943,708 Members | Top Members by Rank

Ad:
You are currently viewing page 1 of this multi-page discussion thread
Feb 29th, 2008
0

help required

Expand Post »
hi, my computer has aquired a virus of some kind, i am inundated with pop ups, re directed on searches etc. I installed webroot spy sweeper prosearching.com appeared but was quarantined however the problem remains. the following is my hijackthis log. please help, all help much appreciated, thanks

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:00:26, on 01/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
d:\elsawin\bin\LcSvrAdm.exe
d:\elsawin\bin\LcSvrDba.exe
d:\elsawin\bin\LcSvrHis.exe
d:\elsawin\bin\LcSvrKdS.exe
d:\elsawin\bin\LcSvrPas.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE
D:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\MsPMSPSv.exe
d:\elsawin\bin\LcSvrAuf.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\explorer.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [EPSON Stylus C46 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE /P23 "EPSON Stylus C46 Series" /O6 "USB001" /M "Stylus C46"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DAEMON Tools] "d:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BBC News alerts] D:\Program Files\BBC News alerts\skinkers.exe
O4 - HKLM\..\Policies\Explorer\Run: [9WkqTfjoCX] rundll32.exe "C:\WINDOWS\nargryxu.dll",DllCleanServer
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [ITD7] "C:\Program Files\Steganos Internet Trace Destructor 7\ITD7.exe" -firstboot (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [ITD7] "C:\Program Files\Steganos Internet Trace Destructor 7\ITD7.exe" -firstboot (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [ITD7] "C:\Program Files\Steganos Internet Trace Destructor 7\ITD7.exe" -firstboot (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = D:\Program Files\microsoft office xp\Office12\ONENOTEM.EXE
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Transfer by Image Converter 3 - C:\PROGRAM FILES\SONY\IMAGE CONVERTER 3\menu.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=www.google.com
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://courses.learndirect.co.uk/pro...er/awswaxf.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://campuscentercam.its.wesleyan.edu/activex/AMC.cab
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/Yazzl...cab?refid=1123
O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} -
O16 - DPF: {B0067CA5-2C37-4C6B-AAEC-5E2CE8635061} (FontDown Class) - http://www.qurancomplex.org/Downloads/FontSmooth.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Image Converter SCSI Service (ICScsiSV) - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\ICScsiSV.exe
O23 - Service: IcVzMonLauncher - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMonLauncher.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ELSA Administration Service (LcSvrAdm) - Volkswagen AG - d:\elsawin\bin\LcSvrAdm.exe
O23 - Service: ELSA Auftragsverwaltungs Service (LcSvrAuf) - Volkswagen AG - d:\elsawin\bin\LcSvrAuf.exe
O23 - Service: ELSA DBA Server (LcSvrDba) - Volkswagen AG - d:\elsawin\bin\LcSvrDba.exe
O23 - Service: ELSA Historie Server (LcSvrHis) - Volkswagen AG - d:\elsawin\bin\LcSvrHis.exe
O23 - Service: ELSA KD-Nummern Server (LcSvrKds) - Volkswagen AG - d:\elsawin\bin\LcSvrKdS.exe
O23 - Service: ELSA PASS Server (LcSvrPAS) - Volkswagen AG - d:\elsawin\bin\LcSvrPas.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 9039 bytes
Similar Threads
Reputation Points: 10
Solved Threads: 0
Newbie Poster
pete17 is offline Offline
20 posts
since Feb 2008
Mar 1st, 2008
0

Re: help required

hi, just did another hjt as my pc got worse. this is the current log, so please disregard the previous. thanks

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:17:07, on 01/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
d:\elsawin\bin\LcSvrAdm.exe
d:\elsawin\bin\LcSvrDba.exe
d:\elsawin\bin\LcSvrHis.exe
d:\elsawin\bin\LcSvrKdS.exe
d:\elsawin\bin\LcSvrPas.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE
D:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\MsPMSPSv.exe
d:\elsawin\bin\LcSvrAuf.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\wuauclt.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [EPSON Stylus C46 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE /P23 "EPSON Stylus C46 Series" /O6 "USB001" /M "Stylus C46"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DAEMON Tools] "d:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BBC News alerts] D:\Program Files\BBC News alerts\skinkers.exe
O4 - HKLM\..\Policies\Explorer\Run: [9WkqTfjoCX] rundll32.exe "C:\WINDOWS\nargryxu.dll",DllCleanServer
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [ITD7] "C:\Program Files\Steganos Internet Trace Destructor 7\ITD7.exe" -firstboot (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [ITD7] "C:\Program Files\Steganos Internet Trace Destructor 7\ITD7.exe" -firstboot (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [ITD7] "C:\Program Files\Steganos Internet Trace Destructor 7\ITD7.exe" -firstboot (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = D:\Program Files\microsoft office xp\Office12\ONENOTEM.EXE
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Transfer by Image Converter 3 - C:\PROGRAM FILES\SONY\IMAGE CONVERTER 3\menu.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=www.google.com
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://courses.learndirect.co.uk/pro...er/awswaxf.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://campuscentercam.its.wesleyan.edu/activex/AMC.cab
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/Yazzl...cab?refid=1123
O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} -
O16 - DPF: {B0067CA5-2C37-4C6B-AAEC-5E2CE8635061} (FontDown Class) - http://www.qurancomplex.org/Downloads/FontSmooth.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Image Converter SCSI Service (ICScsiSV) - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\ICScsiSV.exe
O23 - Service: IcVzMonLauncher - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMonLauncher.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ELSA Administration Service (LcSvrAdm) - Volkswagen AG - d:\elsawin\bin\LcSvrAdm.exe
O23 - Service: ELSA Auftragsverwaltungs Service (LcSvrAuf) - Volkswagen AG - d:\elsawin\bin\LcSvrAuf.exe
O23 - Service: ELSA DBA Server (LcSvrDba) - Volkswagen AG - d:\elsawin\bin\LcSvrDba.exe
O23 - Service: ELSA Historie Server (LcSvrHis) - Volkswagen AG - d:\elsawin\bin\LcSvrHis.exe
O23 - Service: ELSA KD-Nummern Server (LcSvrKds) - Volkswagen AG - d:\elsawin\bin\LcSvrKdS.exe
O23 - Service: ELSA PASS Server (LcSvrPAS) - Volkswagen AG - d:\elsawin\bin\LcSvrPas.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 9541 bytes
Reputation Points: 10
Solved Threads: 0
Newbie Poster
pete17 is offline Offline
20 posts
since Feb 2008
Mar 3rd, 2008
0

Re: help required

Hi pete17 and welcome to DaniWeb

Download Combofix from any of the links below, and save it to your desktop.

Link 1
Link 2
Link 3


**Note: It is important that it is saved directly to your desktop**

--------------------------------------------------------------------

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

If your not sure how to disable them then double-check against the list found >>>HERE<<< This list is not all inclusive, if your programs are not listed and you are unsure then please ask before continuing.

--------------------------------------------------------------------

Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall
Reputation Points: 11
Solved Threads: 10
Junior Poster
MoralTerror is offline Offline
127 posts
since Jul 2007
Mar 3rd, 2008
0

Re: help required

hi there MoralTerror thanks for the reply, the following is the combo fix log followed by the hjt log. just thought i'd mention when combofix rebooted and was preparing the log my ad-aware came on which i quickly disabled. dont know whether this will affect the log or not. thanks - here goes,

