1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

HJT Logfile

Discussion in 'Virus & Other Malware Removal' started by cogent, Jul 31, 2006.

Thread Status:
Not open for further replies.
Advertisement
  1. cogent

    cogent Thread Starter

    Joined:
    Jul 31, 2006
    Messages:
    20
    Logfile of HijackThis v1.99.1
    Scan saved at 10:09:20 PM, on 7/30/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    f:\Program Files\ewido\security suite\ewidoctrl.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ishost.exe
    C:\WINDOWS\system32\issearch.exe
    C:\WINDOWS\Mixer.exe
    C:\WINDOWS\system32\ismon.exe
    C:\Program Files\ASUS\Probe\AsusProb.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    C:\WINDOWS\MXOALDR.EXE
    C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
    F:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Winamp\winampa.exe
    C:\WINDOWS\system32\wfxqhv.exe
    C:\WINDOWS\system32\apbzk.exe
    C:\WINDOWS\system32\apbzk.exe
    C:\WINDOWS\system32\0a6300b7.exe
    C:\WINDOWS\system32\y3aqsoepa.exe
    C:\WINDOWS\system32\afdaqd3.exe
    F:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\palstart.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\WinRAR\WinRAR.exe
    C:\DOCUME~1\SOBRAD~1.AOA\LOCALS~1\Temp\Rar$EX00.265\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\aryxh.exe
    F3 - REG:win.ini: run=
    F2 - REG:system.ini: UserInit=userinit.exe,lmfcsyy.exe
    O1 - Hosts: 205.238.40.2 www.winmx.com
    O1 - Hosts: 205.238.40.2 err.winmx.com
    O1 - Hosts: 205.238.40.2 c3310.z1301.winmx.com
    O1 - Hosts: 67.18.233.36 c3311.z1301.winmx.com
    O1 - Hosts: 82.43.224.20 c3312.z1301.winmx.com
    O1 - Hosts: 209.67.209.50 c3313.z1301.winmx.com
    O1 - Hosts: 212.227.64.159 c3314.z1301.winmx.com
    O1 - Hosts: 205.238.40.2 c3315.z1301.winmx.com
    O1 - Hosts: 67.18.233.36 c3316.z1301.winmx.com
    O1 - Hosts: 82.43.224.20 c3317.z1301.winmx.com
    O1 - Hosts: 209.67.209.50 c3318.z1301.winmx.com
    O1 - Hosts: 212.227.64.159 c3319.z1301.winmx.com
    O1 - Hosts: 205.238.40.2 c3310.z1302.winmx.com
    O1 - Hosts: 67.18.233.36 c3311.z1302.winmx.com
    O1 - Hosts: 82.43.224.20 c3312.z1302.winmx.com
    O1 - Hosts: 209.67.209.50 c3313.z1302.winmx.com
    O1 - Hosts: 212.227.64.159 c3314.z1302.winmx.com
    O1 - Hosts: 205.238.40.2 c3315.z1302.winmx.com
    O1 - Hosts: 67.18.233.36 c3316.z1302.winmx.com
    O1 - Hosts: 82.43.224.20 c3317.z1302.winmx.com
    O1 - Hosts: 209.67.209.50 c3318.z1302.winmx.com
    O1 - Hosts: 212.227.64.159 c3319.z1302.winmx.com
    O1 - Hosts: 82.43.224.20 c3310.z1303.winmx.com
    O1 - Hosts: 67.18.233.36 c3311.z1303.winmx.com
    O1 - Hosts: 205.238.40.2 c3312.z1303.winmx.com
    O1 - Hosts: 82.43.224.20 c3313.z1303.winmx.com
    O1 - Hosts: 67.18.233.36 c3314.z1303.winmx.com
    O1 - Hosts: 205.238.40.2 c3315.z1303.winmx.com
    O1 - Hosts: 82.43.224.20 c3316.z1303.winmx.com
    O1 - Hosts: 67.18.233.36 c3317.z1303.winmx.com
    O1 - Hosts: 205.238.40.2 c3318.z1303.winmx.com
    O1 - Hosts: 82.43.224.20 c3319.z1303.winmx.com
    O1 - Hosts: 205.238.40.2 c3310.z1304.winmx.com
    O1 - Hosts: 67.18.233.36 c3311.z1304.winmx.com
    O1 - Hosts: 82.43.224.20 c3312.z1304.winmx.com
