• Announcements

    • Budfred

      IE 11 copy/paste problem

      It has come to our attention that people using Internet Explorer 11 (IE 11) are having trouble with copy/paste to the forum. If you encounter this problem, using a different browser like Firefox or Chrome seems to get around the problem. We do not know what the problem is, but it seems to be specific to IE 11 and we are hopeful that Microsoft will eventually fix it.
    • Budfred

      PLEASE READ - Reversing upgrade   02/23/2017

      We have found that this new upgrade is somewhat of a disaster.  We are finding lots of glitches in being able to post and administer the forum.  Additionally, there are new costs associated with the upgrade that we simply cannot afford.  As a result, we have decided to reverse course and go back to the previous version of our software.  Since this will involve restoring it from a backup, we will lose posts that have been added since January 30 or possibly even some before that.    If you started a topic during that time, we urge you to make backups of your posts and you will need to start the topics over again after the change.  You can simply paste the copies of your posts that you created at that point.    If you joined the forum this month, you will need to re-register since your membership will be lost along with the posts.  Since you have a concealed password, we cannot simply restore your membership for you.   We are going to backup as much as we can so that it will reduce inconvenience for our members.  Unfortunately we cannot back everything up since much will be incompatible with the old version of our software.  We apologize for the confusion and regret the need to do this even though it is not viable to continue with this version of the software.   We plan to begin the process tomorrow evening and, if it goes smoothly, we shouldn't be offline for very long.  However, since we have not done this before, we are not sure how smoothly it will go.  We ask your patience as we proceed.   EDIT: I have asked our hosting service to do the restore at 9 PM Central time and it looks like it will go forward at that time.  Please prepare whatever you need to prepare so that we can restore your topics when the forum is stable again.
Sign in to follow this  
Followers 0
MistaCollins

OuterInfo Removal

11 posts in this topic

Looks like I am another victim by OuterInfo. It seems to have installed itself on my computer. Any help would be appreciated.

 

Logfile of Trend Micro HijackThis v2.0.0 (BETA)

Scan saved at 7:00:26 PM, on 6/24/2007

Platform: Windows XP (WinNT 5.01.2600)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\System32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Symantec AntiVirus\DefWatch.exe

C:\WINDOWS\System32\HPZipm12.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Symantec AntiVirus\Rtvscan.exe

C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\PROGRA~1\SYMANT~1\VPTray.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe

C:\Program Files\HP\HP UT\bin\hppusg.exe

C:\Program Files\ATI Multimedia\main\ATIDtct.EXE

C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe

C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

C:\WINDOWS\?ppPatch\r?ndll32.exe

C:\Program Files\AIM6\aim6.exe

C:\WINDOWS\System32\rundll32.exe

C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe

C:\WINDOWS\System32\wuauclt.exe

C:\Program Files\AIM6\aolsoftware.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

C:\Documents and Settings\Administrator\Desktop\HiJackThis_v2.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {26FC9CF8-6B58-493C-9993-BCD2A58C073B} - C:\WINDOWS\System32\vturs.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: (no name) - {95ADC989-2005-4F9F-939F-6AD34EA9C0E3} - C:\Program Files\WindowsUpdate\hoke83122.dll (file missing)

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe

O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [ToolBoxFX] "C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /systrayIcon:on /fl:on /fr:on /appData:on

O4 - HKLM\..\Run: [HPUsageTracking] C:\Program Files\HP\HP UT\bin\hppusg.exe "C:\Program Files\HP\HP UT\"

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKCU\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE

O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [Krztw] C:\WINDOWS\?ppPatch\r?ndll32.exe

O4 - HKCU\..\Run: [WebBuying] C:\Program Files\Web Buying\v1.7.4\webbuying.exe

O4 - HKCU\..\Run: [steam] C:\Program Files\Valve\Steam\\Steam.exe -silent

O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp

O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user')

O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe

O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O16 - DPF: {DD8C9372-35FD-4F7D-8CE4-909ABCFAB2C5} - ms-its:mhtml:file://c:\\nores.mht!http://adxtend.net/code/chm/xpre.chm::/xpreload.ocx

O20 - Winlogon Notify: CLSID - C:\WINDOWS\

O20 - Winlogon Notify: gebxuss - C:\WINDOWS\SYSTEM32\gebxuss.dll

O20 - Winlogon Notify: vturs - C:\WINDOWS\System32\vturs.dll

O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

O24 - Desktop Component 0: (no name) - C:\Program Files\Messenger\profsywuy.html

 

--

End of file - 7689 bytes

Share this post


Link to post
Share on other sites

It also appears as if I am getting pop-ups from something else also because I have other pop-ups that don't have the "by OuterInfo" in the heading.