ComboFix 08-03-03.6 - Asif 2008-03-03 13:03:05.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.198 [GMT 0:00]
Running from: C:\Documents and Settings\Asif\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\DOCUME~1\ALLUSE~1\APPLIC~1.\fcvidgzm.dll
C:\Documents and Settings\Asif\Application Data\AntiSpywareBot
C:\Documents and Settings\Asif\Application Data\AntiSpywareBot\Log\2008 Feb 29 - 06_37_34 PM_835.log
C:\Documents and Settings\Asif\Application Data\AntiSpywareBot\rs.dat
C:\Documents and Settings\Asif\Application Data\AntiSpywareBot\Settings\ScanResults.pie
C:\Program Files\Common Files\dobe~1
C:\Program Files\Common Files\ecurit~1
C:\Program Files\Common Files\ecurit~1\?ecurity\
C:\Program Files\version.txt
C:\WINDOWS\cookies.ini
C:\WINDOWS\cpahkpsz.dll
C:\WINDOWS\PerfInfo
C:\WINDOWS\PerfInfo\9WkqTfjoCXwp.exe
C:\WINDOWS\system32\akeukltk.ini
C:\WINDOWS\system32\bdbrveca.dll
C:\WINDOWS\system32\cjbciafm.dll
C:\WINDOWS\system32\dugdywwl.ini
C:\WINDOWS\system32\elhipqmh.dll
C:\WINDOWS\system32\gudjdbqb.dll
C:\WINDOWS\system32\hsmyfsfn.dll
C:\WINDOWS\system32\ihhprcvr.ini
C:\WINDOWS\system32\jaiufxlq.ini
C:\WINDOWS\system32\jkkhhih.dll
C:\WINDOWS\system32\jkvfwqrr.ini
C:\WINDOWS\system32\ktlkueka.dll
C:\WINDOWS\system32\ldhrhpat.ini
C:\WINDOWS\system32\lwwydgud.dll
C:\WINDOWS\system32\mctxhnau.dll
C:\WINDOWS\system32\mfaicbjc.ini
C:\WINDOWS\system32\onnpo.ini
C:\WINDOWS\system32\onnpo.ini2
C:\WINDOWS\system32\opnno.dll
C:\WINDOWS\system32\qlxfuiaj.dll
C:\WINDOWS\system32\rrqwfvkj.dll
C:\WINDOWS\system32\rvcrphhi.dll
C:\WINDOWS\system32\sinasucu.dll
C:\WINDOWS\system32\taebqytw.ini
C:\WINDOWS\system32\taphrhdl.dll
C:\WINDOWS\system32\ufjemlxn.dll

.
((((((((((((((((((((((((( Files Created from 2008-02-03 to 2008-03-03 )))))))))))))))))))))))))))))))
.

