Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 03-24-2008, 07:18 PM   #1 (permalink)
Registered User
 
Join Date: Feb 2005
Posts: 18
OS: win 2000


ucleaner

internet explorer goes to the ucleaner website, and system running very slow
your assistance will be most appreciated
attached is a dss log file

Deckard's System Scanner v20071014.68
Run by mstratman on 2008-03-25 11:34:13
Computer is in Normal Mode.
--------------------------------------------------------------------------------

Backed up registry hives.
Performed disk cleanup.



-- HijackThis (run as mstratman.exe) -------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:35:03 AM, on 25/03/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINNT\TEMP\BW1B03.EXE
C:\Documents and Settings\All Users\Application Data\yfmrqhsn\qrivizyb.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\WINNT\system32\igfxtray.exe
C:\WINNT\system32\hkcmd.exe
C:\Program Files\antiviirus.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\tmp0.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\tmp1.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINNT\system32\yvgnufaf.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\tmp2.exe
C:\Program Files\tmp3.exe
C:\Program Files\Microsoft ActiveSync\WCESMgr.exe
C:\Program Files\dss.exe
C:\WINNT\explorer.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\mstratman.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php...MjI6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.microsoft.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: GNX Bingo - {B2DCA34E-9D1C-4EDA-A1BE-C24D1B4AAE55} - C:\WINNT\kdftlboepta.dll
O3 - Toolbar: qvdntlmw - {8BD58549-BB16-480E-8530-3F957AE09B51} - C:\DOCUME~1\MSTRAT~1.RMG\LOCALS~1\Temp\ac8zt2\qvdntlmw.dll (file missing)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [antiviirus] C:\Program Files\antiviirus.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [pqpohocu] C:\WINNT\system32\yvgnufaf.exe
O4 - HKLM\..\Policies\Explorer\Run: [uJLNy1DPOi] C:\Documents and Settings\All Users\Application Data\yfmrqhsn\qrivizyb.exe
O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Basic) - http://www.boral.com.au/OutdoorDesignGuide/ScriptX.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {A1B8A30B-8AAA-4A3E-8869-1DA509E8A011} (Crystal ActiveX Report Viewer Control 10.0) - http://www.cit.org.au/crystalreportv...iveXViewer.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = rmgpl.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = rmgpl.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = rmgpl.local
O21 - SSODL: DrvDrive - {e56e9ea8-ae04-4f5d-b581-d8b783fc0a16} - C:\WINNT\Installer\{e56e9ea8-ae04-4f5d-b581-d8b783fc0a16}\DrvDrive.dll
O21 - SSODL: zip - {dd76a9ab-b5d8-4f1d-94d6-20829530a33a} - C:\WINNT\Installer\{dd76a9ab-b5d8-4f1d-94d6-20829530a33a}\zip.dll
O21 - SSODL: vbgtorfd - {3153A3B8-DF57-45DC-9A23-E0D23DC05913} - C:\WINNT\vbgtorfd.dll
O21 - SSODL: dwnrpofk - {3F795C44-FCF6-4E4C-82F9-3D6D3257C006} - C:\WINNT\dwnrpofk.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Trend Micro Client/Server Security Agent RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINNT\privacy_danger\index.htm

--
End of file - 6729 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R2 TM_CFW (Common Firewall Driver) - c:\program files\trend micro\officescan client\tm_cfw.sys <Not Verified; Trend Micro Inc.; Trend Micro Common Firewall Module 1.2>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 OfcPfwSvc (Trend Micro Client/Server Security Agent Personal Firewall) - c:\program files\trend micro\officescan client\ofcpfwsvc.exe <Not Verified; Trend Micro Inc.; Trend Micro Client/Server/Messaging Security for SMB>

S4 %AF夶À¨ (Network Security Service (NSS)) - c:\winnt\system32\apiug.exe /s (file missing)


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Files created between 2008-02-25 and 2008-03-25 -----------------------------

2008-03-25 11:32:50 686630 --a------ C:\Program Files\dss.exe
2008-03-24 18:25:51 16384 --a------ C:\WINNT\system32\Perflib_Perfdata_b08.dat
2008-03-24 18:25:46 0 d-------- C:\DrWatson
2008-03-24 17:04:05 0 d-------- C:\WINNT\privacy_danger
2008-03-24 11:40:52 0 d-------- C:\Documents and Settings\All Users\Application Data\yfmrqhsn
2008-03-24 11:40:49 114688 --a------ C:\WINNT\system32\yvgnufaf.exe
2008-03-24 11:39:56 270336 --a------ C:\WINNT\vbgtorfd.dll
2008-03-24 11:39:56 184320 --a------ C:\WINNT\qvdntlmw.dll
2008-03-24 11:39:56 94208 --a------ C:\WINNT\norlatmx.exe
2008-03-24 11:39:56 249856 --a------ C:\WINNT\kdftlboepta.dll
2008-03-24 11:39:56 249856 --a------ C:\WINNT\dwnrpofk.dll
2008-03-24 11:39:45 16444 -r-hs---- C:\Program Files\tmp3.exe
2008-03-24 11:39:40 16444 -r-hs---- C:\Program Files\tmp2.exe
2008-03-24 11:39:35 16444 -r-hs---- C:\Program Files\tmp1.exe
2008-03-24 11:39:30 16444 -r-hs---- C:\Program Files\tmp0.exe
2008-03-24 11:39:29 21568 --a------ C:\Program Files\antiviirus.exe <ANTIVI~1.EXE>


-- Find3M Report ---------------------------------------------------------------

2008-02-29 12:12:48 106 --a------ C:\WINNT\!MemIni
2008-01-10 08:32:54 1285922 ---h----- C:\WINNT\ShellIconCache


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B2DCA34E-9D1C-4EDA-A1BE-C24D1B4AAE55}]
24/03/08 10:41a 249856 --a------ C:\WINNT\kdftlboepta.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [19/06/03 12:05p C:\WINNT\system32\mobsync.exe]
"NeroCheck"="C:\WINNT\System32\\NeroCheck.exe" [09/07/01 08:20p]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [02/05/05 09:16a]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [05/07/05 12:58p]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [24/06/05 03:16p]
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [29/03/07 09:10a]
"IgfxTray"="C:\WINNT\system32\igfxtray.exe" [21/06/05 04:48p]
"HotKeysCmds"="C:\WINNT\system32\hkcmd.exe" [21/06/05 04:44p]
"antiviirus"="C:\Program Files\antiviirus.exe" [24/03/08 11:39a]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="ctfmon.exe" [20/02/01 01:09p C:\WINNT\system32\CTFMON.EXE]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [30/03/06 04:45p]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [15/11/05 07:44p]
"pqpohocu"="C:\WINNT\system32\yvgnufaf.exe" [24/03/08 11:40a]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"internat.exe"=internat.exe

