|
|
Andybib
regular
Reg'd: Thu
Posts: 48
|
|
Hi guys,this is becoming an all too regular occurance,even after following instructions from last postings on how to avoid getting infected!I am running xp sp2 Home on Advent 7082,40GBHDD,1.12GB RAM with Nort I,S.,Spy Guard and Blaster,running Adaware + Spybot occasionally,after disabling NIS in case of conflicts,same for AVG,anti root kit.My problem is regularly getting warnings of new BHOs in IE,plus pop up ads telling me to protect my pivacy.The final straw was an ad.telling me i had so much porn stored on my lappy with visuals,needless to say the missus not very happy,although teenage son finds quite amusing.Please help,i`ve ran several HTs but the logs dont seem to reveal much(in my laymans opinion.I`ve posted a HT log + a Combo f.log,hope this throws some light on the subject.Thanks again in advance,ANDYB ;Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:46:07, on 30/04/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe C:\Program Files\Kontiki\KService.exe C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe C:\WINDOWS\system32\IoctlSvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\SpywareGuard\sgmain.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\SpywareGuard\sgbhp.exe C:\Program Files\Yahoo!\browser\ybrowser.exe C:\PROGRA~1\Yahoo!\browser\ycommon.exe C:\Program Files\Yahoo!\browser\ybrwicon.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.pcservicecall.co.uk O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsof...b?1208406252796 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
-- End of file - 6012 bytes ComboFix 08-04-26.3 - Andy 2008-04-30 19:55:00.4 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.686 [GMT 1:00] Running from: C:\Documents and Settings\Andy\Desktop\ComboFix.exe * Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! .
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) .
C:\WINDOWS\pskt.ini C:\WINDOWS\system32\jkkJdDvu.dll C:\WINDOWS\system32\jkkLFurr.dll C:\WINDOWS\system32\uvDdJkkj.ini C:\WINDOWS\system32\uvDdJkkj.ini2
. ((((((((((((((((((((((((( Files Created from 2008-03-28 to 2008-04-30 ))))))))))))))))))))))))))))))) .
2008-04-30 19:01 . 2008-04-30 19:01 53,312 --a------ C:\WINDOWS\system32\htolfdji.dll 2008-04-30 17:19 . 2008-04-30 17:19 <DIR> d-------- C:\Program Files\UseNeXT 2008-04-29 20:33 . 2008-04-29 22:00 <DIR> d-------- C:\Program Files\coverXP 2008-04-29 20:09 . 2008-04-29 20:09 <DIR> d-------- C:\spoolerlogs 2008-04-29 18:05 . 2008-04-29 18:05 53,312 --a------ C:\WINDOWS\system32\lveaedgc.dll 2008-04-29 18:03 . 2008-04-29 18:03 0 --a------ C:\WINDOWS\BM7fbecf2c.xml 2008-04-27 09:48 . 2008-04-27 09:48 <DIR> d-------- C:\VundoFix Backups 2008-04-27 07:41 . 2007-01-18 13:00 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys 2008-04-27 04:21 . 2008-04-27 04:21 87,608 --a------ C:\Documents and Settings\Andy\Application Data\inst.exe 2008-04-27 02:43 . 2008-04-27 02:50 6,211 --a------ C:\WINDOWS\system32\EPPICResdb0000 2008-04-27 02:43 . 2008-04-27 02:50 117 --a------ C:\WINDOWS\system32\EPPICResdb 2008-04-27 00:46 . 2008-04-27 00:46 0 --a------ C:\WINDOWS\JCMkr32.INI 2008-04-22 19:35 . 2008-04-22 19:35 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\Desktopicon 2008-04-20 18:30 . 2008-04-20 19:04 <DIR> d-------- C:\temp 2008-04-19 22:23 . 2008-04-19 22:23 0 --a------ C:\WINDOWS\tosOBEX.INI 2008-04-19 22:10 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys 2008-04-19 22:10 . 2001-08-17 13:48 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys 2008-04-19 22:06 . 2008-04-19 22:06 <DIR> d-------- C:\Program Files\Toshiba 2008-04-19 20:14 . 2004-08-03 23:10 38,016 --a------ C:\WINDOWS\system32\drivers\bthmodem.sys 2008-04-19 20:14 . 2004-08-03 23:10 38,016 --a--c--- C:\WINDOWS\system32\dllcache\bthmodem.sys 2008-04-19 18:42 . 2008-04-25 05:44 18,413 --a------ C:\Documents and Settings\Andy\Application Data\NMM-MetaData.db 2008-04-19 11:49 . 2008-04-19 11:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TomTom 2008-04-19 11:48 . 2008-04-19 11:48 <DIR> d-------- C:\Program Files\TomTom HOME 2008-04-19 11:47 . 2008-04-19 11:47 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\InstallShield 2008-04-19 10:50 . 2004-08-03 23:08 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys 2008-04-19 10:50 . 2004-08-03 23:08 25,600 --a--c--- C:\WINDOWS\system32\dllcache\usbser.sys 2008-04-19 10:50 . 2008-04-19 10:50 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf 2008-04-19 10:50 . 2008-04-19 10:50 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf 2008-04-19 10:42 . 2008-04-19 10:42 <DIR> d-------- C:\Program Files\Common Files\PCSuite 2008-04-19 10:42 . 2008-04-19 10:42 <DIR> d-------- C:\Program Files\Common Files\Nokia 2008-04-19 10:41 . 