    O1 - Hosts: 209.67.209.50 c3313.z1304.winmx.com
    O1 - Hosts: 212.227.64.159 c3314.z1304.winmx.com
    O1 - Hosts: 205.238.40.2 c3315.z1304.winmx.com
    O1 - Hosts: 67.18.233.36 c3316.z1304.winmx.com
    O1 - Hosts: 82.43.224.20 c3317.z1304.winmx.com
    O1 - Hosts: 209.67.209.50 c3318.z1304.winmx.com
    O1 - Hosts: 212.227.64.159 c3319.z1304.winmx.com
    O1 - Hosts: 205.238.40.2 c3310.z1305.winmx.com
    O1 - Hosts: 67.18.233.36 c3311.z1305.winmx.com
    O1 - Hosts: 82.43.224.20 c3312.z1305.winmx.com
    O1 - Hosts: 209.67.209.50 c3313.z1305.winmx.com
    O1 - Hosts: 212.227.64.159 c3314.z1305.winmx.com
    O1 - Hosts: 205.238.40.2 c3315.z1305.winmx.com
    O1 - Hosts: 67.18.233.36 c3316.z1305.winmx.com
    O1 - Hosts: 82.43.224.20 c3317.z1305.winmx.com
    O1 - Hosts: 209.67.209.50 c3318.z1305.winmx.com
    O1 - Hosts: 212.227.64.159 c3319.z1305.winmx.com
    O1 - Hosts: 205.238.40.2 c3310.z1306.winmx.com
    O1 - Hosts: 67.18.233.36 c3311.z1306.winmx.com
    O1 - Hosts: 82.43.224.20 c3312.z1306.winmx.com
    O1 - Hosts: 209.67.209.50 c3313.z1306.winmx.com
    O1 - Hosts: 212.227.64.159 c3314.z1306.winmx.com
    O1 - Hosts: 205.238.40.2 c3315.z1306.winmx.com
    O1 - Hosts: 67.18.233.36 c3316.z1306.winmx.com
    O1 - Hosts: 82.43.224.20 c3317.z1306.winmx.com
    O1 - Hosts: 209.67.209.50 c3318.z1306.winmx.com
    O1 - Hosts: 212.227.64.159 c3319.z1306.winmx.com
    O1 - Hosts: 205.238.40.2 c3520.z1301.winmx.com
    O1 - Hosts: 67.18.233.36 c3521.z1301.winmx.com
    O1 - Hosts: 82.43.224.20 c3522.z1301.winmx.com
    O1 - Hosts: 209.67.209.50 c3523.z1301.winmx.com
    O1 - Hosts: 212.227.64.159 c3524.z1301.winmx.com
    O1 - Hosts: 205.238.40.2 c3525.z1301.winmx.com
    O1 - Hosts: 67.18.233.36 c3526.z1301.winmx.com
    O1 - Hosts: 82.43.224.20 c3527.z1301.winmx.com
    O1 - Hosts: 209.67.209.50 c3528.z1301.winmx.com
    O1 - Hosts: 212.227.64.159 c3529.z1301.winmx.com
    O1 - Hosts: 205.238.40.2 c3520.z1302.winmx.com
    O1 - Hosts: 67.18.233.36 c3521.z1302.winmx.com
    O1 - Hosts: 82.43.224.20 c3522.z1302.winmx.com
    O1 - Hosts: 209.67.209.50 c3523.z1302.winmx.com
    O1 - Hosts: 212.227.64.159 c3524.z1302.winmx.com
    O1 - Hosts: 205.238.40.2 c3525.z1302.winmx.com
    O1 - Hosts: 67.18.233.36 c3526.z1302.winmx.com
    O1 - Hosts: 82.43.224.20 c3527.z1302.winmx.com
    O1 - Hosts: 209.67.209.50 c3528.z1302.winmx.com
    O1 - Hosts: 212.227.64.159 c3529.z1302.winmx.com
    O1 - Hosts: 205.238.40.2 c3520.z1303.winmx.com
    O1 - Hosts: 67.18.233.36 c3521.z1303.winmx.com
    O1 - Hosts: 82.43.224.20 c3522.z1303.winmx.com
    O1 - Hosts: 209.67.209.50 c3523.z1303.winmx.com
    O1 - Hosts: 212.227.64.159 c3524.z1303.winmx.com
    O1 - Hosts: 205.238.40.2 c3525.z1303.winmx.com
    O1 - Hosts: 67.18.233.36 c3526.z1303.winmx.com
    O1 - Hosts: 82.43.224.20 c3527.z1303.winmx.com
    O1 - Hosts: 209.67.209.50 c3528.z1303.winmx.com
    O1 - Hosts: 212.227.64.159 c3529.z1303.winmx.com
    O1 - Hosts: 205.238.40.2 c3520.z1304.winmx.com
    O1 - Hosts: 67.18.233.36 c3521.z1304.winmx.com
    O1 - Hosts: 82.43.224.20 c3522.z1304.winmx.com
    O1 - Hosts: 209.67.209.50 c3523.z1304.winmx.com
    O1 - Hosts: 212.227.64.159 c3524.z1304.winmx.com
    O1 - Hosts: 205.238.40.2 c3525.z1304.winmx.com