Share this post


Link to post
Share on other sites

Welcome to SWI. We apologize for the delay; our helpers have been very busy.

If you have not received help after 3 days, please CLICK HERE, and post a link to your log and the date it was originally posted.

 

Thank you for your patience.

 

[this is an automated reply]

Share this post


Link to post
Share on other sites

Hi,

 

Download Dr.Web CureIt to the desktop:

ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

Next, please reboot your computer in Safe Mode by doing the following:

1) Restart your computer

2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.

3) Instead of Windows loading as normal, a menu should appear

4) Select the first option, to run Windows in Safe Mode.

 

For additional help in booting into Safe Mode, see the following site:

http://www.pchell.com/support/safemode.shtml

  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found: check.gif
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    move.gif
    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.

Next:

 

1. Download this file - ComboFix

2. Double click combofix.exe & follow the prompts.

3. When finished, it will produce a log for you. Post that log in your next reply

 

Note:

Do not mouseclick combofix's window whilst it's running. That may cause it to stall

 

jedi

Share this post


Link to post
Share on other sites

Jedi,

 

Thanks for the reply. When trying to boot my computer in Safe Mode, all i get is a black screen with the four corners of my monitor saying "safe mode". Is it a problem to run Dr.Web CureIt outside of safe mode?

 

Mista

Share this post


Link to post
Share on other sites

Hi again,

 

all i get is a black screen with the four corners of my monitor saying "safe mode"

Normally, safe mode will load after that, it sometimes takes a while. If it doesn't, run CureIt in normal mode.

 

jedi

Share this post


Link to post
Share on other sites

Sorry for the long delay. I've been out enjoying my holiday and the nice weather.

 

vturs.dll;c:\windows\system32;Trojan.Virtumod;Will be cured after reboot.;

kvwdvrtx.exe;C:\Documents and Settings\Administrator\Local Settings\Temp;Trojan.EzulaAd;Deleted.;

xpre.exe;C:\Documents and Settings\Administrator\Local Settings\Temp;Trojan.DownLoader.24714;Incurable.Moved.;

xrun.exe;C:\Documents and Settings\Administrator\Local Settings\Temp;Trojan.PWS.Tanspy;Deleted.;

setup.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install\6.1.41.2;Probably BACKDOOR.Trojan;Incurable.Moved.;

A0001645.exe\data001;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP15\A0001645.exe;Adware.BookedSpace;;

A0001645.exe\data002;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP15\A0001645.exe;Adware.BookedSpace;;

data003\data001;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP15\A0001645.exe\data003;Adware.BookedSpace;;

data003\data002;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP15\A0001645.exe\data003;Adware.BookedSpace;;

data003\data003;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP15\A0001645.exe\data003;Adware.BookedSpace;;

data003;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP15\A0001645.exe;Archive contains infected objects;;

A0001645.exe\data004;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP15\A0001645.exe;Adware.BookedSpace;;

A0001645.exe;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP15;Archive contains infected objects;Moved.;

A0001646.dll;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP15;Adware.BookedSpace;Incurable.Moved.;

A0001647.dll;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP15;Adware.BookedSpace;Incurable.Moved.;

A0001648.exe;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP15;Trojan.DownLoader.10588;Deleted.;

A0001650.exe\data001;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP15\A0001650.exe;Adware.Bagon;;

A0001650.exe\data002;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP15\A0001650.exe;Trojan.MulDrop.4522;;

A0001650.exe\data003;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP15\A0001650.exe;Trojan.DownLoader.10588;;

A0001650.exe;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP15;Archive contains infected objects;Moved.;

