coriell12277 Posted August 24, 2007 Report Share Posted August 24, 2007 dose this log look ok or do i need to change some stuff to make this computer run a bit better an faster ????>>>>>>>>>>>>>Logfile of Trend Micro HijackThis v2.0.2Scan saved at 2:28:04 AM, on 8/24/2007Platform: Windows 2000 SP4 (WinNT 5.00.2195)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Boot mode: NormalRunning processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\ZoneLabs\vsmon.exeC:\WINNT\system32\spoolsv.exeC:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeC:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeC:\PROGRA~1\Grisoft\AVG7\avgemc.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\regsvc.exeC:\WINNT\system32\MSTask.exeC:\WINNT\System32\WBEM\WinMgmt.exeC:\Program Files\TightVNC\WinVNC.exeC:\WINNT\Explorer.EXEC:\WINNT\system32\svchost.exeC:\Program Files\Zone Labs\ZoneAlarm\zlclient.exeC:\Program Files\Grisoft\AVG7\avgcc.exeC:\Program Files\Trillian Pro\trillian.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearshare.com/R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dllO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dllO3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocxO3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logonO4 - HKLM\..\Run: [AVG7_CC] C:\Program Files\Grisoft\AVG7\avgcc.exe \STARTUPO4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quietO4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')O4 - Startup: Trillian.lnk = C:\Program Files\Trillian Pro\trillian.exeO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\chris\Start Menu\Programs\Absolute Poker\Absolute Poker.lnkO9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\chris\Start Menu\Programs\Absolute Poker\Absolute Poker.lnkO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dllO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1187911231519O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1187911210589O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeO23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeO23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exeO23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exeO23 - Service: VNC Server (winvnc) - TightVNC Group - C:\Program Files\TightVNC\WinVNC.exe--End of file - 4910 bytes Link to post Share on other sites
coriell12277 Posted August 24, 2007 Author Report Share Posted August 24, 2007 an also here is my combofixComboFix 07-08-17.2 - "chris" 08/24/2007 3:11:29.1 - NTFSx86 Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.129 [GMT -7:00]((((((((((((((((((((((((( Files Created from 2007-07-24 to 2007-08-24 )))))))))))))))))))))))))))))))2007-08-24 03:08 51,200 --a------ C:\WINNT\nircmd.exe2007-08-23 22:23 <DIR> d-------- C:\DOCUME~1\chris\APPLIC~1\gtopala2007-08-23 22:19 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_390.dat2007-08-23 16:21 <DIR> d-------- C:\WINNT\system32\SoftwareDistribution2007-08-21 20:16 <DIR> d-------- C:\WINNT\Downloaded Installations2007-08-19 18:26 75,932 --a------ C:\WINNT\system32\drivers\klick.dat2007-08-19 18:26 75,248 --a------ C:\WINNT\zllsputility.exe2007-08-19 18:26 74,396 --a------ C:\WINNT\system32\drivers\klin.dat2007-08-19 18:25 14,368 --ahs---- C:\WINNT\system32\drivers\fidbox.dat2007-08-19 18:25 110,360 --a------ C:\WINNT\system32\drivers\kl1.sys2007-08-19 18:25 1,086,952 --a------ C:\WINNT\system32\zpeng24.dll2007-08-19 18:25 1,056 --ahs---- C:\WINNT\system32\drivers\fidbox2.dat2007-08-19 18:25 <DIR> d-------- C:\WINNT\system32\ZoneLabs2007-08-18 20:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft2007-08-18 10:34 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_2fc.dat2007-08-17 17:35 <DIR> d-------- C:\Program Files\Enigma Software Group2007-08-15 09:48 <DIR> d-------- C:\DOCUME~1\chris\APPLIC~1\OpenOffice.org22007-08-06 10:09 <DIR> d-------- C:\My Downloads2007-08-05 06:56 <DIR> d--h----- C:\WINNT\PIF2007-08-04 22:06 <DIR> d-------- C:\WINNT\pss2007-08-04 17:08 <DIR> d-------- C:\Program Files\Crawler2007-08-04 15:05 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\Motive2007-08-04 15:04 <DIR> d-a------ C:\Program Files\Common Files\Motive2007-08-01 23:29 <DIR> d-a------ C:\WINNT\system32\appmgmt2007-08-01 20:32 <DIR> d-------- C:\Program Files\TightVNC2007-08-01 19:40 4,212 ---h----- C:\WINNT\system32\zllictbl.dat2007-08-01 19:40 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier2007-08-01 19:39 11,264 --a------ C:\WINNT\system32\SpOrder.dll2007-08-01 19:32 <DIR> d-a------ C:\WINNT\Internet Logs2007-08-01 18:00 <DIR> d-------- C:\Program Files\Trend Micro2007-07-30 20:25 <DIR> d-------- C:\DOCUME~1\chris\APPLIC~1\vlc2007-07-30 19:19 203,096 --a------ C:\WINNT\system32\wuweb.dll2007-07-30 19:18 207,736 --a------ C:\WINNT\system32\muweb.dll2007-07-29 10:39 <DIR> d-------- C:\DOCUME~1\chris\Shared2007-07-29 10:39 <DIR> d-------- C:\DOCUME~1\chris\Incomplete2007-07-29 10:38 <DIR> d-------- C:\DOCUME~1\chris\APPLIC~1\LimeWire2007-07-28 23:02 <DIR> d-------- C:\Program Files\Absolute Poker2007-07-28 23:02 <DIR> d-------- C:\Program Files\_uninstallation_info2007-07-28 20:27 <DIR> d-------- C:\DOCUME~1\chris\APPLIC~1\Azureus2007-07-28 20:27 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Azureus2007-07-28 20:19 <DIR> d-------- C:\Program Files\Azureus2007-07-28 20:13 87,040 --a------ C:\WINNT\system32\drmstor.dll2007-07-28 20:13 43,528 --------- C:\WINNT\system32\drivers\PxHelp20.sys2007-07-28 20:13 306,424 --a------ C:\WINNT\system32\drmclien.dll2007-07-28 20:13 129,784 --------- C:\WINNT\system32\pxafs.dll2007-07-28 20:12 <DIR> d-------- C:\Program Files\Winamp2007-07-28 20:08 765,952 --a------ C:\WINNT\system32\xvidcore.dll2007-07-28 20:08 73,728 --a------ C:\WINNT\system32\dpl100.dll2007-07-28 20:08 639,066 --a------ C:\WINNT\system32\divx.dll2007-07-28 20:08 3,596,288 --a------ C:\WINNT\system32\qt-dx331.dll2007-07-28 20:08 200,704 --a------ C:\WINNT\system32\ssldivx.dll2007-07-28 20:08 196,608 --a------ C:\WINNT\system32\dtu100.dll2007-07-28 20:08 180,224 --a------ C:\WINNT\system32\xvidvfw.dll2007-07-28 20:08 10,752 --a------ C:\WINNT\system32\ff_vfw.dll2007-07-28 20:08 1,415,680 --a------ C:\WINNT\system32\wmv9vcm.dll2007-07-28 20:08 1,044,480 --a------ C:\WINNT\system32\libdivx.dll2007-07-28 20:08 <DIR> d-------- C:\Program Files\K-Lite Codec Pack2007-07-28 19:48 <DIR> d-------- C:\WINNT\PCHEALTH2007-07-28 19:43 <DIR> d-------- C:\WINNT\system32\URTTemp2007-07-28 19:18 98,304 --a------ C:\WINNT\system32\wmpshell.dll2007-07-28 19:18 940,544 --a------ C:\WINNT\system32\wmspdmoe.dll2007-07-28 19:18 9,464 --------- C:\WINNT\system32\drivers\cdralw2k.sys2007-07-28 19:18 9,336 --------- C:\WINNT\system32\drivers\cdr4_2K.sys2007-07-28 19:18 895,736 --a------ C:\WINNT\system32\wmvdmod.dll2007-07-28 19:18 774,904 --a------ C:\WINNT\system32\wmsdmod.dll2007-07-28 19:18 716,288 --a------ C:\WINNT\system32\wmadmoe.dll2007-07-28 19:18 7,680 --a------ C:\WINNT\system32\asferror.dll2007-07-28 19:18 6,656 --a------ C:\WINNT\system32\laprxy.dll2007-07-28 19:18 57,344 --a------ C:\WINNT\uneng.exe2007-07-28 19:18 52,224 --a------ C:\WINNT\system32\mspmsnsv.dll2007-07-28 19:18 49,152 --a------ C:\WINNT\system32\cdrtc.dll2007-07-28 19:18 45,056 --a------ C:\WINNT\system32\cdral.dll2007-07-28 19:18 413,944 --a------ C:\WINNT\system32\wmspdmod.dll2007-07-28 19:18 401,462 --a------ C:\WINNT\system32\Msvcp60.dll2007-07-28 19:18 396,528 --a------ C:\WINNT\system32\wmadmod.dll2007-07-28 19:18 384,512 --a------ C:\WINNT\system32\mp4sdmod.dll2007-07-28 19:18 358,912 --a------ C:\WINNT\system32\msscp.dll2007-07-28 19:18 317,176 --a------ C:\WINNT\system32\mp43dmod.dll2007-07-28 19:18 27,136 --a------ C:\WINNT\system32\wmdmlog.dll2007-07-28 19:18 245,760 --a------ C:\WINNT\system32\mswmdm.dll2007-07-28 19:18 240,640 --a------ C:\WINNT\system32\mpg4dmod.dll2007-07-28 19:18 23,552 --a------ C:\WINNT\system32\wmdmps.dll2007-07-28 19:18 225,280 --a------ C:\WINNT\system32\wmpdxm.dll2007-07-28 19:18 208,896 --a------ C:\WINNT\system32\wmpns.dll2007-07-28 19:18 201,728 --a------ C:\WINNT\system32\mspmsp.dll2007-07-28 19:18 20,480 --a------ C:\WINNT\system32\wmpui.dll2007-07-28 19:18 20,480 --a------ C:\WINNT\system32\wmpcore.dll2007-07-28 19:18 20,480 --a------ C:\WINNT\system32\wmpcd.dll2007-07-28 19:18 2,940,928 --a------ C:\WINNT\system32\wmploc.dll2007-07-28 19:18 167,936 --a------ C:\WINNT\system32\wmerror.dll2007-07-28 19:18 159,232 --a------ C:\WINNT\system32\CEWMDM.dll2007-07-28 19:18 151,552 --a------ C:\WINNT\system32\wmidx.dll2007-07-28 19:18 106,496 --a------ C:\WINNT\system32\wmpasf.dll2007-07-28 19:18 103,936 --a------ C:\WINNT\system32\logagent.exe2007-07-28 19:18 1,119,744 --a------ C:\WINNT\system32\wmsdmoe2.dll2007-07-28 19:18 1,022,464 --a------ C:\WINNT\system32\wmnetmgr.dll2007-07-28 19:18 1,003,008 --a------ C:\WINNT\system32\wmvdmoe2.dll2007-07-28 19:18 <DIR> d-------- C:\Program Files\Common Files\Adaptec Shared2007-07-28 19:17 696,320 --a------ C:\WINNT\system32\drmv2clt.dll2007-07-28 19:17 294,400 --a------ C:\WINNT\system32\blackbox.dll(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))12/31/02 05:00a 32528 --a------ C:\WINNT\inf\wbfirdma.sys08/19/07 06:30p 1244 --ahs---- C:\WINNT\system32\drivers\fidbox.idx08/19/07 06:30p 1172 --ahs---- C:\WINNT\system32\drivers\fidbox2.idx07/30/07 07:19p 92504 --a------ C:\WINNT\system32\cdm.dll07/28/07 04:25p 271 ---h----- C:\Program Files\desktop.ini07/28/07 04:25p 21952 ---h----- C:\Program Files\folder.htt06/26/07 02:57a 235280 --a------ C:\WINNT\system32\GDI32.DLL06/06/07 11:50p 1119232 --a------ C:\WINNT\system32\msxml3.dll((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))*Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [06/21/07 09:54p]"Synchronization Manager"="mobsync.exe" [12/31/02 05:00a C:\WINNT\system32\mobsync.exe]"AVG7_CC"="C:\Program Files\Grisoft\AVG7\avgcc.exe" [08/17/07 10:32a]"MSConfig"="C:\Documents and Settings\chris\My Documents\msconfig.exe" [08/04/07 10:06p][HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktopC:\Documents and Settings\chris\Start Menu\Programs\Startup\Trillian.lnk - C:\Program Files\Trillian Pro\trillian.exe [2007-07-28 18:14:43][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]@="Driver"[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]@="Driver"[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quietR1 Avg7RsNT;AVG7 Resident Driver NT;C:\WINNT\system32\Drivers\avg7rsnt.sys*Newly Created Service* - SIWIO**************************************************************************catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2007-08-24 03:13:28Windows 5.0.2195 Service Pack 4 NTFSscanning hidden processes ...scanning hidden autostart entries ...scanning hidden files ...scan completed successfullyhidden files: 0**************************************************************************Completion time: 08/24/2007 3:14:28 --- E O F --- loag also someone please look an expert thank you >>>>>>>>>>>>>>>>> Link to post Share on other sites
coriell12277 Posted August 24, 2007 Author Report Share Posted August 24, 2007 an also here is my combofixComboFix 07-08-17.2 - "chris" 08/24/2007 3:11:29.1 - NTFSx86 Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.129 [GMT -7:00]((((((((((((((((((((((((( Files Created from 2007-07-24 to 2007-08-24 )))))))))))))))))))))))))))))))2007-08-24 03:08 51,200 --a------ C:\WINNT\nircmd.exe2007-08-23 22:23 <DIR> d-------- C:\DOCUME~1\chris\APPLIC~1\gtopala2007-08-23 22:19 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_390.dat2007-08-23 16:21 <DIR> d-------- C:\WINNT\system32\SoftwareDistribution2007-08-21 20:16 <DIR> d-------- C:\WINNT\Downloaded Installations2007-08-19 18:26 75,932 --a------ C:\WINNT\system32\drivers\klick.dat2007-08-19 18:26 75,248 --a------ C:\WINNT\zllsputility.exe2007-08-19 18:26 74,396 --a------ C:\WINNT\system32\drivers\klin.dat2007-08-19 18:25 14,368 --ahs---- C:\WINNT\system32\drivers\fidbox.dat2007-08-19 18:25 110,360 --a------ C:\WINNT\system32\drivers\kl1.sys2007-08-19 18:25 1,086,952 --a------ C:\WINNT\system32\zpeng24.dll2007-08-19 18:25 1,056 --ahs---- C:\WINNT\system32\drivers\fidbox2.dat2007-08-19 18:25 <DIR> d-------- C:\WINNT\system32\ZoneLabs2007-08-18 20:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft2007-08-18 10:34 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_2fc.dat2007-08-17 17:35 <DIR> d-------- C:\Program Files\Enigma Software Group2007-08-15 09:48 <DIR> d-------- C:\DOCUME~1\chris\APPLIC~1\OpenOffice.org22007-08-06 10:09 <DIR> d-------- C:\My Downloads2007-08-05 06:56 <DIR> d--h----- C:\WINNT\PIF2007-08-04 22:06 <DIR> d-------- C:\WINNT\pss2007-08-04 17:08 <DIR> d-------- C:\Program Files\Crawler2007-08-04 15:05 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\Motive2007-08-04 15:04 <DIR> d-a------ C:\Program Files\Common Files\Motive2007-08-01 23:29 <DIR> d-a------ C:\WINNT\system32\appmgmt2007-08-01 20:32 <DIR> d-------- C:\Program Files\TightVNC2007-08-01 19:40 4,212 ---h----- C:\WINNT\system32\zllictbl.dat2007-08-01 19:40 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier2007-08-01 19:39 11,264 --a------ C:\WINNT\system32\SpOrder.dll2007-08-01 19:32 <DIR> d-a------ C:\WINNT\Internet Logs2007-08-01 18:00 <DIR> d-------- C:\Program Files\Trend Micro2007-07-30 20:25 <DIR> d-------- C:\DOCUME~1\chris\APPLIC~1\vlc2007-07-30 19:19 203,096 --a------ C:\WINNT\system32\wuweb.dll2007-07-30 19:18 207,736 --a------ C:\WINNT\system32\muweb.dll2007-07-29 10:39 <DIR> d-------- C:\DOCUME~1\chris\Shared2007-07-29 10:39 <DIR> d-------- C:\DOCUME~1\chris\Incomplete2007-07-29 10:38 <DIR> d-------- C:\DOCUME~1\chris\APPLIC~1\LimeWire2007-07-28 23:02 <DIR> d-------- C:\Program Files\Absolute Poker2007-07-28 23:02 <DIR> d-------- C:\Program Files\_uninstallation_info2007-07-28 20:27 <DIR> d-------- C:\DOCUME~1\chris\APPLIC~1\Azureus2007-07-28 20:27 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Azureus2007-07-28 20:19 <DIR> d-------- C:\Program Files\Azureus2007-07-28 20:13 87,040 --a------ C:\WINNT\system32\drmstor.dll2007-07-28 20:13 43,528 --------- C:\WINNT\system32\drivers\PxHelp20.sys2007-07-28 20:13 306,424 --a------ C:\WINNT\system32\drmclien.dll2007-07-28 20:13 129,784 --------- C:\WINNT\system32\pxafs.dll2007-07-28 20:12 <DIR> d-------- C:\Program Files\Winamp2007-07-28 20:08 765,952 --a------ C:\WINNT\system32\xvidcore.dll2007-07-28 20:08 73,728 --a------ C:\WINNT\system32\dpl100.dll2007-07-28 20:08 639,066 --a------ C:\WINNT\system32\divx.dll2007-07-28 20:08 3,596,288 --a------ C:\WINNT\system32\qt-dx331.dll2007-07-28 20:08 200,704 --a------ C:\WINNT\system32\ssldivx.dll2007-07-28 20:08 196,608 --a------ C:\WINNT\system32\dtu100.dll2007-07-28 20:08 180,224 --a------ C:\WINNT\system32\xvidvfw.dll2007-07-28 20:08 10,752 --a------ C:\WINNT\system32\ff_vfw.dll2007-07-28 20:08 1,415,680 --a------ C:\WINNT\system32\wmv9vcm.dll2007-07-28 20:08 1,044,480 --a------ C:\WINNT\system32\libdivx.dll2007-07-28 20:08 <DIR> d-------- C:\Program Files\K-Lite Codec Pack2007-07-28 19:48 <DIR> d-------- C:\WINNT\PCHEALTH2007-07-28 19:43 <DIR> d-------- C:\WINNT\system32\URTTemp2007-07-28 19:18 98,304 --a------ C:\WINNT\system32\wmpshell.dll2007-07-28 19:18 940,544 --a------ C:\WINNT\system32\wmspdmoe.dll2007-07-28 19:18 9,464 --------- C:\WINNT\system32\drivers\cdralw2k.sys2007-07-28 19:18 9,336 --------- C:\WINNT\system32\drivers\cdr4_2K.sys2007-07-28 19:18 895,736 --a------ C:\WINNT\system32\wmvdmod.dll2007-07-28 19:18 774,904 --a------ C:\WINNT\system32\wmsdmod.dll2007-07-28 19:18 716,288 --a------ C:\WINNT\system32\wmadmoe.dll2007-07-28 19:18 7,680 --a------ C:\WINNT\system32\asferror.dll2007-07-28 19:18 6,656 --a------ C:\WINNT\system32\laprxy.dll2007-07-28 19:18 57,344 --a------ C:\WINNT\uneng.exe2007-07-28 19:18 52,224 --a------ C:\WINNT\system32\mspmsnsv.dll2007-07-28 19:18 49,152 --a------ C:\WINNT\system32\cdrtc.dll2007-07-28 19:18 45,056 --a------ C:\WINNT\system32\cdral.dll2007-07-28 19:18 413,944 --a------ C:\WINNT\system32\wmspdmod.dll2007-07-28 19:18 401,462 --a------ C:\WINNT\system32\Msvcp60.dll2007-07-28 19:18 396,528 --a------ C:\WINNT\system32\wmadmod.dll2007-07-28 19:18 384,512 --a------ C:\WINNT\system32\mp4sdmod.dll2007-07-28 19:18 358,912 --a------ C:\WINNT\system32\msscp.dll2007-07-28 19:18 317,176 --a------ C:\WINNT\system32\mp43dmod.dll2007-07-28 19:18 27,136 --a------ C:\WINNT\system32\wmdmlog.dll2007-07-28 19:18 245,760 --a------ C:\WINNT\system32\mswmdm.dll2007-07-28 19:18 240,640 --a------ C:\WINNT\system32\mpg4dmod.dll2007-07-28 19:18 23,552 --a------ C:\WINNT\system32\wmdmps.dll2007-07-28 19:18 225,280 --a------ C:\WINNT\system32\wmpdxm.dll2007-07-28 19:18 208,896 --a------ C:\WINNT\system32\wmpns.dll2007-07-28 19:18 201,728 --a------ C:\WINNT\system32\mspmsp.dll2007-07-28 19:18 20,480 --a------ C:\WINNT\system32\wmpui.dll2007-07-28 19:18 20,480 --a------ C:\WINNT\system32\wmpcore.dll2007-07-28 19:18 20,480 --a------ C:\WINNT\system32\wmpcd.dll2007-07-28 19:18 2,940,928 --a------ C:\WINNT\system32\wmploc.dll2007-07-28 19:18 167,936 --a------ C:\WINNT\system32\wmerror.dll2007-07-28 19:18 159,232 --a------ C:\WINNT\system32\CEWMDM.dll2007-07-28 19:18 151,552 --a------ C:\WINNT\system32\wmidx.dll2007-07-28 19:18 106,496 --a------ C:\WINNT\system32\wmpasf.dll2007-07-28 19:18 103,936 --a------ C:\WINNT\system32\logagent.exe2007-07-28 19:18 1,119,744 --a------ C:\WINNT\system32\wmsdmoe2.dll2007-07-28 19:18 1,022,464 --a------ C:\WINNT\system32\wmnetmgr.dll2007-07-28 19:18 1,003,008 --a------ C:\WINNT\system32\wmvdmoe2.dll2007-07-28 19:18 <DIR> d-------- C:\Program Files\Common Files\Adaptec Shared2007-07-28 19:17 696,320 --a------ C:\WINNT\system32\drmv2clt.dll2007-07-28 19:17 294,400 --a------ C:\WINNT\system32\blackbox.dll(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))12/31/02 05:00a 32528 --a------ C:\WINNT\inf\wbfirdma.sys08/19/07 06:30p 1244 --ahs---- C:\WINNT\system32\drivers\fidbox.idx08/19/07 06:30p 1172 --ahs---- C:\WINNT\system32\drivers\fidbox2.idx07/30/07 07:19p 92504 --a------ C:\WINNT\system32\cdm.dll07/28/07 04:25p 271 ---h----- C:\Program Files\desktop.ini07/28/07 04:25p 21952 ---h----- C:\Program Files\folder.htt06/26/07 02:57a 235280 --a------ C:\WINNT\system32\GDI32.DLL06/06/07 11:50p 1119232 --a------ C:\WINNT\system32\msxml3.dll((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))*Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [06/21/07 09:54p]"Synchronization Manager"="mobsync.exe" [12/31/02 05:00a C:\WINNT\system32\mobsync.exe]"AVG7_CC"="C:\Program Files\Grisoft\AVG7\avgcc.exe" [08/17/07 10:32a]"MSConfig"="C:\Documents and Settings\chris\My Documents\msconfig.exe" [08/04/07 10:06p][HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktopC:\Documents and Settings\chris\Start Menu\Programs\Startup\Trillian.lnk - C:\Program Files\Trillian Pro\trillian.exe [2007-07-28 18:14:43][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]@="Driver"[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]@="Driver"[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quietR1 Avg7RsNT;AVG7 Resident Driver NT;C:\WINNT\system32\Drivers\avg7rsnt.sys*Newly Created Service* - SIWIO**************************************************************************catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2007-08-24 03:13:28Windows 5.0.2195 Service Pack 4 NTFSscanning hidden processes ...scanning hidden autostart entries ...scanning hidden files ...scan completed successfullyhidden files: 0**************************************************************************Completion time: 08/24/2007 3:14:28 --- E O F --- loag also someone please look an expert thank you >>>>>>>>>>>>>>>>> an heres SMITHFRAUD REPORT ALSO>>>>>>>>>>>>>>>>>>>>>>>> Link to post Share on other sites
coriell12277 Posted August 24, 2007 Author Report Share Posted August 24, 2007 an also here is my combofixComboFix 07-08-17.2 - "chris" 08/24/2007 3:11:29.1 - NTFSx86 Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.129 [GMT -7:00]((((((((((((((((((((((((( Files Created from 2007-07-24 to 2007-08-24 )))))))))))))))))))))))))))))))2007-08-24 03:08 51,200 --a------ C:\WINNT\nircmd.exe2007-08-23 22:23 <DIR> d-------- C:\DOCUME~1\chris\APPLIC~1\gtopala2007-08-23 22:19 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_390.dat2007-08-23 16:21 <DIR> d-------- C:\WINNT\system32\SoftwareDistribution2007-08-21 20:16 <DIR> d-------- C:\WINNT\Downloaded Installations2007-08-19 18:26 75,932 --a------ C:\WINNT\system32\drivers\klick.dat2007-08-19 18:26 75,248 --a------ C:\WINNT\zllsputility.exe2007-08-19 18:26 74,396 --a------ C:\WINNT\system32\drivers\klin.dat2007-08-19 18:25 14,368 --ahs---- C:\WINNT\system32\drivers\fidbox.dat2007-08-19 18:25 110,360 --a------ C:\WINNT\system32\drivers\kl1.sys2007-08-19 18:25 1,086,952 --a------ C:\WINNT\system32\zpeng24.dll2007-08-19 18:25 1,056 --ahs---- C:\WINNT\system32\drivers\fidbox2.dat2007-08-19 18:25 <DIR> d-------- C:\WINNT\system32\ZoneLabs2007-08-18 20:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft2007-08-18 10:34 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_2fc.dat2007-08-17 17:35 <DIR> d-------- C:\Program Files\Enigma Software Group2007-08-15 09:48 <DIR> d-------- C:\DOCUME~1\chris\APPLIC~1\OpenOffice.org22007-08-06 10:09 <DIR> d-------- C:\My Downloads2007-08-05 06:56 <DIR> d--h----- C:\WINNT\PIF2007-08-04 22:06 <DIR> d-------- C:\WINNT\pss2007-08-04 17:08 <DIR> d-------- C:\Program Files\Crawler2007-08-04 15:05 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\Motive2007-08-04 15:04 <DIR> d-a------ C:\Program Files\Common Files\Motive2007-08-01 23:29 <DIR> d-a------ C:\WINNT\system32\appmgmt2007-08-01 20:32 <DIR> d-------- C:\Program Files\TightVNC2007-08-01 19:40 4,212 ---h----- C:\WINNT\system32\zllictbl.dat2007-08-01 19:40 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier2007-08-01 19:39 11,264 --a------ C:\WINNT\system32\SpOrder.dll2007-08-01 19:32 <DIR> d-a------ C:\WINNT\Internet Logs2007-08-01 18:00 <DIR> d-------- C:\Program Files\Trend Micro2007-07-30 20:25 <DIR> d-------- C:\DOCUME~1\chris\APPLIC~1\vlc2007-07-30 19:19 203,096 --a------ C:\WINNT\system32\wuweb.dll2007-07-30 19:18 207,736 --a------ C:\WINNT\system32\muweb.dll2007-07-29 10:39 <DIR> d-------- C:\DOCUME~1\chris\Shared2007-07-29 10:39 <DIR> d-------- C:\DOCUME~1\chris\Incomplete2007-07-29 10:38 <DIR> d-------- C:\DOCUME~1\chris\APPLIC~1\LimeWire2007-07-28 23:02 <DIR> d-------- C:\Program Files\Absolute Poker2007-07-28 23:02 <DIR> d-------- C:\Program Files\_uninstallation_info2007-07-28 20:27 <DIR> d-------- C:\DOCUME~1\chris\APPLIC~1\Azureus2007-07-28 20:27 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Azureus2007-07-28 20:19 <DIR> d-------- C:\Program Files\Azureus2007-07-28 20:13 87,040 --a------ C:\WINNT\system32\drmstor.dll2007-07-28 20:13 43,528 --------- C:\WINNT\system32\drivers\PxHelp20.sys2007-07-28 20:13 306,424 --a------ C:\WINNT\system32\drmclien.dll2007-07-28 20:13 129,784 --------- C:\WINNT\system32\pxafs.dll2007-07-28 20:12 <DIR> d-------- C:\Program Files\Winamp2007-07-28 20:08 765,952 --a------ C:\WINNT\system32\xvidcore.dll2007-07-28 20:08 73,728 --a------ C:\WINNT\system32\dpl100.dll2007-07-28 20:08 639,066 --a------ C:\WINNT\system32\divx.dll2007-07-28 20:08 3,596,288 --a------ C:\WINNT\system32\qt-dx331.dll2007-07-28 20:08 200,704 --a------ C:\WINNT\system32\ssldivx.dll2007-07-28 20:08 196,608 --a------ C:\WINNT\system32\dtu100.dll2007-07-28 20:08 180,224 --a------ C:\WINNT\system32\xvidvfw.dll2007-07-28 20:08 10,752 --a------ C:\WINNT\system32\ff_vfw.dll2007-07-28 20:08 1,415,680 --a------ C:\WINNT\system32\wmv9vcm.dll2007-07-28 20:08 1,044,480 --a------ C:\WINNT\system32\libdivx.dll2007-07-28 20:08 <DIR> d-------- C:\Program Files\K-Lite Codec Pack2007-07-28 19:48 <DIR> d-------- C:\WINNT\PCHEALTH2007-07-28 19:43 <DIR> d-------- C:\WINNT\system32\URTTemp2007-07-28 19:18 98,304 --a------ C:\WINNT\system32\wmpshell.dll2007-07-28 19:18 940,544 --a------ C:\WINNT\system32\wmspdmoe.dll2007-07-28 19:18 9,464 --------- C:\WINNT\system32\drivers\cdralw2k.sys2007-07-28 19:18 9,336 --------- C:\WINNT\system32\drivers\cdr4_2K.sys2007-07-28 19:18 895,736 --a------ C:\WINNT\system32\wmvdmod.dll2007-07-28 19:18 774,904 --a------ C:\WINNT\system32\wmsdmod.dll2007-07-28 19:18 716,288 --a------ C:\WINNT\system32\wmadmoe.dll2007-07-28 19:18 7,680 --a------ C:\WINNT\system32\asferror.dll2007-07-28 19:18 6,656 --a------ C:\WINNT\system32\laprxy.dll2007-07-28 19:18 57,344 --a------ C:\WINNT\uneng.exe2007-07-28 19:18 52,224 --a------ C:\WINNT\system32\mspmsnsv.dll2007-07-28 19:18 49,152 --a------ C:\WINNT\system32\cdrtc.dll2007-07-28 19:18 45,056 --a------ C:\WINNT\system32\cdral.dll2007-07-28 19:18 413,944 --a------ C:\WINNT\system32\wmspdmod.dll2007-07-28 19:18 401,462 --a------ C:\WINNT\system32\Msvcp60.dll2007-07-28 19:18 396,528 --a------ C:\WINNT\system32\wmadmod.dll2007-07-28 19:18 384,512 --a------ C:\WINNT\system32\mp4sdmod.dll2007-07-28 19:18 358,912 --a------ C:\WINNT\system32\msscp.dll2007-07-28 19:18 317,176 --a------ C:\WINNT\system32\mp43dmod.dll2007-07-28 19:18 27,136 --a------ C:\WINNT\system32\wmdmlog.dll2007-07-28 19:18 245,760 --a------ C:\WINNT\system32\mswmdm.dll2007-07-28 19:18 240,640 --a------ C:\WINNT\system32\mpg4dmod.dll2007-07-28 19:18 23,552 --a------ C:\WINNT\system32\wmdmps.dll2007-07-28 19:18 225,280 --a------ C:\WINNT\system32\wmpdxm.dll2007-07-28 19:18 208,896 --a------ C:\WINNT\system32\wmpns.dll2007-07-28 19:18 201,728 --a------ C:\WINNT\system32\mspmsp.dll2007-07-28 19:18 20,480 --a------ C:\WINNT\system32\wmpui.dll2007-07-28 19:18 20,480 --a------ C:\WINNT\system32\wmpcore.dll2007-07-28 19:18 20,480 --a------ C:\WINNT\system32\wmpcd.dll2007-07-28 19:18 2,940,928 --a------ C:\WINNT\system32\wmploc.dll2007-07-28 19:18 167,936 --a------ C:\WINNT\system32\wmerror.dll2007-07-28 19:18 159,232 --a------ C:\WINNT\system32\CEWMDM.dll2007-07-28 19:18 151,552 --a------ C:\WINNT\system32\wmidx.dll2007-07-28 19:18 106,496 --a------ C:\WINNT\system32\wmpasf.dll2007-07-28 19:18 103,936 --a------ C:\WINNT\system32\logagent.exe2007-07-28 19:18 1,119,744 --a------ C:\WINNT\system32\wmsdmoe2.dll2007-07-28 19:18 1,022,464 --a------ C:\WINNT\system32\wmnetmgr.dll2007-07-28 19:18 1,003,008 --a------ C:\WINNT\system32\wmvdmoe2.dll2007-07-28 19:18 <DIR> d-------- C:\Program Files\Common Files\Adaptec