    O1 - Hosts: 67.18.233.36 c3526.z1304.winmx.com
    O1 - Hosts: 82.43.224.20 c3527.z1304.winmx.com
    O1 - Hosts: 209.67.209.50 c3528.z1304.winmx.com
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O3 - Toolbar: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll
    O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\system32\gah95on6.exe
    O4 - HKLM\..\Run: [j3op49o3] C:\WINDOWS\system32\j3op49o3.exe
    O4 - HKLM\..\Run: [pt9j36Q] nvwman.exe
    O4 - HKLM\..\Run: [smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
    O4 - HKLM\..\Run: [MediaGateway] C:\Program Files\MediaGateway\MediaGateway.exe
    O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\whSurvey.exe"
    O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"
    O4 - HKLM\..\Run: [keyboard] C:\\kybrdfg_7.exe
    O4 - HKLM\..\Run: [wGzyM6F48] C:\WINDOWS\system32\apbzk.exe
    O4 - HKLM\..\Run: [ufhqfmcA] C:\WINDOWS\ufhqfmcA.exe
    O4 - HKLM\..\Run: [wGzyM6FtT] C:\WINDOWS\system32\apbzk.exe
    O4 - HKLM\..\Run: [0a6300b7.exe] C:\WINDOWS\system32\0a6300b7.exe
    O4 - HKLM\..\RunOnce: [AAW] "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" "+b1"
    O4 - HKCU\..\Run: [YAqtRWcmi] nvnmlnka.exe
    O4 - HKCU\..\Run: [0a6300b7.exe] C:\Documents and Settings\sobrado.AOA1\Local Settings\Application Data\0a6300b7.exe
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: palstart.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
    O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
    O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
    O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
    O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted Zone: *.elitemediagroup.net
    O15 - Trusted Zone: *.sxload.com
    O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} - http://dl.filekicker.com/send/file/128985-NZIL/PhPSetup.cab
    O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MusicAccess/ie/bridge-c5.cab
    O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} - http://promo.dollarrevenue.com/activex/promocache/3138302D2D2D.exe
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by106fd.bay106.hotmail.msn.com/resources/MsnPUpld.cab
    O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} (mm06ocx.mm06ocxf) - http://cabs.elitemediagroup.net/cabs/mediaview.cab
    O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} - http://67.53.38.204//activex/AMC.cab
    O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
    O16 - DPF: {A762E064-A885-40E4-AC10-671BB62DC2B2} (OFMailHTMLCtl Class) - http://www.eomniform.com/OF5/nsplugins/OFMailX.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.pogo.com/game/deluxe/zuma/popcaploader_v6.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll
    O20 - AppInit_DLLs: C:\WINDOWS\system32\svchost.dll
    O21 - SSODL: cinnamomum - {93ac7c30-3878-4eaa-9420-7977285df5b1} - (no file)
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: ewido security suite control - ewido networks - f:\Program Files\ewido\security suite\ewidoctrl.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
    O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
    O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\ufhqfmc.exe (file missing)