2008-04-19 10:41 <DIR> d-------- C:\Program Files\PC Connectivity Solution 2008-04-19 10:41 . 2007-11-29 10:33 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll 2008-04-19 10:41 . 2007-11-29 10:39 95,744 --a------ C:\WINDOWS\system32\nmwcdcocls.dll 2008-04-19 10:41 . 2007-09-17 15:53 21,632 --a------ C:\WINDOWS\system32\drivers\pccsmcfd.sys 2008-04-19 10:41 . 2007-11-29 10:39 19,328 --a------ C:\WINDOWS\system32\drivers\ccdcmbo.sys 2008-04-19 10:41 . 2007-11-29 10:39 16,896 --a------ C:\WINDOWS\system32\drivers\ccdcmb.sys 2008-04-19 10:41 . 2007-11-29 10:39 8,064 --a------ C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys 2008-04-19 10:41 . 2007-11-29 10:39 8,064 --a------ C:\WINDOWS\system32\drivers\usbser_lowerflt.sys 2008-04-17 18:43 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll 2008-04-17 18:43 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui 2008-04-15 05:58 . 2008-04-15 05:58 <DIR> d-------- C:\Program Files\MSXML 6.0 2008-04-13 02:36 . 2008-04-14 20:43 153 --a------ C:\WINDOWS\wininit.ini 2008-04-13 01:29 . 2008-04-13 01:29 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy 2008-04-13 00:29 . 2008-04-13 00:29 <DIR> d-------- C:\Program Files\Trend Micro 2008-04-11 18:59 . 2008-04-11 18:59 <DIR> d-------- C:\Setup 2008-04-11 18:54 . 2008-04-27 10:49 <DIR> d-------- C:\Program Files\AutoCAD Civil 3D 2008 2008-04-11 18:54 . 2008-04-11 18:54 <DIR> d-------- C:\Civil 3D Projects 2008-04-11 17:33 . 2008-04-13 19:03 <DIR> d-------- C:\Program Files\PowerISO 2008-04-10 13:44 . 2008-04-10 13:44 <DIR> d-------- C:\WINDOWS\WinRAR 2008-04-06 18:49 . 2008-04-06 18:53 <DIR> d-------- C:\Program Files\AutoCAD 2009 2008-04-06 18:47 . 2008-04-27 10:47 <DIR> d-------- C:\Program Files\Common Files\Autodesk Shared 2008-04-06 18:36 . 2008-04-27 10:47 <DIR> d-------- C:\Program Files\Autodesk 2008-04-06 16:02 . 2008-04-13 23:12 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\Autodesk 2008-04-06 16:02 . 2008-04-13 23:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Autodesk 2008-04-06 16:02 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll 2008-04-06 16:00 . 2008-04-06 16:00 <DIR> d-------- C:\Program Files\MSBuild 2008-04-06 15:58 . 2008-04-26 11:39 <DIR> d-------- C:\WINDOWS\system32\XPSViewer 2008-04-06 15:57 . 2008-04-06 15:57 <DIR> d-------- C:\Program Files\Reference Assemblies 2008-04-06 15:57 . 2006-06-29 13:07 14,048 --a------ C:\WINDOWS\system32\spmsg2.dll 2008-04-06 13:35 . 2008-04-10 13:47 <DIR> d-------- C:\Program Files\MagicISO 2008-04-04 19:30 . 2008-04-04 19:30 <DIR> d-------- C:\WINDOWS\Performance 2008-04-04 19:30 . 2008-04-04 19:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Corporation 2008-04-04 19:29 . 2008-04-04 19:29 <DIR> d-------- C:\Program Files\Microsoft Windows Vista Upgrade Advisor 2008-04-02 20:58 . 2008-04-02 21:00 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\dvdcss 2008-03-30 14:50 . <DIR> C:\Documents and Settings\Andy\Application Data\NeroDigitalT 2008-03-29 20:58 . 2008-04-30 19:44 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\UseNeXT 2008-03-29 20:09 . 2008-03-29 20:09 <DIR> d-------- C:\Program Files\Softgogo 2008-03-29 17:58 . 2008-02-18 17:21 402,728 --a------ C:\WINDOWS\system32\ImageDrive.cpl 2008-03-29 12:39 . 2008-03-29 12:39 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\vlc 2008-03-29 06:38 . 2008-03-29 06:38 <DIR> d-------- C:\Program Files\VideoLAN 2008-03-29 01:37 . 2008-04-27 04:26 <DIR> d-------- C:\Program Files\DVDFab Platinum 4 2008-03-28 18:50 . 2008-04-27 04:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\1Click DVD Copy Pro 2008-03-26 21:39 . 2008-04-30 17:51 69 --a------ C:\WINDOWS\NeroDigital.ini 2008-03-26 21:37 . 2008-03-26 21:37 2,525 --a------ C:\WINDOWS\system32\NMMediaServer.cfg 2008-03-26 19:24 . 2008-03-26 19:24 <DIR> d-------- C:\Program Files\NeroInstall.bak 2008-03-26 19:21 . 2008-03-26 19:21 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\Nero 2008-03-26 19:17 . 2008-03-26 19:17 <DIR> d-------- C:\Program Files\Nero 2008-03-26 19:17 . 2008-03-26 19:19 <DIR> d-------- C:\Program Files\Common Files\Nero 2008-03-26 19:17 . 2008-03-26 19:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero 2008-03-24 22:48 . 2004-05-04 12:53 1,645,320 --a------ C:\WINDOWS\gdiplus.dll 2008-03-24 22:48 . 2006-05-20 17:16 1,184,984 --a------ C:\WINDOWS\system32\wvc1dmod.dll 2008-03-24 22:48 . 2006-05-11 20:21 626,688 --a------ C:\WINDOWS\system32\vp7vfw.dll 2008-03-24 22:48 . 2006-09-29 13:24 217,127 --a------ C:\WINDOWS\system32\drv43260.dll 2008-03-24 22:48 . 2006-09-29 13:25 208,935 --a------ C:\WINDOWS\system32\drv33260.dll 2008-03-24 22:48 . 2006-09-29 13:26 176,165 --a------ C:\WINDOWS\system32\drv23260.dll 2008-03-24 22:48 . 