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [16/07/2002 5:25:05 PM]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [23/09/2005 10:05:26 PM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
"uJLNy1DPOi"=C:\Documents and Settings\All Users\Application Data\yfmrqhsn\qrivizyb.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisablePersonalDirChange"=1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINNT\privacy_danger\index.htm
FriendlyName= Privacy Protection

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"DrvDrive"= {e56e9ea8-ae04-4f5d-b581-d8b783fc0a16} - C:\WINNT\Installer\{e56e9ea8-ae04-4f5d-b581-d8b783fc0a16}\DrvDrive.dll [24/03/08 11:39a 14378]
"zip"= {dd76a9ab-b5d8-4f1d-94d6-20829530a33a} - C:\WINNT\Installer\{dd76a9ab-b5d8-4f1d-94d6-20829530a33a}\zip.dll [24/03/08 11:39a 23202]
"vbgtorfd"= {3153A3B8-DF57-45DC-9A23-E0D23DC05913} - C:\WINNT\vbgtorfd.dll [24/03/08 10:41a 270336]
"dwnrpofk"= {3F795C44-FCF6-4E4C-82F9-3D6D3257C006} - C:\WINNT\dwnrpofk.dll [24/03/08 10:41a 249856]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ActiveSync]
WcesWlgn.dll 15/11/05 07:44p 7168 C:\WINNT\system32\WcesWlgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"




-- End of Deckard's System Scanner: finished at 2008-03-25 11:35:39 ------------

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows 2000 Professional (build 2195) SP 4.0
Architecture: X86; Language: English

CPU 0: Intel(R) Pentium(R) 4 CPU 1.70GHz
Percentage of Memory in Use: 69%
Physical Memory (total/avail): 509.8 MiB / 155.43 MiB
Pagefile Memory (total/avail): 1244.45 MiB / 895.82 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1956.36 MiB

A: is Removable (No Media)
C: is Fixed (FAT32) - 37.26 GiB total, 8.63 GiB free.
D: is CDROM (No Media)
E: is Removable (FAT)
G: is Network (NTFS)
H: is Network (NTFS)
I: is Network (NTFS)
J: is Network (NTFS)
S: is Network (NTFS)
V: is Network (NTFS)

\\.\PHYSICALDRIVE0 - ST340014A - 37.27 GiB - 1 partition
\PARTITION0 (bootable) - Unknown - 37.27 GiB - C:

\\.\PHYSICALDRIVE1 - SanDisk USB Flash Drive USB Device - 1898.31 MiB - 1 partition
\PARTITION0 (bootable) - Win95 w/Extended Int 13 - 1905.99 MiB - E:



-- Security Center -------------------------------------------------------------

AUOptions is set to notify before install.


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\mstratman.RMGPL\Application Data
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=WORKSTATION1
ComSpec=C:\WINNT\system32\cmd.exe
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\mstratman.RMGPL
LOGONSERVER=\\SERVER
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Os2LibPath=C:\WINNT\system32\os2\dll;
Path=C:\WINNT\system32;C:\WINNT;C:\WINNT\System32\Wbem;C:\PROGRA~1\MICROS~2\Office
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 1 Stepping 2, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0102
ProgramFiles=C:\Program Files
PROMPT=$P$G
SystemDrive=C:
SystemRoot=C:\WINNT
TEMP=C:\DOCUME~1\MSTRAT~1.RMG\LOCALS~1\Temp
TMP=C:\DOCUME~1\MSTRAT~1.RMG\LOCALS~1\Temp
USERDNSDOMAIN=rmgpl.local
USERDOMAIN=RMGPL
USERNAME=mstratman
USERPROFILE=C:\Documents and Settings\mstratman.RMGPL
windir=C:\WINNT