2008-03-03 13:11 . 2008-03-03 13:11 <DIR> d-------- C:\WINDOWS\PerfInfo
2008-03-01 22:58 . 2008-03-01 22:58 <DIR> d-------- C:\Documents and Settings\Asif\Application Data\Grisoft
2008-03-01 22:58 . 2007-05-30 12:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-01 22:57 . 2008-03-01 22:57 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
2008-03-01 01:00 . 2008-03-01 01:00 <DIR> d-------- C:\Program Files\Webroot
2008-03-01 01:00 . 2008-03-01 01:00 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2008-03-01 01:00 . 2008-03-01 01:00 <DIR> d-------- C:\Documents and Settings\Asif\Application Data\Webroot
2008-03-01 01:00 . 2008-03-01 01:00 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Webroot
2008-03-01 01:00 . 2007-10-01 16:40 1,526,072 --a------ C:\WINDOWS\WRSetup.dll
2008-03-01 01:00 . 2007-10-01 16:24 163,640 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2008-03-01 01:00 . 2007-10-01 16:24 23,864 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2008-03-01 01:00 . 2007-10-01 16:24 21,816 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2008-03-01 01:00 . 2007-10-01 16:24 20,280 --a------ C:\WINDOWS\system32\drivers\SSFS0BB9.sys
2008-02-29 00:07 . 2008-02-29 00:07 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-02-27 23:21 . 2008-02-27 23:21 <DIR> d-------- C:\WINDOWS\ifbkcsif
2008-02-27 23:21 . 2008-02-27 23:21 3,801,830 --a------ C:\WINDOWS\9WkqTfjoCX.exe
2008-02-27 23:21 . 2008-02-27 23:21 187,904 --a------ C:\WINDOWS\nargryxu.dll
2008-02-27 23:21 . 2008-02-27 23:21 89,107 --a------ C:\WINDOWS\system32\mgmrwmrv.exe
2008-02-27 23:21 . 2008-02-27 23:21 89,107 --a------ C:\WINDOWS\rijidgne.exe
2008-02-27 23:21 . 2008-02-27 23:21 4 --a------ C:\WINDOWS\system32\winfrun32.bin
2008-02-27 23:20 . 2008-02-27 23:20 46,592 --a------ C:\WINDOWS\obmnateh.exe
2008-02-27 22:51 . 2008-02-27 22:51 1,152 --a------ C:\WINDOWS\system32\windrv.sys
2008-02-27 09:12 . 2008-03-02 13:55 99,436 --a------ C:\WINDOWS\BMbfd2f053.xml
2008-02-27 09:12 . 2008-03-03 09:18 22 --a------ C:\WINDOWS\pskt.ini
2008-02-25 11:19 . 2008-02-25 11:42 <DIR> d-------- C:\Program Files\NoAdware5.0
2008-02-24 18:22 . 2008-02-24 18:22 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-02-23 21:12 . 2008-02-23 21:12 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Corel
2008-02-23 21:05 . 2008-02-23 21:05 <DIR> d-------- C:\Program Files\Common Files\Corel
2008-02-20 15:53 . 2008-02-23 01:20 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-20 15:53 . 2008-02-20 15:53 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-12 17:58 . 2008-02-12 17:58 <DIR> d-------- C:\Program Files\Log
2008-02-12 17:24 . 2008-02-12 17:24 <DIR> d-------- C:\Program Files\AddonLog
2008-02-12 17:24 . 2007-02-02 19:39 217,088 --a------ C:\Program Files\SsMidAccess.dll
2008-02-12 17:24 . 2007-02-02 19:39 81,920 --a------ C:\Program Files\Cddb2Access.dll
2008-02-12 17:23 . 2008-02-12 17:23 <DIR> d-------- C:\Program Files\Data
2008-02-12 17:23 . 2007-02-05 10:11 5,961,272 --a------ C:\Program Files\Omgjbox.exe
2008-02-12 17:23 . 2007-02-02 19:35 1,323,008 --a------ C:\Program Files\OmgjboxRes.dll
2008-02-12 17:23 . 2007-02-05 10:11 1,201,720 --a------ C:\Program Files\Omgbkup.exe
2008-02-12 17:23 . 2005-03-21 20:30 1,060,864 --a------ C:\Program Files\mfc71.dll
2008-02-12 17:23 . 2007-02-05 10:10 816,696 --a------ C:\Program Files\OMG2OMA.exe
2008-02-12 17:23 . 2007-02-02 19:42 798,720 --a------ C:\Program Files\Si.dll
2008-02-12 17:23 . 2007-02-05 10:10 603,704 --a------ C:\Program Files\Omg1to2.exe
2008-02-12 17:23 . 2007-02-05 10:10 603,704 --a------ C:\Program Files\Ojbsir.exe
2008-02-12 17:23 . 2007-02-02 19:08 536,576 --a------ C:\Program Files\OMG2OMARes.dll
2008-02-12 17:23 . 2007-02-02 20:03 528,384 --a------ C:\Program Files\OjbSirRes.dll
2008-02-12 17:23 . 2005-03-21 20:30 499,712 --a------ C:\Program Files\msvcp71.dll
2008-02-12 17:23 . 2007-02-05 10:11 476,728 --a------ C:\Program Files\SSAAD.exe
2008-02-12 17:23 . 2007-02-02 19:41 434,176 --a------ C:\Program Files\Items.dll
2008-02-12 17:23 . 2007-02-02 19:39 397,312 --a------ C:\Program Files\SsEncMp3.dll
2008-02-12 17:23 . 2005-03-21 20:34 352,256 --a------ C:\Program Files\ijl15.dll
2008-02-12 17:23 . 2005-03-21 20:30 348,160 --a------ C:\Program Files\msvcr71.dll
2008-02-12 17:23 . 2007-02-02 19:39 196,608 --a------ C:\Program Files\RGraph.dll
2008-02-12 17:23 . 2006-12-19 15:03 192,512 --a------ C:\Program Files\XCoreAudio.dll
2008-02-12 17:23 . 2007-02-02 20:07 143,360 --a------ C:\Program Files\OmgbkupRes.dll
2008-02-12 17:23 . 2006-12-26 17:57 143,360 --a------ C:\Program Files\dunzip32.dll
2008-02-12 17:23 . 2007-02-02 19:40 131,072 --a------ C:\Program Files\SsMtp.dll
2008-02-12 17:23 . 2007-02-02 19:36 106,496 --a------ C:\Program Files\RBasis.dll
2008-02-12 17:23 . 2005-03-21 20:30 106,496 --a------ C:\Program Files\atl71.dll
2008-02-12 17:23 . 2007-02-02 19:46 94,208 --a------ C:\Program Files\DMPInternet.dll
2008-02-12 17:23 . 2007-02-02 19:47 69,632 --a------ C:\Program Files\XPanel.dll
2008-02-12 17:23 . 2007-02-02 19:39 65,536 --a------ C:\Program Files\SsEncWma.dll
2008-02-12 17:23 . 2005-03-21 20:30 65,536 --a------ C:\Program Files\JETCOMP.exe
2008-02-12 17:23 . 2007-02-02 19:42 57,344 --a------ C:\Program Files\SsTpl.dll
2008-02-12 17:23 . 2007-02-02 19:39 49,152 --a------ C:\Program Files\SsProxy.dll
2008-02-12 17:23 . 2007-02-02 19:46 45,056 --a------ C:\Program Files\GenMediaKey.dll
2008-02-12 17:23 . 2007-02-05 10:10 38,456 --a------ C:\Program Files\AppReg.exe
2008-02-12 17:23 . 2007-02-02 19:42 32,768 --a------ C:\Program Files\HelpHelper.dll
2008-02-12 17:23 . 2007-02-02 19:08 17,920 --a------ C:\Program Files\XThumbnail.dll
2008-02-12 17:23 . 2007-02-02 19:46 13,312 --a------ C:\Program Files\WtsNotify.dll
2008-02-12 17:23 . 2007-02-02 19:07 12,800 --a------ C:\Program Files\Lam.dll
2008-02-12 17:23 . 2007-02-02 19:05 3,584 --a------ C:\Program Files\Omg1to2Res.dll
2008-02-12 17:08 . 2008-02-12 17:09 <DIR> d-------- C:\ss43_dl
2008-02-12 14:08 . 2008-02-12 14:08 <DIR> d-------- C:\Documents and Settings\All Users\SonicStage
2008-02-12 13:57 . 2001-09-13 02:15 90,112 --------- C:\WINDOWS\snymsico.dll
2008-02-12 13:57 . 2002-08-08 15:51 38,951 --------- C:\WINDOWS\system32\drivers\NETMDUSB.sys
2008-02-12 13:57 . 2005-10-31 10:46 36,679 --------- C:\WINDOWS\system32\drivers\NETMD052.sys
2008-02-12 13:57 . 2003-11-10 12:31 36,232 --------- C:\WINDOWS\system32\drivers\NETMD033.sys
2008-02-12 13:57 . 2003-04-01 18:55 35,319 --------- C:\WINDOWS\system32\drivers\NETMD031.sys
2008-02-12 13:56 . 2008-02-13 11:18 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony Corporation
2008-02-12 13:56 . 2007-01-13 08:24 770,048 --a------ C:\WINDOWS\system32\CDDBUISony.dll
2008-02-12 13:56 . 2007-01-13 08:22 655,360 --a------ C:\WINDOWS\system32\CDDBControlSony.dll
2008-02-12 13:56 . 2007-01-13 08:22 589,824 --a------ C:\WINDOWS\system32\CddbMusicIDSony.dll
2008-02-12 13:56 . 2007-01-13 08:25 532,480 --a------ C:\WINDOWS\system32\CddbPlaylist2Sony.dll
2008-02-12 13:56 . 2006-10-29 01:00 116,472 --------- C:\WINDOWS\system32\pxcpyi64.exe
2008-02-12 13:56 . 2007-01-13 08:24 73,728 --a------ C:\WINDOWS\system32\CddbLinkSony.dll
2008-02-12 13:55 . 2008-02-13 11:12 <DIR> d-------- C:\Program Files\Sony
2008-02-12 13:54 . 2008-02-18 12:42 <DIR> d-------- C:\Program Files\Common Files\Sony Shared
2008-02-12 13:54 . 2008-02-13 11:18 <DIR> d-------- C:\Documents and Settings\Asif\Application Data\Sony Corporation
2008-02-12 13:10 . 2004-08-03 23:00 26,112 --a------ C:\WINDOWS\system32\drivers\MemStPCI.SYS
2008-02-12 13:10 . 2004-08-03 23:00 26,112 --a--c--- C:\WINDOWS\system32\dllcache\memstpci.sys
2008-02-08 23:09 . 2008-02-09 11:53 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-02-07 10:48 . 2008-02-07 10:48 2,560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2008-02-06 21:33 . 2008-02-06 21:33 <DIR> d-------- C:\WINDOWS\RegCure
2008-02-04 12:05 . 2008-02-04 12:05 <DIR> d-------- C:\Program Files\iPod
2008-02-04 12:01 . 2008-02-04 12:03 <DIR> d-------- C:\Program Files\QuickTime
2008-02-04 12:00 . 2008-02-04 12:00 <DIR> d-------- C:\Program Files\Apple Software Update
2008-02-04 11:59 . 2008-02-04 11:59 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-02-04 11:59 . 2008-02-04 11:59 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-01 01:01 --------- d-----w C:\Documents and Settings\Asif\Application Data\uTorrent
2008-02-27 22:38 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
2008-02-26 09:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-23 21:17 --------- d-----w C:\Documents and Settings\Asif\Application Data\Corel
2008-02-18 12:41 --------- d-----w C:\Program Files\DivX
2008-02-09 09:37 --------- d-----w C:\Program Files\Google
2008-02-06 09:41 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-04 12:06 --------- d-----w C:\Documents and Settings\Asif\Application Data\Apple Computer
2008-02-04 12:03 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2008-01-27 18:28 --------- d-----w C:\Documents and Settings\Guest\Application Data\Windows Desktop Search
2007-12-31 18:29 8,464 ----a-w C:\WINDOWS\system32\sporder.dll
2007-12-29 17:53 0 ----a-w C:\Documents and Settings\Asif\Application Data\wklnhst.dat
2007-12-07 02:21 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-08-03 20:32 17,144 -c--a-w C:\Documents and Settings\Asif\Application Data\GDIPFONTCACHEV1.DAT
2007-02-02 20:09 25,600 ----a-w C:\Program Files\SsVerChk.ocx
2007-02-02 20:08 65,536 ----a-w C:\Program Files\StdoutSs2.ax
2007-02-02 20:08 53,248 ----a-w C:\Program Files\SonyWavParser2.ax
2007-01-16 18:13 7,453 ----a-w C:\Program Files\Readme.txt
2005-08-25 09:10 81,920 ----a-w C:\Program Files\SonyFsConvFilter.ax
2005-03-21 20:30 7 ----a-w C:\Program Files\initials.ini
2004-06-18 11:05 45,056 -c--a-w C:\WINDOWS\inf\Slntinst.exe
2003-08-22 11:09 45,056 -c--a-w C:\WINDOWS\inf\slntinst_staticW2k.exe
2006-12-07 21:37 56 -csh--r C:\WINDOWS\system32\7DCBC830BD.sys
2007-02-12 21:25 3,350 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 16:24 1694208]
"AWMON"="C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" [2005-05-25 11:12 517632]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"BBC News alerts"="D:\Program Files\BBC News alerts\skinkers.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-03 23:56 33280 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2006-03-09 14:29 1519616 C:\WINDOWS\system32\nwiz.exe]
"EPSON Stylus C46 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.exe" [2004-01-13 18:00 99840]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-03 23:56 33280 C:\WINDOWS\system32\rundll32.exe]
"DAEMON Tools"="d:\Program Files\DAEMON Tools\daemon.exe" [2005-11-08 23:00 128920]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 09:50 155648]
"WinampAgent"="D:\Program Files\Winamp\winampa.exe" [ ]
"QuickTime Task"="D:\Program Files\qttask.exe" [ ]
"AGEIA PhysX SysTray"="C:\Program Files\AGEIA Technologies\TrayIcon.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:56 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ITD7"="C:\Program Files\Steganos Internet Trace Destructor 7\ITD7.exe" [2005-05-02 10:31 274432]

C:\Documents and Settings\Asif\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - D:\Program Files\microsoft office xp\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"9WkqTfjoCX"= rundll32.exe "C:\WINDOWS\nargryxu.dll",DllCleanServer