A0002650.exe;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP17;Trojan.EzulaAd;Deleted.;

A0002651.exe;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP17;Trojan.DownLoader.22753;Deleted.;

A0002766.exe;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP19;Trojan.DownLoader.22753;Deleted.;

A0002877.exe;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP21;Trojan.DownLoader.22753;Deleted.;

A0002950.exe;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP23;Trojan.DownLoader.22753;Deleted.;

A0003058.exe;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP23;Trojan.DownLoader.22753;Deleted.;

A0003059.dll;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP23;Trojan.Virtumod;Deleted.;

A0004058.exe;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP23;Trojan.DownLoader.22753;Deleted.;

A0004092.exe;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP23;Trojan.DownLoader.22753;Deleted.;

A0004093.dll;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP23;Trojan.Virtumod;Deleted.;

A0004105.exe\data001;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP23\A0004105.exe;Adware.BookedSpace;;

A0004105.exe\data002;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP23\A0004105.exe;Adware.BookedSpace;;

data003\data001;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP23\A0004105.exe\data003;Adware.BookedSpace;;

data003\data002;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP23\A0004105.exe\data003;Adware.BookedSpace;;

data003\data001;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP23\A0004105.exe\data003\data003;Adware.BookedSpace;;

data003\data002;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP23\A0004105.exe\data003\data003;Adware.BookedSpace;;

data003\data003;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP23\A0004105.exe\data003\data003;Adware.BookedSpace;;

data003;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP23\A0004105.exe\data003;Archive contains infected objects;;

data003\data004;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP23\A0004105.exe\data003;Adware.BookedSpace;;

data003;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP23\A0004105.exe;Archive contains infected objects;;

A0004105.exe\data004;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP23\A0004105.exe;Adware.BookedSpace;;

A0004105.exe;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP23;Archive contains infected objects;Moved.;

A0005149.exe;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP23;Trojan.DownLoader.22753;Deleted.;

A0014380.exe;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP26;Trojan.Click.2799;Deleted.;

A0014381.exe;C:\System Volume Information\_restore{93EB1FE8-E6BA-4E91-8FD7-915F04A85138}\RP26;Trojan.LowZones.233;Deleted.;

cfg32a.exe\data001;C:\WINDOWS\cfg32a.exe;Adware.BookedSpace;;

cfg32a.exe\data002;C:\WINDOWS\cfg32a.exe;Adware.BookedSpace;;

data003\data001;C:\WINDOWS\cfg32a.exe\data003;Adware.BookedSpace;;

data003\data002;C:\WINDOWS\cfg32a.exe\data003;Adware.BookedSpace;;

data003\data003;C:\WINDOWS\cfg32a.exe\data003;Adware.BookedSpace;;

data003;C:\WINDOWS\cfg32a.exe;Archive contains infected objects;;

cfg32a.exe\data004;C:\WINDOWS\cfg32a.exe;Adware.BookedSpace;;

cfg32a.exe;C:\WINDOWS;Archive contains infected objects;Moved.;

stub_track4.exe;C:\WINDOWS;Trojan.DownLoader.10588;Deleted.;

atevnkpl.exe;C:\WINDOWS\system32;Trojan.EzulaAd;Deleted.;

csqkbdje.exe;C:\WINDOWS\system32;Trojan.EzulaAd;Deleted.;

gnxfrkww.exe;C:\WINDOWS\system32;Trojan.EzulaAd;Deleted.;

ivsnomdq.dll;C:\WINDOWS\system32;Trojan.Juan;Deleted.;

kcibjfqj.exe;C:\WINDOWS\system32;Trojan.EzulaAd;Deleted.;

ndaffits.exe;C:\WINDOWS\system32;Trojan.EzulaAd;Deleted.;

ofwcoiww.exe;C:\WINDOWS\system32;Trojan.EzulaAd;Deleted.;

qwerty12.exe;C:\WINDOWS\system32;Trojan.EzulaAd;Deleted.;

vturs.dll;C:\WINDOWS\system32;Trojan.Virtumod;Will be cured after reboot.;

wen2.exe;C:\WINDOWS\system32\G2;Trojan.MulDrop.6135;Deleted.;

wr620.exe;C:\WINDOWS\system32\G3;Trojan.DownLoader.24721;Deleted.;