2007-03-18 21:37 65,602 --a------ C:\WINDOWS\system32\cook3260.dll 2008-03-24 18:24 . 2002-12-16 19:09 30,970 --a------ C:\WINDOWS\system32\drivers\SQCaptur.sys 2008-03-24 18:24 . 2002-12-11 12:48 27,235 --a------ C:\WINDOWS\system32\drivers\SQCamD.sys 2008-03-24 18:13 . 2008-03-24 18:13 0 --a------ C:\Documents and Settings\Andy\Application Data\wklnhst.dat 2008-03-24 17:55 . 2004-08-04 01:56 16,384 --a------ C:\WINDOWS\system32\ipsink.ax 2008-03-24 17:55 . 2004-08-04 01:56 16,384 --a--c--- C:\WINDOWS\system32\dllcache\ipsink.ax 2008-03-24 17:55 . 2004-08-04 00:10 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys 2008-03-24 17:55 . 2004-08-04 00:10 15,360 --a--c--- C:\WINDOWS\system32\dllcache\streamip.sys 2008-03-24 17:55 . 2004-08-04 00:10 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys 2008-03-24 17:55 . 2004-08-04 00:10 10,880 --a--c--- C:\WINDOWS\system32\dllcache\ndisip.sys 2008-03-24 17:55 . 2004-08-03 23:58 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys 2008-03-24 17:55 . 2004-08-03 23:58 5,504 --a--c--- C:\WINDOWS\system32\dllcache\mstee.sys 2008-03-24 17:53 . 2008-03-24 17:53 <DIR> d-------- C:\Program Files\ODM 2008-03-24 17:53 . 2008-03-24 17:53 <DIR> d-------- C:\Program Files\directx 2008-03-24 17:53 . 2003-02-27 18:14 226,688 --a------ C:\WINDOWS\system32\drivers\cccp106.sys 2008-03-24 17:53 . 2003-03-08 17:02 192,512 --a------ C:\WINDOWS\select.exe 2008-03-24 17:53 . 2003-02-18 15:48 61,440 --a------ C:\WINDOWS\system32\dcccp106.dll 2008-03-24 17:53 . 2003-02-18 15:48 45,056 --a------ C:\WINDOWS\system32\vcccp106.dll 2008-03-24 17:53 . 2002-11-13 16:54 36,864 --a------ C:\WINDOWS\CleanDev.exe 2008-03-24 17:53 . 2003-02-18 15:48 28,672 --a------ C:\WINDOWS\system32\dcccp106.ax 2008-03-24 17:53 . 2003-02-18 15:48 15,542 --a------ C:\WINDOWS\cccp106.ini 2008-03-24 17:53 . 2003-02-18 15:48 13,023 --------- C:\WINDOWS\cccp106.src 2008-03-24 17:53 . 2003-03-14 21:45 320 --a------ C:\WINDOWS\DC2110a.ini 2008-03-24 17:18 . 2001-08-17 15:55 6,144 --a------ C:\WINDOWS\system32\kbd101b.dll 2008-03-24 17:18 . 2001-08-17 15:55 6,144 --a--c--- C:\WINDOWS\system32\dllcache\kbd101b.dll 2008-03-24 16:05 . 2008-03-24 16:09 <DIR> d-------- C:\WINDOWS\system32\NtmsData 2008-03-24 11:22 . 2008-03-24 11:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software 2008-03-24 11:22 . 2008-03-24 11:22 307,968 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe 2008-03-24 11:22 . 2008-02-27 14:15 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll 2008-03-24 04:27 . 2008-03-24 04:27 0 --a------ C:\WINDOWS\system32\SBRC.dat 2008-03-24 04:27 . 2008-03-24 04:27 0 --a------ C:\WINDOWS\system32\SBFC.dat 2008-03-24 03:12 . 2008-03-24 03:12 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\Motive 2008-03-24 03:10 . 2008-03-24 03:10 <DIR> d-------- C:\WINDOWS\Motive 2008-03-24 03:09 . 2008-03-24 03:09 <DIR> d-------- C:\Program Files\Common Files\Motive 2008-03-24 03:09 . 2008-03-24 03:09 <DIR> d-------- C:\Program Files\btbb_wcm 2008-03-24 03:09 . 2008-03-24 03:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Motive 2008-03-24 03:08 . 2008-03-24 03:08 <DIR> d-------- C:\Program Files\Motive 2008-03-24 03:08 . 2008-03-24 03:10 <DIR> d-------- C:\Program Files\BT Broadband Desktop Help 2008-03-24 00:39 . 2008-03-24 00:39 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\TuneUp Software 2008-03-24 00:38 . 2008-04-18 18:32 <DIR> d-------- C:\Program Files\TuneUp Utilities 2008
. (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-04-19 10:48 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-03-30 13:50 --------- d-----w C:\Documents and Settings\Andy\Application Data\NeroDigital™ 2008-03-17 18:11 --------- d-----w C:\Program Files\Common Files\InstallShield 2008-03-06 21:32 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf 2008-03-06 21:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys 2008-03-06 21:32 10,537 ----a-w C:\WINDOWS\system32\drivers\coh_mon.cat 2008-03-06 04:37 --------- d-----w C:\Program Files\Synaptics 2008-03-06 04:37 --------- d-----w C:\Program Files\Realtek Semiconductor Corp 2008-03-06 04:37 --------- d-----w C:\Program Files\Realtek AC97 2008-03-06 04:37 --------- d-----w C:\Program Files\RALINK 2008-03-06 04:36 --------- d-----w C:\Program Files\NewTech Infosystems 2008-03-06 04:36 --------- d-----w C:\Program Files\Microsoft Works 2008-03-06 04:36 --------- d-----w C:\Program Files\InterVideo 2008-03-06 04:36 --------- d-----w C:\Program Files\AvRack 2008-03-06 04:36 --------- d-----w C:\Program Files\ATI Technologies 2008-03-06 04:36 --------- d-----w C:\Program Files\AMD 2008-02-28 17:38 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe 2008-02-26 16:14 972,072 ----a-w C:\WINDOWS\UNRecode.exe 2003-08-27 21:19 36,963 ----a-r C:\Program Files\Common Files\SM1updtr.dll .