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="LogonUI.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iiffcaw]
iiffcaw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winmoy32]
winmoy32.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Metacafe.lnk]
backup=C:\WINDOWS\pss\Metacafe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Asif^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Asif\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Asif^Start Menu^Programs^Startup^MetaCafe.lnk]
backup=C:\WINDOWS\pss\MetaCafe.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGEIA PhysX SysTray]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AWMON]
--a------ 2005-05-25 11:12 517632 C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BBC News alerts]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2005-11-08 23:00 128920 d:\Program Files\DAEMON Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 09:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-03-09 14:29 86016 C:\WINDOWS\system32\NvMcTray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Documents and Settings\\Asif\\My Documents\\utorrent.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"D:\\Program Files\\microsoft office xp\\Office12\\OUTLOOK.EXE"=
"D:\\Program Files\\microsoft office xp\\Office12\\groove.exe"=
"D:\\Program Files\\microsoft office xp\\Office12\\ONENOTE.EXE"=
"D:\\Program Files\\iTunes.exe"=

R2 LcSvrAdm;ELSA Administration Service;d:\elsawin\bin\LcSvrAdm.exe [2003-03-13 15:46]
R2 LcSvrDba;ELSA DBA Server;d:\elsawin\bin\LcSvrDba.exe [2003-03-13 15:38]
R2 LcSvrHis;ELSA Historie Server;d:\elsawin\bin\LcSvrHis.exe [2003-03-13 15:42]
R2 LcSvrKds;ELSA KD-Nummern Server;d:\elsawin\bin\LcSvrKdS.exe [2003-03-13 15:51]
R2 LcSvrPAS;ELSA PASS Server;d:\elsawin\bin\LcSvrPas.exe [2003-03-13 16:06]
R3 BTCOMM;BTCOMM;C:\WINDOWS\system32\drivers\Btcomm.sys [2004-09-28 16:18]
R3 BTKRNBDG;Bluetooth COM Bridge;C:\WINDOWS\system32\DRIVERS\btkrnbdg.sys [2003-03-18 11:31]
R3 LcSvrAuf;ELSA Auftragsverwaltungs Service;d:\elsawin\bin\LcSvrAuf.exe [2003-03-13 15:41]
R3 vad_multi;Windigo Virtual Audio Device (WDM);C:\WINDOWS\system32\drivers\vadmulti.sys [2005-06-30 12:57]
S3 CSRBC01;%CSRBC01.SvcDesc%;C:\WINDOWS\system32\Drivers\csrbc01.sys [2005-06-28 19:46]
S3 ICScsiSV;Image Converter SCSI Service;C:\Program Files\Sony\IMAGE CONVERTER 3\ICScsiSV.exe [2007-01-26 11:39]
S3 IcVzMonLauncher;IcVzMonLauncher;"C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMonLauncher.exe" [2007-01-26 11:38]
S3 Image Converter video recording monitor for VAIO Entertainment;Image Converter video recording monitor for VAIO Entertainment;C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMon.exe [2007-01-26 11:38]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\k510bus.sys [2007-03-01 14:25]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k510mdfl.sys [2007-03-01 14:25]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\k510mdm.sys [2007-03-01 14:25]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\k510mgmt.sys [2007-03-01 14:25]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\k510obex.sys [2007-03-01 14:25]
S3 MemStPCI;Sony Memory Stick controller (PCI);C:\WINDOWS\system32\DRIVERS\MemStPCI.SYS [2004-08-03 23:00]
S3 pohci13F;pohci13F;C:\DOCUME~1\Asif\LOCALS~1\Temp\pohci13F.sys []

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-03 13:12:00
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\MSN Messenger\usnsvc.exe
.
**************************************************************************
.
Completion time: 2008-03-03 13:14:46 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-03 13:14:40
.
2008-02-13 12:12:58 --- E O F ---



HIJACKTHIS LOG
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:18:00, on 03/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
d:\elsawin\bin\LcSvrAdm.exe
d:\elsawin\bin\LcSvrDba.exe
d:\elsawin\bin\LcSvrHis.exe
d:\elsawin\bin\LcSvrKdS.exe
d:\elsawin\bin\LcSvrPas.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\MsPMSPSv.exe
d:\elsawin\bin\LcSvrAuf.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE
D:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [EPSON Stylus C46 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE" /P23 "EPSON Stylus C46 Series" /O6 "USB001" /M "Stylus C46"
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DAEMON Tools] "d:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BBC News alerts] D:\Program Files\BBC News alerts\skinkers.exe
O4 - HKLM\..\Policies\Explorer\Run: [9WkqTfjoCX] rundll32.exe "C:\WINDOWS\nargryxu.dll",DllCleanServer
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [ITD7] "C:\Program Files\Steganos Internet Trace Destructor 7\ITD7.exe" -firstboot (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [ITD7] "C:\Program Files\Steganos Internet Trace Destructor 7\ITD7.exe" -firstboot (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [ITD7] "C:\Program Files\Steganos Internet Trace Destructor 7\ITD7.exe" -firstboot (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = D:\Program Files\microsoft office xp\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Transfer by Image Converter 3 - C:\PROGRAM FILES\SONY\IMAGE CONVERTER 3\menu.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=www.google.com
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://courses.learndirect.co.uk/pro...er/awswaxf.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://campuscentercam.its.wesleyan.edu/activex/AMC.cab
O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} -
O16 - DPF: {B0067CA5-2C37-4C6B-AAEC-5E2CE8635061} (FontDown Class) - http://www.qurancomplex.org/Downloads/FontSmooth.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: iiffcaw - iiffcaw.dll (file missing)
O20 - Winlogon Notify: winmoy32 - winmoy32.dll (file missing)
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Image Converter SCSI Service (ICScsiSV) - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\ICScsiSV.exe
O23 - Service: IcVzMonLauncher - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMonLauncher.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ELSA Administration Service (LcSvrAdm) - Volkswagen AG - d:\elsawin\bin\LcSvrAdm.exe
O23 - Service: ELSA Auftragsverwaltungs Service (LcSvrAuf) - Volkswagen AG - d:\elsawin\bin\LcSvrAuf.exe
O23 - Service: ELSA DBA Server (LcSvrDba) - Volkswagen AG - d:\elsawin\bin\LcSvrDba.exe
O23 - Service: ELSA Historie Server (LcSvrHis) - Volkswagen AG - d:\elsawin\bin\LcSvrHis.exe
O23 - Service: ELSA KD-Nummern Server (LcSvrKds) - Volkswagen AG - d:\elsawin\bin\LcSvrKdS.exe
O23 - Service: ELSA PASS Server (LcSvrPAS) - Volkswagen AG - d:\elsawin\bin\LcSvrPas.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 9871 bytes
Reputation Points: 10
Solved Threads: 0
Newbie Poster
pete17 is offline Offline
20 posts
since Feb 2008
Mar 3rd, 2008
0

Re: help required

Hi pete

Scan with HijackThis and check the following entries (If they still exist) (make sure not to miss any)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} -



Remember to close all other windows and click Fix Checked

-------------------------------


1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

Quote ...
File::
C:\WINDOWS\nargryxu.dll
C:\WINDOWS\9WkqTfjoCX.exe
C:\WINDOWS\system32\mgmrwmrv.exe
C:\WINDOWS\rijidgne.exe
C:\WINDOWS\system32\winfrun32.bin
C:\WINDOWS\obmnateh.exe
C:\WINDOWS\pskt.ini
C:\WINDOWS\BMbfd2f053.xml
Folder::
C:\Program Files\Enigma Software Group
C:\WINDOWS\ifbkcsif
Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BBC News alerts"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"=-
"QuickTime Task"=-
"AGEIA PhysX SysTray"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"9WkqTfjoCX"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iiffcaw]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winmoy32]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BBC News alerts]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGEIA PhysX SysTray]
Driver::
pohci13F

Save this as CFScript.txt, in the same location as ComboFix.exe


Click image for larger version

Name:	CFScript.gif
Views:	66
Size:	27.1 KB
ID:	5300


Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt"

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall


-------------------------------

Establish an internet connection & perform an online scan with Internet Explorer at Kaspersky Online Scanner

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure to:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.

-------------------------------

Upload this file C:\WINDOWS\system32\windrv.sys to http://virusscan.jotti.org/ and submit it. Wait for the analysis and post it here in your next reply.

