
:mozilla.18:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Yieldmanager : Error during cleaning.
:mozilla.19:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Yieldmanager : Error during cleaning.


::Report end


Chris - 06-09-20 9:30:15.73 Service Pack 2
ComboFix 06.09.20 - Running from: "C:\Documents and Settings\Chris\desktop"
Command switches used :: /v awtqn

(((((((((((((((((((((((((((((((((((((((((((((((( Vundo Log )))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\awtqn.dll
C:\WINDOWS\system32\nqtwa.bak1
C:\WINDOWS\system32\nqtwa.bak2
C:\WINDOWS\system32\nqtwa.ini
C:\WINDOWS\system32\nqtwa.ini2
C:\WINDOWS\system32\nqtwa.tmp


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\components


((((((((((((((((((((((((((((((( Files Created from 2009-19-06 to 2009/20/2006 ))))))))))))))))))))))))))))))))))


No new files created in this timespan


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2012/18/2004 08:32 PM 38229 --------- C:\WINDOWS\system32\drivers\StMp3Rec.sys
2012/17/2004 08:13 PM 145920 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2012/15/2004 11:18 AM 703232 --a------ C:\WINDOWS\system32\drivers\HSF_CNXT.sys
2012/15/2004 11:18 AM 207232 --a------ C:\WINDOWS\system32\drivers\HSFHWICH.sys
2012/15/2004 11:18 AM 1038208 --a------ C:\WINDOWS\system32\drivers\HSF_DP.sys
2011/17/2004 06:17 AM 293120 --a------ C:\WINDOWS\system32\drivers\camcaud.sys
2011/17/2004 06:17 AM 280192 --a------ C:\WINDOWS\system32\drivers\camchal.sys


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"LSBWatcher"="c:\\hp\\drivers\\hplsbwatcher\\lsburnwatcher.exe"
"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Enterprise"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"vptray"="C:\\PROGRA~1\\SYMANT~1\\VPTray.exe"
"PrevxOne"="\"C:\\Program Files\\Prevx1\\PXConsole.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,50,01,00,00,00,00,00,00,40,05,00,00,f8,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~2.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
"backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\MICROS~4\\Office10\\OSA.EXE -b -l"
"item"="Microsoft Office"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^Chris^Start Menu^Programs^Startup^Zeno.lnk]
"backup"="C:\\WINDOWS\\pss\\Zeno.lnkStartup"
"location"="Startup"
"item"="Zeno"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\AIM]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="aim"
"hkey"="HKCU"
"command"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\ATIPTA]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="atiptaxx"
"hkey"="HKLM"
"command"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\BearShare]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="BearShare"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\BearShare\\BearShare.exe\" /pause"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\BrowserUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="lwinlsaw"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\fmuz]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="fmuzm"
"hkey"="HKCU"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\hpWirelessAssistant]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="HP Wireless Assistant"
"hkey"="HKLM"
"command"="C:\\Program Files\\hpq\\HP Wireless Assistant\\HP Wireless Assistant.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\MsnMsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MsnMsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\MSPY2002]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ImScInst"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\IME\\PINTLGNT\\ImScInst.exe /SYNC"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\NaviSearch]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nls"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\PHIME2002A]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TINTSETP"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\PHIME2002ASync]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TINTSETP"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime Alternative\\qttask.exe\" -atboottime"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Screen Calendar]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="scrcal"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Screen Calendar\\scrcal.exe\" -m"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\services32]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mc-110-12-0000187"
"hkey"="HKCU"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Symantec NetDriver Monitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SNDMon"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\SynTPLpr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SynTPLpr"
"hkey"="HKLM"
"command"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\WhenUSave]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Save"
"hkey"="HKLM"
"inimapping"="0"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winpsa32

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job

Completion time: Wed 09/20/2006 9:37:05.65
ComboFix.txt


SmitFraudFix v2.96

Scan done at 22:00:37.57, 06-09-20
Run from C:\Documents and Settings\Chris\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

C:\WINDOWS\system32\ot.ico FOUND !
C:\WINDOWS\system32\ts.ico FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Chris\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Chris\FAVORI~1

C:\DOCUME~1\Chris\FAVORI~1\Antivirus Test Online.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32