((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}] 2007-08-25 04:51 316784 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}] 2008-03-06 02:11 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= "C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll" [2007-08-25 04:51 316784]
[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}] [HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1] [HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [2007-08-25 04:51 316784]
[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}] [HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1] [HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-14 12:01 51048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360] "Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2008-03-26 18:41 1232896]
C:\Documents and Settings\Andy\Start Menu\Programs\Startup\ SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 20:05:35 360448]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbXRLcAq]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkLFurr] jkkLFurr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.scg726"= scg726.acm "msacm.alf2cd"= alf2cd.acm "vidc.dvsd"= mcdvd_32.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 "kdx"=C:\Program Files\Kontiki\KHost.exe -all "Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe" /NoDialog "EPSON Stylus DX4200 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE /P26 "EPSON Stylus DX4200 Series" /M "Stylus DX4200" /EF "HKCU"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" "btbb_McciTrayApp"=C:\Program Files\BT Broadband Desktop Help\bin\BTHelpNotifier.exe "CardReaderReset"=C:\Program Files\Realtek Semiconductor Corp\Card Reader Software\Reset.exe "SM1BG"=C:\WINDOWS\SM1BG.EXE "btbb_wcm_McciTrayApp"=C:\Program Files\btbb_wcm\McciTrayApp.exe "SoundMan"=SOUNDMAN.EXE "YBrowser"=C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe "PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE "BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent "TomTomHOME.exe"="C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"= "C:\\Program Files\\Kontiki\\KService.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\uTorrent\\uTorrent.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"=
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon [] R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 13:00] S3 CCCP106;CIF USB Camera (2110A);C:\WINDOWS\system32\DRIVERS\cccp106.sys [2003-02-27 18:14] S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-03-06 22:32] S3 pccsmcfd;PCCS Mode Change Filter Driver;C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 15:53] S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-03-24 11:22] S3 upperdev;upperdev;C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2007-11-29 10:39] S3 UsbserFilt;UsbserFilt;C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2007-11-29 10:39]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E] \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
*Newly Created Service* - COMHOST . Contents of the 'Scheduled Tasks' folder "2008-04-30 19:03:11 C:\WINDOWS\Tasks\1-Click Maintenance.job" - C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe "2008-04-27 19:07:19 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Andy.job" - C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeh/TASK: . **************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-04-30 20:04:36 Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully hidden files: 0
************************************************************************** . --------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe -> ?:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82\gdiplus.dll . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\system32\ati2evxx.exe C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe C:\WINDOWS\system32\ati2evxx.exe C:\Program Files\Kontiki\KService.exe C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe C:\WINDOWS\system32\IoctlSvc.exe C:\WINDOWS\system32\imapi.exe . ************************************************************************** . Completion time: 2008-04-30 20:08:17 - machine was rebooted ComboFix-quarantined-files.txt 2008-04-30 19:08:03 ComboFix2.txt 2008-04-15 23:33:31
Pre-Run: 20,148,396,032 bytes free Post-Run: 20,162,777,088 bytes free
286 --- E O F --- 2008-04-26 10:41:17 One of the files deleted was the bho warned about by Spyware Guard.
|
|
bricat
HijackThis Helper
Reg'd: Wed
Posts: 29240
Loc: belfast
|
|
Please copy this page to *Notepad* and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.
It's IMPORTANT to carry out the instructions in the sequence listed below.
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Open *notepad* and copy/paste the text in the quotebox below into it:
Quote:
Killall::
File:: C:\WINDOWS\system32\htolfdji.dll C:\WINDOWS\system32\lveaedgc.dll C:\WINDOWS\BM7fbecf2c.xml C:\Documents and Settings\Andy\Application Data\inst.exe C:\WINDOWS\tosOBEX.INI C:\WINDOWS\JCMkr32.INI
Folder:: C:\Documents and Settings\Andy\Application Data\Desktopicon
Registry:: [-HKEY_LOCAL_MACHINE\software\microsoft\windowsnt\currentversion\winlogon\notify\cbXRLcAq] [-HKEY_LOCAL_MACHINE\software\microsoft\windowsnt\currentversion\winlogon\notify\jkkLFurr] "jkkLFurr.dll"=-
Save this as CFScript.txt, in the same location as ComboFix.exe which is on the Desktop.

Referring to the picture above, drag CFScript.txt into ComboFix.exe.
This will start ComboFix again.(it may ask you to reboot your computer)
When finished, it shall produce a log for you at C:\ComboFix.txt
Please copy and paste the ComboFix.txt along with a fresh HijackThis log in your next reply please and let me know how it is running.
*Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall*
-------------------- MY HELP IS FREE,BUT PLEASE CONSIDER GIVING A DONATION TO HELP IN MY FIGHT AGAINST SPYWARE.
You don't stop laughing when you get old, you get old when you stop laughing!
|
Andybib
regular
Reg'd: Thu
Posts: 48
|
|
Done as requested,heres the resultant logs;Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 01:30:53, on 01/05/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe C:\Program Files\Kontiki\KService.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe C:\WINDOWS\system32\IoctlSvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\SpywareGuard\sgmain.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.pcservicecall.co.uk O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsof...b?1208406252796 O20 - Winlogon Notify: cbXRLcAq - C:\WINDOWS\ O20 - Winlogon Notify: jkkLFurr - jkkLFurr.dll (file missing) O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
-- End of file - 6963 bytes ComboFix 08-04-26.3 - Andy 2008-05-01 1:20:40.5 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.700 [GMT 1:00] Running from: C:\Documents and Settings\Andy\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Andy\Desktop\CFScript.txt * Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE :: C:\Documents and Settings\Andy\Application Data\inst.exe C:\WINDOWS\BM7fbecf2c.xml C:\WINDOWS\JCMkr32.INI C:\WINDOWS\system32\htolfdji.dll C:\WINDOWS\system32\lveaedgc.dll C:\WINDOWS\tosOBEX.INI .