-------------------------------
Required Logs

c:\ComboFix.txt
Kaspersky report
Jotti results
new HijackThis log << taken after the online scan


Please also provide an update on system behaviour
Reputation Points: 11
Solved Threads: 10
Junior Poster
MoralTerror is offline Offline
127 posts
since Jul 2007
Mar 4th, 2008
0

Re: help required

hi there, since i performed the combifix the pc has been running fine, no popups at all, i'm over the moon thanks very much. i did do what you told me to on the last reply though. the results of the hjt show prosearching but even when i fix them they still appear on the next scan, but still pc is fine. i ran the combofix as prescribed. when i ran the kaspersky online scan, because it was going to take some time , i went to bed. after a few hours sleep checked pc and xoftspy se had performed a scan, dont no how that happened.so i closed it. the kaspersky had done the scan but there was no option to save a log report. it had found 7 viruses and 63 suspicious objects but no report other than that. when i clicked stop scan (which was the only button to click) pop up said you have not saved scan report do you want to continue, checked again but no save report anywhere, so unfortunately had to close it with no report. that was a shame as it had ran for 4.5 hours. i ran the jotti scan on the file you mentioned except my file did noy have the .sys at the end of it. the scan came clear as the results show but at the bottom of the jotti page was some other report but i am not sure whether it applies to my pc as therr was a similar report before the scan, not sure if it was the same, dont think it was. sorry for the long winded report but look forward to your reply. thanks in the meantime, pc still running fine
start with the hjt log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 05:12:26, on 04/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
d:\elsawin\bin\LcSvrAdm.exe
d:\elsawin\bin\LcSvrDba.exe
d:\elsawin\bin\LcSvrHis.exe
d:\elsawin\bin\LcSvrKdS.exe
d:\elsawin\bin\LcSvrPas.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\MsPMSPSv.exe
d:\elsawin\bin\LcSvrAuf.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE
D:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [EPSON Stylus C46 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE /P23 "EPSON Stylus C46 Series" /O6 "USB001" /M "Stylus C46"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DAEMON Tools] "d:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BBC News alerts] D:\Program Files\BBC News alerts\skinkers.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [ITD7] "C:\Program Files\Steganos Internet Trace Destructor 7\ITD7.exe" -firstboot (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [ITD7] "C:\Program Files\Steganos Internet Trace Destructor 7\ITD7.exe" -firstboot (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [ITD7] "C:\Program Files\Steganos Internet Trace Destructor 7\ITD7.exe" -firstboot (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = D:\Program Files\microsoft office xp\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Transfer by Image Converter 3 - C:\PROGRAM FILES\SONY\IMAGE CONVERTER 3\menu.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=www.google.com
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://courses.learndirect.co.uk/pro...er/awswaxf.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://campuscentercam.its.wesleyan.edu/activex/AMC.cab
O16 - DPF: {B0067CA5-2C37-4C6B-AAEC-5E2CE8635061} (FontDown Class) - http://www.qurancomplex.org/Downloads/FontSmooth.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Image Converter SCSI Service (ICScsiSV) - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\ICScsiSV.exe
O23 - Service: IcVzMonLauncher - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMonLauncher.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ELSA Administration Service (LcSvrAdm) - Volkswagen AG - d:\elsawin\bin\LcSvrAdm.exe
O23 - Service: ELSA Auftragsverwaltungs Service (LcSvrAuf) - Volkswagen AG - d:\elsawin\bin\LcSvrAuf.exe
O23 - Service: ELSA DBA Server (LcSvrDba) - Volkswagen AG - d:\elsawin\bin\LcSvrDba.exe
O23 - Service: ELSA Historie Server (LcSvrHis) - Volkswagen AG - d:\elsawin\bin\LcSvrHis.exe
O23 - Service: ELSA KD-Nummern Server (LcSvrKds) - Volkswagen AG - d:\elsawin\bin\LcSvrKdS.exe
O23 - Service: ELSA PASS Server (LcSvrPAS) - Volkswagen AG - d:\elsawin\bin\LcSvrPas.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 9993 bytes






the results of the combifix

ComboFix 08-03-03.6 - Asif 2008-03-03 21:13:34.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.248 [GMT 0:00]
Running from: C:\Documents and Settings\Asif\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Asif\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\9WkqTfjoCX.exe
C:\WINDOWS\BMbfd2f053.xml
C:\WINDOWS\nargryxu.dll
C:\WINDOWS\obmnateh.exe
C:\WINDOWS\pskt.ini
C:\WINDOWS\rijidgne.exe
C:\WINDOWS\system32\mgmrwmrv.exe
C:\WINDOWS\system32\winfrun32.bin
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Enigma Software Group
C:\Program Files\Enigma Software Group\SpyHunter\AXList.txt
C:\Program Files\Enigma Software Group\SpyHunter\scan.log
C:\Program Files\Enigma Software Group\SpyHunter\spyhunter.log
C:\Program Files\Enigma Software Group\SpyHunter\support.log
C:\WINDOWS\9WkqTfjoCX.exe
C:\WINDOWS\BMbfd2f053.xml
C:\WINDOWS\ifbkcsif
C:\WINDOWS\ifbkcsif\1.png
C:\WINDOWS\ifbkcsif\2.png
C:\WINDOWS\ifbkcsif\3.png
C:\WINDOWS\ifbkcsif\4.png
C:\WINDOWS\ifbkcsif\5.png
C:\WINDOWS\ifbkcsif\6.png
C:\WINDOWS\ifbkcsif\7.png
C:\WINDOWS\ifbkcsif\8.png
C:\WINDOWS\ifbkcsif\9.png
C:\WINDOWS\ifbkcsif\bottom-rc.gif
C:\WINDOWS\ifbkcsif\config.png
C:\WINDOWS\ifbkcsif\content.png
C:\WINDOWS\ifbkcsif\download.gif
C:\WINDOWS\ifbkcsif\frame-bg.gif
C:\WINDOWS\ifbkcsif\frame-bottom-left.gif
C:\WINDOWS\ifbkcsif\frame-h1bg.gif
C:\WINDOWS\ifbkcsif\head.png
C:\WINDOWS\ifbkcsif\icon.png
C:\WINDOWS\ifbkcsif\indexwp.html
C:\WINDOWS\ifbkcsif\main.css
C:\WINDOWS\ifbkcsif\memory-prots.png
C:\WINDOWS\ifbkcsif\net.png
C:\WINDOWS\ifbkcsif\pc-mag.gif
C:\WINDOWS\ifbkcsif\pc.gif
C:\WINDOWS\ifbkcsif\poloska1.png
C:\WINDOWS\ifbkcsif\poloska2.png
C:\WINDOWS\ifbkcsif\poloska3.png
C:\WINDOWS\ifbkcsif\promowp1.html
C:\WINDOWS\ifbkcsif\promowp2.html
C:\WINDOWS\ifbkcsif\promowp3.html
C:\WINDOWS\ifbkcsif\promowp4.html
C:\WINDOWS\ifbkcsif\promowp5.html
C:\WINDOWS\ifbkcsif\reg.png
C:\WINDOWS\ifbkcsif\repair.png
C:\WINDOWS\ifbkcsif\scr-1.png
C:\WINDOWS\ifbkcsif\scr-2.png
C:\WINDOWS\ifbkcsif\start.png
C:\WINDOWS\ifbkcsif\styles.css
C:\WINDOWS\ifbkcsif\Thumbs.db
C:\WINDOWS\ifbkcsif\top-rc.gif
C:\WINDOWS\ifbkcsif\vline.gif
C:\WINDOWS\ifbkcsif\wp.png
C:\WINDOWS\nargryxu.dll
C:\WINDOWS\obmnateh.exe
C:\WINDOWS\PerfInfo
C:\WINDOWS\PerfInfo\9WkqTfjoCXwp.exe
C:\WINDOWS\pskt.ini
C:\WINDOWS\rijidgne.exe
C:\WINDOWS\system32\mgmrwmrv.exe
C:\WINDOWS\system32\winfrun32.bin

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_POHCI13F
-------\pohci13F


((((((((((((((((((((((((( Files Created from 2008-02-03 to 2008-03-03 )))))))))))))))))))))))))))))))
.