    Please help
     
  2. cogent

    cogent Thread Starter

    Joined:
    Jul 31, 2006
    Messages:
    20
    Okay I think I fixed my problem. Here is my most recent logfile, hopefully I get no more pop-ups or downloaders.

    Logfile of HijackThis v1.99.1
    Scan saved at 11:12:47 PM, on 7/30/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    f:\Program Files\ewido\security suite\ewidoctrl.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ishost.exe
    C:\WINDOWS\system32\issearch.exe
    C:\WINDOWS\Mixer.exe
    C:\WINDOWS\system32\ismon.exe
    C:\Program Files\ASUS\Probe\AsusProb.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    C:\WINDOWS\MXOALDR.EXE
    C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
    F:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Winamp\winampa.exe
    F:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\WINDOWS\system32\regsvr32.exe
    C:\Documents and Settings\sobrado.AOA1\Desktop\KillBox.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\sobrado.AOA1\Desktop\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\aryxh.exe
    F3 - REG:win.ini: run=
    F2 - REG:system.ini: UserInit=userinit.exe,lmfcsyy.exe
    O1 - Hosts: 205.238.40.2 www.winmx.com
    O1 - Hosts: 205.238.40.2 err.winmx.com
    O1 - Hosts: 205.238.40.2 c3310.z1301.winmx.com
    O1 - Hosts: 67.18.233.36 c3311.z1301.winmx.com
    O1 - Hosts: 82.43.224.20 c3312.z1301.winmx.com
    O1 - Hosts: 209.67.209.50 c3313.z1301.winmx.com
    O1 - Hosts: 212.227.64.159 c3314.z1301.winmx.com
    O1 - Hosts: 205.238.40.2 c3315.z1301.winmx.com
    O1 - Hosts: 67.18.233.36 c3316.z1301.winmx.com
    O1 - Hosts: 82.43.224.20 c3317.z1301.winmx.com
    O1 - Hosts: 209.67.209.50 c3318.z1301.winmx.com
    O1 - Hosts: 212.227.64.159 c3319.z1301.winmx.com
    O1 - Hosts: 205.238.40.2 c3310.z1302.winmx.com
    O1 - Hosts: 67.18.233.36 c3311.z1302.winmx.com
    O1 - Hosts: 82.43.224.20 c3312.z1302.winmx.com
    O1 - Hosts: 209.67.209.50 c3313.z1302.winmx.com
    O1 - Hosts: 212.227.64.159 c3314.z1302.winmx.com
    O1 - Hosts: 205.238.40.2 c3315.z1302.winmx.com
    O1 - Hosts: 67.18.233.36 c3316.z1302.winmx.com
    O1 - Hosts: 82.43.224.20 c3317.z1302.winmx.com
    O1 - Hosts: 209.67.209.50 c3318.z1302.winmx.com
    O1 - Hosts: 212.227.64.159 c3319.z1302.winmx.com
    O1 - Hosts: 82.43.224.20 c3310.z1303.winmx.com
    O1 - Hosts: 67.18.233.36 c3311.z1303.winmx.com
    O1 - Hosts: 205.238.40.2 c3312.z1303.winmx.com
    O1 - Hosts: 82.43.224.20 c3313.z1303.winmx.com
    O1 - Hosts: 67.18.233.36 c3314.z1303.winmx.com
    O1 - Hosts: 205.238.40.2 c3315.z1303.winmx.com
    O1 - Hosts: 82.43.224.20 c3316.z1303.winmx.com
    O1 - Hosts: 67.18.233.36 c3317.z1303.winmx.com
    O1 - Hosts: 205.238.40.2 c3318.z1303.winmx.com
    O1 - Hosts: 82.43.224.20 c3319.z1303.winmx.com
    O1 - Hosts: 205.238.40.2 c3310.z1304.winmx.com
    O1 - Hosts: 67.18.233.36 c3311.z1304.winmx.com
    O1 - Hosts: 82.43.224.20 c3312.z1304.winmx.com
    O1 - Hosts: 209.67.209.50 c3313.z1304.winmx.com
    O1 - Hosts: 212.227.64.159 c3314.z1304.winmx.com
    O1 - Hosts: 205.238.40.2 c3315.z1304.winmx.com
    O1 - Hosts: 67.18.233.36 c3316.z1304.winmx.com
    O1 - Hosts: 82.43.224.20 c3317.z1304.winmx.com
    O1 - Hosts: 209.67.209.50 c3318.z1304.winmx.com
    O1 - Hosts: 212.227.64.159 c3319.z1304.winmx.com
    O1 - Hosts: 205.238.40.2 c3310.z1305.winmx.com
    O1 - Hosts: 67.18.233.36 c3311.z1305.winmx.com
    O1 - Hosts: 82.43.224.20 c3312.z1305.winmx.com
    O1 - Hosts: 209.67.209.50 c3313.z1305.winmx.com
    O1 - Hosts: 212.227.64.159 c3314.z1305.winmx.com
    O1 - Hosts: 205.238.40.2 c3315.z1305.winmx.com
    O1 - Hosts: 67.18.233.36 c3316.z1305.winmx.com
    O1 - Hosts: 82.43.224.20 c3317.z1305.winmx.com
    O1 - Hosts: 209.67.209.50 c3318.z1305.winmx.com
    O1 - Hosts: 212.227.64.159 c3319.z1305.winmx.com
    O1 - Hosts: 205.238.40.2 c3310.z1306.winmx.com
    O1 - Hosts: 67.18.233.36 c3311.z1306.winmx.com