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) .
C:\Documents and Settings\Andy\Application Data\Desktopicon C:\Documents and Settings\Andy\Application Data\Desktopicon\config.ini C:\Documents and Settings\Andy\Application Data\Desktopicon\eBayShortcuts.exe C:\Documents and Settings\Andy\Application Data\inst.exe C:\WINDOWS\BM7fbecf2c.xml C:\WINDOWS\JCMkr32.INI C:\WINDOWS\system32\htolfdji.dll C:\WINDOWS\system32\lveaedgc.dll C:\WINDOWS\tosOBEX.INI
. ((((((((((((((((((((((((( Files Created from 2008-04-01 to 2008-05-01 ))))))))))))))))))))))))))))))) .
2008-04-30 17:19 . 2008-04-30 17:19 <DIR> d-------- C:\Program Files\UseNeXT 2008-04-29 20:33 . 2008-04-29 22:00 <DIR> d-------- C:\Program Files\coverXP 2008-04-29 20:09 . 2008-04-29 20:09 <DIR> d-------- C:\spoolerlogs 2008-04-27 09:48 . 2008-04-27 09:48 <DIR> d-------- C:\VundoFix Backups 2008-04-27 07:41 . 2007-01-18 13:00 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys 2008-04-27 02:43 . 2008-04-27 02:50 6,211 --a------ C:\WINDOWS\system32\EPPICResdb0000 2008-04-27 02:43 . 2008-04-27 02:50 117 --a------ C:\WINDOWS\system32\EPPICResdb 2008-04-20 18:30 . 2008-04-20 19:04 <DIR> d-------- C:\temp 2008-04-19 22:10 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys 2008-04-19 22:10 . 2001-08-17 13:48 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys 2008-04-19 22:06 . 2008-04-19 22:06 <DIR> d-------- C:\Program Files\Toshiba 2008-04-19 20:14 . 2004-08-03 23:10 38,016 --a------ C:\WINDOWS\system32\drivers\bthmodem.sys 2008-04-19 20:14 . 2004-08-03 23:10 38,016 --a--c--- C:\WINDOWS\system32\dllcache\bthmodem.sys 2008-04-19 18:42 . 2008-04-25 05:44 18,413 --a------ C:\Documents and Settings\Andy\Application Data\NMM-MetaData.db 2008-04-19 11:49 . 2008-04-19 11:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TomTom 2008-04-19 11:48 . 2008-04-19 11:48 <DIR> d-------- C:\Program Files\TomTom HOME 2008-04-19 11:47 . 2008-04-19 11:47 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\InstallShield 2008-04-19 10:50 . 2004-08-03 23:08 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys 2008-04-19 10:50 . 2004-08-03 23:08 25,600 --a--c--- C:\WINDOWS\system32\dllcache\usbser.sys 2008-04-19 10:50 . 2008-04-19 10:50 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf 2008-04-19 10:50 . 2008-04-19 10:50 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf 2008-04-19 10:42 . 2008-04-19 10:42 <DIR> d-------- C:\Program Files\Common Files\PCSuite 2008-04-19 10:42 . 2008-04-19 10:42 <DIR> d-------- C:\Program Files\Common Files\Nokia 2008-04-19 10:41 . 2008-04-19 10:41 <DIR> d-------- C:\Program Files\PC Connectivity Solution 2008-04-19 10:41 . 2007-11-29 10:33 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll 2008-04-19 10:41 . 2007-11-29 10:39 95,744 --a------ C:\WINDOWS\system32\nmwcdcocls.dll 2008-04-19 10:41 . 2007-09-17 15:53 21,632 --a------ C:\WINDOWS\system32\drivers\pccsmcfd.sys 2008-04-19 10:41 . 2007-11-29 10:39 19,328 --a------ C:\WINDOWS\system32\drivers\ccdcmbo.sys 2008-04-19 10:41 . 2007-11-29 10:39 16,896 --a------ C:\WINDOWS\system32\drivers\ccdcmb.sys 2008-04-19 10:41 . 2007-11-29 10:39 8,064 --a------ C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys 2008-04-19 10:41 . 2007-11-29 10:39 8,064 --a------ C:\WINDOWS\system32\drivers\usbser_lowerflt.sys 2008-04-17 18:43 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll 2008-04-17 18:43 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui 2008-04-15 05:58 . 2008-04-15 05:58 <DIR> d-------- C:\Program Files\MSXML 6.0 2008-04-13 02:36 . 2008-04-14 20:43 153 --a------ C:\WINDOWS\wininit.ini 2008-04-13 01:29 . 2008-04-13 01:29 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy 2008-04-13 00:29 . 2008-04-13 00:29 <DIR> d-------- C:\Program Files\Trend Micro 2008-04-11 18:59 . 2008-04-11 18:59 <DIR> d-------- C:\Setup 2008-04-11 18:54 . 2008-04-27 10:49 <DIR> d-------- C:\Program Files\AutoCAD Civil 3D 2008 2008-04-11 18:54 . 2008-04-11 18:54 <DIR> d-------- C:\Civil 3D Projects 2008-04-11 17:33 . 2008-04-13 19:03 <DIR> d-------- C:\Program Files\PowerISO 2008-04-10 13:44 . 2008-04-10 13:44 <DIR> d-------- C:\WINDOWS\WinRAR 2008-04-06 18:49 . 2008-04-06 18:53 <DIR> d-------- C:\Program Files\AutoCAD 2009 2008-04-06 18:47 . 2008-04-27 10:47 <DIR> d-------- C:\Program Files\Common Files\Autodesk Shared 2008-04-06 18:36 . 2008-04-27 10:47 <DIR> d-------- C:\Program Files\Autodesk 2008-04-06 16:02 . 2008-04-13 23:12 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\Autodesk 2008-04-06 16:02 . 2008-04-13 23:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Autodesk 2008-04-06 16:02 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll 2008-04-06 16:00 . 2008-04-06 16:00 <DIR> d-------- C:\Program Files\MSBuild 2008-04-06 15:58 . 2008-04-26 11:39 <DIR> d-------- C:\WINDOWS\system32\XPSViewer 2008-04-06 15:57 . 2008-04-06 15:57 <DIR> d-------- C:\Program Files\Reference Assemblies 2008-04-06 15:57 . 2006-06-29 13:07 14,048 --a------ C:\WINDOWS\system32\spmsg2.dll 2008-04-06 13:35 . 2008-04-10 13:47 <DIR> d-------- C:\Program Files\MagicISO 2008-04-04 19:30 . 2008-04-04 19:30 <DIR> d-------- C:\WINDOWS\Performance 2008-04-04 19:30 . 2008-04-04 19:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Corporation 2008-04-04 19:29 . 2008-04-04 19:29 <DIR> d-------- C:\Program Files\Microsoft Windows Vista Upgrade Advisor 2008-04-02 20:58 . 2008-04-02 21:00 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\dvdcss