2008-03-01 22:58 . 2008-03-01 22:58 <DIR> d-------- C:\Documents and Settings\Asif\Application Data\Grisoft
2008-03-01 22:58 . 2007-05-30 12:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-01 22:57 . 2008-03-01 22:57 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
2008-03-01 01:00 . 2008-03-01 01:00 <DIR> d-------- C:\Program Files\Webroot
2008-03-01 01:00 . 2008-03-01 01:00 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2008-03-01 01:00 . 2008-03-01 01:00 <DIR> d-------- C:\Documents and Settings\Asif\Application Data\Webroot
2008-03-01 01:00 . 2008-03-01 01:00 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Webroot
2008-03-01 01:00 . 2007-10-01 16:40 1,526,072 --a------ C:\WINDOWS\WRSetup.dll
2008-03-01 01:00 . 2007-10-01 16:24 163,640 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2008-03-01 01:00 . 2007-10-01 16:24 23,864 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2008-03-01 01:00 . 2007-10-01 16:24 21,816 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2008-03-01 01:00 . 2007-10-01 16:24 20,280 --a------ C:\WINDOWS\system32\drivers\SSFS0BB9.sys
2008-02-27 22:51 . 2008-02-27 22:51 1,152 --a------ C:\WINDOWS\system32\windrv.sys
2008-02-25 11:19 . 2008-02-25 11:42 <DIR> d-------- C:\Program Files\NoAdware5.0
2008-02-24 18:22 . 2008-02-24 18:22 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-02-23 21:12 . 2008-02-23 21:12 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Corel
2008-02-23 21:05 . 2008-02-23 21:05 <DIR> d-------- C:\Program Files\Common Files\Corel
2008-02-20 15:53 . 2008-02-23 01:20 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-20 15:53 . 2008-02-20 15:53 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-12 17:58 . 2008-02-12 17:58 <DIR> d-------- C:\Program Files\Log
2008-02-12 17:24 . 2008-02-12 17:24 <DIR> d-------- C:\Program Files\AddonLog
2008-02-12 17:24 . 2007-02-02 19:39 217,088 --a------ C:\Program Files\SsMidAccess.dll
2008-02-12 17:24 . 2007-02-02 19:39 81,920 --a------ C:\Program Files\Cddb2Access.dll
2008-02-12 17:23 . 2008-02-12 17:23 <DIR> d-------- C:\Program Files\Data
2008-02-12 17:23 . 2007-02-05 10:11 5,961,272 --a------ C:\Program Files\Omgjbox.exe
2008-02-12 17:23 . 2007-02-02 19:35 1,323,008 --a------ C:\Program Files\OmgjboxRes.dll
2008-02-12 17:23 . 2007-02-05 10:11 1,201,720 --a------ C:\Program Files\Omgbkup.exe
2008-02-12 17:23 . 2005-03-21 20:30 1,060,864 --a------ C:\Program Files\mfc71.dll
2008-02-12 17:23 . 2007-02-05 10:10 816,696 --a------ C:\Program Files\OMG2OMA.exe
2008-02-12 17:23 . 2007-02-02 19:42 798,720 --a------ C:\Program Files\Si.dll
2008-02-12 17:23 . 2007-02-05 10:10 603,704 --a------ C:\Program Files\Omg1to2.exe
2008-02-12 17:23 . 2007-02-05 10:10 603,704 --a------ C:\Program Files\Ojbsir.exe
2008-02-12 17:23 . 2007-02-02 19:08 536,576 --a------ C:\Program Files\OMG2OMARes.dll
2008-02-12 17:23 . 2007-02-02 20:03 528,384 --a------ C:\Program Files\OjbSirRes.dll
2008-02-12 17:23 . 2005-03-21 20:30 499,712 --a------ C:\Program Files\msvcp71.dll
2008-02-12 17:23 . 2007-02-05 10:11 476,728 --a------ C:\Program Files\SSAAD.exe
2008-02-12 17:23 . 2007-02-02 19:41 434,176 --a------ C:\Program Files\Items.dll
2008-02-12 17:23 . 2007-02-02 19:39 397,312 --a------ C:\Program Files\SsEncMp3.dll
2008-02-12 17:23 . 2005-03-21 20:34 352,256 --a------ C:\Program Files\ijl15.dll
2008-02-12 17:23 . 2005-03-21 20:30 348,160 --a------ C:\Program Files\msvcr71.dll
2008-02-12 17:23 . 2007-02-02 19:39 196,608 --a------ C:\Program Files\RGraph.dll
2008-02-12 17:23 . 2006-12-19 15:03 192,512 --a------ C:\Program Files\XCoreAudio.dll
2008-02-12 17:23 . 2007-02-02 20:07 143,360 --a------ C:\Program Files\OmgbkupRes.dll
2008-02-12 17:23 . 2006-12-26 17:57 143,360 --a------ C:\Program Files\dunzip32.dll
2008-02-12 17:23 . 2007-02-02 19:40 131,072 --a------ C:\Program Files\SsMtp.dll
2008-02-12 17:23 . 2007-02-02 19:36 106,496 --a------ C:\Program Files\RBasis.dll
2008-02-12 17:23 . 2005-03-21 20:30 106,496 --a------ C:\Program Files\atl71.dll
2008-02-12 17:23 . 2007-02-02 19:46 94,208 --a------ C:\Program Files\DMPInternet.dll
2008-02-12 17:23 . 2007-02-02 19:47 69,632 --a------ C:\Program Files\XPanel.dll
2008-02-12 17:23 . 2007-02-02 19:39 65,536 --a------ C:\Program Files\SsEncWma.dll
2008-02-12 17:23 . 2005-03-21 20:30 65,536 --a------ C:\Program Files\JETCOMP.exe
2008-02-12 17:23 . 2007-02-02 19:42 57,344 --a------ C:\Program Files\SsTpl.dll
2008-02-12 17:23 . 2007-02-02 19:39 49,152 --a------ C:\Program Files\SsProxy.dll
2008-02-12 17:23 . 2007-02-02 19:46 45,056 --a------ C:\Program Files\GenMediaKey.dll
2008-02-12 17:23 . 2007-02-05 10:10 38,456 --a------ C:\Program Files\AppReg.exe
2008-02-12 17:23 . 2007-02-02 19:42 32,768 --a------ C:\Program Files\HelpHelper.dll
2008-02-12 17:23 . 2007-02-02 19:08 17,920 --a------ C:\Program Files\XThumbnail.dll
2008-02-12 17:23 . 2007-02-02 19:46 13,312 --a------ C:\Program Files\WtsNotify.dll
2008-02-12 17:23 . 2007-02-02 19:07 12,800 --a------ C:\Program Files\Lam.dll
2008-02-12 17:23 . 2007-02-02 19:05 3,584 --a------ C:\Program Files\Omg1to2Res.dll
2008-02-12 17:08 . 2008-02-12 17:09 <DIR> d-------- C:\ss43_dl
2008-02-12 14:08 . 2008-02-12 14:08 <DIR> d-------- C:\Documents and Settings\All Users\SonicStage
2008-02-12 13:57 . 2001-09-13 02:15 90,112 --------- C:\WINDOWS\snymsico.dll
2008-02-12 13:57 . 2002-08-08 15:51 38,951 --------- C:\WINDOWS\system32\drivers\NETMDUSB.sys
2008-02-12 13:57 . 2005-10-31 10:46 36,679 --------- C:\WINDOWS\system32\drivers\NETMD052.sys
2008-02-12 13:57 . 2003-11-10 12:31 36,232 --------- C:\WINDOWS\system32\drivers\NETMD033.sys
2008-02-12 13:57 . 2003-04-01 18:55 35,319 --------- C:\WINDOWS\system32\drivers\NETMD031.sys
2008-02-12 13:56 . 2008-02-13 11:18 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony Corporation
2008-02-12 13:56 . 2007-01-13 08:24 770,048 --a------ C:\WINDOWS\system32\CDDBUISony.dll
2008-02-12 13:56 . 2007-01-13 08:22 655,360 --a------ C:\WINDOWS\system32\CDDBControlSony.dll
2008-02-12 13:56 . 2007-01-13 08:22 589,824 --a------ C:\WINDOWS\system32\CddbMusicIDSony.dll
2008-02-12 13:56 . 2007-01-13 08:25 532,480 --a------ C:\WINDOWS\system32\CddbPlaylist2Sony.dll
2008-02-12 13:56 . 2006-10-29 01:00 116,472 --------- C:\WINDOWS\system32\pxcpyi64.exe
2008-02-12 13:56 . 2007-01-13 08:24 73,728 --a------ C:\WINDOWS\system32\CddbLinkSony.dll
2008-02-12 13:55 . 2008-02-13 11:12 <DIR> d-------- C:\Program Files\Sony
2008-02-12 13:54 . 2008-02-18 12:42 <DIR> d-------- C:\Program Files\Common Files\Sony Shared
2008-02-12 13:54 . 2008-02-13 11:18 <DIR> d-------- C:\Documents and Settings\Asif\Application Data\Sony Corporation
2008-02-12 13:10 . 2004-08-03 23:00 26,112 --a------ C:\WINDOWS\system32\drivers\MemStPCI.SYS
2008-02-12 13:10 . 2004-08-03 23:00 26,112 --a--c--- C:\WINDOWS\system32\dllcache\memstpci.sys
2008-02-08 23:09 . 2008-02-09 11:53 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-02-07 10:48 . 2008-02-07 10:48 2,560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2008-02-06 21:33 . 2008-02-06 21:33 <DIR> d-------- C:\WINDOWS\RegCure
2008-02-04 12:05 . 2008-02-04 12:05 <DIR> d-------- C:\Program Files\iPod
2008-02-04 12:01 . 2008-02-04 12:03 <DIR> d-------- C:\Program Files\QuickTime
2008-02-04 12:00 . 2008-02-04 12:00 <DIR> d-------- C:\Program Files\Apple Software Update
2008-02-04 11:59 . 2008-02-04 11:59 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-02-04 11:59 . 2008-02-04 11:59 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-01 01:01 --------- d-----w C:\Documents and Settings\Asif\Application Data\uTorrent
2008-02-27 22:38 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
2008-02-26 09:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-23 21:17 --------- d-----w C:\Documents and Settings\Asif\Application Data\Corel
2008-02-18 12:41 --------- d-----w C:\Program Files\DivX
2008-02-09 09:37 --------- d-----w C:\Program Files\Google
2008-02-06 09:41 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-04 12:06 --------- d-----w C:\Documents and Settings\Asif\Application Data\Apple Computer
2008-02-04 12:03 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2008-01-27 18:28 --------- d-----w C:\Documents and Settings\Guest\Application Data\Windows Desktop Search
2007-12-29 17:53 0 ----a-w C:\Documents and Settings\Asif\Application Data\wklnhst.dat
2007-08-03 20:32 17,144 -c--a-w C:\Documents and Settings\Asif\Application Data\GDIPFONTCACHEV1.DAT
2007-02-02 20:09 25,600 ----a-w C:\Program Files\SsVerChk.ocx
2007-02-02 20:08 65,536 ----a-w C:\Program Files\StdoutSs2.ax
2007-02-02 20:08 53,248 ----a-w C:\Program Files\SonyWavParser2.ax
2007-01-16 18:13 7,453 ----a-w C:\Program Files\Readme.txt
2005-08-25 09:10 81,920 ----a-w C:\Program Files\SonyFsConvFilter.ax
2005-03-21 20:30 7 ----a-w C:\Program Files\initials.ini
2004-06-18 11:05 45,056 -c--a-w C:\WINDOWS\inf\Slntinst.exe
2003-08-22 11:09 45,056 -c--a-w C:\WINDOWS\inf\slntinst_staticW2k.exe
2006-12-07 21:37 56 -csh--r C:\WINDOWS\system32\7DCBC830BD.sys
2007-02-12 21:25 3,350 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 16:24 1694208]
"AWMON"="C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" [2005-05-25 11:12 517632]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"BBC News alerts"="D:\Program Files\BBC News alerts\skinkers.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-03-09 14:29 7561216]
"nwiz"="nwiz.exe" [2006-03-09 14:29 1519616 C:\WINDOWS\system32\nwiz.exe]
"EPSON Stylus C46 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.exe" [2004-01-13 18:00 99840]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-03-09 14:29 86016]
"DAEMON Tools"="d:\Program Files\DAEMON Tools\daemon.exe" [2005-11-08 23:00 128920]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 09:50 155648]
"WinampAgent"="D:\Program Files\Winamp\winampa.exe" [ ]
"QuickTime Task"="D:\Program Files\qttask.exe" [ ]
"AGEIA PhysX SysTray"="C:\Program Files\AGEIA Technologies\TrayIcon.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:56 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ITD7"="C:\Program Files\Steganos Internet Trace Destructor 7\ITD7.exe" [2005-05-02 10:31 274432]