 

"Administrator" - 2007-07-11 21:53:37 - ComboFix 07-07-12.3

 

 

(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

C:\WINDOWS\system32\esybgmqv.dll

C:\WINDOWS\system32\kgketxih.dll

C:\WINDOWS\system32\najriwkv.dll

C:\WINDOWS\system32\prbsktoo.dll

C:\WINDOWS\system32\sldoecli.dll

C:\WINDOWS\system32\spvwfied.dll

C:\WINDOWS\system32\srutv.bak1

C:\WINDOWS\system32\srutv.bak2

C:\WINDOWS\system32\srutv.ini

C:\WINDOWS\system32\srutv.ini2

C:\WINDOWS\system32\srutv.tmp

C:\WINDOWS\system32\vqmgbyse.ini

C:\WINDOWS\system32\hixtekgk.ini

C:\WINDOWS\system32\vkwirjan.ini

C:\WINDOWS\system32\ootksbrp.ini

C:\WINDOWS\system32\ilceodls.ini

C:\WINDOWS\system32\deifwvps.ini

C:\WINDOWS\system32\srutv.bak1

C:\WINDOWS\system32\srutv.bak2

C:\WINDOWS\system32\srutv.ini

C:\WINDOWS\system32\srutv.ini2

C:\WINDOWS\system32\srutv.tmp

C:\WINDOWS\system32\srutv.bak1

C:\WINDOWS\system32\srutv.bak2

C:\WINDOWS\system32\srutv.ini

C:\WINDOWS\system32\srutv.ini2

C:\WINDOWS\system32\srutv.tmp

C:\WINDOWS\system32\vturs.dll

 

 

* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

 

 

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

 

 

C:\DOCUME~1\ADMINI~1\APPLIC~1.\fnts~1

C:\DOCUME~1\ADMINI~1\APPLIC~1.\fnts~1\wuaclt.exe

C:\Program Files\Common Files\ecurit~1

C:\Program Files\Common Files\ecurit~1\chkntfs.exe

C:\Program Files\Messenger\profsywuy.html

C:\Program Files\racle~1

C:\Program Files\winpop

C:\Program Files\winpop\UnInstall.exe

C:\temp\0b9

C:\temp\0b9\tmpTF.log

C:\temp\iee

C:\temp\iee\tmpZTF.log

C:\temp\tn3

C:\WINDOWS\cs_cache.ini

C:\WINDOWS\DOWNLO~1.\xpreload.ocx

C:\WINDOWS\rau001978.exe

C:\WINDOWS\system32\drivers\core.cache.dsk

C:\WINDOWS\system32\drivers\core.sys

C:\WINDOWS\system32\G1

C:\WINDOWS\system32\G2

C:\WINDOWS\system32\G3

C:\WINDOWS\system32\G4

C:\WINDOWS\system32\G4\mwspasrt83122.exe

C:\WINDOWS\system32\G5

C:\WINDOWS\system32\o02PrEz

C:\WINDOWS\system32\o05PrEz

C:\WINDOWS\system32\win

C:\WINDOWS\system32\wnstsisv.exe

C:\WINDOWS\wr.txt

 

 

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

 

 

-------\LEGACY_CORE

-------\LEGACY_DOMAINSERVICE

-------\core

-------\DomainService

 

 

((((((((((((((((((((((((( Files Created from 2007-06-12 to 2007-07-12 )))))))))))))))))))))))))))))))

 

 