. (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-05-01 00:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kontiki 2008-05-01 00:18 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP 2008-05-01 00:02 --------- d-----w C:\Documents and Settings\Andy\Application Data\UseNeXT 2008-04-30 23:35 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2008-04-30 23:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec 2008-04-30 19:10 --------- d-----w C:\Program Files\SpywareGuard 2008-04-30 15:58 --------- d-----w C:\Documents and Settings\Andy\Application Data\uTorrent 2008-04-27 03:26 --------- d-----w C:\Program Files\DVDFab Platinum 4 2008-04-27 03:21 47,360 ----a-w C:\Documents and Settings\Andy\Application Data\pcouffin.sys 2008-04-27 03:21 --------- d-----w C:\Documents and Settings\Andy\Application Data\Vso 2008-04-27 03:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\1Click DVD Copy Pro 2008-04-19 17:42 --------- d-----w C:\Documents and Settings\Andy\Application Data\Nokia 2008-04-19 10:48 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-04-19 09:40 --------- d-----w C:\Program Files\Nokia 2008-04-19 09:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations 2008-04-18 17:32 --------- d-----w C:\Program Files\TuneUp Utilities 2008 2008-04-13 01:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-04-12 17:33 --------- d-----w C:\Program Files\SpywareBlaster 2008-04-10 19:35 --------- d-----w C:\Documents and Settings\Andy\Application Data\ImgBurn 2008-04-06 17:24 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2008-04-06 16:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft 2008-03-30 13:50 --------- d-----w C:\Documents and Settings\Andy\Application Data\NeroDigital™ 2008-03-29 19:09 --------- d-----w C:\Program Files\Softgogo 2008-03-29 11:39 --------- d-----w C:\Documents and Settings\Andy\Application Data\vlc 2008-03-29 05:38 --------- d-----w C:\Program Files\VideoLAN 2008-03-29 00:37 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys 2008-03-28 16:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\1Click DVD Copy 2008-03-26 18:24 --------- d-----w C:\Program Files\NeroInstall.bak 2008-03-26 18:21 --------- d-----w C:\Documents and Settings\Andy\Application Data\Nero 2008-03-26 18:19 --------- d-----w C:\Program Files\Common Files\Nero 2008-03-26 18:17 --------- d-----w C:\Program Files\Nero 2008-03-26 18:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero 2008-03-24 22:28 --------- d-----w C:\Documents and Settings\Andy\Application Data\DVD Flick 2008-03-24 21:48 --------- d-----w C:\Program Files\vso 2008-03-24 17:13 0 ----a-w C:\Documents and Settings\Andy\Application Data\wklnhst.dat 2008-03-24 16:53 --------- d-----w C:\Program Files\ODM 2008-03-24 16:53 --------- d-----w C:\Program Files\directx 2008-03-24 10:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software 2008-03-24 02:12 --------- d-----w C:\Documents and Settings\Andy\Application Data\Motive 2008-03-24 02:10 --------- d-----w C:\Program Files\BT Broadband Desktop Help 2008-03-24 02:09 --------- d-----w C:\Program Files\Common Files\Motive 2008-03-24 02:09 --------- d-----w C:\Program Files\btbb_wcm 2008-03-24 02:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Motive 2008-03-24 02:08 --------- d-----w C:\Program Files\Motive 2008-03-23 23:39 --------- d-----w C:\Documents and Settings\Andy\Application Data\TuneUp Software 2008-03-23 15:11 --------- d-----w C:\Documents and Settings\Andy\Application Data\AVSMedia 2008-03-23 15:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\AVS4YOU 2008-03-23 15:10 --------- d-----w C:\Program Files\Common Files\AVSMedia 2008-03-23 15:09 --------- d-----w C:\Program Files\AVSMedia 2008-03-21 14:47 --------- d-----w C:\Program Files\CCleaner 2008-03-17 19:08 --------- d-----w C:\Documents and Settings\Andy\Application Data\EPSON 2008-03-17 18:11 --------- d-----w C:\Program Files\Common Files\InstallShield 2008-03-17 18:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\UDL 2008-03-17 18:04 --------- d-----w C:\Program Files\epson 2008-03-16 17:39 --------- d-----w C:\Program Files\uTorrent 2008-03-16 17:08 --------- d-----w C:\Program Files\KC Softwares 2008-03-15 16:50 --------- d-----w C:\Program Files\Ahead 2008-03-15 01:17 --------- d-----w C:\Documents and Settings\Andy\Application Data\InterVideo 2008-03-14 06:04 46,652 ----a-w C:\WINDOWS\system32\drivers\scdemu.sys 2008-03-08 11:55 --------- d-----w C:\Program Files\Xvid 2008-03-07 20:05 --------- d-----w C:\Documents and Settings\Andy\Application Data\PC Suite 2008-03-07 20:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite 2008-03-07 20:02 --------- d-----w C:\Program Files\DIFX 2008-03-06 21:32 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf 2008-03-06 21:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys 2008-03-06 21:32 10,537 ----a-w C:\WINDOWS\system32\drivers\coh_mon.cat 2008-03-06 14:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion 2008-03-06 14:26 --------- d-----w C:\Program Files\Common Files\Adobe 2008-03-06 14:20 --------- d-----w C:\Documents and Settings\Andy\Application Data\AdobeUM 2008-03-06 14:18 --------- d-----w C:\Program Files\DVD Flick 2008-03-06 12:24 --------- d-----w C:\Program Files\Windows Media Connect 2 2008-03-06 11:50 --------- d-----w C:\Program Files\Kontiki 2008-03-06 11:49 --------- d-----w C:\Program Files\Channel4 2008-03-06 11:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Channel4 2008-03-06 11:17 --------- d-----w C:\Program Files\Norton Internet Security 2008-03-06 11:11 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF 2008-03-06 11:11 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS 2008-03-06 11:11 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT 2008-03-06 11:11 --------- d-----w C:\Program Files\Symantec 2008-03-06 04:37 --------- d-----w C:\Program Files\Synaptics 2008-03-06 04:37 --------- d-----w C:\Program Files\Realtek Semiconductor Corp 2008-03-06 04:37 --------- d-----w C:\Program Files\Realtek AC97 2008-03-06 04:37 --------- d-----w C:\Program Files\RALINK 2008-03-06 04:36 --------- d-----w C:\Program Files\NewTech Infosystems 2008-03-06 04:36 --------- d-----w C:\Program Files\Microsoft Works 2008-03-06 04:36 --------- d-----w C:\Program Files\InterVideo 2008-03-06 04:36 --------- d-----w C:\Program Files\AvRack 2008-03-06 04:36 --------- d-----w C:\Program Files\ATI Technologies 2008-03-06 04:36 --------- d-----w C:\Program Files\AMD 2008-03-06 03:01 --------- d-----w C:\Program Files\MSXML 4.0 2008-03-06 02:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\yahoo! 2008-03-06 01:05 --------- d-----w C:\Program Files\Yahoo! 2008-03-06 01:05 --------- d-----w C:\Documents and Settings\Andy\Application Data\Yahoo! 2008-03-06 00:48 --------- d-----w C:\Documents and Settings\Andy\Application Data\Symantec 2008-03-06 00:46 --------- d-----w C:\Program Files\Windows Sidebar 2008-02-28 17:38 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe 2008-02-26 16:14 972,072 ----a-w C:\WINDOWS\UNRecode.exe 2003-08-27 21:19 36,963 ----a-r C:\Program Files\Common Files\SM1updtr.dll .