Shared2007-07-28 19:17 696,320 --a------ C:\WINNT\system32\drmv2clt.dll2007-07-28 19:17 294,400 --a------ C:\WINNT\system32\blackbox.dll(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))12/31/02 05:00a 32528 --a------ C:\WINNT\inf\wbfirdma.sys08/19/07 06:30p 1244 --ahs---- C:\WINNT\system32\drivers\fidbox.idx08/19/07 06:30p 1172 --ahs---- C:\WINNT\system32\drivers\fidbox2.idx07/30/07 07:19p 92504 --a------ C:\WINNT\system32\cdm.dll07/28/07 04:25p 271 ---h----- C:\Program Files\desktop.ini07/28/07 04:25p 21952 ---h----- C:\Program Files\folder.htt06/26/07 02:57a 235280 --a------ C:\WINNT\system32\GDI32.DLL06/06/07 11:50p 1119232 --a------ C:\WINNT\system32\msxml3.dll((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))*Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [06/21/07 09:54p]"Synchronization Manager"="mobsync.exe" [12/31/02 05:00a C:\WINNT\system32\mobsync.exe]"AVG7_CC"="C:\Program Files\Grisoft\AVG7\avgcc.exe" [08/17/07 10:32a]"MSConfig"="C:\Documents and Settings\chris\My Documents\msconfig.exe" [08/04/07 10:06p][HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktopC:\Documents and Settings\chris\Start Menu\Programs\Startup\Trillian.lnk - C:\Program Files\Trillian Pro\trillian.exe [2007-07-28 18:14:43][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]@="Driver"[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]@="Driver"[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quietR1 Avg7RsNT;AVG7 Resident Driver NT;C:\WINNT\system32\Drivers\avg7rsnt.sys*Newly Created Service* - SIWIO**************************************************************************catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2007-08-24 03:13:28Windows 5.0.2195 Service Pack 4 NTFSscanning hidden processes ...scanning hidden autostart entries ...scanning hidden files ...scan completed successfullyhidden files: 0**************************************************************************Completion time: 08/24/2007 3:14:28 --- E O F --- loag also someone please look an expert thank you >>>>>>>>>>>>>>>>> an heres SMITHFRAUD REPORT ALSO>>>>>>>>>>>>>>>>>>>>>>>>SMITH FRAUD REPORT ALSO >>>>>>>>>>>>>>>>>>>>SmitFraudFix v2.216Scan done at 12:00:13.67, Fri 08/24/2007Run from C:\Program Files\Mozilla Firefox\SmitfraudFixOS: Microsoft Windows 2000 [Version 5.00.2195] - Windows_NTThe filesystem type is NTFSFix run in normal mode»»»»»»»»»»»»»»»»»»»»»»»» ProcessC:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\spoolsv.exeC:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeC:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeC:\PROGRA~1\Grisoft\AVG7\avgemc.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\regsvc.exeC:\WINNT\system32\MSTask.exeC:\WINNT\System32\WBEM\WinMgmt.exeC:\Program Files\TightVNC\WinVNC.exeC:\WINNT\system32\svchost.exeC:\WINNT\explorer.exeC:\Program Files\Zone Labs\ZoneAlarm\zlclient.exeC:\Program Files\Grisoft\AVG7\avgcc.exeC:\WINNT\system32\ZoneLabs\vsmon.exeC:\Program Files\Trillian Pro\trillian.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\WINNT\system32\cmd.exe»»»»»»»»»»»»»»»»»»»»»»»» hosts»»»»»»»»»»»»»»»»»»»»»»»» C:\»»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT»»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\system»»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\Web»»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\system32»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\chris»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\chris\Application Data»»»»»»»»»»»»»»»»»»»»»»»» Start Menu»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\chris\FAVORI~1»»»»»»»»»»»»»»»»»»»»»»»» Desktop»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components]"Source"="About:Home""SubscribedURL"="About:Home""FriendlyName"="My Current Home Page"»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler!!!Attention, following keys are not inevitably infected!!!SrchSTS.exe by S!RiSearch SharedTaskScheduler's .dll»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs!!!Attention, following keys are not inevitably infected!!![HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]"AppInit_DLLs"=""»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System!!!Attention, following keys are not inevitably infected!!![HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]"System"=""»»»»»»»»»»»»»»»»»»»»»»»» Rustock»»»»»»»»»»»»»»»»»»»»»»»» DNSDescription: NDIS 5.0 driver DNS Server Search Order: 192.168.2.1HKLM\SYSTEM\CCS\Services\Tcpip\..\{0516AB7D-9AF5-48F6-B899-ACB54132F533}: DhcpNameServer=192.168.2.1HKLM\SYSTEM\CS1\Services\Tcpip\..\{0516AB7D-9AF5-48F6-B899-ACB54132F533}: DhcpNameServer=192.168.2.1HKLM\SYSTEM\CS2\Services\Tcpip\..\{0516AB7D-9AF5-48F6-B899-ACB54132F533}: DhcpNameServer=192.168.2.1HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection»»»»»»»»»»»»»»»»»»»»»»»» End Link to post Share on other sites
coriell12277 Posted August 25, 2007 Author Report Share Posted August 25, 2007 an also here is my combofixComboFix 07-08-17.2 - "chris" 08/24/2007 3:11:29.1 - NTFSx86 Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.129 [GMT -7:00]((((((((((((((((((((((((( Files Created from 2007-07-24 to 2007-08-24 )))))))))))))))))))))))))))))))2007-08-24 03:08 51,200 --a------ C:\WINNT\nircmd.exe2007-08-23 22:23 <DIR> d-------- C:\DOCUME~1\chris\APPLIC~1\gtopala2007-08-23 22:19 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_390.dat2007-08-23 16:21 <DIR> d-------- C:\WINNT\system32\SoftwareDistribution2007-08-21 20:16 <DIR> d-------- C:\WINNT\Downloaded Installations2007-08-19 18:26 75,932 --a------ C:\WINNT\system32\drivers\klick.dat2007-08-19 18:26 75,248 --a------ C:\WINNT\zllsputility.exe2007-08-19 18:26 74,396 --a------ C:\WINNT\system32\drivers\klin.dat2007-08-19 18:25 14,368 --ahs---- C:\WINNT\system32\drivers\fidbox.dat2007-08-19 18:25 110,360 --a------ C:\WINNT\system32\drivers\kl1.sys2007-08-19 18:25 1,086,952 --a------ C:\WINNT\system32\zpeng24.dll2007-08-19 18:25 1,056 --ahs---- C:\WINNT\system32\drivers\fidbox2.dat2007-08-19 18:25 <DIR> d-------- C:\WINNT\system32\ZoneLabs2007-08-18 20:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft2007-08-18 10:34 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_2fc.dat2007-08-17 17:35 <DIR> d-------- C:\Program Files\Enigma Software Group2007-08-15 09:48 <DIR> d-------- C:\DOCUME~1\chris\APPLIC~1\OpenOffice.org22007-08-06 10:09 <DIR> d-------- C:\My Downloads2007-08-05 06:56 <DIR> d--h----- C:\WINNT\PIF2007-08-04 22:06 <DIR> d-------- C:\WINNT\pss2007-08-04 17:08 <DIR> d-------- C:\Program Files\Crawler2007-08-04 15:05 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\Motive2007-08-04 15:04 <DIR> d-a------ C:\Program Files\Common Files\Motive2007-08-01 23:29 <DIR> d-a------ C:\WINNT\system32\appmgmt2007-08-01 20:32 <DIR> d-------- C:\Program Files\TightVNC2007-08-01 19:40 4,212 ---h----- C:\WINNT\system32\zllictbl.dat2007-08-01 19:40 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier2007-08-01 19:39 11,264 --a------ C:\WINNT\system32\SpOrder.dll2007-08-01 19:32 <DIR> d-a------ C:\WINNT\Internet Logs2007-08-01 18:00 <DIR> d-------- C:\Program Files\Trend Micro2007-07-30 20:25 <DIR> d-------- C:\DOCUME~1\chris\APPLIC~1\vlc2007-07-30 19:19 203,096 --a------ C:\WINNT\system32\wuweb.dll2007-07-30 19:18 207,736 --a------ C:\WINNT\system32\muweb.dll2007-07-29 10:39 <DIR> d-------- C:\DOCUME~1\chris\Shared2007-07-29 10:39 <DIR> d-------- C:\DOCUME~1\chris\Incomplete2007-07-29 10:38 <DIR> d-------- C:\DOCUME~1\chris\APPLIC~1\LimeWire2007-07-28 23:02 <DIR> d-------- C:\Program Files\Absolute Poker2007-07-28 23:02 <DIR> d-------- C:\Program Files\_uninstallation_info2007-07-28 20:27 <DIR> d-------- C:\DOCUME~1\chris\APPLIC~1\Azureus2007-07-28 20:27 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Azureus2007-07-28 20:19 <DIR> d-------- C:\Program Files\Azureus2007-07-28 20:13 87,040 --a------ C:\WINNT\system32\drmstor.dll2007-07-28 20:13 43,528 --------- C:\WINNT\system32\drivers\PxHelp20.sys2007-07-28 20:13 306,424 --a------ C:\WINNT\system32\drmclien.dll2007-07-28 20:13 129,784 --------- C:\WINNT\system32\pxafs.dll2007-07-28 20:12 <DIR> d-------- C:\Program Files\Winamp2007-07-28 20:08 765,952 --a------ C:\WINNT\system32\xvidcore.dll2007-07-28 20:08 73,728 --a------ C:\WINNT\system32\dpl100.dll2007-07-28 20:08 639,066 --a------ C:\WINNT\system32\divx.dll2007-07-28 20:08 3,596,288 --a------ C:\WINNT\system32\qt-dx331.dll2007-07-28 20:08 200,704 --a------ C:\WINNT\system32\ssldivx.dll2007-07-28 20:08 196,608 --a------ C:\WINNT\system32\dtu100.dll2007-07-28 20:08 180,224 --a------ C:\WINNT\system32\xvidvfw.dll2007-07-28 20:08 10,752 --a------ C:\WINNT\system32\ff_vfw.dll2007-07-28 20:08 1,415,680 --a------ C:\WINNT\system32\wmv9vcm.dll2007-07-28 20:08 1,044,480 --a------ C:\WINNT\system32\libdivx.dll2007-07-28 20:08 <DIR> d-------- C:\Program Files\K-Lite Codec Pack2007-07-28 19:48 <DIR> d-------- C:\WINNT\PCHEALTH2007-07-28 19:43 <DIR> d-------- C:\WINNT\system32\URTTemp2007-07-28 19:18 98,304 --a------ C:\WINNT\system32\wmpshell.dll2007-07-28 19:18 940,544 --a------ C:\WINNT\system32\wmspdmoe.dll2007-07-28 19:18 9,464 --------- C:\WINNT\system32\drivers\cdralw2k.sys2007-07-28 19:18 9,336 --------- C:\WINNT\system32\drivers\cdr4_2K.sys2007-07-28 19:18 895,736 --a------ C:\WINNT\system32\wmvdmod.dll2007-07-28 19:18 774,904 --a------ C:\WINNT\system32\wmsdmod.dll2007-07-28 19:18 716,288 --a------ C:\WINNT\system32\wmadmoe.dll2007-07-28 19:18 7,680 --a------ C:\WINNT\system32\asferror.dll2007-07-28 19:18 6,656 --a------ C:\WINNT\system32\laprxy.dll2007-07-28 19:18 57,344 --a------ C:\WINNT\uneng.exe2007-07-28 19:18 52,224 --a------ C:\WINNT\system32\mspmsnsv.dll2007-07-28 19:18 49,152 --a------ C:\WINNT\system32\cdrtc.dll2007-07-28 19:18 45,056 --a------ C:\WINNT\system32\cdral.dll2007-07-28 19:18 413,944 --a------ C:\WINNT\system32\wmspdmod.dll2007-07-28 19:18 401,462 --a------ C:\WINNT\system32\Msvcp60.dll2007-07-28 19:18 396,528 --a------ C:\WINNT\system32\wmadmod.dll2007-07-28 19:18 384,512 --a------ C:\WINNT\system32\mp4sdmod.dll2007-07-28 19:18 358,912 --a------ C:\WINNT\system32\msscp.dll2007-07-28 19:18 317,176 --a------ C:\WINNT\system32\mp43dmod.dll2007-07-28 19:18 27,136 --a------ C:\WINNT\system32\wmdmlog.dll2007-07-28 19:18 245,760 --a------ C:\WINNT\system32\mswmdm.dll2007-07-28 19:18 240,640 --a------ C:\WINNT\system32\mpg4dmod.dll2007-07-28 19:18 23,552 --a------ C:\WINNT\system32\wmdmps.dll2007-07-28 19:18 225,280 --a------ C:\WINNT\system32\wmpdxm.dll2007-07-28 19:18 208,896 --a------ C:\WINNT\system32\wmpns.dll2007-07-28 19:18 201,728 --a------ C:\WINNT\system32\mspmsp.dll2007-07-28 19:18 20,480 --a------ C:\WINNT\system32\wmpui.dll2007-07-28 19:18 20,480 --a------ C:\WINNT\system32\wmpcore.dll2007-07-28 19:18 20,480 --a------ C:\WINNT\system32\wmpcd.dll2007-07-28 19:18 2,940,928 --a------ C:\WINNT\system32\wmploc.dll2007-07-28 19:18 167,936 --a------ C:\WINNT\system32\wmerror.dll2007-07-28 19:18 159,232 --a------ C:\WINNT\system32\CEWMDM.dll2007-07-28 19:18 151,552 --a------ C:\WINNT\system32\wmidx.dll2007-07-28 19:18 106,496 --a------ C:\WINNT\system32\wmpasf.dll2007-07-28 19:18 103,936 --a------ C:\WINNT\system32\logagent.exe2007-07-28 19:18 1,119,744 --a------ C:\WINNT\system32\wmsdmoe2.dll2007-07-28 19:18 1,022,464 --a------ C:\WINNT\system32\wmnetmgr.dll2007-07-28 19:18 1,003,008 --a------ C:\WINNT\system32\wmvdmoe2.dll2007-07-28 19:18 <DIR> d-------- C:\Program Files\Common Files\Adaptec Shared2007-07-28 19:17 696,320 --a------ C:\WINNT\system32\drmv2clt.dll2007-07-28 19:17 294,400 --a------ C:\WINNT\system32\blackbox.dll(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))12/31/02 05:00a 32528 --a------ C:\WINNT\inf\wbfirdma.sys08/19/07 06:30p 1244 --ahs---- C:\WINNT\system32\drivers\fidbox.idx08/19/07 06:30p 1172 --ahs---- C:\WINNT\system32\drivers\fidbox2.idx07/30/07 07:19p 92504 --a------ C:\WINNT\system32\cdm.dll07/28/07 04:25p 271 ---h----- C:\Program Files\desktop.ini07/28/07 04:25p 21952 ---h----- C:\Program Files\folder.htt06/26/07 02:57a 235280 --a------ C:\WINNT\system32\GDI32.DLL06/06/07 11:50p 1119232 --a------ C:\WINNT\system32\msxml3.dll((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))*Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [06/21/07 09:54p]"Synchronization Manager"="mobsync.exe" [12/31/02 05:00a C:\WINNT\system32\mobsync.exe]"AVG7_CC"="C:\Program Files\Grisoft\AVG7\avgcc.exe" [08/17/07 10:32a]"MSConfig"="C:\Documents and Settings\chris\My Documents\msconfig.exe" [08/04/07 10:06p][HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktopC:\Documents and Settings\chris\Start Menu\Programs\Startup\Trillian.lnk - C:\Program Files\Trillian Pro\trillian.exe [2007-07-28 18:14:43][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]@="Driver"[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]@="Driver"[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quietR1 Avg7RsNT;AVG7 Resident Driver NT;C:\WINNT\system32\Drivers\avg7rsnt.sys*Newly Created Service* - SIWIO**************************************************************************catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2007-08-24 03:13:28Windows 5.0.2195 Service Pack 4 NTFSscanning hidden processes ...scanning hidden autostart entries ...scanning hidden files ...scan completed successfullyhidden files: 0**************************************************************************Completion time: 08/24/2007 3:14:28 --- E O F --- loag also someone please look an expert thank you >>>>>>>>>>>>>>>>> an heres SMITHFRAUD REPORT ALSO>>>>>>>>>>>>>>>>>>>>>>>>SMITH FRAUD REPORT ALSO >>>>>>>>>>>>>>>>>>>>SmitFraudFix v2.216Scan done at 12:00:13.67, Fri 08/24/2007Run from C:\Program Files\Mozilla Firefox\SmitfraudFixOS: Microsoft Windows 2000 [Version 5.00.2195] - Windows_NTThe filesystem type is NTFSFix run in normal mode»»»»»»»»»»»»»»»»»»»»»»»» ProcessC:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\spoolsv.exeC:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeC:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeC:\PROGRA~1\Grisoft\AVG7\avgemc.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\regsvc.exeC:\WINNT\system32\MSTask.exeC:\WINNT\System32\WBEM\WinMgmt.exeC:\Program Files\TightVNC\WinVNC.exeC:\WINNT\system32\svchost.exeC:\WINNT\explorer.exeC:\Program Files\Zone Labs\ZoneAlarm\zlclient.exeC:\Program Files\Grisoft\AVG7\avgcc.exeC:\WINNT\system32\ZoneLabs\vsmon.exeC:\Program Files\Trillian Pro\trillian.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\WINNT\system32\cmd.exe»»»»»»»»»»»»»»»»»»»»»»»» hosts»»»»»»»»»»»»»»»»»»»»»»»» C:\»»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT»»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\system»»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\Web»»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\system32»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\chris»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\chris\Application Data»»»»»»»»»»»»»»»»»»»»»»»» Start Menu»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\chris\FAVORI~1»»»»»»»»»»»»»»»»»»»»»»»» Desktop»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components]"Source"="About:Home""SubscribedURL"="About:Home""FriendlyName"="My Current Home Page"»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler!!!Attention, following keys are not inevitably infected!!!SrchSTS.exe by S!RiSearch SharedTaskScheduler's .dll»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs!!!Attention, following keys are not inevitably infected!!![HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]"AppInit_DLLs"=""»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System!!!Attention, following keys are not inevitably infected!!![HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]"System"=""»»»»»»»»»»»»»»»»»»»»»»»» Rustock»»»»»»»»»»»»»»»»»»»»»»»» DNSDescription: NDIS 5.0 driver DNS Server Search Order: 192.168.2.1HKLM\SYSTEM\CCS\Services\Tcpip\..\{0516AB7D-9AF5-48F6-B899-ACB54132F533}: DhcpNameServer=192.168.2.1HKLM\SYSTEM\CS1\Services\Tcpip\..\{0516AB7D-9AF5-48F6-B899-ACB54132F533}: DhcpNameServer=192.168.2.1HKLM\SYSTEM\CS2\Services\Tcpip\..\{0516AB7D-9AF5-48F6-B899-ACB54132F533}: DhcpNameServer=192.168.2.1HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection»»»»»»»»»»»»»»»»»»»»»»»» Endwow this site takes forever for to get some help cant belive this stuff Link to post Share on other sites
Besttechie Posted August 25, 2007 Report Share Posted August 25, 2007 Hi coriell12277,By replying to your own log it makes it seem you're getting help. The helpers here look for posts with 0 replies first. Sorry about the wait, please post a new HJT log and I will have someone on the look out for your thread. B Link to post Share on other sites