2007-07-11 21:48 51,200 --a------ C:\WINDOWS\nircmd.exe

2007-07-11 21:47 66,624 --a------ C:\WINDOWS\system32\dpmhrfsu.dll

2007-07-11 21:46 66,112 --a------ C:\WINDOWS\system32\ffkoeamo.exe

2007-07-11 21:46 50,688 --a------ C:\WINDOWS\system32\qwerty12.exe

2007-07-11 21:10 <DIR> d-------- C:\DOCUME~1\ADMINI~1\DoctorWeb

2007-07-11 18:54 66,624 --a------ C:\WINDOWS\system32\kcjlxufu.dll

2007-07-11 18:51 66,112 --a------ C:\WINDOWS\system32\nxfuxdgt.exe

2007-07-08 20:07 <DIR> d-------- C:\WINDOWS\system32\Resource

2007-07-08 20:07 <DIR> d-------- C:\Program Files\Citrix

2007-07-05 18:07 577,536 --a------ C:\WINDOWS\soundman.exe

2007-07-05 18:07 57,344 --a------ C:\WINDOWS\system32\drivers\drmk.sys

2007-07-05 18:07 4,024,832 -ra------ C:\WINDOWS\system32\drivers\alcxwdm.sys

2007-07-05 18:07 135,040 --a------ C:\WINDOWS\system32\drivers\portcls.sys

2007-07-05 18:06 <DIR> d-------- C:\Program Files\Realtek AC97

2007-06-30 22:30 <DIR> d-------- C:\WINDOWS\LastGood

2007-06-25 20:56 <DIR> d-------- C:\Program Files\Full Tilt Poker

2007-06-24 19:28 <DIR> d-------- C:\ATI

2007-06-24 19:06 24,576 --a------ C:\WINDOWS\system32\xpsp1hfm.exe

2007-06-24 19:06 <DIR> d--h-c--- C:\WINDOWS\$xpsp1hfm$

2007-06-24 19:06 <DIR> d-------- C:\WINDOWS\LastGood.Tmp

2007-06-24 18:55 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys

2007-06-24 18:46 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Hewlett-Packard