((((((((((((((((((((((((((((( snapshot@2008-04-30_20.07.47.31 ))))))))))))))))))))))))))))))))))))))))) . - 2008-04-30 19:02:41 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2008-05-01 00:23:34 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2008-05-01 00:24:28 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_654.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}] 2007-08-25 04:51 316784 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}] 2008-03-06 02:11 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= "C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll" [2007-08-25 04:51 316784]
[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}] [HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1] [HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [2007-08-25 04:51 316784]
[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}] [HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1] [HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-14 12:01 51048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360] "Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2008-03-26 18:41 1232896]
C:\Documents and Settings\Andy\Start Menu\Programs\Startup\ SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 20:05:35 360448]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbXRLcAq]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkLFurr] jkkLFurr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.scg726"= scg726.acm "msacm.alf2cd"= alf2cd.acm "vidc.dvsd"= mcdvd_32.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 "kdx"=C:\Program Files\Kontiki\KHost.exe -all "Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe" /NoDialog "EPSON Stylus DX4200 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE /P26 "EPSON Stylus DX4200 Series" /M "Stylus DX4200" /EF "HKCU"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" "btbb_McciTrayApp"=C:\Program Files\BT Broadband Desktop Help\bin\BTHelpNotifier.exe "CardReaderReset"=C:\Program Files\Realtek Semiconductor Corp\Card Reader Software\Reset.exe "SM1BG"=C:\WINDOWS\SM1BG.EXE "btbb_wcm_McciTrayApp"=C:\Program Files\btbb_wcm\McciTrayApp.exe "SoundMan"=SOUNDMAN.EXE "YBrowser"=C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe "PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE "BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent "TomTomHOME.exe"="C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"= "C:\\Program Files\\Kontiki\\KService.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\uTorrent\\uTorrent.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"=
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon [] R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 13:00] S3 CCCP106;CIF USB Camera (2110A);C:\WINDOWS\system32\DRIVERS\cccp106.sys [2003-02-27 18:14] S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-03-06 22:32] S3 pccsmcfd;PCCS Mode Change Filter Driver;C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 15:53] S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-03-24 11:22] S3 upperdev;upperdev;C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2007-11-29 10:39] S3 UsbserFilt;UsbserFilt;C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2007-11-29 10:39]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E] \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
*Newly Created Service* - COMHOST . Contents of the 'Scheduled Tasks' folder "2008-05-01 00:24:13 C:\WINDOWS\Tasks\1-Click Maintenance.job" - C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe "2008-04-27 19:07:19 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Andy.job" - C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeh/TASK: . **************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-05-01 01:25:00 Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully hidden files: 0
************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\system32\ati2evxx.exe C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe C:\Program Files\Kontiki\KService.exe C:\WINDOWS\system32\ati2evxx.exe C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe C:\WINDOWS\system32\IoctlSvc.exe . ************************************************************************** . Completion time: 2008-05-01 1:28:31 - machine was rebooted ComboFix-quarantined-files.txt 2008-05-01 00:28:23 ComboFix2.txt 2008-04-30 19:08:18 ComboFix3.txt 2008-04-15 23:33:31
Pre-Run: 20,158,451,712 bytes free Post-Run: 20,157,120,512 bytes free
311 --- E O F --- 2008-04-26 10:41:17 All seems to be ok,however its a bit late ,so will try again in morning.
|
bricat
HijackThis Helper
Reg'd: Wed
Posts: 29240
Loc: belfast
|
|
Rerun HJT,and put a checkmark beside these :-
O20 - Winlogon Notify: cbXRLcAq - C:\WINDOWS\ O20 - Winlogon Notify: jkkLFurr - jkkLFurr.dll (file missing)
now close all windows and browsers and click FIX CHECKED
then :-
Time for some housekeeping
- Click START then RUN
- Now type Combofix /u in the runbox and click OK
[list] 
When shown the disclaimer, Select "2"[/list]
The above procedure will:
- Delete the following:[list]
- ComboFix and its associated files and folders.