»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End



Incident Status Location

Adware:adware/securityerror Not disinfected c:\windows\system32\ot.ico
Adware:adware/savenow Not disinfected Windows Registry
Adware:adware/sqwire Not disinfected Windows Registry
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Chris\Cookies\chris@atwola[1].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Chris\Cookies\chris@casalemedia[2].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Chris\Desktop\SmitfraudFix\SmitfraudFix\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Chris\Desktop\SmitfraudFix.zip[SmitfraudFix/Process.exe]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\8X6VSPIJ\SmitfraudFix[1].zip[SmitfraudFix/Process.exe]
Spyware:Cookie/Atlas DMT Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.atdmt.com/]
Spyware:Cookie/Advertising Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.advertising.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.doubleclick.net/]
Spyware:Cookie/Coremetrics Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][data.coremetrics.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.ads.pointroll.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.questionmarket.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.realmedia.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.tribalfusion.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][ad.yieldmanager.com/]
Spyware:Cookie/FastClick Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.fastclick.net/]
Spyware:Cookie/Casalemedia Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.casalemedia.com/]
Spyware:Cookie/Atwola Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{EB311F4D-F2A3-410F-AF4D-80086B1E1E3D}.txt[{EB311F4D-F2A3-410F-AF4D-80086B1E1E3D}.txt]
Spyware:Cookie/Atwola Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{19D31794-AE2B-4680-8BC8-376B5CD1EEE2}.txt[{19D31794-AE2B-4680-8BC8-376B5CD1EEE2}.txt]
Spyware:Cookie/YieldManager Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt[{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt][ad.yieldmanager.com/]
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe


Logfile of HijackThis v1.99.1
Scan saved at 19:10, on 06-09-21
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\doom.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Enterprise
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
calechko is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 09-21-2006, 07:12 PM   #9 (permalink)
Analyst, Security Team ; TSF Supporter
 
fredmh's Avatar
 
Join Date: May 2006
Location: Phila,Pa
Posts: 2,335
OS: XP


Please check your SmitFraud logs (c:rapport.txt). The log you just posted is
the same as the first log, which identifies the infection.
date/time stamp: 06/09/20 2200:37.


I need the log produced after you ran Option #2 which will tell me if it cleaned out the infection.
fredmh is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 09-21-2006, 07:17 PM   #10 (permalink)
Registered User
 
Join Date: Sep 2006
Posts: 5
OS: XP


sorry i found the new log.

SmitFraudFix v2.96

Scan done at 16:59:32.71, Thu 09/21/2006
Run from C:\Documents and Settings\Chris\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\system32\ot.ico Deleted
C:\WINDOWS\system32\ts.ico Deleted

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End
calechko is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 09-23-2006, 09:07 AM   #11 (permalink)
Analyst, Security Team ; TSF Supporter
 
fredmh's Avatar
 
Join Date: May 2006
Location: Phila,Pa
Posts: 2,335
OS: XP


Download the attached cal.zip file at the bottom of this post to your desktop. Double click on the zip folder,
then double click on the .reg file within.
Click yes to allow it to merge into your registry.

You still have a few registry entries which need to be deleted. This zip file will delete the 'junk" from your registry.


----------------------------------------

Good job. Your logs are now clean. Please follow these "housekeeping steps" and read through the below information

----------------------------------------

Windows XP - Reset Hidden Files

  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Deselect the Show hidden files and folders option.
  • Select the Hide file extensions for known types option.
  • Select the Hide protected operating system files option.
  • Click Yes to confirm.
  • Click OK.

----------------------------------------

Clean-out and Reset System Restore

This will clean out any junk or malicious files left behind in System Restore
  • To turn off System Restore click Start > Right Click My Computer > Properties.
  • Click the System Restore tab and Check
  • "Turn off System Restore" or "Turn off System Restore on all drives" Click Apply.
  • When turning off System Restore, the existing restore points will be deleted. Click Yes to do this then Click OK.

  • Turn on System Restore by Clicking Start. Right-click My Computer, and then click Properties.
  • Click the System Restore tab. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives."
  • Click Apply, and then OK.

This will create a new Restore Point.