-- User Profiles ---------------------------------------------------------------

Administrator.APG (admin)
PJRYAN
mstratman (admin)
lmcmanus (new local, net ready)
mstratman.RMGPL (admin)
pjryan.RMGPL
sgoyne (admin)
fax.RMGPL
CorporateDiary (admin)
kmarcato
admin
realagribusiness
rzessig (new local, net ready)
awatson (new local, net ready)
administrator.RMGPL (admin)
mstratman.WORKSTATION1 (admin)
Administrator (admin)
mstratman.APG (admin)
EOvermaat
pjryan.APG
Jarrod Ryan
Rosemary Saunders
corporate diary
Mal Parker (admin)
TBrown
Michael Bryant (new local, net ready)
Travel Diary (admin)
Michael Dillon (new local, net ready)
clive wilson (new local, admin, net ready)
Shanene Romano
Megan Dempsey (new local, net ready)
Ken Daly (new local, net ready)
fax
administrator.APG.000 (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> C:\Program Files\Installshield Installation Information\{1002F324-18D1-4A79-95C8-84EA3E940287}\QBReplace.exe {1002F324-18D1-4A79-95C8-84EA3E940287}#{BB9C4072-0110-4192-A351-6DCEF8B67AFD}
ACD FotoSlate --> C:\PROGRA~1\ACDSYS~1\FOTOSL~1\UNWISE.EXE C:\PROGRA~1\ACDSYS~1\FOTOSL~1\INSTALL.LOG
Ad-Aware SE Personal --> C:\PROGRA~1\LAVASOFT\AD-AWA~2\UNWISE.EXE C:\PROGRA~1\LAVASOFT\AD-AWA~2\INSTALL.LOG
Ad-Aware SE Personal --> MsiExec.exe /X{78CC3BAB-DE2A-4FB4-8FBB-E4DADDC26747}
Adobe Acrobat 5.0 --> C:\WINNT\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll"
Adobe Download Manager 1.2 (Remove Only) --> "C:\Program Files\Common Files\Adobe\ESD\uninst.exe"
Adobe Flash Player 9 ActiveX --> C:\WINNT\system32\Macromed\Flash\FlashUtil9c.exe -uninstallUnlock
Adobe Reader 7.0.9 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}
Avanquest update --> C:\Program Files\InstallShield Installation Information\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}\Setup.exe -runfromtemp -l0x0009 -removeonly
BurnInTest --> C:\WINNT\IsUninst.exe -f"C:\Program Files\PassMark\BurnInTest\Uninst.isu"
CleanUp! --> C:\Program Files\CleanUp!\uninstall.exe
DirectX 8.1 Hotfix - KB839643 --> C:\WINNT\$NtUninstallKB839643-DirectX81$\spuninst\spuninst.exe
Express Burn --> C:\Program Files\NCH Swift Sound\ExpressBurn\uninst.exe
getPlus(R)_ocx --> rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\inf\GETPLUSo.INF, DefaultUninstall
Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Icon Converter Plus --> C:\WINNT\Icon Converter Plus Uninstaller.exe
Intel(R) Extreme Graphics Driver --> RUNDLL32.EXE C:\WINNT\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2562
Intel(R) PRO Ethernet Adapter and Software --> Prounstl.exe
Internet Explorer Q903235 --> C:\WINNT\ieuninst.exe C:\WINNT\INF\Q903235.inf
iriver plus 3 (remove only) --> "C:\Program Files\iriver\iriver plus 3\uninstall.exe"
iTunes --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{47808F78-F178-49DC-B708-15FE538B16FF}
Macromedia Shockwave Player --> C:\WINNT\system32\MACROMED\SHOCKW~1\UNWISE.EXE C:\WINNT\system32\MACROMED\SHOCKW~1\Install.log
Microsoft ActiveSync 4.0 --> MsiExec.exe /I{B208806F-A231-4FA0-AB3F-5C1B8979223E}
Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{91110409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Project Professional 2003 --> MsiExec.exe /I{913B0409-6000-11D3-8CFE-0150048383C9}
Microsoft XML Parser and SDK --> MsiExec.exe /I{3E908702-AF35-4611-9518-955DA24B7E07}
Motorola Phone Tools --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BAD8CA9C-77C0-4663-B00B-A8D3B13C341B}\setup.exe" -l0x9 -removeonly
MSXML 4.0 SP2 (KB927978) --> MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181) --> MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MYOB Accounting Plus v12 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{21057832-D865-4049-BCA4-CEF3C55A394F}
MYOB Accounting Plus v13 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{BCC46C36-9460-409C-BF33-589445B0A0F1}
MYOB Accounting Plus v13.5 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{5F73DF33-F605-4EE7-8035-A5A69E8EAAE7}
MYOB Accounting Plus v14 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{C0C2A5D4-34E9-45EA-B529-D640E384B612}
MYOB ODBC Direct v7 --> C:\Program Files\InstallShield Installation Information\{C71F2873-3229-4A9E-A2A2-F14DCBF63F56}\setup.exe -runfromtemp -l0x0409
MYOB Premier v10 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{DEC02295-F5D5-4371-ABB0-9818C45DDDBF}
MYOB Premier v11 --> C:\Program Files\InstallShield Installation Information\{56A27C76-F24A-49BD-BA67-A969ABF954B4}\setup.exe -runfromtemp -l0x0409
MYOB Premier v8 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{3F5CFC8C-2F9C-4D50-9F81-EB96D2790448}
MYOB Premier v9 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{61D794E5-8899-461D-A4CA-8F91CD0FBADC}
Nero - Burning Rom --> MsiExec.exe /X{A4D7B764-4140-11D4-88EB-0050DA3579C0}
QuickBooks Premier: Multi User Accounting 2005/06 --> C:\Program Files\Installshield Installation Information\{442E5924-1BB6-4EAA-893D-62291D87219A}\QBReplace.exe {442E5924-1BB6-4EAA-893D-62291D87219A}#{BA0FD89C-32B4-4D4E-A024-D2B071C84749}
QuickLine Version 5.0 SR-2 --> C:\QUICKL~1\UNWISE.EXE C:\QUICKL~1\INSTALL.LOG
QuickTime --> C:\WINNT\unvise32qt.exe C:\WINNT\system32\QuickTime\Uninstall.log
RALPH-Chambers Screen Saver --> C:\WINNT\system32\RALPH-Chambers.scr /u
RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Security Update for DirectX 8 (KB941568) --> "C:\WINNT\$NtUninstallKB941568_DX8$\spuninst\spuninst.exe"
Security Update for Windows 2000 (KB904706) --> "C:\WINNT\$NtUninstallKB904706$\spuninst\spuninst.exe"
Security Update for Windows 2000 (KB923689) --> "C:\WINNT\$NtUninstallKB923689$\spuninst\spuninst.exe"
Security Update for Windows 2000 (KB941569) --> "C:\WINNT\$NtUninstallKB941569$\spuninst\spuninst.exe"
SigmaTel AC97 Audio Drivers --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7959721D-8268-4565-9E0E-C41A9F4848A9}\setup.exe" -nodialog -uninstall
Spybot - Search & Destroy 1.3 --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
SpywareBlaster v3.5.1 --> "C:\Program Files\SpywareBlaster\unins000.exe"
SpywareGuard v2.2 --> "C:\Program Files\SpywareGuard\unins000.exe"
TNA 5 Service Release --> C:\Program Files\TNA5\Uninst_TNA 5 Service Release.exe /U "C:\Program Files\TNA5\Uninst_TNA 5 Service Release.log"
Trend Micro Client/Server Security Agent --> "C:\Program Files\Trend Micro\OfficeScan Client\ntrmv.exe"
Viewpoint Media Player (Remove Only) --> C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe -u
VX2 Cleaner plug-in for Ad-Aware SE --> C:\PROGRA~1\LAVASOFT\AD-AWA~2\PLUGINS\VX2CLE~1\UNWISE.EXE C:\PROGRA~1\LAVASOFT\AD-AWA~2\PLUGINS\VX2CLE~1\INSTALL.LOG
WebVideo Support --> C:\WINNT\norlatmx.exe
Window Active --> C:\Program Files\Window Active\winactive.exe -uninstall
Windows 2000 Service Pack 4 --> C:\WINNT\$NtServicePackUninstall$\spuninst\spuninst.exe
Windows Media Player system update (9 Series) --> C:\PROGRA~1\WINDOW~2\setup_wm.exe /Uninstall
WinZip --> "C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
Yahoo! Toolbar --> C:\PROGRA~1\YAHOO!\COMMON\unyt.exe


-- Application Event Log -------------------------------------------------------

Event Record #/Type6759 / Error
Event Submitted/Written: 03/24/2008 00:25:04 PM
Event ID/Source: 1000 / Userenv
Event Description:
Windows cannot unload your registry file. If you have a roaming profile, your settings are not replicated. Contact your administrator.

DETAIL - Access is denied. , Build number ((2195)).

Event Record #/Type6748 / Error
Event Submitted/Written: 03/17/2008 07:12:55 PM
Event ID/Source: 1000 / Userenv
Event Description:
Windows cannot unload your registry file. If you have a roaming profile, your settings are not replicated. Contact your administrator.

DETAIL - Access is denied. , Build number ((2195)).

Event Record #/Type6746 / Error
Event Submitted/Written: 03/17/2008 11:35:54 AM
Event ID/Source: 1000 / Userenv
Event Description:
Windows cannot unload your registry file. If you have a roaming profile, your settings are not replicated. Contact your administrator.