    O1 - Hosts: 82.43.224.20 c3312.z1306.winmx.com
    O1 - Hosts: 209.67.209.50 c3313.z1306.winmx.com
    O1 - Hosts: 212.227.64.159 c3314.z1306.winmx.com
    O1 - Hosts: 205.238.40.2 c3315.z1306.winmx.com
    O1 - Hosts: 67.18.233.36 c3316.z1306.winmx.com
    O1 - Hosts: 82.43.224.20 c3317.z1306.winmx.com
    O1 - Hosts: 209.67.209.50 c3318.z1306.winmx.com
    O1 - Hosts: 212.227.64.159 c3319.z1306.winmx.com
    O1 - Hosts: 205.238.40.2 c3520.z1301.winmx.com
    O1 - Hosts: 67.18.233.36 c3521.z1301.winmx.com
    O1 - Hosts: 82.43.224.20 c3522.z1301.winmx.com
    O1 - Hosts: 209.67.209.50 c3523.z1301.winmx.com
    O1 - Hosts: 212.227.64.159 c3524.z1301.winmx.com
    O1 - Hosts: 205.238.40.2 c3525.z1301.winmx.com
    O1 - Hosts: 67.18.233.36 c3526.z1301.winmx.com
    O1 - Hosts: 82.43.224.20 c3527.z1301.winmx.com
    O1 - Hosts: 209.67.209.50 c3528.z1301.winmx.com
    O1 - Hosts: 212.227.64.159 c3529.z1301.winmx.com
    O1 - Hosts: 205.238.40.2 c3520.z1302.winmx.com
    O1 - Hosts: 67.18.233.36 c3521.z1302.winmx.com
    O1 - Hosts: 82.43.224.20 c3522.z1302.winmx.com
    O1 - Hosts: 209.67.209.50 c3523.z1302.winmx.com
    O1 - Hosts: 212.227.64.159 c3524.z1302.winmx.com
    O1 - Hosts: 205.238.40.2 c3525.z1302.winmx.com
    O1 - Hosts: 67.18.233.36 c3526.z1302.winmx.com
    O1 - Hosts: 82.43.224.20 c3527.z1302.winmx.com
    O1 - Hosts: 209.67.209.50 c3528.z1302.winmx.com
    O1 - Hosts: 212.227.64.159 c3529.z1302.winmx.com
    O1 - Hosts: 205.238.40.2 c3520.z1303.winmx.com
    O1 - Hosts: 67.18.233.36 c3521.z1303.winmx.com
    O1 - Hosts: 82.43.224.20 c3522.z1303.winmx.com
    O1 - Hosts: 209.67.209.50 c3523.z1303.winmx.com
    O1 - Hosts: 212.227.64.159 c3524.z1303.winmx.com
    O1 - Hosts: 205.238.40.2 c3525.z1303.winmx.com
    O1 - Hosts: 67.18.233.36 c3526.z1303.winmx.com
    O1 - Hosts: 82.43.224.20 c3527.z1303.winmx.com
    O1 - Hosts: 209.67.209.50 c3528.z1303.winmx.com
    O1 - Hosts: 212.227.64.159 c3529.z1303.winmx.com
    O1 - Hosts: 205.238.40.2 c3520.z1304.winmx.com
    O1 - Hosts: 67.18.233.36 c3521.z1304.winmx.com
    O1 - Hosts: 82.43.224.20 c3522.z1304.winmx.com
    O1 - Hosts: 209.67.209.50 c3523.z1304.winmx.com
    O1 - Hosts: 212.227.64.159 c3524.z1304.winmx.com
    O1 - Hosts: 205.238.40.2 c3525.z1304.winmx.com
    O1 - Hosts: 67.18.233.36 c3526.z1304.winmx.com
    O1 - Hosts: 82.43.224.20 c3527.z1304.winmx.com
    O1 - Hosts: 209.67.209.50 c3528.z1304.winmx.com
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\system32\gah95on6.exe
    O4 - HKLM\..\Run: [j3op49o3] C:\WINDOWS\system32\j3op49o3.exe
    O4 - HKLM\..\Run: [pt9j36Q] nvwman.exe
    O4 - HKLM\..\Run: [smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
    O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\clbcatix.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\clbcatix.dll
    O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\clbcatix.dll
    O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\clbcatix.dll
    O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
    O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
    O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by106fd.bay106.hotmail.msn.com/resources/MsnPUpld.cab
    O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} - http://67.53.38.204//activex/AMC.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.pogo.com/game/deluxe/zuma/popcaploader_v6.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll
    O20 - AppInit_DLLs: C:\WINDOWS\system32\svchost.dll
    O21 - SSODL: cinnamomum - {93ac7c30-3878-4eaa-9420-7977285df5b1} - (no file)
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: ewido security suite control - ewido networks - f:\Program Files\ewido\security suite\ewidoctrl.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
    O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
    O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\ufhqfmc.exe (file missing)
     