C:\Documents and Settings\Asif\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - D:\Program Files\microsoft office xp\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="LogonUI.EXE"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Metacafe.lnk]
backup=C:\WINDOWS\pss\Metacafe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Asif^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Asif\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Asif^Start Menu^Programs^Startup^MetaCafe.lnk]
backup=C:\WINDOWS\pss\MetaCafe.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AWMON]
--a------ 2005-05-25 11:12 517632 C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2005-11-08 23:00 128920 d:\Program Files\DAEMON Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 09:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-03-09 14:29 86016 C:\WINDOWS\system32\NvMcTray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Documents and Settings\\Asif\\My Documents\\utorrent.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"D:\\Program Files\\microsoft office xp\\Office12\\OUTLOOK.EXE"=
"D:\\Program Files\\microsoft office xp\\Office12\\groove.exe"=
"D:\\Program Files\\microsoft office xp\\Office12\\ONENOTE.EXE"=
"D:\\Program Files\\iTunes.exe"=

R2 LcSvrAdm;ELSA Administration Service;d:\elsawin\bin\LcSvrAdm.exe [2003-03-13 15:46]
R2 LcSvrDba;ELSA DBA Server;d:\elsawin\bin\LcSvrDba.exe [2003-03-13 15:38]
R2 LcSvrHis;ELSA Historie Server;d:\elsawin\bin\LcSvrHis.exe [2003-03-13 15:42]
R2 LcSvrKds;ELSA KD-Nummern Server;d:\elsawin\bin\LcSvrKdS.exe [2003-03-13 15:51]
R2 LcSvrPAS;ELSA PASS Server;d:\elsawin\bin\LcSvrPas.exe [2003-03-13 16:06]
R3 BTCOMM;BTCOMM;C:\WINDOWS\system32\drivers\Btcomm.sys [2004-09-28 16:18]
R3 BTKRNBDG;Bluetooth COM Bridge;C:\WINDOWS\system32\DRIVERS\btkrnbdg.sys [2003-03-18 11:31]
R3 LcSvrAuf;ELSA Auftragsverwaltungs Service;d:\elsawin\bin\LcSvrAuf.exe [2003-03-13 15:41]
R3 vad_multi;Windigo Virtual Audio Device (WDM);C:\WINDOWS\system32\drivers\vadmulti.sys [2005-06-30 12:57]
S3 CSRBC01;%CSRBC01.SvcDesc%;C:\WINDOWS\system32\Drivers\csrbc01.sys [2005-06-28 19:46]
S3 ICScsiSV;Image Converter SCSI Service;C:\Program Files\Sony\IMAGE CONVERTER 3\ICScsiSV.exe [2007-01-26 11:39]
S3 IcVzMonLauncher;IcVzMonLauncher;"C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMonLauncher.exe" [2007-01-26 11:38]
S3 Image Converter video recording monitor for VAIO Entertainment;Image Converter video recording monitor for VAIO Entertainment;C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMon.exe [2007-01-26 11:38]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\k510bus.sys [2007-03-01 14:25]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k510mdfl.sys [2007-03-01 14:25]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\k510mdm.sys [2007-03-01 14:25]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\k510mgmt.sys [2007-03-01 14:25]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\k510obex.sys [2007-03-01 14:25]
S3 MemStPCI;Sony Memory Stick controller (PCI);C:\WINDOWS\system32\DRIVERS\MemStPCI.SYS [2004-08-03 23:00]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-03 21:18:39
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\MSN Messenger\usnsvc.exe
.
**************************************************************************
.
Completion time: 2008-03-03 21:21:13 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-03 21:21:08
ComboFix2.txt 2008-03-03 13:14:47
.
2008-02-13 12:12:58 --- E O F ---


jotti scan results

Scan taken on 04 Mar 2008 05:00:38 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Rising Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing




the other info at the bottom of the jotti page;

