Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
Virus & Other Malware Removal
Tag Cloud
access acer asus bios bsod computer crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop malware memory modem monitor motherboard network printer problem ram registry router security slow software sound toshiba trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > Virus & Other Malware Removal >
fake Windows Security Alert - Trojan/Malware (In Progress)

Reply  
Thread Tools
Cookiegal's Avatar
Administrator & Malware Removal Specialist with 79,287 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
10-Jan-2009, 07:48 PM #61
Please remove the version of ComboFix you have by dragging it from your desktop to the recycle bin and then grab the latest version, do a new scan and post the resulting log please.

Please visit Combofix Guide & Instructions for instructions for downloading and running ComboFix.

The only thing different from the instructions there is that when downloading and saving the ComboFix.exe I would like you to rename it to Combo-Fix.exe please.

Post the log from ComboFix when you've accomplished that along with a new HijackThis log.
__________________
Microsoft MVP - Consumer Security
heleneh's Avatar
Computer Specs
Member with 60 posts.
 
Join Date: Dec 2008
Experience: Intermediate
10-Jan-2009, 08:42 PM #62
combofix problem

I am following your instructions from above.

combofix has completed stage 50.

in the blue box, i have the following message:
'"C:\WINDOWS\system32\"' is not recognized as an internal or external command, operable program or batch file.




-----------------------------------

OK, an hour went by and I got antsy. I hit the enter key, and the machine rebooted.
My desktop returned, I did recieve this error

microsoft visual c++ runtime library
Roxwatchtray.exe
Runtime error - asked to terminate in an unusual way

Then I had to say ''ok'' to a selective startup, and then got THE ERROR.

Here is the combofix log:


ComboFix 09-01-10.01 - Helene 2009-01-10 19:15:33.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.257 [GMT -5:00]
Running from: c:\documents and settings\Helene\Desktop\ComboFix\Combo-Fix.exe
Command switches used :: c:\documents and settings\Helene\Desktop\ComboFix\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: AOL Firewall *enabled*
FW: McAfee Personal Firewall *disabled*
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\java2.sys c:\windows\system32\snjava.dll
c:\windows\system32\mfcans32.DLL
c:\windows\system32\mfcuia32.dll
c:\windows\system32\msexcl35.dll
c:\windows\system32\msltus35.dll
c:\windows\system32\mspdox35.dll
c:\windows\system32\msrdo20.dll
c:\windows\system32\mstext35.dll
c:\windows\system32\msxbse35.dll
c:\windows\system32\rdocurs.dll

.
((((((((((((((((((((((((( Files Created from 2008-12-11 to 2009-01-11 )))))))))))))))))))))))))))))))
.

2009-01-10 07:55 . 2009-01-10 07:55 <DIR> d-------- c:\documents and settings\Robbie\Application Data\Malwarebytes
2009-01-10 07:34 . 2009-01-10 07:34 <DIR> d-------- c:\documents and settings\Joanie\Application Data\Malwarebytes
2009-01-10 00:10 . 2009-01-10 00:10 <DIR> d-------- c:\documents and settings\Becca\Application Data\Malwarebytes
2009-01-08 01:51 . 2009-01-08 01:51 <DIR> d-------- c:\documents and settings\Robbie\Application Data\Viewpoint
2009-01-08 01:47 . 2009-01-08 01:47 <DIR> d-------- c:\documents and settings\Robbie\Application Data\McAfee
2009-01-08 01:41 . 2009-01-08 01:41 <DIR> d-------- c:\documents and settings\Joanie\Application Data\McAfee
2009-01-08 01:32 . 2009-01-08 01:32 <DIR> d-------- c:\documents and settings\Becca\Application Data\McAfee
2009-01-04 20:12 . 2009-01-04 20:12 <DIR> d-------- c:\program files\Viewpoint
2009-01-04 17:31 . 2009-01-04 17:30 410,984 --a------ c:\windows\SYSTEM32\deploytk.dll
2009-01-04 17:31 . 2009-01-04 17:30 73,728 --a------ c:\windows\SYSTEM32\javacpl.cpl
2009-01-04 16:55 . 2009-01-04 16:55 <DIR> d-------- c:\program files\Windows Installer Clean Up
2009-01-04 16:55 . 2009-01-04 16:55 <DIR> d-------- c:\program files\MSECACHE
2009-01-01 11:09 . 2009-01-01 11:09 <DIR> d-------- c:\program files\McAfee DesktopDoctor
2008-12-28 22:36 . 2008-12-28 22:36 <DIR> d-------- c:\documents and settings\LocalService\Application Data\McAfee
2008-12-28 21:53 . 2008-12-28 21:54 <DIR> d-------- c:\program files\ATFCleaner
2008-12-28 21:50 . 2008-12-29 07:47 <DIR> d-------- c:\program files\Trend Micro
2008-12-28 12:38 . 2009-01-10 00:12 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-28 12:38 . 2008-12-28 12:38 <DIR> d-------- c:\documents and settings\Helene\Application Data\Malwarebytes
2008-12-28 12:38 . 2008-12-28 12:38 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-28 12:38 . 2009-01-04 18:38 38,496 --a------ c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2008-12-28 12:38 . 2009-01-04 18:38 15,504 --a------ c:\windows\SYSTEM32\DRIVERS\mbam.sys
2008-12-22 21:09 . 2008-12-22 21:09 <DIR> d-------- c:\program files\TeaTimer (Spybot - Search & Destroy)
2008-12-22 21:09 . 2008-12-22 21:09 <DIR> d-------- c:\program files\SDHelper (Spybot - Search & Destroy)
2008-12-22 19:57 . 2008-12-22 19:57 <DIR> d-------- c:\documents and settings\Helene\Application Data\McAfee

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-11 01:00 --------- d-----w c:\documents and settings\Helene\Application Data\Skype
2009-01-10 21:00 --------- d-----w c:\documents and settings\Helene\Application Data\skypePM
2009-01-10 13:35 --------- d-----w c:\program files\Greetings Workshop
2009-01-10 12:52 --------- d--h--w c:\documents and settings\Robbie\Application Data\GTek
2009-01-10 12:26 --------- d--h--w c:\documents and settings\Joanie\Application Data\Gtek
2009-01-05 13:36 --------- d-----w c:\program files\Canon
2009-01-05 13:15 --------- d-----w c:\documents and settings\Helene\Application Data\MSN6
2009-01-05 02:09 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2009-01-05 01:31 --------- d-----w c:\program files\Common Files\AOL
2009-01-04 22:30 --------- d-----w c:\program files\Java
2009-01-02 21:58 --------- d-----w c:\program files\Upromise_RemindU
2009-01-01 15:41 --------- d-----w c:\program files\iTunes
2009-01-01 15:17 --------- d-----w c:\program files\ICopyDVDs2
2008-12-29 19:57 195,168 ----a-w c:\documents and settings\Helene\Application Data\GDIPFONTCACHEV1.DAT
2008-12-29 15:43 --------- d-----w c:\program files\Dell Computer
2008-12-29 03:37 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-12-29 03:04 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-23 20:28 --------- d-----w c:\documents and settings\Helene\Application Data\Nero
2008-12-23 00:56 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee
2008-12-05 22:20 --------- d--h--w c:\documents and settings\Helene\Application Data\Move Networks
2008-11-18 00:48 --------- d-----w c:\documents and settings\Helene\Application Data\LimeWire
2008-08-26 17:04 56,912 ----a-w c:\documents and settings\Helene\g2mdlhlpx.exe
2008-03-14 01:38 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2008-02-25 04:18 61,480 ----a-w c:\documents and settings\Helene\GoToAssistDownloadHelper.exe
2006-01-23 13:50 134,944 ----a-w c:\documents and settings\Robbie\Application Data\GDIPFONTCACHEV1.DAT
2003-11-02 09:50 130,832 ------w c:\documents and settings\Becca\Application Data\GDIPFONTCACHEV1.DAT
2003-08-21 21:00 130,832 ------w c:\documents and settings\Joanie\Application Data\GDIPFONTCACHEV1.DAT
2000-12-12 15:17 100,432 ------w c:\program files\Win2000PPAHotfix.exe
2008-12-20 20:08 67,688 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-12-20 20:08 54,368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-20 20:08 34,944 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-12-20 20:08 46,712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-12-20 20:08 172,136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((( snapshot@2008-12-29_20.43.19.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 01:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE
- 2006-05-19 15:52:16 65,536 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\ARPPRODUCTICON.exe
+ 2009-01-10 12:17:13 65,536 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\ARPPRODUCTICON.exe
- 2006-05-19 15:52:12 65,536 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\Contribute.exe
+ 2009-01-10 12:17:13 65,536 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\Contribute.exe
- 2006-05-19 15:52:12 65,536 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\NewShortcut1_1.D404042C_B1B4_413E_B1C0_526D0BBE80E3.exe
+ 2009-01-10 12:17:13 65,536 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\NewShortcut1_1.D404042C_B1B4_413E_B1C0_526D0BBE80E3.exe
- 2006-05-19 15:52:17 65,536 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\NewShortcut1_B673A475445E47568AB1AE72FDC5B639.exe
+ 2009-01-10 12:17:14 65,536 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\NewShortcut1_B673A475445E47568AB1AE72FDC5B639.exe
- 2006-05-19 15:52:17 65,536 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\NewShortcut11_2388ED126A5243258E7B1A229914C1AE.exe
+ 2009-01-10 12:17:14 65,536 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\NewShortcut11_2388ED126A5243258E7B1A229914C1AE.exe
- 2006-05-19 15:52:15 4,133,376 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\NewShortcut2_1.D404042C_B1B4_413E_B1C0_526D0BBE80E3.bat
+ 2009-01-10 12:17:13 4,133,376 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\NewShortcut2_1.D404042C_B1B4_413E_B1C0_526D0BBE80E3.bat
- 2008-12-29 22:58:23 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
+ 2009-01-10 21:16:31 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
- 2008-12-29 22:58:23 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
+ 2009-01-10 21:16:31 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
- 2006-04-01 15:36:47 172,704 ----a-w c:\windows\SYSTEM32\GDIPFONTCACHEV1.DAT
+ 2009-01-08 06:48:17 195,104 ----a-w c:\windows\SYSTEM32\GDIPFONTCACHEV1.DAT
- 2008-06-10 05:21:01 135,168 ----a-w c:\windows\SYSTEM32\java.exe
+ 2009-01-04 22:30:50 144,792 ----a-w c:\windows\SYSTEM32\java.exe
- 2008-06-10 05:21:04 135,168 ----a-w c:\windows\SYSTEM32\javaw.exe
+ 2009-01-04 22:30:51 144,792 ----a-w c:\windows\SYSTEM32\javaw.exe
- 2008-06-10 06:32:34 139,264 ----a-w c:\windows\SYSTEM32\javaws.exe
+ 2009-01-04 22:30:51 148,888 ----a-w c:\windows\SYSTEM32\javaws.exe
+ 2009-01-11 01:22:24 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_210.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 241664]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2002-09-24 290816]
"tgcmd"="c:\program files\support.com\bin\tgcmd.exe" [2002-04-24 1544192]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-16 28738]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe" [2005-11-22 163840]
"RoxioDragToDisc"="c:\program files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe" [2005-11-21 1687552]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 71216]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-06-02 267048]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"MBkLogOnHook"="c:\program files\McAfee\MBK\LogOnHook.exe" [2007-01-08 20480]
"MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2005-09-26 169984]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 c:\windows\SYSTEM32\Ati2mdxx.exe]

c:\documents and settings\Robbie\Start Menu\Programs\Startup\
Greetings Workshop Reminders.lnk - c:\program files\Greetings Workshop\GWREMIND.EXE [1996-06-25 40448]
Quicken Scheduled Updates.lnk - c:\documents and settings\All Users\Documents\2448\bagent.exe [2004-07-16 57344]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2003-02-16 113664]
D-Link AirPlus G Wireless Utility.lnk - c:\program files\D-Link\AirPlus G Wireless Adapter Utility\AirPlus.exe [2005-12-15 774220]
D-Link REG Utility.lnk - c:\program files\D-Link\AirPlus G Wireless Adapter Utility\Reg.exe [2005-12-15 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 241664]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 53248]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
MySoftware InterCom.lnk - c:\program files\Common Files\MySoftware\InterCom.exe [2003-02-28 260608]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
-ra------ 2002-08-14 19:22 28672 c:\windows\SYSTEM32\DSentry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 09:50 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
--a------ 2005-01-16 11:44 26112 c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2009-01-04 17:30 136600 c:\program files\Java\jre6\bin\jusched.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\ypager.exe" -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\All Users\\Documents\\2448\\qw.exe"=
"c:\\Program Files\\PowerDVD\\CLDMA.EXE"=
"c:\\Program Files\\HP\\Digital Imaging\\Diagnostics\\HPSysDig.exe"=
"c:\\TAX98\\32BIT\\TTXMPC98.EXE"=
"c:\\Program Files\\FTP Explorer\\ftpx.exe"=
"c:\\WINDOWS\\SYSTEM32\\ntvdm.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\WINDOWS\\SYSTEM32\\fxsclnt.exe"=
"c:\\Program Files\\support.com\\bin\\tgcmd.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\America Online 9.0c\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1132598226\\ee\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Roxio\\Easy Media Creator 8\\Audio Master\\MusicDiscCreator.exe"=
"c:\\Program Files\\Common Files\\Roxio Shared\\SharedCom\\RoxUpnpRenderer.exe"=
"c:\\Program Files\\Common Files\\AOL\\1132598226\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AIM95\\aim.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Roxio\\Easy Media Creator 8\\Digital Home\\RoxUpnpServer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Glob allyOpenPorts\List]
"1700:TCP"= 1700:TCP:MioNet Remote Drive Access
"1641:TCP"= 1641:TCP:MioNet Remote Drive Verification

R4 ColdFusion MX 7 ODBC Agent;ColdFusion MX 7 ODBC Agent;c:\cfusionmx7\db\slserver54\bin\swagent.exe "ColdFusion MX 7 ODBC Agent" --> c:\cfusionmx7\db\slserver54\bin\swagent.exe ColdFusion MX 7 ODBC Agent [?]
R4 ColdFusion MX 7 ODBC Server;ColdFusion MX 7 ODBC Server;c:\cfusionmx7\db\slserver54\bin\swstrtr.exe "ColdFusion MX 7 ODBC Server" --> c:\cfusionmx7\db\slserver54\bin\swstrtr.exe ColdFusion MX 7 ODBC Server [?]
S3 hpusbwdm;HP DVD Movie Writer dc3000/dc4000;c:\windows\SYSTEM32\DRIVERS\hpusbwdm.sys [2003-12-30 1080832]
S3 Wdm1;USB Bridge Cable Driver;c:\windows\SYSTEM32\DRIVERS\usbbc.sys [2003-02-27 15576]
S4 ColdFusion MX 7 Application Server;ColdFusion MX 7 Application Server;c:\cfusionmx7\runtime\bin\jrunsvc.exe [2006-04-15 61440]
.
Contents of the 'Scheduled Tasks' folder

2009-01-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]

2003-07-03 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\System32\OOBE\OOBEBALN.EXE [2004-08-04 02:56]

2009-01-11 c:\windows\Tasks\jselxtca.job
- c:\windows\system32\rundll32.exe [2004-08-04 02:56]

2008-02-25 c:\windows\Tasks\McAfee Cleanup.job
- c:\docume~1\Helene\LOCALS~1\Temp\MCPR.tmp\mccleanup.exe []

2008-12-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]

2008-12-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]

2003-06-28 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2002-08-07 09:04]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://registration.aol.com/mail?s_url=http%3a%2f%2fwebmail.aol.com%2f_cqr%2fLoginSuccess.aspx%3fsitedo main%3dsns.webmail.aol.com%26siteState%3dver%253a1%25252c0%2526ld%253awebma il.aol.com%2526pv%253aAOL%2526lc%253aen-us%2526ud%253aaol.com%2526br%253aWebSuite-CurrentProd
mWindow Title = Microsoft Internet Explorer provided by Comcast
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
IE: RemindU - file://c:\program files\Upromise_RemindU\Sy1050\Tp1050\scri1050a.htm
Trusted Zone: *.internet
Trusted Zone: *.mcafee.com

O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

O16 -: {FFFFFFFF-CAFE-BABE-BABE-01AA0055595A} - hxxp://www.truesuite.com/trueclean/TrueCleanInstall.exe
FF - ProfilePath - c:\documents and settings\Helene\Application Data\Mozilla\Firefox\Profiles\e3w25nyj.default\
FF - prefs.js: browser.startup.homepage - hxxps://my.screenname.aol.com/_cqr/login/login.psp?mcState=initialized&seamless=novl&sitedomain=sns.webmail.aol.com& lang=en&locale=us&authLev=2&siteState=ver%3a2%7cac%3aWS%7cat%3aSNS%7cld%3aw ebmail.aol.com%7cuv%3aAOL%7clc%3aen-us
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll

---- FIREFOX POLICIES ----
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-10 20:27:17
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2257554901-1753557314-821268821-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SYSTEM32\acs.exe
c:\program files\Common Files\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\SYSTEM32\ati2evxx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
c:\windows\SYSTEM32\DRIVERS\CDAC11BA.EXE
c:\cfusionmx7\db\slserver54\bin\swagent.exe
c:\cfusionmx7\db\slserver54\bin\swstrtr.exe
c:\cfusionmx7\db\slserver54\bin\swsoc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\McAfee\MBK\MBackMonitor.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
c:\program files\Photodex\ProShowProducer\scsiaccess.exe
c:\progra~1\McAfee.com\Agent\mcagent.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\wanmpsvc.exe
c:\program files\Common Files\AOL\1132598226\ee\aolsoftware.exe
c:\program files\HP\Digital Imaging\bin\hpqgalry.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
c:\progra~1\McAfee\MSC\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2009-01-10 20:37:49 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-11 01:36:53
ComboFix2.txt 2009-01-01 00:10:48
ComboFix3.txt 2008-12-31 04:02:22
ComboFix4.txt 2008-12-31 01:37:41
ComboFix5.txt 2009-01-11 00:13:35

Pre-Run: 31,840,944,128 bytes free
Post-Run: 31,926,620,160 bytes free

306 --- E O F --- 2009-01-05 18:17:20

Last edited by heleneh; 10-Jan-2009 at 09:50 PM..
heleneh's Avatar
Computer Specs
Member with 60 posts.
 
Join Date: Dec 2008
Experience: Intermediate
10-Jan-2009, 09:51 PM #63
and here is the hijackthis log
HIjackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:47:50 PM, on 1/10/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\CFusionMX7\db\slserver54\bin\swagent.exe
C:\CFusionMX7\db\slserver54\bin\swstrtr.exe
C:\CFusionMX7\db\slserver54\bin\swsoc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\D-Link\AirPlus G Wireless Adapter Utility\AirPlus.exe
C:\Program Files\Common Files\AOL\1132598226\ee\aolsoftware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\MySoftware\InterCom.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://registration.aol.com/mail?s_u...te-CurrentProd
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/yco.../www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: D-Link AirPlus G Wireless Utility.lnk = ?
O4 - Global Startup: D-Link REG Utility.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MySoftware InterCom.lnk = C:\Program Files\Common Files\MySoftware\InterCom.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: RemindU - file://C:\Program Files\Upromise_RemindU\Sy1050\Tp1050\scri1050a.htm
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/...oUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} (AOL Content Update) - http://esupport.aol.com/help/acp2/en...ach_core_1.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/...oUploader3.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/sh...23/mcgdmgr.cab
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/...ploader4_5.cab
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://trueswitch.com/TrueInstall.exe
O16 - DPF: {FFFFFFFF-CAFE-BABE-BABE-01AA0055595A} - http://www.truesuite.com/trueclean/TrueCleanInstall.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: ColdFusion MX 7 Application Server - Macromedia Inc. - C:\CFusionMX7\runtime\bin\jrunsvc.exe
O23 - Service: ColdFusion MX 7 ODBC Agent - Unknown owner - C:\CFusionMX7\db\slserver54\bin\swagent.exe
O23 - Service: ColdFusion MX 7 ODBC Server - Unknown owner - C:\CFusionMX7\db\slserver54\bin\swstrtr.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 13140 bytes


thanks
Helene
Cookiegal's Avatar
Administrator & Malware Removal Specialist with 79,287 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
12-Jan-2009, 04:51 PM #64
Go to Control Panel - Add/Remove programs and remove any of these you see there:

Viewpoint
Viewpoint Manager
Viewpoint Media Player



Then delete these folders:

c:\documents and settings\Robbie\Application Data\Viewpoint
c:\program files\Viewpoint



What can you tell me about this program? It may be known as WebSniffer, possibly belonging to McAfee:

c:\program files\Common Files\MySoftware\InterCom.exe

Do you have MioNet which is used for remote access?

This is a scheduled task. Can you tell me what it does?

c:\windows\Tasks\jselxtca.job

You have McAfee but there is a scheduled task to run LiveUpdate for Symantec. Did you remove Symantec in favour of McAfee? If so, please delete this Scheduled Task:

c:\windows\Tasks\Symantec NetDetect.job

See if LiveUpdate (Symantec) is listing in the Add/Remove programs and if so remove it from there.

Then if you no longer have any Symantec products, delete this folder:

- c:\program files\Symantec

Now please do this:

Download GMER from: http://gmer.net/index.php

Save it on your desktop and unzip it.

Double click the gmer.exe to run it and select the rootkit tab and press scan. When the scan is done, click Copy. This will copy the report to the clipboard. Paste it into Notepad and save it and also paste the log report back here please.
__________________
Microsoft MVP - Consumer Security
heleneh's Avatar
Computer Specs
Member with 60 posts.
 
Join Date: Dec 2008
Experience: Intermediate
12-Jan-2009, 07:38 PM #65
1) Go to Control Panel - Add/Remove programs and remove any of these you see there:

Viewpoint
Viewpoint Manager
Viewpoint Media Player - removed



2) Then delete these folders:

c:\documents and settings\Robbie\Application Data\Viewpoint -deleted
c:\program files\Viewpoint -not found



3) What can you tell me about this program? It may be known as WebSniffer, possibly belonging to McAfee:
c:\program files\Common Files\MySoftware\InterCom.exe
This was bundled with a label printing software - I have always been suspicious of it, what I learned from googling it is that it it is used to check for updates to the software - totally unnecessary

4) Do you have MioNet which is used for remote access?
no, not that I am aware

5) This is a scheduled task. Can you tell me what it does?

c:\windows\Tasks\jselxtca.job
(I have never noticed it running)
From the properties tab:
Run exe "C:\WINDOWS\system32\khfEWPGw.dll",ShellPath
Run as : DBZGB421\Helene

6) You have McAfee but there is a scheduled task to run LiveUpdate for Symantec. Did you remove Symantec in favour of McAfee? probably, long ago. If so, please delete this Scheduled Task:

c:\windows\Tasks\Symantec NetDetect.job - deleted

See if LiveUpdate (Symantec) is listing in the Add/Remove programs and if so remove it from there. - not found

Then if you no longer have any Symantec products, delete this folder:

- c:\program files\Symantec -deleted

7) gmer log attached

thanks again
Helene
Attachment Blocked
Attachments in the HJT forum are often designed to solve a specific issue and not meant to be used without instructions specific to your computer. If you want help specific to your computer, please post a HiJackThis Log. If you started this thread, please make sure you are logged in to be able to view attachments.
Cookiegal's Avatar
Administrator & Malware Removal Specialist with 79,287 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
12-Jan-2009, 08:46 PM #66
Delete both of these files:

c:\windows\Tasks\jselxtca.job
C:\WINDOWS\system32\khfEWPGw.dll


MioNet appears to be legit and would be likely from Western Digital for backups.


How are things now?
heleneh's Avatar
Computer Specs
Member with 60 posts.
 
Join Date: Dec 2008
Experience: Intermediate
12-Jan-2009, 09:01 PM #67
Delete both of these files:

c:\windows\Tasks\jselxtca.job deleted
C:\WINDOWS\system32\khfEWPGw.dll not found


MioNet appears to be legit and would be likely from Western Digital for backups.
I went to the mionet website, and if it is related to the module you are seeing (i see no reference to it, didn't even know I had it), I'd just as soon get rid of it


How are things now?

i ran msconfig
in the ''general tab'', selective start up is selected
I went to the startup tab
i unchecked 2 items
i hit ''apply''
i am still getting the access denied error!


I did a little poking around on the internet, and the hp software seems to be implicated in the access denied error, as you mentioned days ago. do you think that is worth chasing down?

thanks again

Helene
Cookiegal's Avatar
Administrator & Malware Removal Specialist with 79,287 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
13-Jan-2009, 02:30 PM #68
Try logging in as Administrator and see if you can access msconfig under that account. You will have to do that in safe mode.
heleneh's Avatar
Computer Specs
Member with 60 posts.
 
Join Date: Dec 2008
Experience: Intermediate
13-Jan-2009, 03:07 PM #69
I did not see your post above, I saw the following email:

Yes, is it possible any of your HP hardware updated itself or drivers recently?
Lets try this:
Go to *Start *– *Run *- type *msconfig* – click OK and click on the *startup
tab*. Uncheck everything there except for your anti-virus program. Then reboot
Let me know if the problem persists after doing that.


Well, there are definitley fewer processes running than normal! And I run
msconfig, and everything is still unchecked. So, it may be working!

So am I running in selective mode from now on, not normal?

Will this startup definition apply to all accounts?

Next, I'd like to identify the services that don't have
to run unless specifically invoked by user.

the machine is running much faster!

thank
Helene
Cookiegal's Avatar
Administrator & Malware Removal Specialist with 79,287 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
13-Jan-2009, 07:11 PM #70
I don't understand. Are you no longer getting the Access Denied error message?
heleneh's Avatar
Computer Specs
Member with 60 posts.
 
Join Date: Dec 2008
Experience: Intermediate
13-Jan-2009, 08:28 PM #71
Sorry, I was not clear. Per your instructions in post #69,

i ran msconfig
in the ''general tab'', selective start up is selected
I went to the startup tab
i unchecked all but mcafee stuff
i hit ''apply''
i got the access denied error
i hit ''ok''
i got the access denied error

Then I rebooted
All of the items are still unchecked in the startup tab

and there are many fewer processes running.

so it appears to be working, and that the error is not a true error?

Helene
Cookiegal's Avatar
Administrator & Malware Removal Specialist with 79,287 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
14-Jan-2009, 06:37 PM #72
This sounds more like the HP problem as those users were able to uncheck items in msconfig even though they got that error.

I'm posting a link with instructions to change the startup of one of the HP services. Let me know if you understand it and think you can make the changes in the registry.

You can back up your registry first in case you make a mistake by doing the following:

Please go to Start - Run and copy and paste the following and then click OK:

regedit /e c:\registrybackup2.reg

It won't appear to be doing anything and that's normal. Your mouse pointer may turn to an hour glass for a minute.

When it no longer has the hour glass, check in your C drive to be sure you have a file called registrybackup2.reg before continuing. If you do not see that file, please let me know before doing anything else.

http://www.ehow.com/how_4531999_fix-...ror-using.html
__________________
Microsoft MVP - Consumer Security
heleneh's Avatar
Computer Specs
Member with 60 posts.
 
Join Date: Dec 2008
Experience: Intermediate
14-Jan-2009, 08:26 PM #73
Per your instructions,

I backed up the registry.

I changed the key according to instructions - the only difference being that the value in the key was '4', and I changed it to '3' (the instructions assumed the key value would be changed from '2' to '3')

I rebooted

I ran msconfig, checked an item in the startup tab, clicked ''apply'', and
unfortunately, am still getting the access denied error.

But, man, does it boot fast now!

Helene
Cookiegal's Avatar
Administrator & Malware Removal Specialist with 79,287 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
15-Jan-2009, 05:30 PM #74
Try uninstalling your printer software and see if that solves the problem.
heleneh's Avatar
Computer Specs
Member with 60 posts.
 
Join Date: Dec 2008
Experience: Intermediate
18-Jan-2009, 08:48 PM #75
CookieGal,

I am unable to find the printer software to re-install the software, and working with HP is a long arduous process. Since I was able, for now, to update msconfig/startup, I'm going to set that problem aside for now.

At this point, I would love help with a couple of things:
1) reducing the number of services running, including AOL that I thought I had removed
2) Getting rid of McAfee in favor of something less resource intensive - I see that in other posts, AVAST, COMODO FIrewall, and Malwarebytes are recommended. Would you concur with that?
3) Any other recommendations you might have

Again, thanks for everything
Helene
Reply

Tags
malware, trojan

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 10:20 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.