DETAIL - Access is denied. , Build number ((2195)).

Event Record #/Type6742 / Error
Event Submitted/Written: 03/14/2008 05:11:04 PM
Event ID/Source: 1000 / Userenv
Event Description:
Windows cannot unload your registry file. If you have a roaming profile, your settings are not replicated. Contact your administrator.

DETAIL - Access is denied. , Build number ((2195)).

Event Record #/Type6737 / Error
Event Submitted/Written: 03/11/2008 07:17:17 PM
Event ID/Source: 1000 / Userenv
Event Description:
Windows cannot unload your registry file. If you have a roaming profile, your settings are not replicated. Contact your administrator.

DETAIL - Access is denied. , Build number ((2195)).



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type13582 / Error
Event Submitted/Written: 03/25/2008 11:30:20 AM
Event ID/Source: 2504 / Server
Event Description:
The server could not bind to the transport \Device\NetBT_Tcpip_{A6EBB69A-36F7-4E5B-9CB6-17D5344D1944}.

Event Record #/Type13581 / Error
Event Submitted/Written: 03/25/2008 11:30:20 AM
Event ID/Source: 2000 / Srv
Event Description:
The server's call to a system service failed unexpectedly.

Event Record #/Type13580 / Error
Event Submitted/Written: 03/25/2008 11:30:20 AM
Event ID/Source: 2000 / Srv
Event Description:
The server's call to a system service failed unexpectedly.

Event Record #/Type13577 / Error
Event Submitted/Written: 03/25/2008 11:29:47 AM
Event ID/Source: 7024 / Service Control Manager
Event Description:
The Computer Browser service terminated with service-specific error 2250.

Event Record #/Type13533 / Error
Event Submitted/Written: 03/25/2008 07:49:22 AM
Event ID/Source: 2504 / Server
Event Description:
The server could not bind to the transport \Device\NetBT_Tcpip_{A6EBB69A-36F7-4E5B-9CB6-17D5344D1944}.



-- End of Deckard's System Scanner: finished at 2008-03-25 11:35:39 ------------
Moggie is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 03-28-2008, 06:49 PM   #2 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,723
OS: 2000 Pro; XP Pro; XP Home


Re: ucleaner

Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingcomputer.com/comb...o-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery mode. This allows us to help you in the case that your computer has a problem after an attempted removal of malware.

Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.

If you have any questions along the way, STOP and ask them before proceeding.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-31-2008, 04:10 PM   #3 (permalink)
Registered User
 
Join Date: Feb 2005
Posts: 18
OS: win 2000


Re: ucleaner

is the recovery console available for 2000 or only xp
Moggie is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-31-2008, 04:45 PM   #4 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,723
OS: 2000 Pro; XP Pro; XP Home


Re: ucleaner

Windows 2000 users typically have an installation CD.

Install the Windows Recovery Console After Windows is Already Installed on the Computer
1. Click Start, click Run, and then type <CD-ROM drive letter>:\i386\winnt32.exe /cmdcons in the Open box, where <CD-ROM drive letter> is the drive letter assigned to your CD-ROM drive.
2. Click OK, follow the instructions on the screen to finish Setup, and then restart your computer.

If you do not have an installation CD, there is no similar download package for Windows 2000 as there is for XP.

http://support.microsoft.com/kb/216417
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-31-2008, 07:32 PM   #5 (permalink)
Registered User
 
Join Date: Feb 2005
Posts: 18
OS: win 2000


Re: ucleaner

New HJT log file below. attached the combofix file

ComboFix 08-03-24.1 - mstratman 2008-04-01 11:44:58.2 - FAT32x86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.345 [GMT 9.5:30]
Running from: C:\Documents and Settings\mstratman.RMGPL\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\mstratman.RMGPL\Desktop\Privacy Protector.url
C:\WINNT\dwnrpofk.dll

.
((((((((((((((((((((((((( Files Created from 2008-03-01 to 2008-04-01 )))))))))))))))))))))))))))))))
.

2008-04-01 11:45 . 08-04-01 11:45 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_30c.dat
2008-04-01 07:39 . 08-04-01 07:39 16,384 --a------ C:\WINNT\system32\Perflib_Perfdata_320.dat
2008-03-31 12:00 . 08-03-31 12:00 94,208 --a------ C:\WINNT\system32\betkdotc.exe
2008-03-30 09:55 . 08-03-30 09:55 <DIR> d-------- C:\WINNT\Favorites
2008-03-25 11:35 . 08-03-25 11:35 16,384 --a------ C:\WINNT\system32\Perflib_Perfdata_32c.dat
2008-03-25 11:33 . 08-03-25 11:33 <DIR> d-------- C:\Deckard
2008-03-25 11:32 . 08-03-25 10:02 686,630 --a------ C:\Program Files\dss.exe
2008-03-25 07:45 . 08-03-25 07:45 0 --a------ C:\si0.1k
2008-03-24 18:25 . 08-03-24 18:25 <DIR> d-------- C:\DrWatson
2008-03-24 18:25 . 08-03-24 18:25 16,384 --a------ C:\WINNT\system32\Perflib_Perfdata_b08.dat
2008-03-24 11:40 . 08-03-24 11:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\yfmrqhsn
2008-03-24 11:39 . 08-03-24 10:41 270,336 --a------ C:\WINNT\vbgtorfd.dll
2008-03-24 11:39 . 08-03-24 10:41 249,856 --a------ C:\WINNT\kdftlboepta.dll
2008-03-24 11:39 . 08-03-24 10:41 94,208 --a------ C:\WINNT\norlatmx.exe
2008-03-17 18:13 . 08-03-24 11:42 54,156 --ah----- C:\WINNT\QTFont.qfn
2008-03-17 18:13 . 08-03-17 18:13 1,409 --a------ C:\WINNT\QTFont.for

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-06 00:18 25,755,448 ----a-w C:\wmp11-windowsxp-x86-enu.exe
2007-01-12 06:52 92,064 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmmdm.sys
2007-01-12 06:52 9,232 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmmdfl.sys
2007-01-12 06:52 79,328 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmserd.sys
2007-01-12 06:52 66,656 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmbus.sys
2007-01-12 06:52 6,208 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmcmnt.sys
2007-01-12 06:52 5,936 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmwhnt.sys
2007-01-12 06:52 4,048 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmcr.sys
2007-01-12 06:52 25,600 ----a-w C:\Documents and Settings\mstratman.RMGPL\usbsermptxp.sys
2007-01-12 06:52 22,768 ----a-w C:\Documents and Settings\mstratman.RMGPL\usbsermpt.sys
2006-06-13 08:29 1,023,486 ----a-w C:\Documents and Settings\mstratman.RMGPL\speakers.zip
2005-05-01 23:44 21,848,504 ----a-w C:\Program Files\iTunesSetup.exe
2002-06-19 05:00 271 ---h--w C:\Program Files\desktop.ini
2002-06-19 05:00 21,952 ---h--w C:\Program Files\folder.htt
2001-05-08 13:30 32,528 ----a-w C:\WINNT\inf\wbfirdma.sys
2004-10-25 03:30 56 --sh--r C:\WINNT\system32\C2095087DE.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B2DCA34E-9D1C-4EDA-A1BE-C24D1B4AAE55}]
08-03-24 10:41 249856 --a------ C:\WINNT\kdftlboepta.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="ctfmon.exe" [01-02-20 13:09 8192 C:\WINNT\system32\CTFMON.EXE]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [06-03-30 16:45 313472]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [05-11-15 19:44 1200128]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [08-01-28 11:43 2097488]
"pqpohocu"="C:\WINNT\system32\yvgnufaf.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [03-06-19 12:05 111376 C:\WINNT\system32\mobsync.exe]
"NeroCheck"="C:\WINNT\System32\\NeroCheck.exe" [01-07-09 20:20 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [05-05-02 09:16 98304]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [05-07-05 12:58 180269]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [05-06-24 15:16 278528]
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [07-03-29 09:10 394952]
"IgfxTray"="C:\WINNT\system32\igfxtray.exe" [05-06-21 16:48 155648]
"HotKeysCmds"="C:\WINNT\system32\hkcmd.exe" [05-06-21 16:44 126976]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [01-05-08 23:00 20752 C:\WINNT\system32\internat.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [03-06-19 12:05 186640]

C:\Documents and Settings\mstratman.APG\Start Menu\Programs\Startup\
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 19:05:35 360448]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2002-07-16 17:25:05 106560]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"uJLNy1DPOi"= C:\Documents and Settings\All Users\Application Data\yfmrqhsn\qrivizyb.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisablePersonalDirChange"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINNT\privacy_danger\index.htm
FriendlyName= Privacy Protection

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"DrvDrive"= {e56e9ea8-ae04-4f5d-b581-d8b783fc0a16} - C:\WINNT\Installer\{e56e9ea8-ae04-4f5d-b581-d8b783fc0a16}\DrvDrive.dll [08-03-24 11:39 14378]
"zip"= {dd76a9ab-b5d8-4f1d-94d6-20829530a33a} - C:\WINNT\Installer\{dd76a9ab-b5d8-4f1d-94d6-20829530a33a}\zip.dll [08-03-24 11:39 23202]
"vbgtorfd"= {3153A3B8-DF57-45DC-9A23-E0D23DC05913} - C:\WINNT\vbgtorfd.dll [08-03-24 10:41 270336]
"dwnrpofk"= {3F795C44-FCF6-4E4C-82F9-3D6D3257C006} - C:\WINNT\dwnrpofk.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ActiveSync]
WcesWlgn.dll 05-11-15 19:44 7168 C:\WINNT\system32\WcesWlgn.dll

R3 usb_rndisy;USB RNDIS Adapter;C:\WINNT\system32\DRIVERS\usb8023y.sys [05-10-25 09:02 ]
R3 usbhub20;USB Hub Support;C:\WINNT\system32\DRIVERS\usbhub20.sys [03-06-19 12:05 ]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-01 11:47:33
Windows 5.0.2195 Service Pack 4 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-04-01 11:48:13
ComboFix-quarantined-files.txt 2008-04-01 02:18:12
.
2008-02-04 23:53:48 --- E O F ---


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:56, on 2008-04-01
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Documents and Settings\All Users\Application Data\yfmrqhsn\qrivizyb.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINNT\system32\igfxtray.exe
C:\WINNT\system32\hkcmd.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Microsoft ActiveSync\WCESMgr.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntupd.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINNT\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php...MjI6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: GNX Bingo - {B2DCA34E-9D1C-4EDA-A1BE-C24D1B4AAE55} - C:\WINNT\kdftlboepta.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [pqpohocu] C:\WINNT\system32\yvgnufaf.exe
O4 - HKLM\..\Policies\Explorer\Run: [uJLNy1DPOi] C:\Documents and Settings\All Users\Application Data\yfmrqhsn\qrivizyb.exe
O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Basic) - http://www.boral.com.au/OutdoorDesignGuide/ScriptX.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {A1B8A30B-8AAA-4A3E-8869-1DA509E8A011} (Crystal ActiveX Report Viewer Control 10.0) - http://www.cit.org.au/crystalreportv...iveXViewer.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = rmgpl.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = rmgpl.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = rmgpl.local
O21 - SSODL: DrvDrive - {e56e9ea8-ae04-4f5d-b581-d8b783fc0a16} - C:\WINNT\Installer\{e56e9ea8-ae04-4f5d-b581-d8b783fc0a16}\DrvDrive.dll
O21 - SSODL: zip - {dd76a9ab-b5d8-4f1d-94d6-20829530a33a} - C:\WINNT\Installer\{dd76a9ab-b5d8-4f1d-94d6-20829530a33a}\zip.dll
O21 - SSODL: vbgtorfd - {3153A3B8-DF57-45DC-9A23-E0D23DC05913} - C:\WINNT\vbgtorfd.dll
O21 - SSODL: dwnrpofk - {3F795C44-FCF6-4E4C-82F9-3D6D3257C006} - C:\WINNT\dwnrpofk.dll (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Trend Micro Client/Server Security Agent RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINNT\privacy_danger\index.htm

--
End of file - 6758 bytes
Attached Files
File Type: txt ComboFix.txt (7.6 KB, 1 views)

Last edited by tetonbob; 03-31-2008 at 07:35 PM.
Moggie is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-31-2008, 07:45 PM   #6 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,723
OS: 2000 Pro; XP Pro; XP Home


Re: ucleaner

S& D Spybot's Tea Timer

While TeaTimer is an excellent tool for the prevention of spyware, it can sometimes prevent our tools from fixing certain things.
Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your HijackThis log is clean.
  • Open Spybot Search & Destroy.
  • In the Mode menu click "Advanced mode" if not already selected.
  • Choose "Yes" at the Warning prompt.
  • Expand the "Tools" menu.
  • Click "Resident".
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • In the File menu click "Exit" to exit Spybot Search & Destroy.
  • See this link for a tutorial

Download ResetTeaTimer.bat by right-clicking on the link, and choosing Save As. Save it to your desktop, or somewhere you can find it easily.
Double click ResetTeaTimer.bat to remove all entries set by TeaTimer.

Spywareguard

Please disable Spywareguard, as it may hinder the removal of some entries. You can re-enable it after you're clean.
  • Right click the running icon of Spywareguard located in the system tray
  • Go to Menu > File > Exit and confirm the programs close.



Open notepad and copy/paste the text in the quotebox below into it:

Quote:
http://www.techsupportforum.com/security-center/hijackthis-log-help/233473-ucleaner.html#post1405008

File::
C:\si0.1k

Folder::
C:\WINNT\Installer\{e56e9ea8-ae04-4f5d-b581-d8b783fc0a16}
C:\WINNT\Installer\{dd76a9ab-b5d8-4f1d-94d6-20829530a33a}

DirLook::
C:\Documents and Settings\All Users\Application Data\yfmrqhsn

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B2DCA34E-9D1C-4EDA-A1BE-C24D1B4AAE55}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"pqpohocu"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"uJLNy1DPOi"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"DrvDrive"=-
"zip"=-
"vbgtorfd"=-
"dwnrpofk"=-

Collect::
C:\WINNT\system32\betkdotc.exe
C:\WINNT\vbgtorfd.dll
C:\WINNT\kdftlboepta.dll
C:\WINNT\norlatmx.exe
C:\Documents and Settings\All Users\Application Data\yfmrqhsn\qrivizyb.exe

Save this as CFScript.txt




Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you, C:\ComboFix.txt. Post that log in your next reply.

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall


When CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture a file to submit for analysis.

Ensure you are connected to the internet and click OK. A browser will open. Simply follow the instructions to copy/paste/send the requested file.

---------------------------------------------------------------------------------------------

Go to Control Panel click Display>Desktop>Customize Desktop>Web> Now, Uncheck Everything and delete if present:
  • "Security Info"
  • "Warning Message"
  • "Security Desktop"
  • "Warning Homepage"
  • "Desktop Uninstall"
  • "Privacy Danger" or something similar
Also make sure the 'Lock desktop items' box is unticked. Click OK, and then Click Apply, then OK.

---------------------------------------------------------------------------------------------

Open HijackThis and click on 'Do a System Scan and save a Logfile'. Save the log file and post it here.

---------------------------------------------------------------------------------------------
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-31-2008, 10:57 PM   #7 (permalink)
Registered User
 
Join Date: Feb 2005
Posts: 18
OS: win 2000


Re: ucleaner

All seems to have gone through OK
no spybot in the system tray to stop
In the combofix, had an error message of missing file, but clicked OK and it worked OK
Also at the end, it rebooted the computer before it prepared the log

looked in control panel > display>web tab
- only item (other than home page) was privacy protection that I deleted

new HJT log below and combofix log attached

ComboFix 08-03-24.1 - mstratman 2008-04-01 13:58:53.3 - FAT32x86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.215 [GMT 9.5:30]
Running from: C:\Documents and Settings\mstratman.RMGPL\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\mstratman.RMGPL\Desktop\CFScript.txt

FILE ::
C:\si0.1k
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\yfmrqhsn\qrivizyb.exe
C:\si0.1k
C:\WINNT\Installer\{dd76a9ab-b5d8-4f1d-94d6-20829530a33a}
C:\WINNT\Installer\{dd76a9ab-b5d8-4f1d-94d6-20829530a33a}\zip.dll
C:\WINNT\Installer\{e56e9ea8-ae04-4f5d-b581-d8b783fc0a16}
C:\WINNT\Installer\{e56e9ea8-ae04-4f5d-b581-d8b783fc0a16}\DrvDrive.dll
C:\WINNT\kdftlboepta.dll
C:\WINNT\norlatmx.exe
C:\WINNT\system32\betkdotc.exe
C:\WINNT\vbgtorfd.dll

.
((((((((((((((((((((((((( Files Created from 2008-03-01 to 2008-04-01 )))))))))))))))))))))))))))))))
.

2008-04-01 14:09 . 08-04-01 14:09 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_434.dat
2008-04-01 14:04 . 03-06-19 12:05 17,680 --a------ C:\WINNT\system32\CF_init.exe
2008-04-01 13:58 . 08-04-01 13:58 270,336 --a------ C:\WINNT\vbgtorfd.dll.vir
2008-04-01 13:58 . 08-04-01 13:58 249,856 --a------ C:\WINNT\kdftlboepta.dll.vir
2008-04-01 13:58 . 08-04-01 13:58 94,208 --a------ C:\WINNT\system32\betkdotc.exe.vir
2008-04-01 13:58 . 08-04-01 13:58 94,208 --a------ C:\WINNT\norlatmx.exe.vir
2008-03-30 09:55 . 08-03-30 09:55 <DIR> d-------- C:\WINNT\Favorites
2008-03-25 11:33 . 08-03-25 11:33 <DIR> d-------- C:\Deckard
2008-03-25 11:32 . 08-03-25 10:02 686,630 --a------ C:\Program Files\dss.exe
2008-03-24 18:25 . 08-03-24 18:25 <DIR> d-------- C:\DrWatson
2008-03-24 11:40 . 08-03-24 11:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\yfmrqhsn
2008-03-17 18:13 . 08-03-24 11:42 54,156 --ah----- C:\WINNT\QTFont.qfn
2008-03-17 18:13 . 08-03-17 18:13 1,409 --a------ C:\WINNT\QTFont.for

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-06 00:18 25,755,448 ----a-w C:\wmp11-windowsxp-x86-enu.exe
2007-01-12 06:52 92,064 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmmdm.sys
2007-01-12 06:52 9,232 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmmdfl.sys
2007-01-12 06:52 79,328 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmserd.sys
2007-01-12 06:52 66,656 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmbus.sys
2007-01-12 06:52 6,208 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmcmnt.sys
2007-01-12 06:52 5,936 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmwhnt.sys
2007-01-12 06:52 4,048 ----a-w C:\Documents and Settings\mstratman.RMGPL\mqdmcr.sys
2007-01-12 06:52 25,600 ----a-w C:\Documents and Settings\mstratman.RMGPL\usbsermptxp.sys
2007-01-12 06:52 22,768 ----a-w C:\Documents and Settings\mstratman.RMGPL\usbsermpt.sys
2006-06-13 08:29 1,023,486 ----a-w C:\Documents and Settings\mstratman.RMGPL\speakers.zip
2005-05-01 23:44 21,848,504 ----a-w C:\Program Files\iTunesSetup.exe
2002-06-19 05:00 271 ---h--w C:\Program Files\desktop.ini
2002-06-19 05:00 21,952 ---h--w C:\Program Files\folder.htt
2001-05-08 13:30 32,528 ----a-w C:\WINNT\inf\wbfirdma.sys
2004-10-25 03:30 56 --sh--r C:\WINNT\system32\C2095087DE.sys
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

---- Directory of C:\Documents and Settings\All Users\Application Data\yfmrqhsn ----

08-04-01 13:58 43008 --a------ C:\Documents and Settings\All Users\Application Data\yfmrqhsn\qrivizyb.exe.vir
08-03-24 11:40 43008 --a------ C:\Documents and Settings\All Users\Application Data\yfmrqhsn\qrivizyb.exe


((((((((((((((((((((((((((((( snapshot@Tue 2008-04-01_11.47.55.68 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-03-28 23:40:02 214,712 ----a-w C:\WINNT\TEMP\YY219.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="ctfmon.exe" [01-02-20 13:09 8192 C:\WINNT\system32\CTFMON.EXE]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [06-03-30 16:45 313472]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [05-11-15 19:44 1200128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [03-06-19 12:05 111376 C:\WINNT\system32\mobsync.exe]
"NeroCheck"="C:\WINNT\System32\\NeroCheck.exe" [01-07-09 20:20 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [05-05-02 09:16 98304]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [05-07-05 12:58 180269]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [05-06-24 15:16 278528]
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [07-03-29 09:10 394952]
"IgfxTray"="C:\WINNT\system32\igfxtray.exe" [05-06-21 16:48 155648]
"HotKeysCmds"="C:\WINNT\system32\hkcmd.exe" [05-06-21 16:44 126976]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [01-05-08 23:00 20752 C:\WINNT\system32\internat.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [03-06-19 12:05 186640]

C:\Documents and Settings\mstratman.APG\Start Menu\Programs\Startup\
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 19:05:35 360448]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2002-07-16 17:25:05 106560]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisablePersonalDirChange"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINNT\privacy_danger\index.htm
FriendlyName= Privacy Protection

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ActiveSync]
WcesWlgn.dll 05-11-15 19:44 7168 C:\WINNT\system32\WcesWlgn.dll

R3 usbhub20;USB Hub Support;C:\WINNT\system32\DRIVERS\usbhub20.sys [03-06-19 12:05 ]
S3 usb_rndisy;USB RNDIS Adapter;C:\WINNT\system32\DRIVERS\usb8023y.sys [05-10-25 09:02 ]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-01 14:09:15
Windows 5.0.2195 Service Pack 4 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINNT\TEMP\YY219.EXE
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft ActiveSync\WCESMgr.exe
.
**************************************************************************
.
Completion time: 2008-04-01 13:23:07 - machine was rebooted [mstratman]
ComboFix-quarantined-files.txt 2008-04-01 03:51:12
ComboFix2.txt 2008-04-01 02:18:16
.
2008-02-04 23:53:48 --- E O F ---



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:13, on 2008-04-01
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINNT\TEMP\YY219.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\WINNT\system32\igfxtray.exe
C:\WINNT\system32\hkcmd.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft ActiveSync\WCESMgr.exe
C:\WINNT\system32\wuauclt.exe
C:\WINNT\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php...MjI6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Basic) - http://www.boral.com.au/OutdoorDesignGuide/ScriptX.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {A1B8A30B-8AAA-4A3E-8869-1DA509E8A011} (Crystal ActiveX Report Viewer Control 10.0) - http://www.cit.org.au/crystalreportv...iveXViewer.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = rmgpl.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = rmgpl.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = rmgpl.local
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Trend Micro Client/Server Security Agent RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe

--
End of file - 5454 bytes
Attached Files
File Type: txt log.txt (8.0 KB, 1 views)

Last edited by tetonbob; 03-31-2008 at 11:23 PM.
Moggie is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-31-2008, 11:35 PM   #8 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,723
OS: 2000 Pro; XP Pro; XP Home


Re: ucleaner

Please now delete the zip file on your desktop.

Open NOTEPAD.exe and copy/paste the text in the codebox below into it:
Code:
@echo off
if exist "%temp%\log.txt" del "%temp%\log.txt"

for %%g in (

"C:\WINNT\system32\CF_init.exe"
"C:\WINNT\vbgtorfd.dll.vir"
"C:\WINNT\kdftlboepta.dll.vir"
"C:\WINNT\system32\betkdotc.exe.vir"
"C:\WINNT\norlatmx.exe.vir"

) do (
del /a/f %%g >nul 2>&1
if exist %%g echo.%%g>>"%temp%\log.txt"
)

for %%g in (

%systemdrive%\Deckard
"C:\Documents and Settings\All Users\Application Data\yfmrqhsn"
) do (
rd /s/q %%g >nul 2>&1
if exist %%g echo.%%g>>"%temp%\log.txt"
)
if exist "%temp%\log.txt" ( start notepad "%temp%\log.txt"
) else echo.Deleted Successfully !!

pause
del %0
Save this as fix.bat Choose to "Save type as - All Files"
It should look like this:
Double click on fix.bat & allow it to run

Post back to tell me what it says
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-01-2008, 12:12 AM   #9 (permalink)
Registered User
 
Join Date: Feb 2005
Posts: 18
OS: win 2000


Re: ucleaner

message was "deleted successfully"
Moggie is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-01-2008, 12:18 AM   #10 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,723
OS: 2000 Pro; XP Pro; XP Home


Re: ucleaner

Open HijackThis and click on 'Do a System Scan Only'. Check the following entries if they exist (make sure you do not miss any) and click Fix Checked

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php...MjI6Ojg5&lid=2

Close HijackThis now.

---------------------------------------------------------------------------------------------

For a final check.....

Please run this online scan to help look for remnants.

First, Go to Start>Control Panel>Add/Remove Programs and remove Kaspersky online scanner if present prior to downloading the most up-to-date one.

Next, establish an internet connection & perform an online scan using Internet Explorer at Kaspersky Online Scanner

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure to:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan

Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

---------------------------------------------------------------------------------------------

How is the machine behaving?
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-01-2008, 12:57 AM   #11 (permalink)
Registered User
 
Join Date: Feb 2005
Posts: 18
OS: win 2000


Re: ucleaner

download of the files is unusually slow - taken 10 minutes for 2.5 meg so may take an hour or so
have downloaded 500K from another site in 12 sec, so must be kaspersky
Moggie is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-06-2008, 04:17 PM   #12 (permalink)
Registered User
 
Join Date: Feb 2005
Posts: 18
OS: win 2000


Re: ucleaner

results of the kaspersky scan attached
still some residual items
Attached Files
File Type: txt report0704.txt (27.0 KB, 2 views)
Moggie is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-06-2008, 06:14 PM   #13 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,723
OS: 2000 Pro; XP Pro; XP Home


Re: ucleaner

There are some suspicious mails found in your archives....though they've been there a while, new definitions have identified them as exploits.

C:\contacts.pst
/Personal Folders/Inbox/06 Oct 2001 17:26 from Vanessa Lintner:WWW.APGL.COM.AU.rtf
/Personal Folders/Inbox/07 Dec 2001 03:28 from Antony Bolton:Re: PROPOSED FUNCTIONS 2001

C:\outlook backup\mstratman desktop.pst /Personal Folders/Inbox/13 Oct 2002 23:01 from kym willett:Fwd: SICK WORLD RECORDS

/Personal Folders/Inbox/13 Oct 2002 06:32 from Kevin:Fw: School Photo Site

/Personal Folders/Inbox/02 Oct 2002 00:07 from Tiffany Gordon:Read story before opening
/Personal Folders/Sent Items/23 May 2001 08:46 to Ros Doherty:FW: 'Wirreebilla' vineyard proj.rtf
/Personal Folders/Sent Items/30 Apr 2001 05:59 to 'CHUCK (E-mail)'; 'VANESSA HOME (E-mail)':F

C:\outlook backup\backuplaptopall.pst

/Personal Folders/Inbox/13 Oct 2002 23:01 from kym willett:Fwd: SICK WORLD RECORDS

/Personal Folders/Inbox/13 Oct 2002 06:32 from Kevin:Fw: School Photo Site

/Personal Folders/Inbox/02 Oct 2002 00:07 from Tiffany Gordon:Read story before opening



Locate and delete these:

C:\Documents and Settings\mstratman.RMGPL\Desktop\[4]-Submit_Tue 2008-04-01@13.58.zip
C:\Program Files\Trend Micro\HijackThis\backups

Other than that, the other items found by Kaspersky will be addressed by uninstalling ComboFix as instructed below.



Go to -> Run -> copy/paste in the following single line command & click OK

combofix /u



This will uninstall ComboFix. It will also implement some cleanup procedures and reset System Restore points.

Now that your system is clean, to help protect your computer in the future I recommend that you follow these steps and use the following free programs:
  • Microsoft Windows Update - http://www.windowsupdate.com
    Visit regularly. This will ensure your computer always has the latest security updates. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • SpywareBlaster to help prevent spyware from installing in the first place.
    • Install & update SpywareBlaster with the latest definitions.
      After you have updated, click the button - enable protection for all unprotected items

  • MVPS HOST FILE
    The MVPS Hosts file replaces your current HOSTS file with one that will restrict known ad sites form serving you unsolicited advertisements. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is the IP of your local computer.
    • Download Host.zip to your desktop.
    • From your Desktop right-click (hosts.zip) and select:
      Extract All from the menu.
    • Click Next, click Next, select the option:
      "Show Extracted files", click Finish
    • This will open the newly created hosts folder on your Desktop.
    • Double-click on the included mvps.bat file, this will rename the existing HOSTS file to HOSTS.MVP, then it will copy the included updated HOSTS file to the correct location on your machine.
    • Once updated you should see another prompt that the task was completed.
  • ANTIVIRUS SOFTWARE
    It is very important that you have anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperative that you update your antivirus software at least once a week (even more if you wish). If you do not update your antivirus software then it will not be able to catch new malware that may have come out.

    Do not install more than one AntiVirus program because they will conflict with each other.

  • FIREWALL
    Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. A tutorial on Firewalls and a listing of some available ones can be found here

    Do not install more than one firewall program because they will conflict with each other.

Scan here http://secunia.com/software_inspector/ for out of date & vulnerable common applications on your computer

Here are some additional utilities that will further enhance your safety.
  • http://www.trillian.cc ? Trillian or http://www.miranda-im.com ? Miranda-IM - These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)

  • http://www.mozilla.org/products/firefox/ - Firefox - Use this alternate browser. While Internet Explorer is not a bad browser, almost every exploit crafted is targeted to take advantage of an IE weakness.

  • http://java.com/en/index.jsp - Sun's Java - It's much more secure than Microsoft's Java Virtual Machine.

  • http://www.aumha.org/downloads/erunt-setup.exe - ERUNT - A useful freeware utility for users of Windows 2000/XP. It's made up of two parts - ERUNT & NTREGOPT.

    ERUNT will create daily complete backups of your computer's Registry. Whilst System Restore does the same thing, a corrupt registry file may prevent Windows from booting & this effectively renders disables System Restore. With ERUNT, you're able to restore the damaged Registry.

    NTREGOPT works by recreating each registry hive "from scratch", thus removing any slack space that may be left from previously modified or deleted keys. In other words, it compacts the Registry to a small size which allows Windows to load & perform faster.


In light of your recent troubles, I'm sure you'll like to avoid any future infections. Please take a look at these well written articles
If you want to fight back the Malware Writers that have made your life a misery, please take a look here and read what you can do against it.

Please respond to this thread one more time so we can mark this thread as resolved.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-07-2008, 08:25 PM   #14 (permalink)
Registered User
 
Join Date: Feb 2005
Posts: 18
OS: win 2000


Re: ucleaner

where I've got to:
deleted the files
the emails arent currently used so will copy of and clean up later
combofix uninstalled
windows update installed
spyblaster installed

rebooted the computer this morning to continue, and it is running extremely slow again
no popups though
rebooted again just in case and still running very slow

attached a current HJT log in case I missed something
Attached Files
File Type: txt HJT.txt (5.6 KB, 2 views)
Moggie is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-07-2008, 08:27 PM   #15 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,723
OS: 2000 Pro; XP Pro; XP Home


Re: ucleaner

Is this a work machine?
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-08-2008, 01:10 AM   #16 (permalink)
Registered User
 
Join Date: Feb 2005
Posts: 18
OS: win 2000


Re: ucleaner

its a work machine i use at home. has been back in the office for a couple months
Moggie is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-08-2008, 07:46 AM   #17 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,723
OS: 2000 Pro; XP Pro; XP Home


Re: ucleaner

There are nearly three dozen user profiles listed on this machine. Are they all necessary?

We are typically here to support the home user. Is there not an IT dept at the workplace?

It's possible that recent updates to the Trend Micro AntiVirus package are now using more resources than before.

There is less than 512MB memory on this machine; though that is typically enough for Windows 2000, more is better.

There is no more infection showing in the logs. Some machines never recover from infection, and must be formatted and installed clean.

See if the information on this page helps, as far as a slow machine goes.

http://users.telenet.be/bluepatchy/m...wcomputer.html
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 04-08-2008, 01:34 PM   #18 (permalink)
Registered User
 
Join Date: Feb 2005
Posts: 18
OS: win 2000


Re: ucleaner

thanks tetonbob

small operation in an even smaller town
have rerun kaspersky and spybot and both clean
the user profiles are different people who have come and gone over time using the machine

will do a cleanup of the system, check the ram and see how it goes

thanks again for your help
Moggie is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 05:41 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85