2007-06-24 18:46 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\HP

2007-06-24 18:42 <DIR> d-------- C:\Program Files\Hewlett-Packard

2007-06-24 18:40 94,208 --a------ C:\WINDOWS\system32\HPZipt12.dll

2007-06-24 18:40 69,632 --a------ C:\WINDOWS\system32\HPZipm12.exe

2007-06-24 18:40 65,536 --a------ C:\WINDOWS\system32\HPZinw12.exe

2007-06-24 18:40 57,344 --a------ C:\WINDOWS\system32\HPZisn12.dll

2007-06-24 18:40 <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard

2007-06-24 18:39 306,688 --a------ C:\WINDOWS\IsUninst.exe

2007-06-24 18:36 53,631 --a------ C:\WINDOWS\hppins02.dat

2007-06-24 18:36 2,037 --------- C:\WINDOWS\hppmdl02.dat

2007-06-24 18:35 508 --a------ C:\WINDOWS\system32\HPPAPR01.DAT

2007-06-24 18:35 45,056 --a------ C:\WINDOWS\system32\HPPAPTS0.DLL

2007-06-24 18:35 36,864 --a------ C:\WINDOWS\system32\HPPASNM0.DLL

2007-06-24 18:35 36,864 --a------ C:\WINDOWS\system32\HPPAPML0.DLL

2007-06-24 18:35 36,864 --a------ C:\WINDOWS\system32\HPPADT40.DLL

2007-06-24 18:35 32,768 --a------ C:\WINDOWS\system32\HPPAMON0.DLL

2007-06-24 18:35 208,896 --a------ C:\WINDOWS\system32\HPPAPR01.DLL

2007-06-24 18:35 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys

2007-06-24 18:34 9,344 -ra------ C:\WINDOWS\system32\drivers\hpfxbulk.sys

2007-06-24 18:34 8,704 --a------ C:\WINDOWS\system32\drivers\Dot4Scan.sys

2007-06-24 18:34 765,952 -ra------ C:\WINDOWS\system32\hpptpml3.dll

2007-06-24 18:34 49,920 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys

2007-06-24 18:34 278,584 --a------ C:\WINDOWS\system32\HPZidr12.dll

2007-06-24 18:34 278,528 -ra------ C:\WINDOWS\system32\hpgwiamd.dll

2007-06-24 18:34 266,240 -ra------ C:\WINDOWS\system32\hppasc01.dll

2007-06-24 18:34 204,800 --a------ C:\WINDOWS\system32\HPZipr12.dll

2007-06-24 18:34 17,024 -ra------ C:\WINDOWS\system32\drivers\hpfxgen.sys

2007-06-24 18:34 102,400 -ra------ C:\WINDOWS\system32\hpfxbulk.dll

2007-06-24 18:29 <DIR> d-------- C:\WINDOWS\system32\NtmsData

2007-06-24 18:27 <DIR> d-------- C:\Program Files\HP

2007-06-24 18:26 <DIR> d-------- C:\WINDOWS\system32\bits

2007-06-24 18:24 7,680 --a------ C:\WINDOWS\system32\bitsprx2.dll

2007-06-24 18:24 7,168 --a------ C:\WINDOWS\system32\bitsprx3.dll

2007-06-24 18:24 331,776 --a------ C:\WINDOWS\system32\winhttp.dll

2007-06-24 18:24 17,408 --a------ C:\WINDOWS\system32\qmgrprxy.dll

2007-06-24 18:24 158,720 --a------ C:\WINDOWS\system32\xpob2res.dll

2007-06-24 18:22 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution

2007-06-24 18:22 <DIR> d-------- C:\Program Files\Common Files\SWF Studio

2007-06-24 18:21 549,720 --a------ C:\WINDOWS\system32\wuapi.dll

2007-06-24 18:21 33,624 --a------ C:\WINDOWS\system32\wups.dll

2007-06-24 18:21 325,976 --a------ C:\WINDOWS\system32\wucltui.dll

2007-06-24 18:21 203,096 --a------ C:\WINDOWS\system32\wuweb.dll

2007-06-24 18:21 186,136 --a------ C:\WINDOWS\system32\wuaueng1.dll

2007-06-24 18:21 167,704 --a------ C:\WINDOWS\system32\wuauclt1.exe

2007-06-24 18:21 <DIR> d-------- C:\WINDOWS\SoftwareDistribution

2007-06-24 18:18 185,624 --a------ C:\WINDOWS\system32\iuengine.dll

2007-06-24 17:23 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP

2007-06-24 17:23 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL

2007-06-24 17:23 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\acccore

2007-06-24 17:22 <DIR> d-------- C:\Program Files\Viewpoint

2007-06-24 17:22 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint

2007-06-24 17:21 <DIR> d-------- C:\Program Files\Common Files\AOL

2007-06-24 17:20 <DIR> d-------- C:\Program Files\AIM6

2007-06-24 17:19 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL Downloads

2007-06-24 16:36 <DIR> d-------- C:\Program Files\Valve

2007-06-24 11:08 <DIR> d---s---- C:\DOCUME~1\ADMINI~1\UserData

2007-06-23 18:46 8,704 --a------ C:\command.exe

2007-06-23 17:53 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\X10 Commander

2007-06-23 17:34 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys

2007-06-23 17:34 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys

2007-06-23 17:34 43,528 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys

2007-06-23 17:34 129,784 --a------ C:\WINDOWS\system32\pxafs.dll

2007-06-23 17:33 <DIR> d-------- C:\Program Files\Winamp

2007-06-23 14:25 <DIR> d-------- C:\WINDOWS\Downloaded Installations

2007-06-23 12:46 <DIR> d--hs---- C:\RECYCLER

2007-06-23 11:59 1,688 --a------ C:\WINDOWS\mozver.dat

2007-06-23 11:58 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy

2007-06-23 11:53 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Talkback

2007-06-23 11:52 335 --a------ C:\WINDOWS\nsreg.dat

2007-06-23 11:50 <DIR> d-------- C:\Temp

2007-06-23 11:44 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Google

2007-06-23 11:41 <DIR> d-------- C:\Program Files\Google

2007-06-23 11:41 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google

2007-06-23 11:38 79,616 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys

2007-06-23 11:38 57,472 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys

2007-06-23 11:38 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys

2007-06-23 11:38 50,048 --a------ C:\WINDOWS\system32\drivers\DMusic.sys

2007-06-23 11:38 5,632 --a------ C:\WINDOWS\system32\drivers\splitter.sys

 

 

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

 

2007-06-24 22:22:51 1,386,496 ----a-w C:\WINDOWS\system32\msvbvm60.dll

2007-05-18 03:57:33 43,136 ----a-w C:\WINDOWS\system32\drivers\ativvpxx.vp

2007-05-18 01:58:58 339,968 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll

2007-05-18 01:58:04 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll

2007-05-18 01:57:53 268,288 ----a-w C:\WINDOWS\system32\ati2dvag.dll

2007-05-18 01:57:34 2,164,736 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys

2007-05-18 01:51:01 139,264 ----a-w C:\WINDOWS\system32\atipdlxx.dll

2007-05-18 01:50:52 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe

2007-05-18 01:50:46 42,496 ----a-w C:\WINDOWS\system32\ati2edxx.dll

2007-05-18 01:50:34 118,784 ----a-w C:\WINDOWS\system32\ati2evxx.dll

2007-05-18 01:49:14 479,232 ----a-w C:\WINDOWS\system32\ati2evxx.exe

2007-05-18 01:48:26 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL

2007-05-18 01:41:03 2,922,144 ----a-w C:\WINDOWS\system32\ati3duag.dll

2007-05-18 01:39:54 7,610,368 ----a-w C:\WINDOWS\system32\atioglx2.dll

2007-05-18 01:30:58 1,512,960 ----a-w C:\WINDOWS\system32\ativvaxx.dll

2007-05-18 01:30:41 972,072 ----a-w C:\WINDOWS\system32\ativva6x.dat

2007-05-18 01:30:41 3,107,788 ----a-w C:\WINDOWS\system32\ativva5x.dat

2007-05-18 01:30:40 3,107,788 ----a-w C:\WINDOWS\system32\ativvaxx.dat

2007-05-18 01:19:50 5,431,296 ----a-w C:\WINDOWS\system32\atioglxx.dll

2007-05-18 01:17:27 262,144 ----a-w C:\WINDOWS\system32\atikvmag.dll

2007-05-18 01:16:04 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll

2007-05-18 01:15:22 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll

2007-05-18 01:14:21 46,592 ----a-w C:\WINDOWS\system32\atiok3x2.dll

2007-05-18 01:10:21 368,640 ----a-w C:\WINDOWS\system32\ati2cqag.dll

2007-04-17 02:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll

2007-04-17 02:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll

 

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

 

 

*Note* empty entries & legit default entries are not shown

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]

2006-10-22 23:08 62080 --a------ C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]

2005-05-31 01:04 853672 --a------ C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95ADC989-2005-4F9F-939F-6AD34EA9C0E3}]

C:\Program Files\WindowsUpdate\hoke83122.dll

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]

2007-06-23 11:41 2403392 -ra------ c:\program files\google\googletoolbar1.dll

 

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]

2007-06-25 17:39 325048 --a------ C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-11-03 21:10]

"@"="" []

"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2004-11-03 22:21]

"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-24 17:14]

"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-06-15 01:40]

"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09]

"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]

"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-05-14 18:22]

"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 15:49]

"ToolBoxFX"="C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe" [2006-02-02 08:12]

"HPUsageTracking"="C:\Program Files\HP\HP UT\bin\hppusg.exe" [2005-09-07 03:25]

"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25]

"SoundMan"="SOUNDMAN.EXE" [2006-08-03 05:12 C:\WINDOWS\soundman.exe]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"@"="" []

"ATI DeviceDetect"="C:\Program Files\ATI Multimedia\main\ATIDtct.EXE" [2004-09-22 22:16]

"ATI Remote Control"="C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe" [2004-07-08 10:49]

"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 17:40]

"Krztw"="C:\WINDOWS\?ppPatch\r?ndll32.exe" []

"Steam"="C:\Program Files\Valve\Steam\\Steam.exe" [2003-06-27 19:30]

"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 17:17]

"Bosh"="C:\DOCUME~1\ADMINI~1\APPLIC~1\FNTS~1\wuaclt.exe" []

 

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]

"<NO NAME>"=

"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime

 

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]

Source= C:\Program Files\Messenger\profsywuy.html

FriendlyName=

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 08:29]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\CLSID]

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]

 

*Newly Created Service* - ALG

*Newly Created Service* - IPNAT

*Newly Created Service* - RASAUTO

*Newly Created Service* - RASMAN

 

HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{ACC563BC-4266-43f0-B6ED-9D38C4202C7E}

rundll32 iesetup.dll,IEAccessUserInst

 

**************************************************************************

 

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net

Rootkit scan 2007-07-11 21:56:54

Windows 5.1.2600 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

 

Completion time: 2007-07-11 21:57:47 - machine was rebooted

C:\ComboFix-quarantined-files.txt ... 2007-07-11 21:57

 

--- E O F ---

Share this post


Link to post
Share on other sites

Hi again,

 

That looks better, please now post a fresh HiJackThis log. (No need to put logs in a quote box, copy and paste is fine.)