- VundoFix backups, if present
- The C:\Deckard folder, if present
- The C:_OtMoveIt folder, if present
Reset the clock settings. Hide file extensions, if required. Hide System/Hidden files, if required. Reset System Restore.[/list]
then :-
Please download Malwarebytes' Anti-Malware from Here or Here
Double Click mbam-setup.exe to install the application.- Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select "Perform Quick Scan", then click Scan.
- The scan may take some time to finish,so please be patient.
- When the scan is complete, click OK, then Show Results to view the results.
- Make sure that everything is checked, and click Remove Selected.
- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
- Copy&Paste the entire report in your next reply.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.
-------------------- MY HELP IS FREE,BUT PLEASE CONSIDER GIVING A DONATION TO HELP IN MY FIGHT AGAINST SPYWARE.
You don't stop laughing when you get old, you get old when you stop laughing!
|
Andybib
regular
Reg'd: Thu
Posts: 48
|
|
All seems to be ok,removed the two items in HT,and the MBAM ran without any disinfecting.Heres the logs of both;Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 18:26:36, on 01/05/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe C:\Program Files\Kontiki\KService.exe C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe C:\WINDOWS\system32\IoctlSvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\SpywareGuard\sgmain.exe C:\Program Files\SpywareGuard\sgbhp.exe C:\PROGRA~1\Yahoo!\browser\ycommon.exe C:\Program Files\Yahoo!\browser\ybrwicon.exe C:\Program Files\Yahoo!\browser\ybrowser.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.pcservicecall.co.uk O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsof...b?1208406252796 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
-- End of file - 7238 bytes Malwarebytes' Anti-Malware 1.11 Database version: 707
Scan type: Quick Scan Objects scanned: 36931 Time elapsed: 11 minute(s), 39 second(s)
Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0
Memory Processes Infected: (No malicious items detected)
Memory Modules Infected: (No malicious items detected)
Registry Keys Infected: (No malicious items detected)
Registry Values Infected: (No malicious items detected)
Registry Data Items Infected: (No malicious items detected)
Folders Infected: (No malicious items detected)
Files Infected: (No malicious items detected) I`m hoping this means alls well,seems to be after a little more use.Andyb.
|
bricat
HijackThis Helper
Reg'd: Wed
Posts: 29240
Loc: belfast
|
|
that looks clean now. 
Download and scan with CCleaner - CCleaner installs the Yahoo Toolbar as an option which IS checkmarked by default during the installation.
IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbar-free or Slim versions instead of the Standard Build.
- Before first use, select Options > Advanced and UNCHECK "Only delete files in Windows Temp folder older than 48 hours"
Then select "Cookies" Move any cookies you wish to retain, e.g. login cookies, in the left-hand window to the right-hand window by highlighting them and clicking the right arrow in the centre.
- Then select the items you wish to clean up.
In the Windows Tab:
• Clean all entries in the "Internet Explorer" section. • Clean all the entries in the "Windows Explorer" section. • Clean all entries in the "System" section. • Clean all entries in the "Advanced" section. • Clean any others that you choose.
In the Applications Tab:
• Clean all entries in the Mozilla Firefox Section. • Clean all in the Opera section if you use it. • Clean Sun Java in the Internet Section. • Clean any others that you choose.
- Click the "Run Cleaner" button.
- A pop up box will appear advising this process will permanently delete files from your system.
- Click "OK" and it will scan and clean your system.
- Click "exit" when done.
then DEFRAG your C:\ drive.
to help speed up your system.
then let us know how the computer is running.
HOW DID I GET INFECTED
-------------------- MY HELP IS FREE,BUT PLEASE CONSIDER GIVING A DONATION TO HELP IN MY FIGHT AGAINST SPYWARE.
You don't stop laughing when you get old, you get old when you stop laughing!
Edited by bricat (Thu May 01 2008 06:43 PM)
|
Andybib
regular
Reg'd: Thu
Posts: 48
|
|
Cleaned and freed over a GB of files however didnt need to defrag. as recently completed.All seems to be running well,its now trying to keep clean!I think ive got quite a strong base of online defence,its now down to taking care of programmes i run or d/load.Any other ideas appreciated.Andyb.
|
bricat
HijackThis Helper
Reg'd: Wed
Posts: 29240
Loc: belfast
|
|
I would recommend you install SPYWAREBLASTER this does not use any resources so doesn't conflict with any other program. but it will stop a lot of bad stuff getting to your registry. just update it once a week. then you just need to be careful what you click on.
-------------------- MY HELP IS FREE,BUT PLEASE CONSIDER GIVING A DONATION TO HELP IN MY FIGHT AGAINST SPYWARE.
You don't stop laughing when you get old, you get old when you stop laughing!
|
Andybib
regular
Reg'd: Thu
Posts: 48
|
|
Cheers for all help,already running S.B.just hadnt updated recently!A drinks on its way as atoken of my appreciation,ta.Andyb.
|
bricat
HijackThis Helper
Reg'd: Wed
Posts: 29240
Loc: belfast
|
|
thank you for your kind donation, it's really appreciated. just happy to help.
-------------------- MY HELP IS FREE,BUT PLEASE CONSIDER GIVING A DONATION TO HELP IN MY FIGHT AGAINST SPYWARE.
You don't stop laughing when you get old, you get old when you stop laughing!
| |