coriell12277 Posted August 25, 2007 Author Report Share Posted August 25, 2007 ok heres my new log guys thanx ill be here all day thanx hjt log >>>>>>>>>>>>>>>>>>>>>>Logfile of Trend Micro HijackThis v2.0.2Scan saved at 2:56:46 PM, on 8/25/2007Platform: Windows 2000 SP4 (WinNT 5.00.2195)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Boot mode: NormalRunning processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\ZoneLabs\vsmon.exeC:\WINNT\system32\spoolsv.exeC:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeC:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeC:\PROGRA~1\Grisoft\AVG7\avgemc.exeC:\Program Files\Comodo\CBOClean\BOCORE.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\regsvc.exeC:\WINNT\system32\MSTask.exeC:\WINNT\System32\WBEM\WinMgmt.exeC:\Program Files\TightVNC\WinVNC.exeC:\WINNT\Explorer.EXEC:\WINNT\system32\svchost.exeC:\Program Files\Zone Labs\ZoneAlarm\zlclient.exeC:\Program Files\Grisoft\AVG7\avgcc.exeC:\Program Files\Trillian Pro\trillian.exeC:\Program Files\Comodo\CBOClean\BOC425.EXEC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearshare.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blankR3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllR3 - URLSearchHook: Wisdom-soft toolbar - {6dfc55bb-bfff-485a-9709-90c3fdf6db58} - C:\Program Files\Wisdom-soft\tbWisd.dllO2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dllO2 - BHO: Wisdom-soft toolbar - {6dfc55bb-bfff-485a-9709-90c3fdf6db58} - C:\Program Files\Wisdom-soft\tbWisd.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dllO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dllO3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocxO3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO3 - Toolbar: Wisdom-soft toolbar - {6dfc55bb-bfff-485a-9709-90c3fdf6db58} - C:\Program Files\Wisdom-soft\tbWisd.dllO4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logonO4 - HKLM\..\Run: [AVG7_CC] C:\Program Files\Grisoft\AVG7\avgcc.exe \STARTUPO4 - HKLM\..\Run: [bOC-425] C:\PROGRA~1\Comodo\CBOClean\BOC425.exeO4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')O4 - Startup: Trillian.lnk = C:\Program Files\Trillian Pro\trillian.exeO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\chris\Start Menu\Programs\Absolute Poker\Absolute Poker.lnkO9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\chris\Start Menu\Programs\Absolute Poker\Absolute Poker.lnkO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dllO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1187911231519O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1187911210589O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeO23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeO23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exeO23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exeO23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exeO23 - Service: VNC Server (winvnc) - TightVNC Group - C:\Program Files\TightVNC\WinVNC.exe--End of file - 5484 bytes Link to post Share on other sites
rmurphy Posted August 25, 2007 Report Share Posted August 25, 2007 Hi coriell. I'm Ryan and I'll be helping you clean your computer.You will want to print out these instructions, or save them to notepad so that you can refer to them later.Please download ATF Cleaner by Atribune.This program is for XP and Windows 2000 onlyClose all Internet Explorer, Firefox, and Opera windows before continuing.Double-click ATF-Cleaner.exe to run the program.Under Main choose: Select AllClick the Empty Selected button.If you use Firefox browserClick Firefox at the top and choose: Select AllClick the Empty Selected button.NOTE: If you would like to keep your saved passwords, please click No at the prompt.If you use Opera browserClick Opera at the top and choose: Select AllClick the Empty Selected button.NOTE: If you would like to keep your saved passwords, please click No at the prompt.Click Exit on the Main menu to close the program.For Technical Support, double-click the e-mail address located at the bottom of each menu.Please do an online scan with Kaspersky WebScanner You will need to use Internet Explorer to do thisClick on Kaspersky Online ScannerYou will be promted to install an ActiveX component from Kaspersky, Click Yes.The program will launch and then begin downloading the latest definition files:Once the files have been downloaded click on NEXTNow click on Scan SettingsIn the scan settings make that the following are selected:Scan using the following Anti-Virus database:Extended (if available otherwise Standard)Scan Options:Scan ArchivesScan Mail Bases[*]Click OK[*]Now under select a target to scan:Select My Computer[*]This will program will start and scan your system.[*]The scan will take a while so be patient and let it run.[*]Once the scan is complete it will display if your system has been infected.Now click on the Save as Text button:[*]Save the file to your desktop.[*]Copy and paste that information in your next post.I would like to see an Uninstall list.Open HijackThis, click Config, click Misc ToolsClick "Open Uninstall Manager"Click "Save List" (generates uninstall_list.txt)-Ryan Link to post Share on other sites
coriell12277 Posted August 25, 2007 Author Report Share Posted August 25, 2007 Hi coriell. I'm Ryan and I'll be helping you clean your computer.You will want to print out these instructions, or save them to notepad so that you can refer to them later.Please download ATF Cleaner by Atribune.This program is for XP and Windows 2000 onlyClose all Internet Explorer, Firefox, and Opera windows before continuing.Double-click ATF-Cleaner.exe to run the program.Under Main choose: Select AllClick the Empty Selected button.If you use Firefox browserClick Firefox at the top and choose: Select AllClick the Empty Selected button.NOTE: If you would like to keep your saved passwords, please click No at the prompt.If you use Opera browserClick Opera at the top and choose: Select AllClick the Empty Selected button.NOTE: If you would like to keep your saved passwords, please click No at the prompt.Click Exit on the Main menu to close the program.For Technical Support, double-click the e-mail address located at the bottom of each menu.Please do an online scan with Kaspersky WebScanner You will need to use Internet Explorer to do thisClick on Kaspersky Online ScannerYou will be promted to install an ActiveX component from Kaspersky, Click Yes.The program will launch and then begin downloading the latest definition files:Once the files have been downloaded click on NEXTNow click on Scan SettingsIn the scan settings make that the following are selected:Scan using the following Anti-Virus database:Extended (if available otherwise Standard)Scan Options:Scan ArchivesScan Mail Bases[*]Click OK[*]Now under select a target to scan:Select My Computer[*]This will program will start and scan your system.[*]The scan will take a while so be patient and let it run.[*]Once the scan is complete it will display if your system has been infected.Now click on the Save as Text button:[*]Save the file to your desktop.[*]Copy and paste that information in your next post.I would like to see an Uninstall list.Open HijackThis, click Config, click Misc ToolsClick "Open Uninstall Manager"Click "Save List" (generates uninstall_list.txt)-Ryanheres what ya needed unstalled list from hjt >>>>>>>>>>>>>>>>>>>>>>>>>.Absolute PokerAdobe Flash Player ActiveXAdobe Reader 8.1.0Adobe Shockwave PlayerAVG 7.5Azureus VuzeBOCleanCCleaner (remove only)Google Toolbar for Internet ExplorerGoogle Toolbar for Internet ExplorerHijackThis 2.0.2Hotfix for MDAC 2.53 (KB927779)Java 6 Update 2K-Lite Codec Pack 2.84 FullLimeWire PRO 4.12.3Microsoft .NET Framework 1.1Microsoft .NET Framework 1.1Microsoft .NET Framework 1.1 Hotfix (KB928366)Microsoft .NET Framework 2.0Microsoft Base Smart Card Cryptographic Service Provider PackageMozilla Firefox (2.0.0.6)MSN Messenger 7.0OpenOffice.org 2.2QuickTime Alternative 1.81Real Alternative 1.52Recuva (remove only)Security Update for Microsoft .NET Framework 2.0 (KB928365)Security Update for Windows 2000 (KB904706)Security Update for Windows 2000 (KB923689)Security Update for Windows Media Player (KB911564)Security Update for Windows Media Player 6.4 (KB925398)Security Update for Windows Media Player 9 (KB917734)Security Update for Windows Media Player 9 (KB936782)Spybot - Search & Destroy 1.4TightVNC 1.3.9Trillian Pro 3.1 Build 121 FinalUpdate Rollup 1 for Windows 2000 SP4VideoLAN VLC media player 0.8.6bWinamp (remove only)Windows 2000 Hotfix - KB842773Windows 2000 Hotfix - KB890046Windows 2000 Hotfix - KB893756Windows 2000 Hotfix - KB896358Windows 2000 Hotfix - KB896422Windows 2000 Hotfix - KB896423Windows 2000 Hotfix - KB899587Windows 2000 Hotfix - KB899589Windows 2000 Hotfix - KB900725Windows 2000 Hotfix - KB901017Windows 2000 Hotfix - KB901214Windows 2000 Hotfix - KB905414Windows 2000 Hotfix - KB905495Windows 2000 Hotfix - KB905749Windows 2000 Hotfix - KB908519Windows 2000 Hotfix - KB908531Windows 2000 Hotfix - KB911280Windows 2000 Hotfix - KB913580Windows 2000 Hotfix - KB914388Windows 2000 Hotfix - KB914389Windows 2000 Hotfix - KB917008Windows 2000 Hotfix - KB917736Windows 2000 Hotfix - KB917953Windows 2000 Hotfix - KB918118Windows 2000 Hotfix - KB920213Windows 2000 Hotfix - KB920670Windows 2000 Hotfix - KB920683Windows 2000 Hotfix - KB920685Windows 2000 Hotfix - KB921398Windows 2000 Hotfix - KB921503Windows 2000 Hotfix - KB922582Windows 2000 Hotfix - KB923191Windows 2000 Hotfix - KB923414Windows 2000 Hotfix - KB923694Windows 2000 Hotfix - KB923980Windows 2000 Hotfix - KB924191Windows 2000 Hotfix - KB924270Windows 2000 Hotfix - KB924667Windows 2000 Hotfix - KB925902Windows 2000 Hotfix - KB926122Windows 2000 Hotfix - KB926436Windows 2000 Hotfix - KB927891Windows 2000 Hotfix - KB928843Windows 2000 Hotfix - KB929969Windows 2000 Hotfix - KB930178Windows 2000 Hotfix - KB931784Windows 2000 Hotfix - KB932168Windows 2000 Hotfix - KB933566Windows 2000 Hotfix - KB935839Windows 2000 Hotfix - KB935840Windows 2000 Hotfix - KB936021Windows 2000 Hotfix - KB937143Windows 2000 Hotfix - KB938127Windows 2000 Hotfix - KB938829Windows Installer 3.1 (KB893803)Windows Installer Clean UpWindows Media Player Hotfix [see Q828026 for more information]Windows Media Player system update (9 Series)WinRAR archiverWisdom-soft ScreenHunter 5.0 FreeWisdom-soft ToolbarYahoo! Install ManagerYahoo! MessengerYahoo! ToolbarZoneAlarm Link to post Share on other sites
rmurphy Posted August 26, 2007 Report Share Posted August 26, 2007 Based on the uninstall list, here are 3 potential programs to uninstall.Azureus VuzeLimeWire PRO 4.12.3P2P file sharing programs like the above have their legitimate uses, but can also be used to download copyrighted material, and increases the risk of infecting your computer.TightVNC 1.3.9Allows remote users to connect to the computer. If you or someone else that uses this computer did not install it, please uninstall it and let me know.Please do an online scan with Kaspersky WebScanner You will need to use Internet Explorer to do thisClick on Kaspersky Online ScannerYou will be promted to install an ActiveX component from Kaspersky, Click Yes.The program will launch and then begin downloading the latest definition files:Once the files have been downloaded click on NEXTNow click on Scan SettingsIn the scan settings make that the following are selected:Scan using the following Anti-Virus database:Extended (if available otherwise Standard)Scan Options:Scan ArchivesScan Mail Bases[*]Click OK[*]Now under select a target to scan:Select My Computer[*]This will program will start and scan your system.[*]The scan will take a while so be patient and let it run.[*]Once the scan is complete it will display if your system has been infected.Now click on the Save as Text button:[*]Save the file to your desktop.[*]Copy and paste that information in your next post.-Ryan Link to post Share on other sites
coriell12277 Posted August 26, 2007 Author Report Share Posted August 26, 2007 heres the kaspersky scan log said i got 1 virus an 5 objects infected >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\dzgcd2ni.default\cert8.db Object is locked skipped C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\dzgcd2ni.default\formhistory.dat Object is locked skipped C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\dzgcd2ni.default\history.dat Object is locked skipped C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\dzgcd2ni.default\key3.db Object is locked skipped C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\dzgcd2ni.default\parent.lock Object is locked skipped C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\dzgcd2ni.default\search.sqlite Object is locked skipped C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\dzgcd2ni.default\urlclassifier2.sqlite Object is locked skipped C:\Documents and Settings\chris\Cookies\index.dat Object is locked skipped C:\Documents and Settings\chris\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\chris\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\chris\Local Settings\Application Data\Mozilla\Firefox\Profiles\dzgcd2ni.default\Cache\_CACHE_001_ Object is locked skipped C:\Documents and Settings\chris\Local Settings\Application Data\Mozilla\Firefox\Profiles\dzgcd2ni.default\Cache\_CACHE_002_ Object is locked skipped C:\Documents and Settings\chris\Local Settings\Application Data\Mozilla\Firefox\Profiles\dzgcd2ni.default\Cache\_CACHE_003_ Object is locked skipped C:\Documents and Settings\chris\Local Settings\Application Data\Mozilla\Firefox\Profiles\dzgcd2ni.default\Cache\_CACHE_MAP_ Object is locked skipped C:\Documents and Settings\chris\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\chris\Local Settings\Temp\~DF43DE.tmp Object is locked skipped C:\Documents and Settings\chris\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\chris\My Documents\AIM\Console\AIM - coriell12277.log Object is locked skipped C:\Documents and Settings\chris\My Documents\AIM\Console\AIM - coriell12374.log Object is locked skipped C:\Documents and Settings\chris\My Documents\AIM\Console\AIM - coriellmo.log Object is locked skipped C:\Documents and Settings\chris\My Documents\MSN\Console\MSN - [email protected] Object is locked skipped C:\Documents and Settings\chris\My Documents\MSN\Console\MSN - [email protected] Object is locked skipped C:\Documents and Settings\chris\My Documents\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\chris\My Documents\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\chris\My Documents\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\chris\My Documents\SmitfraudFix.exe RarSFX: infected - 2 skipped C:\Documents and Settings\chris\My Documents\YAHOO\Console\YAHOO - coriell12277.log Object is locked skipped C:\Documents and Settings\chris\My Documents\YAHOO\Console\YAHOO - tigger_12374.log Object is locked skipped C:\Documents and Settings\chris\NTUSER.DAT Object is locked skipped C:\Documents and Settings\chris\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Default User\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Default User\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Program Files\Mozilla Firefox\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\WINNT\CSC0000001 Object is locked skipped C:\WINNT\Debug\ipsecpa.log Object is locked skipped C:\WINNT\Debug\oakley.log Object is locked skipped C:\WINNT\Debug\PASSWD.LOG Object is locked skipped C:\WINNT\Internet Logs\CHRIS-673DA2015.ldb Object is locked skipped C:\WINNT\Internet Logs\fwdbglog.txt Object is locked skipped C:\WINNT\Internet Logs\fwpktlog.txt Object is locked skipped C:\WINNT\Internet Logs\IAMDB.RDB Object is locked skipped C:\WINNT\Internet Logs\tvDebug.log Object is locked skipped C:\WINNT\SchedLgU.Txt Object is locked skipped C:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped C:\WINNT\system32\config\default Object is locked skipped C:\WINNT\system32\config\default.LOG Object is locked skipped C:\WINNT\system32\config\SAM Object is locked skipped C:\WINNT\system32\config\SAM.LOG Object is locked skipped C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped C:\WINNT\system32\config\SECURITY Object is locked skipped C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped C:\WINNT\system32\config\software Object is locked skipped C:\WINNT\system32\config\software.LOG Object is locked skipped C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped C:\WINNT\system32\config\system Object is locked skipped C:\WINNT\system32\config\SYSTEM.ALT Object is locked skipped C:\WINNT\system32\drivers\fidbox.dat Object is locked skipped C:\WINNT\system32\drivers\fidbox.idx Object is locked skipped C:\WINNT\system32\drivers\fidbox2.dat Object is locked skipped C:\WINNT\system32\drivers\fidbox2.idx Object is locked skipped C:\WINNT\temp\ZLT02bb8.TMP Object is locked skipped C:\WINNT\temp\ZLT02bc2.TMP Object is locked skipped C:\WINNT\WindowsUpdate.log Object is locked skipped Scan process completed. Link to post Share on other sites
coriell12277 Posted August 26, 2007 Author Report Share Posted August 26, 2007 Total number of scanned objects 21840 Number of viruses found 1 Number of infected objects 5 Number of suspicious objects 0 Duration of the scan process 01:35:55 Link to post Share on other sites
rmurphy Posted August 26, 2007 Report Share Posted August 26, 2007 Congratulations, your log is clean For information on how to protect yourself in the future, read Infection PreventionDo you have any other questions or concerns? This thread will be left open for a few more days, so feel free to ask.-Ryan Link to post Share on other sites
coriell12277 Posted August 26, 2007 Author Report Share Posted August 26, 2007 Congratulations, your log is clean For information on how to protect yourself in the future, read Infection PreventionDo you have any other questions or concerns? This thread will be left open for a few more days, so feel free to ask.-Ryanummmmmmmmmmmmmm how is it clean when it said i have one virus an 5 infected objects >????????????????// Link to post Share on other sites
coriell12277 Posted August 26, 2007 Author Report Share Posted August 26, 2007 ima just wondering i sat here for an hour an half an it says 1 virus an 5 infected objects i like to get rid of those tooooooooooo thanx Link to post Share on other sites
rmurphy Posted August 26, 2007 Report Share Posted August 26, 2007 The only thing that the Kaspersky scan found were risk tools - that is, tools that can be used for both good and bad. In this case, it was a tool included in the SmitFraudFix program that is used to reboot your computer.If you want to, you can remove the following file and folder.C:\Documents and Settings\chris\My Documents\SmitfraudFix.exeC:\Program Files\Mozilla Firefox\SmitfraudFix\-Ryan Link to post Share on other sites
coriell12277 Posted August 26, 2007 Author Report Share Posted August 26, 2007 ok were do i go to remove theses ????????????????????? Link to post Share on other sites
rmurphy Posted August 26, 2007 Report Share Posted August 26, 2007 You just delete them like any other file/folder.-Ryan Link to post Share on other sites
coriell12277 Posted August 26, 2007 Author Report Share Posted August 26, 2007 well ok i guess i have to do this ill just go to add / remove programs an delete it from there right Link to post Share on other sites
coriell12277 Posted August 26, 2007 Author Report Share Posted August 26, 2007 i looked in files an folders not there i looked in add/remove programs not there were is it ???????/ Link to post Share on other sites
rmurphy Posted August 26, 2007 Report Share Posted August 26, 2007 Just do the following:go to start > Run: paste del "C:\Documents and Settings\chris\My Documents\SmitfraudFix.exe" and hit enter. Then paste: rmdir "C:\Program Files\Mozilla Firefox\SmitfraudFix\" /S /Q and hit enter.-Ryan Link to post Share on other sites
coriell12277 Posted August 26, 2007 Author Report Share Posted August 26, 2007 it says cannot find the file Link to post Share on other sites
coriell12277 Posted August 26, 2007 Author Report Share Posted August 26, 2007 i just went everywhere to find it an deleted it my self heres another hjt log >>>>>>>>>>>>>>>>>>.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 5:17:29 PM, on 8/26/2007Platform: Windows 2000 SP4 (WinNT 5.00.2195)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Boot mode: NormalRunning processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\ZoneLabs\vsmon.exeC:\WINNT\system32\spoolsv.exeC:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeC:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeC:\PROGRA~1\Grisoft\AVG7\avgemc.exeC:\Program Files\Comodo\CBOClean\BOCORE.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\regsvc.exeC:\WINNT\system32\MSTask.exeC:\WINNT\Explorer.EXEC:\WINNT\System32\WBEM\WinMgmt.exeC:\Program Files\TightVNC\WinVNC.exeC:\WINNT\system32\svchost.exeC:\Program Files\Zone Labs\ZoneAlarm\zlclient.exeC:\Program Files\Grisoft\AVG7\avgcc.exeC:\PROGRA~1\Comodo\CBOClean\BOC425.exeC:\WINNT\StartupMonitor.exeC:\Program Files\FirefoxPreloader\FirefoxPreloader.exeC:\Program Files\Trillian Pro\trillian.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearshare.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blankR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllR3 - URLSearchHook: Wisdom-soft toolbar - {6dfc55bb-bfff-485a-9709-90c3fdf6db58} - C:\Program Files\Wisdom-soft\tbWisd.dllF3 - REG:win.ini: load= F3 - REG:win.ini: run= O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dllO2 - BHO: Wisdom-soft toolbar - {6dfc55bb-bfff-485a-9709-90c3fdf6db58} - C:\Program Files\Wisdom-soft\tbWisd.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dllO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dllO3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocxO3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO3 - Toolbar: Wisdom-soft toolbar - {6dfc55bb-bfff-485a-9709-90c3fdf6db58} - C:\Program Files\Wisdom-soft\tbWisd.dllO4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logonO4 - HKLM\..\Run: [AVG7_CC] C:\Program Files\Grisoft\AVG7\avgcc.exe \STARTUPO4 - HKLM\..\Run: [bOC-425] C:\PROGRA~1\Comodo\CBOClean\BOC425.exeO4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exeO4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')O4 - Startup: Trillian.lnk = C:\Program Files\Trillian Pro\trillian.exeO4 - Global Startup: Firefox Preloader.lnk = C:\Program Files\FirefoxPreloader\FirefoxPreloader.exeO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\chris\Start Menu\Programs\Absolute Poker\Absolute Poker.lnkO9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\chris\Start Menu\Programs\Absolute Poker\Absolute Poker.lnkO16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dllO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1187911231519O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1187911210589O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeO23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeO23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exeO23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exeO23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exeO23 - Service: VNC Server (winvnc) - TightVNC Group - C:\Program Files\TightVNC\WinVNC.exe--End of file - 6043 bytes Link to post Share on other sites
rmurphy Posted August 26, 2007 Report Share Posted August 26, 2007 You can fix these items, they are clutter and don't need to be fixed.R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blankR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =F3 - REG:win.ini: load= F3 - REG:win.ini: run=Other than that, the log is fine.-Ryan Link to post Share on other sites
coriell12277 Posted August 27, 2007 Author Report Share Posted August 27, 2007 i went to the log from hjt an put a check mark by them an hit fix checked is that the way i was suppose to do it ????????? heres the log again to make sure >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>Logfile of Trend Micro HijackThis v2.0.2Scan saved at 8:28:27 PM, on 8/26/2007Platform: Windows 2000 SP4 (WinNT 5.00.2195)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Boot mode: NormalRunning processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\ZoneLabs\vsmon.exeC:\WINNT\system32\spoolsv.exeC:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeC:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeC:\PROGRA~1\Grisoft\AVG7\avgemc.exeC:\Program Files\Comodo\CBOClean\BOCORE.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\regsvc.exeC:\WINNT\system32\MSTask.exeC:\WINNT\Explorer.EXEC:\WINNT\System32\WBEM\WinMgmt.exeC:\Program Files\TightVNC\WinVNC.exeC:\WINNT\system32\svchost.exeC:\Program Files\Zone Labs\ZoneAlarm\zlclient.exeC:\Program Files\Grisoft\AVG7\avgcc.exeC:\PROGRA~1\Comodo\CBOClean\BOC425.exeC:\WINNT\StartupMonitor.exeC:\Program Files\FirefoxPreloader\FirefoxPreloader.exeC:\Program Files\Trillian Pro\trillian.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearshare.com/R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllR3 - URLSearchHook: Wisdom-soft toolbar - {6dfc55bb-bfff-485a-9709-90c3fdf6db58} - C:\Program Files\Wisdom-soft\tbWisd.dllO2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dllO2 - BHO: Wisdom-soft toolbar - {6dfc55bb-bfff-485a-9709-90c3fdf6db58} - C:\Program Files\Wisdom-soft\tbWisd.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dllO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dllO3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocxO3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO3 - Toolbar: Wisdom-soft toolbar - {6dfc55bb-bfff-485a-9709-90c3fdf6db58} - C:\Program Files\Wisdom-soft\tbWisd.dllO4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logonO4 - HKLM\..\Run: [AVG7_CC] C:\Program Files\Grisoft\AVG7\avgcc.exe \STARTUPO4 - HKLM\..\Run: [bOC-425] C:\PROGRA~1\Comodo\CBOClean\BOC425.exeO4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exeO4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')O4 - Startup: Trillian.lnk = C:\Program Files\Trillian Pro\trillian.exeO4 - Global Startup: Firefox Preloader.lnk = C:\Program Files\FirefoxPreloader\FirefoxPreloader.exeO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\chris\Start Menu\Programs\Absolute Poker\Absolute Poker.lnkO9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\chris\Start Menu\Programs\Absolute Poker\Absolute Poker.lnkO16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dllO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1187911231519O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1187911210589O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeO23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeO23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exeO23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exeO23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exeO23 - Service: VNC Server (winvnc) - TightVNC Group - C:\Program Files\TightVNC\WinVNC.exe--End of file - 5780 bytes Link to post Share on other sites
Recommended Posts