 

jedi

Share this post


Link to post
Share on other sites

Logfile of Trend Micro HijackThis v2.0.0 (BETA)

Scan saved at 8:10:56 PM, on 7/12/2007

Platform: Windows XP (WinNT 5.01.2600)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\System32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

C:\Program Files\Symantec AntiVirus\DefWatch.exe

C:\WINDOWS\System32\HPZipm12.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Symantec AntiVirus\Rtvscan.exe

C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\PROGRA~1\SYMANT~1\VPTray.exe

C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe

C:\Program Files\HP\HP UT\bin\hppusg.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Program Files\ATI Multimedia\main\ATIDtct.EXE

C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\AIM6\aim6.exe

C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe

C:\WINDOWS\System32\rundll32.exe

C:\Program Files\AIM6\aolsoftware.exe

C:\WINDOWS\System32\wuauclt.exe

C:\Documents and Settings\Administrator\Desktop\HiJackThis_v2.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

O2 - BHO: (no name) - {95ADC989-2005-4F9F-939F-6AD34EA9C0E3} - C:\Program Files\WindowsUpdate\hoke83122.dll (file missing)

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe

O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe

O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [ToolBoxFX] "C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /systrayIcon:on /fl:on /fr:on /appData:on

O4 - HKLM\..\Run: [HPUsageTracking] C:\Program Files\HP\HP UT\bin\hppusg.exe "C:\Program Files\HP\HP UT\"

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKCU\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE

O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [Krztw] C:\WINDOWS\?ppPatch\r?ndll32.exe

O4 - HKCU\..\Run: [steam] C:\Program Files\Valve\Steam\\Steam.exe -silent

O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp

O4 - HKCU\..\Run: [bosh] "C:\DOCUME~1\ADMINI~1\APPLIC~1\FNTS~1\wuaclt.exe" -vt ndrv

O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user')

O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe

O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL

O16 - DPF: {DD8C9372-35FD-4F7D-8CE4-909ABCFAB2C5} - ms-its:mhtml:file://c:\\nores.mht!http://adxtend.net/code/chm/xpre.chm::/xpreload.ocx

O20 - Winlogon Notify: CLSID - C:\WINDOWS\

O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

O24 - Desktop Component 0: (no name) - C:\Program Files\Messenger\profsywuy.html

 

--

End of file - 7476 bytes

Share this post


Link to post
Share on other sites

Hi again,

 

Scan with HiJackThis and put a check in the box next to the following items;

 

O2 - BHO: (no name) - {95ADC989-2005-4F9F-939F-6AD34EA9C0E3} - C:\Program Files\WindowsUpdate\hoke83122.dll (file missing)

O4 - HKCU\..\Run: [Krztw] C:\WINDOWS\?ppPatch\r?ndll32.exe

O24 - Desktop Component 0: (no name) - C:\Program Files\Messenger\profsywuy.html

 

Close all browsers and windows, click on ‘fix selected’ and allow HJT to fix these entries.

 

Restart.

 

Please do the following:

Run a BitDefender Online scan Here and post the results.

 

 

Scan again with HJT, (with all browsers and windows closed) and post the new log in this thread.

 

jedi

Share this post


Link to post
Share on other sites

Due to the lack of feedback this Topic is closed.

 

If you need this topic reopened, please tell the moderating team by replying here with the address of the thread. This applies only to the original topic starter.

 

Everyone else please begin a New Topic.

Share this post


Link to post
Share on other sites
Guest
This topic is now closed to further replies.
Sign in to follow this  
Followers 0