----------------------------------------

Clear IE's Cookies and Cache
  • Close all instances of Outlook Express and Internet Explorer.
  • Go to Control Panel » Internet Options » General tab.
  • Click the Delete Cookies.
  • Next to it, Click the Delete Files button.
  • When prompted, place a check in: Delete all offline content, click OK.

NORTON QUARANTINE

Please visit This Siteto clear Norton's Quarantine Files.


SYSTEM MECHANIC 6

Please clear the files in Mechanic's Quarantine

----------------------------------------

RE-ENABLE ANTI-SPYWARE APPLICATIONS

If you were instructed to dis-able Anti-spyware applications during this fix, you may re-enable them

----------------------------------------

Please read through the following information to help protect your computer in the future.


KEEP YOUR OPERATING SYSTEM UPDATED

Please ensure that you have already patched your system against the recent WMF exploit. Go to this page to get the KB912919 patch

MICROSOFT UPDATES

It is very important that you get all of the critical updates for your Operating System and Internet Explorer. Keeping your OS and browser
up to date will help make you less susceptible to attacks by Trojans and viruses. Please go to Microsoft
and download all the critical updates to help prevent possible re-infection.


ENABLE WINDOWS AUTO UPDATE

Go to Start>Run - type wuaucpl.cpl
tick on the checkbox - "Keep my computer up to date"
Under settings, choose "Automatically download the updates, and install them on the schedule that I specify".
Click on "OK".


TOOLS TO HELP KEEP YOUR SYSTEM CLEAN

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programs:

SpywareBlaster to help prevent spyware from installing in the first place.
  • Install & update SpywareBlaster with the latest definitions.
  • After you have updated, click the button - enable protection for all unprotected items


SpywareGuard to catch and block spyware before it can execute.


SPYBOT - SEARCH & DESTROY Download and install Spybot - Search & Destroy with its
TeaTimer option.
This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with
the program on a regular basis just as you would an antivirus software. A tutorial on installing & using this product can be found here


AD-AWARE Download and install Ad-Aware. You should use this program to scan
your computer on a regular basis just as you would an antivirus software in conjunction with Spybot. A tutorial on installing & using this product
can be found here


IE-SPYAD IE/Spyad places more than 4000 dubious websites and domains in the IE Restricted list. This severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • Download IE-SpyAD - Extract the contents to a new folder
  • From within the folder, double-click install.bat
  • Select Option #2 - Install the new IE-SPYAD list.
  • Then return to the main menu.
  • Select option #4 - Add the old porn sites domain

A tutorial for IE-SPYAD can be found here


MVPS HOST FILE The MVPS Hosts file replaces your current HOSTS file
with one that will restrict known ad sites form serving you unsolicited advertisements. Basically, this prevents your computer from connecting to
those sites by redirecting them to 127.0.0.1 which is the IP of your local computer.
  • Download Host.zip to your desktop.
  • From your Desktop right-click (hosts.zip) and select:
    Extract All from the menu.
  • Click Next, click Next, select the option:
    "Show Extracted files"
  • Click Finish

This will open the newly created hosts folder on your Desktop.

Double-click on the included mvps.bat file, this will rename the existing HOSTS file to HOSTS.MVP, then it will copy the included updated
HOSTS file to the correct location on your machine.


MCAFEE SITE ADVISOR SITE ADVISOR is a free IE plug-in (also suport for Firefox browser)
which is used in conjunction with the Google search engine. It advises which web sites are considered safe and which sites could pose a problem. It also
shows what problems were encountered with each site.


ANTI-VIRUS AND FIREWALL PROGRAMS


ANTIVIRUS SOFTWARE It is very important that you have anti-virus software running on your machine.
This alone can save you a lot of trouble with malware in the future.
See this link for a listing of some online antivirus scanners: Anti-Spyware Tutorial

Here are some very good free Antivirus products which are available:



If you do not have a firewall, here are 4 free ones available for personal use:

Understanding and Using Firewalls


INFORMATIONAL READING


In light of your recent troubles, I'm sure you'll like to avoid any future infections. Please take a look at these well written articles:



Please respond one more time and let me know you received this post so it can be marked resolved
fredmh is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 08:07 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85