Last file scanned at least one scanner reported something about: bxlrvps.dll (MD5: 868f972e28faa7aad561ae97de2a30bb, size: 323584 bytes), detected by:

Scanner Malware name
A-Squared X
AntiVir ADSPY/Agent.PB
ArcaVir Adware.Vapsup.Bvr
Avast Win32:Agent-LTS
AVG Antivirus X
BitDefender X
ClamAV X
CPsecure X
Dr.Web Trojan.Mutastik
F-Prot Antivirus X
F-Secure Anti-Virus not-a-virus:AdWare.Win32.Vapsup.bvr (4, 1, 400)
Fortinet X
Ikarus Virus.Win32.Agent.LTS
Kaspersky Anti-Virus not-a-virus:AdWare.Win32.Vapsup.bvr
NOD32 a variant of Win32/Adware.Vapsup.X application
Norman Virus Control W32/Vapsup.BCX
Panda Antivirus X
Rising Antivirus X
Sophos Antivirus X
VirusBuster X
VBA32 Downloader.Zlob.7
Reputation Points: 10
Solved Threads: 0
Newbie Poster
pete17 is offline Offline
20 posts
since Feb 2008
Mar 4th, 2008
0

Re: help required

Hi pete

I see no evidence of an Anti-virus program on board. Please install update and run an Anti-virus (or if you do have 1 make sure it is enabled). Here are some links for anti-virus software.

AVG
Avast
BitDefender Free Edition v7.2

*NOTE It is important you only have 1 anti-virus program running.

---------------------------------------

Please disable the following programs (and your anti-virus program) so they don't interfere with the fixes. You can re-enable them again after completing the steps in this post.

AD-AWARE AD-WATCH
  • Right click on the Ad-Watch icon in the system tray.
  • At the bottom of the screen there will be two checkable items called "Active" and "Automatic".
    • Active: This will turn Ad-Watch On\Off without closing it.
    • Automatic: Suspicious activity will be blocked automatically.
  • Uncheck both of those boxes.
  • (When done, you can re-enable it using the same steps but this time check both boxes.)

AVG ANTI-SPYWARE
  • Launch AVG Anti-Spyware.
  • From the "Status" menu, select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'.
  • Then right click on AVG Anti-Spyware in the system tray and uncheck "Start with Windows".


SPY SWEEPER
  • Open Spy Sweeper and click on Options > Program Options and uncheck "load at windows startup".
  • On the left click "shields" and then uncheck everything there.
  • Uncheck "home page shield".
  • Uncheck "automatically restore default without notification".
  • Exit the program.
  • (When we are done, you can re-enable it using the same steps but this time reverse them.)


---------------------------------------

Scan with HijackThis and check the following entries (If they still exist) (make sure not to miss any)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKCU\..\Run: [BBC News alerts] D:\Program Files\BBC News alerts\skinkers.exe


Remember to close all other windows and click Fix Checked

---------------------------------------

Please re-scan at Kaspersky, once the scan has completed the 'Stop Scan' button will no longer be available and the 'Save Report' button will be active. Leaving your other security programs disabled may speed the scan up a bit. You can disconnect from the internet once the scan has started, remember to re-connect BEFORE clicking on Save Report.

---------------------------------------
Required Logs

Kaspersky report
new HijackThis log
Reputation Points: 11
Solved Threads: 10
Junior Poster
MoralTerror is offline Offline
127 posts
since Jul 2007
Mar 4th, 2008
0

Re: help required

hi. installed and ran avg anti virus and then hjt (log below). i then ran kaspersky again but as before does not give me an option to save the report. it indicates that the scan has been 'done' but the stop scan button is the only option to click. at the bottom of the windows page appears the yellow warning sign followed by error on page. the number of viruses found has decreased to 6 and number of infected to 17 down from 63


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:54:22, on 04/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
d:\elsawin\bin\LcSvrAdm.exe
d:\elsawin\bin\LcSvrDba.exe
d:\elsawin\bin\LcSvrHis.exe
d:\elsawin\bin\LcSvrKdS.exe
d:\elsawin\bin\LcSvrPas.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\MsPMSPSv.exe
d:\elsawin\bin\LcSvrAuf.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [EPSON Stylus C46 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE" /P23 "EPSON Stylus C46 Series" /O6 "USB001" /M "Stylus C46"
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DAEMON Tools] "d:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [ITD7] "C:\Program Files\Steganos Internet Trace Destructor 7\ITD7.exe" -firstboot (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [ITD7] "C:\Program Files\Steganos Internet Trace Destructor 7\ITD7.exe" -firstboot (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [ITD7] "C:\Program Files\Steganos Internet Trace Destructor 7\ITD7.exe" -firstboot (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = D:\Program Files\microsoft office xp\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Transfer by Image Converter 3 - C:\PROGRAM FILES\SONY\IMAGE CONVERTER 3\menu.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=www.google.com
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://courses.learndirect.co.uk/pro...er/awswaxf.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://campuscentercam.its.wesleyan.edu/activex/AMC.cab
O16 - DPF: {B0067CA5-2C37-4C6B-AAEC-5E2CE8635061} (FontDown Class) - http://www.qurancomplex.org/Downloads/FontSmooth.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Image Converter SCSI Service (ICScsiSV) - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\ICScsiSV.exe
O23 - Service: IcVzMonLauncher - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMonLauncher.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\IMAGE CONVERTER 3\IcVzMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ELSA Administration Service (LcSvrAdm) - Volkswagen AG - d:\elsawin\bin\LcSvrAdm.exe
O23 - Service: ELSA Auftragsverwaltungs Service (LcSvrAuf) - Volkswagen AG - d:\elsawin\bin\LcSvrAuf.exe
O23 - Service: ELSA DBA Server (LcSvrDba) - Volkswagen AG - d:\elsawin\bin\LcSvrDba.exe
O23 - Service: ELSA Historie Server (LcSvrHis) - Volkswagen AG - d:\elsawin\bin\LcSvrHis.exe
O23 - Service: ELSA KD-Nummern Server (LcSvrKds) - Volkswagen AG - d:\elsawin\bin\LcSvrKdS.exe
O23 - Service: ELSA PASS Server (LcSvrPAS) - Volkswagen AG - d:\elsawin\bin\LcSvrPas.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 9460 bytes
Reputation Points: 10
Solved Threads: 0
Newbie Poster
pete17 is offline Offline
20 posts
since Feb 2008
Mar 4th, 2008
0

Re: help required

OK pete try this one
  • Please go to the following link ESET Online Scanner Link
  • Tick the box YES, I accept the Terms Of Use
  • Click the Start button
  • Now click the Install button
  • Click Start

    The scanner engine will initialise and update
  • Do Not tick the box Remove found threats
  • Click the Scan button

    The scan will now run, please be patient
  • When the scan finishes click the Details tab
  • Copy and paste the contents of the %ProgramFiles%\EsetOnlineScanner\log.txt back here.
Reputation Points: 11
Solved Threads: 10
Junior Poster
MoralTerror is offline Offline
127 posts
since Jul 2007
Mar 5th, 2008
0

Re: help required

hi, results of eset scan are, 2 threats found. clicked details to reveal;

Win32/Adware.Virtumonde application
C\:QooBox\Quarantine\C\Windows\system32\jkkhhih.dll.vir

Win32/Adware.UltimateDefender application
C:\QooBox\Quarantine\C\Windows\9WkgTfjoCX.exe.vir

it would not allow copy & paste so typed the above in and no sign of, %ProgramFiles%\EsetOnlineScanner\log.txt

would it be ok for me to use my ebay account and access my online bank account now?
much thanks
Reputation Points: 10
Solved Threads: 0
Newbie Poster
pete17 is offline Offline
20 posts
since Feb 2008

This thread is solved

Either the thread starter or a moderator has marked this thread as solved. You can most likely trust the responses and answers given. There is most likely no reason for any further responses to be posted here. If you have a related question, please start a new thread in this forum instead.

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Message:
Previous Thread in Viruses, Spyware and other Nasties Forum Timeline: Ahh here we go... Hijack This help...!
Next Thread in Viruses, Spyware and other Nasties Forum Timeline: Desktop Icons when click on will make duplicate shortcut





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC