keenankern Posted January 4, 2009 Report Share Posted January 4, 2009 Here's the log:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 12:14:17 PM, on 1/4/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16762)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Alwil Software\Avast4\aswUpdSv.exeC:\Program Files\Alwil Software\Avast4\ashServ.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\nvsvc32.exeC:\WINDOWS\system32\PnkBstrA.exeC:\Program Files\Viewpoint\Common\ViewpointService.exeC:\Program Files\Alwil Software\Avast4\ashMaiSv.exeC:\Program Files\Alwil Software\Avast4\ashWebSv.exeC:\Program Files\AlienGUIse\wbload.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Microsoft IntelliType Pro\itype.exeC:\Program Files\Microsoft IntelliPoint\ipoint.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\Search Settings\SearchSettings.exeC:\WINDOWS\system32\RUNDLL32.EXEC:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Messenger\msmsgs.exeC:\Program Files\Windows Live\Messenger\msnmsgr.exeC:\Program Files\AIM6\aim6.exeC:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exeC:\Program Files\Microsoft IntelliPoint\dpupdchk.exeC:\WINDOWS\system32\mdm.exeC:\Program Files\AIM6\aolsoftware.exeC:\Program Files\AIM6\anotify.exeC:\WINDOWS\system32\rundll32.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBRR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBRR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://centurytel.myway.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBRR3 - URLSearchHook: (no name) - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - (no file)O3 - Toolbar: (no name) - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - (no file)O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dllO4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"O4 - HKLM\..\Run: [intelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systrayO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [searchSettings] C:\Program Files\Search Settings\SearchSettings.exeO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeO4 - HKLM\..\Run: [prunnet] "C:\WINDOWS\system32\prunnet.exe"O4 - HKLM\..\Run: [Nnixupadewiyohu] rundll32.exe "C:\WINDOWS\Jtihuwaq.dll",eO4 - HKLM\..\Run: [10f7a49b] rundll32.exe "C:\WINDOWS\system32\swcqmcyw.dll",bO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /backgroundO4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imAppO4 - HKCU\..\Run: [prunnet] "C:\WINDOWS\system32\prunnet.exe"O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')O4 - S-1-5-18 Startup: Rapid Antivirus.lnk = C:\Program Files\Rapid Antivirus\Rapid Antivirus.exe (User 'SYSTEM')O4 - .DEFAULT Startup: Rapid Antivirus.lnk = C:\Program Files\Rapid Antivirus\Rapid Antivirus.exe (User 'Default user')O4 - Startup: Alienware Dock.lnk = C:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exeO4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htmO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO15 - Trusted Zone: *.antimalwareguard.comO15 - Trusted Zone: *.gomyhit.comO15 - Trusted Zone: *.antimalwareguard.com (HKLM)O15 - Trusted Zone: *.gomyhit.com (HKLM)O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cabO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...83/mcinsctl.cabO16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cabO16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cabO16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin...ows-i586-jc.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cabO16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cabO16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cabO16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cabO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLLO20 - AppInit_DLLs: wbsys.dll ecxbwv.dllO23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exeO23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exeO23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exeO23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exeO23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exeO23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exeO23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exeO23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exeO23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe--End of file - 8893 bytes Link to post Share on other sites
sarahw Posted January 4, 2009 Report Share Posted January 4, 2009 We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool: http://www.bleepingcomputer.com/combofix/how-to-use-combofix* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Please include the C:\ComboFix.txt in your next reply for further review. Link to post Share on other sites
keenankern Posted January 4, 2009 Author Report Share Posted January 4, 2009 Problem, the virus does something funky to the internet, making every web page undisplayable. Link to post Share on other sites
sarahw Posted January 4, 2009 Report Share Posted January 4, 2009 ok,Download this:http://subs.geekstogo.com/ComboFix.exerun it.Do not use the comuter while it is scanning, it will produce a log in notepad when it is finnished.So not mouse-click anything while it is scanning either.Post the log in a reply when you have finnished. Link to post Share on other sites
keenankern Posted January 4, 2009 Author Report Share Posted January 4, 2009 Can't download anything because if I go to the link, the webpage is unable to connect. Link to post Share on other sites
sarahw Posted January 5, 2009 Report Share Posted January 5, 2009 Write down that link.Reboot the computer.When the computer starts to boot, keep tapping F8 untill you see a list of options. Choose Safe Mode with Networking. (Do not stay on Safe Mode with Networking longer than neccessary). Open Internet explorer and go to that website to download Combofix. Link to post Share on other sites
keenankern Posted January 5, 2009 Author Report Share Posted January 5, 2009 ComboFix 09-01-05.02 - Keeno 2009-01-05 16:50:48.1 - NTFSx86Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1735 [GMT -6:00]Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe.((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))).C:\bold.logc:\program files\Rapid Antivirusc:\program files\Rapid Antivirus\Uninstall.exec:\windows\Downloaded Program Files\setup.infc:\windows\system32\20ae0f0.dllc:\windows\system32\2KPeLX26.exe.a_ac:\windows\system32\config\systemprofile\Desktop\Rapid Antivirus.lnkc:\windows\system32\drivers\seneka.sysc:\windows\system32\drivers\senekawswwqjnt.sysc:\windows\system32\ecxbwv.dllc:\windows\system32\ijmTvyay.inic:\windows\system32\ijmTvyay.ini2c:\windows\system32\kvlniyhp.inic:\windows\system32\M0XQnlgP.exe.a_ac:\windows\system32\mdm.exec:\windows\system32\O6ASpniR.dllc:\windows\system32\prunnet.exec:\windows\system32\seneka.datc:\windows\system32\senekadf.datc:\windows\system32\senekalog.datc:\windows\system32\senekaplrdlypu.dllc:\windows\system32\senekatfmqhtiv.dllc:\windows\system32\senekayqjhipjo.dllc:\windows\system32\sjrkcqax.dllc:\windows\system32\swcqmcyw.dllc:\windows\system32\vghazx.dllc:\windows\system32\voxrquii.dllc:\windows\system32\wycmqcws.inic:\windows\system32\xaqckrjs.inic:\windows\system32\xwdmbbgv.inic:\windows\system32\xywuaify.dllc:\windows\system32\yayvTmji.dllc:\windows\system32\yvihegve.dllc:\windows\system32\zyuoue.dll.((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))).-------\Service_SENEKA-------\Legacy_ONESTEP_SEARCH_SERVICE((((((((((((((((((((((((( Files Created from 2008-12-05 to 2009-01-05 ))))))))))))))))))))))))))))))).2009-01-05 16:20 . 2009-01-05 16:20 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Search Settings2009-01-02 22:06 . 2009-01-02 22:06 <DIR> d-------- c:\windows\system32\config\systemprofile\Application Data\s_4610_fHx8fHx8fDEyNDM1ODUwMTN8_2009-01-02 22:06 . 2009-01-02 22:11 <DIR> d-------- c:\windows\system32\config\systemprofile\Application Data\Rapid Antivirus2009-01-02 21:44 . 2009-01-02 21:44 72,192 --a------ c:\windows\system32\hgGwXOFX.dll2009-01-02 21:44 . 2009-01-02 21:44 40,448 --a------ c:\windows\system32\k9261108.exe2008-12-30 00:17 . 2008-12-30 00:17 268 --ah----- C:\sqmdata15.sqm2008-12-30 00:17 . 2008-12-30 00:17 268 --ah----- C:\sqmdata14.sqm2008-12-30 00:17 . 2008-12-30 00:17 244 --ah----- C:\sqmnoopt15.sqm2008-12-30 00:17 . 2008-12-30 00:17 244 --ah----- C:\sqmnoopt14.sqm2008-12-28 17:55 . 2008-12-28 17:55 268 --ah----- C:\sqmdata13.sqm2008-12-28 17:55 . 2008-12-28 17:55 244 --ah----- C:\sqmnoopt13.sqm2008-12-24 18:07 . 2005-02-01 14:20 5,760,056 --a------ c:\windows\Darkstar.bmp2008-12-24 18:06 . 2008-12-24 18:06 5,760,054 --a------ c:\windows\ALX_1600x1200.bmp2008-12-24 18:04 . 2008-12-24 18:10 3,932,214 --a------ c:\windows\AW_XenoMorph1280.bmp2008-12-24 18:03 . 2008-12-24 18:03 <DIR> d-------- c:\program files\Common Files\Stardock2008-12-24 18:03 . 2008-12-24 18:07 <DIR> d-------- c:\program files\AlienGUIse2008-12-24 18:03 . 2003-02-26 22:27 36,864 --a------ c:\windows\system32\wbsys.dll2008-12-24 18:03 . 2008-12-24 18:03 56 --a------ c:\windows\wb.ini2008-12-24 15:45 . 2008-04-13 13:47 25,856 --a------ c:\windows\system32\drivers\usbprint.sys2008-12-24 15:45 . 2008-04-13 13:47 25,856 --a--c--- c:\windows\system32\dllcache\usbprint.sys2008-12-11 22:07 . 2008-12-11 22:07 268 --ah----- C:\sqmdata12.sqm2008-12-11 22:07 . 2008-12-11 22:07 244 --ah----- C:\sqmnoopt12.sqm.(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2009-01-03 04:44 --------- d-----w c:\program files\Bots2008-12-27 03:17 --------- d-----w c:\program files\AIM62008-12-27 03:17 --------- d-----w c:\documents and settings\All Users\Application Data\AOL Downloads2008-12-21 20:34 --------- d-----w c:\program files\Workspace Macro Pro 6.52008-12-21 20:33 --------- d-----w c:\program files\Total Video Converter2008-12-21 20:31 --------- d-----w c:\program files\Cheat Engine2008-12-21 20:29 --------- d-----w c:\program files\Starcraft2008-12-21 20:28 --------- d-----w c:\program files\SwiftSwitch2008-12-21 20:28 --------- d-----w c:\program files\SwiftKit2008-12-21 01:10 --------- d-----w c:\program files\Dofus2008-12-19 03:53 --------- d-----w c:\program files\WarRock2008-11-07 23:37 --------- d-----w c:\program files\Alwil Software2008-10-27 23:22 121,396 -c--a-w c:\program files\lalalala.exe2008-07-25 03:19 23 -c--a-w c:\documents and settings\Keeno\jagex_runescape_preferences.dat2008-03-18 20:43 32 -c--a-w c:\documents and settings\All Users\Application Data\ezsid.dat2007-10-12 20:02 121 -c--a-w c:\documents and settings\Keeno\Install_WLMessenger.exe2007-09-22 05:26 9,870,032 -c--a-w c:\documents and settings\Keeno\fp2006-final-3.00-setup.zip2007-09-22 04:07 241,664 -c--a-w c:\program files\Uninstall Ask Toolbar.dll2008-12-21 03:47 67,688 ----a-w c:\program files\mozilla firefox\components\jar50.dll2008-12-21 03:47 54,368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll2008-12-21 03:47 34,944 ----a-w c:\program files\mozilla firefox\components\myspell.dll2008-12-21 03:47 46,712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll2008-12-21 03:47 172,136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll2008-08-21 15:22 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082120080822\index.dat.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]"Aim6"="c:\program files\AIM6\aim6.exe" [2008-01-03 50528][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2007-08-31 988584]"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736]"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-01-11 185896]"SearchSettings"="c:\program files\Search Settings\SearchSettings.exe" [2007-12-06 1069920]"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-02 13529088]"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-02 86016]"nwiz"="nwiz.exe" [2008-05-02 c:\windows\system32\nwiz.exe][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]"RunNarrator"="Narrator.exe" [2008-04-13 c:\windows\system32\narrator.exe]c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-06-27 113664][HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]2001-12-20 23:34 24576 c:\program files\AlienGUIse\fastload.dll[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]"AppInit_DLLs"=wbsys.dll ecxbwv.dll[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]"VIDC.XFR1"= xfcodec.dll[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Workspace Macro Pro Hotkeys.lnk]path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Workspace Macro Pro Hotkeys.lnkbackup=c:\windows\pss\Workspace Macro Pro Hotkeys.lnkCommon Startup[HKLM\~\startupfolder\C:^Documents and Settings^Keeno^Start Menu^Programs^Startup^Xfire.lnk]path=c:\documents and settings\Keeno\Start Menu\Programs\Startup\Xfire.lnkbackup=c:\windows\pss\Xfire.lnkStartup[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]--a------ 2007-10-10 18:51 39792 c:\program files\Adobe\Reader 8.0\Reader\Reader_SL.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]--a------ 2008-01-03 10:15 50528 c:\program files\AIM6\aim6.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]--a------ 2008-04-13 18:12 15360 c:\windows\system32\ctfmon.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]--a--c--- 2007-03-15 11:09 460784 c:\program files\DellSupport\DSAgnt.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLA]--a--c--- 2005-09-08 04:20 122940 c:\windows\system32\DLA\DLACTRLW.EXE[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]-----c--- 2005-02-23 15:19 53248 c:\program files\CyberLink\PowerDVD\DVDLauncher.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]--a--c--- 2005-09-20 08:32 77824 c:\windows\system32\hkcmd.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]--a--c--- 2005-09-20 08:36 114688 c:\windows\system32\igfxpers.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]--a--c--- 2005-09-20 08:35 94208 c:\windows\system32\igfxtray.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]--a--c--- 2004-07-27 15:50 221184 c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]--a--c--- 2004-07-27 15:50 81920 c:\program files\Common Files\InstallShield\UpdateService\issch.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MP10_EnsureFileVer]--a------ 2007-06-26 21:10 317440 c:\windows\inf\unregmp2.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]--a------ 2008-04-13 18:12 1695232 c:\program files\Messenger\msmsgs.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]--a------ 2007-10-18 10:34 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]-ra------ 2008-09-29 16:57 21755688 c:\program files\Skype\Phone\Skype.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]--a--c--- 2004-10-14 13:42 1404928 c:\program files\Analog Devices\Core\smax4pnp.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]--a--c--- 2007-07-12 03:00 132496 c:\program files\Java\jre1.6.0_02\bin\jusched.exe[HKEY_LOCAL_MACHINE\software\microsoft\security center]"AntiVirusOverride"=dword:00000001[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"%windir%\\system32\\sessmgr.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe"="c:\\Program Files\\Messenger\\msmsgs.exe"="c:\\Program Files\\Mozilla Firefox\\firefox.exe"="c:\\WINDOWS\\system32\\java.exe"="c:\\WINDOWS\\system32\\dpvsetup.exe"="c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="c:\\Program Files\\AIM6\\aim6.exe"="c:\\Program Files\\Real\\RealPlayer\\realplay.exe"="c:\\Program Files\\Xfire\\xfire.exe"="c:\\Program Files\\Bots\\bots.dat"="c:\\Documents and Settings\\All Users\\Application Data\\Nexon\\NGM\\NGM.exe"="c:\\Documents and Settings\\All Users\\Application Data\\Nexon\\Common\\NMService.exe"="c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"="\\\\Mah-pc\\Combat Arms\\NMService.exe"="c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe"c:\\Nexon\\Combat Arms\\NMService.exe"="c:\\Program Files\\Skype\\Phone\\Skype.exe"=[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]"43594:TCP"= 43594:TCP:RSPSR4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-12-30 24652][HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1d20604e-75f2-11dc-ae36-001676aa3570}]\Shell\AutoRun\command - F:\setupSNK.exe.Contents of the 'Scheduled Tasks' folder2009-01-05 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]2009-01-05 c:\windows\Tasks\tujvdgkg.job- c:\windows\system32\rundll32.exe [2008-04-13 18:12].- - - - ORPHANS REMOVED - - - -URLSearchHooks-{2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - (no file)BHO-{1C1B8A44-61FE-411E-8F33-813A4E2E2984} - c:\windows\system32\avgsafe.dllBHO-{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - c:\windows\system32\ljJDWOiH.dllBHO-{8c3e2c42-3fbb-435d-b10b-840e79462b1b} - c:\windows\system32\ecxbwv.dllBHO-{DFBD8876-9F2E-418C-99A9-9215D3704519} - c:\windows\system32\yayvTmji.dllToolbar-{2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - (no file)WebBrowser-{2BA521AC-B9B9-4433-BA45-DBA2F02CBA5A} - (no file)HKCU-Run-prunnet - c:\windows\system32\prunnet.exeHKLM-Run-NapsterShell - c:\program files\Napster\napster.exeHKLM-Run-prunnet - c:\windows\system32\prunnet.exeHKLM-Run-Nnixupadewiyohu - c:\windows\Jtihuwaq.dllShellExecuteHooks-{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - c:\windows\system32\ljJDWOiH.dllNotify-ljJDWOiH - ljJDWOiH.dllMSConfigStartUp-DownloadAccelerator - c:\program files\DAP\DAP.EXEMSConfigStartUp-NexonPlug - c:\documents and settings\Keeno\Desktop\NexonPlug\NexonPlug.exeMSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe.------- Supplementary Scan -------.uStart Page = hxxp://centurytel.myway.comIE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htmTrusted Zone: *.antimalwareguard.comTrusted Zone: *.gomyhit.comTrusted Zone: *.antimalwareguard.comTrusted Zone: *.gomyhit.comO16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cabc:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osdc:\windows\Downloaded Program Files\GoPetsWeb.ocx - O16 -: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8}hxxps://secure.gopetslive.com/dev/GoPetsWeb.cabc:\windows\Downloaded Program Files\GoPetsWeb.infFF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w0nnx40o.default\FF - prefs.js: browser.search.selectedEngine - YahooFF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=vmn&type=vendio&p=FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dllFF - component: c:\program files\Mozilla Firefox\extensions\[email protected]\components\SearchSettingsFF.dll.**************************************************************************catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2009-01-05 17:07:39Windows 5.1.2600 Service Pack 3 NTFSscanning hidden processes ... scanning hidden autostart entries ...scanning hidden files ... scan completed successfullyhidden files: 0**************************************************************************.--------------------- DLLs Loaded Under Running Processes ---------------------- - - - - - - > 'winlogon.exe'(600)c:\program files\AlienGUIse\fastload.dll.------------------------ Other Running Processes ------------------------.c:\windows\system32\nvsvc32.exec:\windows\system32\PnkBstrA.exe.**************************************************************************.Completion time: 2009-01-05 17:14:18 - machine was rebootedComboFix-quarantined-files.txt 2009-01-05 23:14:15Pre-Run: 33,827,475,456 bytes freePost-Run: 33,917,235,200 bytes free267 --- E O F --- 2008-12-18 04:32:44 Link to post Share on other sites
sarahw Posted January 6, 2009 Report Share Posted January 6, 2009 1.Go to this link, fill in your username and the link to this thread, then click on browse and locate this file on your computer (if you cant find it, copy and paste it into the right field), then click on "send file".c:\program files\lalalala.exe2.Right click Here and select Save As to download WinHelp2002's DelDomains.inf. Please save the file somewhere you can find it like on the desktop. To run the inf file, right click on it and select Install.3.1. Close any open browsers.2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. 3. Open notepad and copy/paste the text in the quotebox below into it:File::C:\sqmdata15.sqmC:\sqmdata14.sqmC:\sqmnoopt15.sqmC:\sqmnoopt14.sqmC:\sqmdata13.sqmC:\sqmnoopt13.sqmC:\sqmdata12.sqmC:\sqmnoopt12.sqmC:\windows\system32\ecxbwv.dllRegistry::[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]"appinit_dlls"=""Save this as CFScript.txt, in the same location as ComboFix.exeRefering to the picture above, drag CFScript into ComboFix.exeWhen finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.Can you boot into normal mode now? Link to post Share on other sites
keenankern Posted January 6, 2009 Author Report Share Posted January 6, 2009 I can now use my browser, the internet is working. Here's the log:ComboFix 09-01-05.03 - Keeno 2009-01-05 21:39:05.2 - NTFSx86Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1657 [GMT -6:00]Running from: c:\documents and settings\Keeno\Desktop\ComboFix.exeCommand switches used :: c:\documents and settings\Keeno\Desktop\CFScript.txt * Created a new restore point.((((((((((((((((((((((((( Files Created from 2008-12-06 to 2009-01-06 ))))))))))))))))))))))))))))))).2009-01-05 21:28 . 2008-04-13 18:12 82,432 ---h---t- c:\windows\system32\27840fb0.dll2009-01-05 21:28 . 2008-04-13 18:12 82,432 ---h---t- c:\windows\system32\1ece69a.dll2009-01-05 16:20 . 2009-01-05 16:20 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Search Settings2009-01-02 22:06 . 2009-01-02 22:06 <DIR> d-------- c:\windows\system32\config\systemprofile\Application Data\s_4610_fHx8fHx8fDEyNDM1ODUwMTN8_2009-01-02 22:06 . 2009-01-02 22:11 <DIR> d-------- c:\windows\system32\config\systemprofile\Application Data\Rapid Antivirus2009-01-02 21:44 . 2009-01-02 21:44 72,192 --a------ c:\windows\system32\hgGwXOFX.dll2009-01-02 21:44 . 2009-01-02 21:44 40,448 --a------ c:\windows\system32\k9261108.exe2008-12-30 00:17 . 2008-12-30 00:17 268 --ah----- C:\sqmdata15.sqm2008-12-30 00:17 . 2008-12-30 00:17 268 --ah----- C:\sqmdata14.sqm2008-12-30 00:17 . 2008-12-30 00:17 244 --ah----- C:\sqmnoopt15.sqm2008-12-30 00:17 . 2008-12-30 00:17 244 --ah----- C:\sqmnoopt14.sqm2008-12-28 17:55 . 2008-12-28 17:55 268 --ah----- C:\sqmdata13.sqm2008-12-28 17:55 . 2008-12-28 17:55 244 --ah----- C:\sqmnoopt13.sqm2008-12-24 18:07 . 2005-02-01 14:20 5,760,056 --a------ c:\windows\Darkstar.bmp2008-12-24 18:06 . 2008-12-24 18:06 5,760,054 --a------ c:\windows\ALX_1600x1200.bmp2008-12-24 18:04 . 2008-12-24 18:10 3,932,214 --a------ c:\windows\AW_XenoMorph1280.bmp2008-12-24 18:03 . 2008-12-24 18:03 <DIR> d-------- c:\program files\Common Files\Stardock2008-12-24 18:03 . 2008-12-24 18:07 <DIR> d-------- c:\program files\AlienGUIse2008-12-24 18:03 . 2003-02-26 22:27 36,864 --a------ c:\windows\system32\wbsys.dll2008-12-24 18:03 . 2008-12-24 18:03 56 --a------ c:\windows\wb.ini2008-12-24 15:45 . 2008-04-13 13:47 25,856 --a------ c:\windows\system32\drivers\usbprint.sys2008-12-24 15:45 . 2008-04-13 13:47 25,856 --a--c--- c:\windows\system32\dllcache\usbprint.sys2008-12-11 22:07 . 2008-12-11 22:07 268 --ah----- C:\sqmdata12.sqm2008-12-11 22:07 . 2008-12-11 22:07 244 --ah----- C:\sqmnoopt12.sqm.(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2009-01-03 04:44 --------- d-----w c:\program files\Bots2008-12-27 03:17 --------- d-----w c:\program files\AIM62008-12-27 03:17 --------- d-----w c:\documents and settings\All Users\Application Data\AOL Downloads2008-12-21 20:34 --------- d-----w c:\program files\Workspace Macro Pro 6.52008-12-21 20:33 --------- d-----w c:\program files\Total Video Converter2008-12-21 20:31 --------- d-----w c:\program files\Cheat Engine2008-12-21 20:29 --------- d-----w c:\program files\Starcraft2008-12-21 20:28 --------- d-----w c:\program files\SwiftSwitch2008-12-21 20:28 --------- d-----w c:\program files\SwiftKit2008-12-21 01:10 --------- d-----w c:\program files\Dofus2008-12-19 03:53 --------- d-----w c:\program files\WarRock2008-11-07 23:37 --------- d-----w c:\program files\Alwil Software2008-10-27 23:22 121,396 -c--a-w c:\program files\lalalala.exe2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll2008-10-19 04:31 182,928 -c--a-w c:\windows\system32\PnkBstrB.exe2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll2008-10-16 20:13 202,776 ----a-w c:\windows\system32\wuweb.dll2008-10-16 20:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll2008-10-16 20:12 561,688 ----a-w c:\windows\system32\wuapi.dll2008-10-16 20:12 323,608 ----a-w c:\windows\system32\wucltui.dll2008-10-16 20:09 92,696 ----a-w c:\windows\system32\cdm.dll2008-10-16 20:09 51,224 ----a-w c:\windows\system32\wuauclt.exe2008-10-16 20:09 43,544 ----a-w c:\windows\system32\wups2.dll2008-10-16 20:08 34,328 ----a-w c:\windows\system32\wups.dll2008-10-16 20:06 268,648 ----a-w c:\windows\system32\mucltui.dll2008-10-16 20:06 208,744 ----a-w c:\windows\system32\muweb.dll2008-10-09 00:47 42,320 ----a-w c:\windows\system32\xfcodec.dll2008-07-25 03:19 23 -c--a-w c:\documents and settings\Keeno\jagex_runescape_preferences.dat2008-03-18 20:43 32 -c--a-w c:\documents and settings\All Users\Application Data\ezsid.dat2007-10-12 20:02 121 -c--a-w c:\documents and settings\Keeno\Install_WLMessenger.exe2007-09-22 05:26 9,870,032 -c--a-w c:\documents and settings\Keeno\fp2006-final-3.00-setup.zip2007-09-22 04:07 241,664 -c--a-w c:\program files\Uninstall Ask Toolbar.dll2008-12-21 03:47 67,688 ----a-w c:\program files\mozilla firefox\components\jar50.dll2008-12-21 03:47 54,368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll2008-12-21 03:47 34,944 ----a-w c:\program files\mozilla firefox\components\myspell.dll2008-12-21 03:47 46,712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll2008-12-21 03:47 172,136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll2008-08-21 15:22 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082120080822\index.dat.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]"Aim6"="c:\program files\AIM6\aim6.exe" [2008-01-03 50528][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2007-08-31 988584]"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736]"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-01-11 185896]"SearchSettings"="c:\program files\Search Settings\SearchSettings.exe" [2007-12-06 1069920]"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-02 13529088]"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-02 86016]"nwiz"="nwiz.exe" [2008-05-02 c:\windows\system32\nwiz.exe][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]"RunNarrator"="Narrator.exe" [2008-04-13 c:\windows\system32\narrator.exe]c:\documents and settings\Keeno\Start Menu\Programs\Startup\Alienware Dock.lnk - c:\program files\AlienGUIse\AlienwareDock\ObjectDock.exe [2008-12-24 2074360]c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-06-27 113664][HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]2001-12-20 23:34 24576 c:\program files\AlienGUIse\fastload.dll[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]"VIDC.XFR1"= xfcodec.dll[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Workspace Macro Pro Hotkeys.lnk]path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Workspace Macro Pro Hotkeys.lnkbackup=c:\windows\pss\Workspace Macro Pro Hotkeys.lnkCommon Startup[HKLM\~\startupfolder\C:^Documents and Settings^Keeno^Start Menu^Programs^Startup^Xfire.lnk]path=c:\documents and settings\Keeno\Start Menu\Programs\Startup\Xfire.lnkbackup=c:\windows\pss\Xfire.lnkStartup[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]--a------ 2007-10-10 18:51 39792 c:\program files\Adobe\Reader 8.0\Reader\Reader_SL.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]--a------ 2008-01-03 10:15 50528 c:\program files\AIM6\aim6.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]--a------ 2008-04-13 18:12 15360 c:\windows\system32\ctfmon.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]--a--c--- 2007-03-15 11:09 460784 c:\program files\DellSupport\DSAgnt.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLA]--a--c--- 2005-09-08 04:20 122940 c:\windows\system32\DLA\DLACTRLW.EXE[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]-----c--- 2005-02-23 15:19 53248 c:\program files\CyberLink\PowerDVD\DVDLauncher.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]--a--c--- 2005-09-20 08:32 77824 c:\windows\system32\hkcmd.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]--a--c--- 2005-09-20 08:36 114688 c:\windows\system32\igfxpers.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]--a--c--- 2005-09-20 08:35 94208 c:\windows\system32\igfxtray.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]--a--c--- 2004-07-27 15:50 221184 c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]--a--c--- 2004-07-27 15:50 81920 c:\program files\Common Files\InstallShield\UpdateService\issch.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MP10_EnsureFileVer]--a------ 2007-06-26 21:10 317440 c:\windows\inf\unregmp2.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]--a------ 2008-04-13 18:12 1695232 c:\program files\Messenger\msmsgs.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]--a------ 2007-10-18 10:34 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]-ra------ 2008-09-29 16:57 21755688 c:\program files\Skype\Phone\Skype.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]--a--c--- 2004-10-14 13:42 1404928 c:\program files\Analog Devices\Core\smax4pnp.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]--a--c--- 2007-07-12 03:00 132496 c:\program files\Java\jre1.6.0_02\bin\jusched.exe[HKEY_LOCAL_MACHINE\software\microsoft\security center]"AntiVirusOverride"=dword:00000001[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"%windir%\\system32\\sessmgr.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe"="c:\\Program Files\\Messenger\\msmsgs.exe"="c:\\Program Files\\Mozilla Firefox\\firefox.exe"="c:\\WINDOWS\\system32\\java.exe"="c:\\WINDOWS\\system32\\dpvsetup.exe"="c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="c:\\Program Files\\AIM6\\aim6.exe"="c:\\Program Files\\Real\\RealPlayer\\realplay.exe"="c:\\Program Files\\Xfire\\xfire.exe"="c:\\Program Files\\Bots\\bots.dat"="c:\\Documents and Settings\\All Users\\Application Data\\Nexon\\NGM\\NGM.exe"="c:\\Documents and Settings\\All Users\\Application Data\\Nexon\\Common\\NMService.exe"="c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"="\\\\Mah-pc\\Combat Arms\\NMService.exe"="c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe"c:\\Nexon\\Combat Arms\\NMService.exe"="c:\\Program Files\\Skype\\Phone\\Skype.exe"=[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]"43594:TCP"= 43594:TCP:RSPSR4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-12-30 24652][HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1d20604e-75f2-11dc-ae36-001676aa3570}]\Shell\AutoRun\command - F:\setupSNK.exe.Contents of the 'Scheduled Tasks' folder2009-01-06 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]2009-01-06 c:\windows\Tasks\tujvdgkg.job- c:\windows\system32\rundll32.exe [2008-04-13 18:12]..------- Supplementary Scan -------.uStart Page = hxxp://centurytel.myway.comIE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htmO16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cabc:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osdc:\windows\Downloaded Program Files\GoPetsWeb.ocx - O16 -: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8}hxxps://secure.gopetslive.com/dev/GoPetsWeb.cabc:\windows\Downloaded Program Files\GoPetsWeb.infFF - ProfilePath - c:\documents and settings\Keeno\Application Data\Mozilla\Firefox\Profiles\dtjkidwf.default\FF - prefs.js: browser.search.selectedEngine - YahooFF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:officialFF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=vmn&type=vendio&p=FF - component: c:\documents and settings\Keeno\Application Data\Mozilla\Firefox\Profiles\dtjkidwf.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}\components\WinampPlayer.dllFF - component: c:\program files\Mozilla Firefox\components\xpinstal.dllFF - component: c:\program files\Mozilla Firefox\extensions\[email protected]\components\SearchSettingsFF.dll.**************************************************************************catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2009-01-05 21:41:31Windows 5.1.2600 Service Pack 3 NTFSscanning hidden processes ... scanning hidden autostart entries ...scanning hidden files ... **************************************************************************.--------------------- LOCKED REGISTRY KEYS ---------------------[HKEY_USERS\S-1-5-21-1275210071-2025429265-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]@Denied: (Full) (LocalSystem).--------------------- DLLs Loaded Under Running Processes ---------------------- - - - - - - > 'winlogon.exe'(600)c:\program files\AlienGUIse\fastload.dll.Completion time: 2009-01-05 21:44:27ComboFix-quarantined-files.txt 2009-01-06 03:43:10ComboFix2.txt 2009-01-05 23:14:19Pre-Run: 33,931,177,984 bytes freePost-Run: 33,926,680,576 bytes free221 --- E O F --- 2008-12-18 04:32:44 Link to post Share on other sites
sarahw Posted January 6, 2009 Report Share Posted January 6, 2009 1. Close any open browsers.2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. 3. Open notepad and copy/paste the text in the quotebox below into it:File::c:\windows\system32\27840fb0.dllc:\windows\system32\1ece69a.dllC:\sqmdata15.sqmC:\sqmdata14.sqmC:\sqmnoopt15.sqmC:\sqmnoopt14.sqmC:\sqmdata13.sqmC:\sqmnoopt13.sqmC:\sqmdata12.sqmC:\sqmnoopt12.sqmFolder::c:\windows\system32\config\systemprofile\Application Data\s_4610_fHx8fHx8fDEyNDM1ODUwMTN8_Save this as CFScript.txt, in the same location as ComboFix.exeRefering to the picture above, drag CFScript into ComboFix.exeWhen finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply. Link to post Share on other sites
keenankern Posted January 21, 2009 Author Report Share Posted January 21, 2009 ComboFix 09-01-21.02 - Keeno 2009-01-21 17:41:48.4 - NTFSx86Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1609 [GMT -6:00]Running from: c:\documents and settings\Keeno\Desktop\ComboFix.exeCommand switches used :: c:\documents and settings\Keeno\Desktop\CFScript.txt * Created a new restore point.((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))).c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.datc:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.datc:\windows\system32\abusalel.inic:\windows\system32\afofamuy.inic:\windows\system32\afubukun.inic:\windows\system32\alezikis.inic:\windows\system32\alusuzar.inic:\windows\system32\asovojop.inic:\windows\system32\bizugosi.dllc:\windows\system32\brofdx.dllc:\windows\system32\bubedena.dllc:\windows\system32\bupuyafo.dllc:\windows\system32\cwsmrt.dllc:\windows\system32\dafanole.dllc:\windows\system32\dihusivu.dllc:\windows\system32\divimuvo.dllc:\windows\system32\duvabova.dllc:\windows\system32\ejimeren.inic:\windows\system32\elonafad.inic:\windows\system32\fetijonu.dllc:\windows\system32\fijiveni.dllc:\windows\system32\fuehmu.dllc:\windows\system32\geniweji.dllc:\windows\system32\gigiweme.dllc:\windows\system32\gijeluhe.dllc:\windows\system32\gogogahi.dllc:\windows\system32\hefihiru.dllc:\windows\system32\herawuve.dllc:\windows\system32\hezjte.dllc:\windows\system32\hijagolu.dllc:\windows\system32\howefapi.dllc:\windows\system32\hunayeko.dllc:\windows\system32\huvifima.dllc:\windows\system32\ijewineg.inic:\windows\system32\jakokoba.dllc:\windows\system32\jemjnb.dllc:\windows\system32\kjjeyd.dllc:\windows\system32\koveranu.dllc:\windows\system32\lazimiki.dllc:\windows\system32\lelasuba.dllc:\windows\system32\mileyige.dllc:\windows\system32\nikalute.dllc:\windows\system32\nisawoyi.dllc:\windows\system32\nqtcml.dllc:\windows\system32\nugedoka.dllc:\windows\system32\nukubufa.dllc:\windows\system32\obinihut.inic:\windows\system32\okonatuv.inic:\windows\system32\pebigamu.dllc:\windows\system32\pehuraba.dllc:\windows\system32\pogewaso.dllc:\windows\system32\pojovosa.dllc:\windows\system32\pokihuyi.dllc:\windows\system32\ravufuge.dllc:\windows\system32\razusula.dllc:\windows\system32\reziguge.dllc:\windows\system32\rihuhavu.dllc:\windows\system32\rituvuza.dllc:\windows\system32\rudagitu.dllc:\windows\system32\ruyupuno.dllc:\windows\system32\sikizela.dllc:\windows\system32\subirahu.dllc:\windows\system32\sumovena.dllc:\windows\system32\tareniva.dllc:\windows\system32\telowewa.dllc:\windows\system32\tepaduve.dllc:\windows\system32\tpdzbi.dllc:\windows\system32\tuhinibo.dllc:\windows\system32\turenugu.dllc:\windows\system32\unojitef.inic:\windows\system32\upigihez.inic:\windows\system32\urihifeh.inic:\windows\system32\uvahuhir.inic:\windows\system32\vafubamu.dllc:\windows\system32\viliwesi.dllc:\windows\system32\vosevodi.dllc:\windows\system32\vumeburi.dllc:\windows\system32\vutanoko.dllc:\windows\system32\yivudosu.dllc:\windows\system32\yuzuzunu.dllc:\windows\system32\zehigipu.dllc:\windows\system32\zuqhjh.dll----- BITS: Possible infected sites -----hxxp://childhe.comhxxp://77.74.48.105.((((((((((((((((((((((((( Files Created from 2008-12-21 to 2009-01-21 ))))))))))))))))))))))))))))))).2009-01-17 22:30 . 2009-01-18 01:49 <DIR> d-------- c:\program files\TalismanOnline2009-01-16 20:02 . 2009-01-16 22:45 <DIR> d-------- c:\program files\DofusArena22009-01-15 10:35 . 2009-01-15 10:35 244 --ah----- C:\sqmnoopt18.sqm2009-01-15 10:35 . 2009-01-15 10:35 232 --ah----- C:\sqmdata18.sqm2009-01-13 22:23 . 2009-01-13 22:23 268 --ah----- C:\sqmdata17.sqm2009-01-13 22:23 . 2009-01-13 22:23 244 --ah----- C:\sqmnoopt17.sqm2009-01-12 16:37 . 2009-01-12 16:37 244 --ah----- C:\sqmnoopt16.sqm2009-01-12 16:37 . 2009-01-12 16:37 232 --ah----- C:\sqmdata16.sqm2009-01-07 17:01 . 2009-01-16 21:39 <DIR> d-------- C:\Downloads2009-01-05 16:20 . 2009-01-05 16:20 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Search Settings2009-01-02 22:06 . 2009-01-02 22:06 <DIR> d-------- c:\windows\system32\config\systemprofile\Application Data\s_4610_fHx8fHx8fDEyNDM1ODUwMTN8_2009-01-02 22:06 . 2009-01-02 22:11 <DIR> d-------- c:\windows\system32\config\systemprofile\Application Data\Rapid Antivirus2009-01-02 21:44 . 2009-01-02 21:44 72,192 --a------ c:\windows\system32\hgGwXOFX.dll2009-01-02 21:44 . 2009-01-02 21:44 40,448 --a------ c:\windows\system32\k9261108.exe2008-12-30 00:17 . 2008-12-30 00:17 268 --ah----- C:\sqmdata15.sqm2008-12-30 00:17 . 2008-12-30 00:17 268 --ah----- C:\sqmdata14.sqm2008-12-30 00:17 . 2008-12-30 00:17 244 --ah----- C:\sqmnoopt15.sqm2008-12-30 00:17 . 2008-12-30 00:17 244 --ah----- C:\sqmnoopt14.sqm2008-12-28 17:55 . 2008-12-28 17:55 268 --ah----- C:\sqmdata13.sqm2008-12-28 17:55 . 2008-12-28 17:55 244 --ah----- C:\sqmnoopt13.sqm2008-12-24 18:07 . 2005-02-01 14:20 5,760,056 --a------ c:\windows\Darkstar.bmp2008-12-24 18:06 . 2008-12-24 18:06 5,760,054 --a------ c:\windows\ALX_1600x1200.bmp2008-12-24 18:04 . 2008-12-24 18:10 3,932,214 --a------ c:\windows\AW_XenoMorph1280.bmp2008-12-24 18:03 . 2008-12-24 18:03 <DIR> d-------- c:\program files\Common Files\Stardock2008-12-24 18:03 . 2008-12-24 18:07 <DIR> d-------- c:\program files\AlienGUIse2008-12-24 18:03 . 2003-02-26 22:27 36,864 --a------ c:\windows\system32\wbsys.dll2008-12-24 18:03 . 2008-12-24 18:03 56 --a------ c:\windows\wb.ini2008-12-24 15:45 . 2008-04-13 13:47 25,856 --a------ c:\windows\system32\drivers\usbprint.sys2008-12-24 15:45 . 2008-04-13 13:47 25,856 --a--c--- c:\windows\system32\dllcache\usbprint.sys.(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2009-01-08 00:55 --------- d-----w c:\program files\WarRock2009-01-07 23:57 --------- d-----w c:\program files\Bots2008-12-27 03:17 --------- d-----w c:\program files\AIM62008-12-27 03:17 --------- d-----w c:\documents and settings\All Users\Application Data\AOL Downloads2008-12-21 20:34 --------- d-----w c:\program files\Workspace Macro Pro 6.52008-12-21 20:33 --------- d-----w c:\program files\Total Video Converter2008-12-21 20:31 --------- d-----w c:\program files\Cheat Engine2008-12-21 20:29 --------- d-----w c:\program files\Starcraft2008-12-21 20:28 --------- d-----w c:\program files\SwiftSwitch2008-12-21 20:28 --------- d-----w c:\program files\SwiftKit2008-12-21 01:10 --------- d-----w c:\program files\Dofus2008-10-27 23:22 121,396 -c--a-w c:\program files\lalalala.exe2008-07-25 03:19 23 -c--a-w c:\documents and settings\Keeno\jagex_runescape_preferences.dat2008-03-18 20:43 32 -c--a-w c:\documents and settings\All Users\Application Data\ezsid.dat2007-10-12 20:02 121 -c--a-w c:\documents and settings\Keeno\Install_WLMessenger.exe2007-09-22 05:26 9,870,032 -c--a-w c:\documents and settings\Keeno\fp2006-final-3.00-setup.zip2007-09-22 04:07 241,664 -c--a-w c:\program files\Uninstall Ask Toolbar.dll2008-12-21 03:47 67,688 ----a-w c:\program files\mozilla firefox\components\jar50.dll2008-12-21 03:47 54,368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll2008-12-21 03:47 34,944 ----a-w c:\program files\mozilla firefox\components\myspell.dll2008-12-21 03:47 46,712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll2008-12-21 03:47 172,136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll2008-08-21 15:22 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082120080822\index.dat.((((((((((((((((((((((((((((( snapshot@2009-01-05_17.13.47.84 ))))))))))))))))))))))))))))))))))))))))).- 2000-08-31 14:00:00 28,672 ----a-w c:\windows\NIRCMD.exe+ 2000-08-31 14:00:00 29,696 ----a-w c:\windows\NIRCMD.exe- 2009-01-05 22:22:57 16,384 -c--a-w c:\windows\system32\config\systemprofile\Cookies\index.dat+ 2009-01-18 01:00:53 32,768 -c--a-w c:\windows\system32\config\systemprofile\Cookies\index.dat- 2009-01-05 22:22:57 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat+ 2009-01-18 01:00:53 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat+ 2009-01-18 01:00:57 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009011720090118\index.dat+ 2009-01-13 00:26:51 78,924 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat+ 2009-01-18 01:00:53 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat+ 2009-01-16 05:33:57 127,789 --sha-w c:\windows\system32\ligalijo.dll+ 2009-01-15 16:33:36 127,743 --sha-w c:\windows\system32\puwukehe.dll+ 2009-01-15 17:33:46 127,969 --sha-w c:\windows\system32\zobumava.dll.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]"Aim6"="c:\program files\AIM6\aim6.exe" [2008-01-03 50528][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2007-08-31 988584]"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736]"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-01-11 185896]"SearchSettings"="c:\program files\Search Settings\SearchSettings.exe" [2007-12-06 1069920]"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-02 13529088]"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-02 86016]"tozopimema"="c:\windows\system32\dotipiwu.dll" [bU]"nwiz"="nwiz.exe" [2008-05-02 c:\windows\system32\nwiz.exe][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]"RunNarrator"="Narrator.exe" [2008-04-13 c:\windows\system32\narrator.exe]c:\documents and settings\Keeno\Start Menu\Programs\Startup\Alienware Dock.lnk - c:\program files\AlienGUIse\AlienwareDock\ObjectDock.exe [2008-12-24 2074360]c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-06-27 113664][HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]2001-12-20 23:34 24576 c:\program files\AlienGUIse\fastload.dll[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]"AppInit_DLLs"=G G,c:\windows\system32\neganosu.dll[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]"VIDC.XFR1"= xfcodec.dll[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Workspace Macro Pro Hotkeys.lnk]path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Workspace Macro Pro Hotkeys.lnkbackup=c:\windows\pss\Workspace Macro Pro Hotkeys.lnkCommon Startup[HKLM\~\startupfolder\C:^Documents and Settings^Keeno^Start Menu^Programs^Startup^Xfire.lnk]path=c:\documents and settings\Keeno\Start Menu\Programs\Startup\Xfire.lnkbackup=c:\windows\pss\Xfire.lnkStartup[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]--a------ 2007-10-10 18:51 39792 c:\program files\Adobe\Reader 8.0\Reader\Reader_SL.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]--a------ 2008-01-03 10:15 50528 c:\program files\AIM6\aim6.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]--a------ 2008-04-13 18:12 15360 c:\windows\system32\ctfmon.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]--a--c--- 2007-03-15 11:09 460784 c:\program files\DellSupport\DSAgnt.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLA]--a--c--- 2005-09-08 04:20 122940 c:\windows\system32\DLA\DLACTRLW.EXE[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]-----c--- 2005-02-23 15:19 53248 c:\program files\CyberLink\PowerDVD\DVDLauncher.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]--a--c--- 2005-09-20 08:32 77824 c:\windows\system32\hkcmd.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]--a--c--- 2005-09-20 08:36 114688 c:\windows\system32\igfxpers.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]--a--c--- 2005-09-20 08:35 94208 c:\windows\system32\igfxtray.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]--a--c--- 2004-07-27 15:50 221184 c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]--a--c--- 2004-07-27 15:50 81920 c:\program files\Common Files\InstallShield\UpdateService\issch.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MP10_EnsureFileVer]--a------ 2007-06-26 21:10 317440 c:\windows\inf\unregmp2.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]--a------ 2008-04-13 18:12 1695232 c:\program files\Messenger\msmsgs.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]--a------ 2007-10-18 10:34 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]-ra------ 2008-09-29 16:57 21755688 c:\program files\Skype\Phone\Skype.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]--a--c--- 2004-10-14 13:42 1404928 c:\program files\Analog Devices\Core\smax4pnp.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]--a--c--- 2007-07-12 03:00 132496 c:\program files\Java\jre1.6.0_02\bin\jusched.exe[HKEY_LOCAL_MACHINE\software\microsoft\security center]"UpdatesDisableNotify"=dword:00000001"AntiVirusOverride"=dword:00000001[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"%windir%\\system32\\sessmgr.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe"="c:\\Program Files\\Messenger\\msmsgs.exe"="c:\\Program Files\\Mozilla Firefox\\firefox.exe"="c:\\WINDOWS\\system32\\java.exe"="c:\\WINDOWS\\system32\\dpvsetup.exe"="c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="c:\\Program Files\\AIM6\\aim6.exe"="c:\\Program Files\\Real\\RealPlayer\\realplay.exe"="c:\\Program Files\\Xfire\\xfire.exe"="c:\\Program Files\\Bots\\bots.dat"="c:\\Documents and Settings\\All Users\\Application Data\\Nexon\\NGM\\NGM.exe"="c:\\Documents and Settings\\All Users\\Application Data\\Nexon\\Common\\NMService.exe"="c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"="\\\\Mah-pc\\Combat Arms\\NMService.exe"="c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe"c:\\Nexon\\Combat Arms\\NMService.exe"="c:\\Program Files\\Skype\\Phone\\Skype.exe"="c:\\WINDOWS\\system32\\nvsvc32.exe"="c:\\WINDOWS\\system32\\PnkBstrA.exe"="c:\\WINDOWS\\system32\\spoolsv.exe"="c:\\Program Files\\Viewpoint\\Common\\ViewpointService.exe"="c:\\Program Files\\Windows Live Toolbar\\msn_sl.exe"="c:\\Program Files\\Common Files\\Microsoft Shared\\Windows Live\\WLLoginProxy.exe"="c:\\Program Files\\AlienGUIse\\wbload.exe"="c:\\Program Files\\Microsoft IntelliType Pro\\itype.exe"=[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]"43594:TCP"= 43594:TCP:RSPS"20738:TCP"= 20738:TCP:BitCometLite 20738 TCP"20738:UDP"= 20738:UDP:BitCometLite 20738 UDPR4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-12-30 24652][HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1d20604e-75f2-11dc-ae36-001676aa3570}]\Shell\AutoRun\command - F:\setupSNK.exe.Contents of the 'Scheduled Tasks' folder2009-01-21 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]2009-01-21 c:\windows\Tasks\tujvdgkg.job- c:\windows\system32\hgGwXOFX.dll [2009-01-02 21:44].- - - - ORPHANS REMOVED - - - -BHO-{0e75ccb8-9cc0-4824-b946-2f9a9d5a9b7b} - c:\windows\system32\fijiveni.dllBHO-{94807b61-05f3-47f5-925c-d459d9ce2f95} - c:\windows\system32\brofdx.dll.------- Supplementary Scan -------.uStart Page = hxxp://centurytel.myway.comIE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htmDPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cabDPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cabFF - ProfilePath - c:\documents and settings\Keeno\Application Data\Mozilla\Firefox\Profiles\dtjkidwf.default\FF - prefs.js: browser.search.selectedEngine - YahooFF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:officialFF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=vmn&type=vendio&p=FF - component: c:\documents and settings\Keeno\Application Data\Mozilla\Firefox\Profiles\dtjkidwf.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}\components\WinampPlayer.dllFF - component: c:\program files\Mozilla Firefox\components\xpinstal.dllFF - component: c:\program files\Mozilla Firefox\extensions\[email protected]\components\SearchSettingsFF.dll.**************************************************************************catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2009-01-21 17:46:00Windows 5.1.2600 Service Pack 3 NTFSscanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfullyhidden files: 0**************************************************************************.--------------------- LOCKED REGISTRY KEYS ---------------------[HKEY_USERS\S-1-5-21-1275210071-2025429265-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]@Denied: (Full) (LocalSystem).--------------------- DLLs Loaded Under Running Processes ---------------------- - - - - - - > 'winlogon.exe'(604)c:\program files\AlienGUIse\fastload.dll.------------------------ Other Running Processes ------------------------.c:\windows\system32\nvsvc32.exec:\windows\system32\PnkBstrA.exec:\windows\system32\rundll32.exec:\program files\Microsoft IntelliPoint\dpupdchk.exec:\program files\AIM6\aolsoftware.exe.**************************************************************************.Completion time: 2009-01-21 17:56:59 - machine was rebootedComboFix-quarantined-files.txt 2009-01-21 23:56:39ComboFix2.txt 2009-01-21 23:37:25ComboFix3.txt 2009-01-06 03:44:29ComboFix4.txt 2009-01-05 23:14:19Pre-Run: 32,297,488,384 bytes freePost-Run: 32,252,395,520 bytes free342 --- E O F --- 2008-12-18 04:32:44 Link to post Share on other sites
sarahw Posted January 23, 2009 Report Share Posted January 23, 2009 Please download Malwarebytes' Anti-Malware from Here or HereDouble Click mbam-setup.exe to install the application.Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.If an update is found, it will download and install the latest version.Once the program has loaded, select "Perform Quick Scan", then click Scan.The scan may take some time to finish,so please be patient.When the scan is complete, click OK, then Show Results to view the results.Make sure that everything is checked, and click Remove Selected.When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.Copy&Paste the entire report in your next reply.Extra Note:If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. Link to post Share on other sites
sarahw Posted February 14, 2009 Report Share Posted February 14, 2009 Inactive topic...If you still need help on this problem, contact me or one of the Moderators to re-open this up.Topic closed. Link to post Share on other sites
Recommended Posts