  3. Cookiegal

    Cookiegal Administrator Malware Specialist Coordinator

    Joined:
    Aug 27, 2003
    Messages:
    112,034
    Hi and welcome to TSG,

    Please move HijackThis out of the Temporary files and into a separate folder of its own in program files, so that it can function properly and create back-ups which can be restored, if necessary and then post a new log.
     
  4. cogent

    cogent Thread Starter

    Joined:
    Jul 31, 2006
    Messages:
    20
    Logfile of HijackThis v1.99.1
    Scan saved at 5:52:21 PM, on 7/31/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    f:\Program Files\ewido\security suite\ewidoctrl.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ASUS\Probe\AsusProb.exe
    C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    C:\WINDOWS\MXOALDR.EXE
    C:\WINDOWS\system32\rundll32.exe
    F:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Winamp\winampa.exe
    F:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Documents and Settings\sobrado.AOA1\Desktop\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\aryxh.exe
    F2 - REG:system.ini: UserInit=userinit.exe,lmfcsyy.exe
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [pt9j36Q] nvwman.exe
    O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\clbcatix.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\clbcatix.dll
    O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\clbcatix.dll
    O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\clbcatix.dll
    O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
    O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
    O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by106fd.bay106.hotmail.msn.com/resources/MsnPUpld.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll
    O20 - AppInit_DLLs: C:\WINDOWS\system32\svchost.dll
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: ewido security suite control - ewido networks - f:\Program Files\ewido\security suite\ewidoctrl.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
    O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
     
  5. Cookiegal

    Cookiegal Administrator Malware Specialist Coordinator

    Joined:
    Aug 27, 2003
    Messages:
    112,034
    Please download Qoofix by Rubber Ducky to your desktop.
    • Right click on the Qoofix folder, and choose "Extract All". Extract Qoofix to your C: drive
    • Close all windows and programs, including internet windows.
    • Go to C:\Qoofix and open the folder, then double click on Qoofix.exe
    • Click Begin Removal and wait for the scan to finish
    • If Qoofix finds an infection, select yes to restart your computer
    • You will now find a log from this tool, located at C:\Qoofix\Qoofix Logfile.txt Copy and paste the contents of that report into your next reply here.


    Download the trial version of Ewido Anti-spyware from HERE and save that file to your desktop. When the trial period expires it becomes freeware with reduced functions but still worth keeping.



    • Once you have downloaded Ewido Anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
    • Once the setup is complete you will need run Ewido and update the definition files.
    • On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
    • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
    • Once in the Settings screen click on "Recommended actions" and then select "Quarantine"
    • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"

    Close Ewido Anti-spyware, Do NOT run a scan yet. We will do that later in safe mode.


    • Reboot your computer into Safe Mode now. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.
      IMPORTANT: Do not open any other windows or programs while Ewido is scanning as it may interfere with the scanning process:
    • Launch Ewido Anti-spyware by double-clicking the icon on your desktop.
    • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
    • Ewido will now begin the scanning process. Be patient this may take a little time.
      Once the scan is complete do the following:
    • If you have any infections you will prompted, then select "Apply all actions"
    • Next select the "Reports" icon at the top.
    • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
    • Close Ewido and reboot your system back into Normal Mode.


    Please go HERE to run Panda's ActiveScan
    • Once you are on the Panda site click the Scan your PC button
    • A new window will open...click the Check Now button
    • Enter your Country
    • Enter your State/Province
    • Enter your e-mail address and click send
    • Select either Home User or Company
    • Click the big Scan Now button
    • If it wants to install an ActiveX component allow it
    • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    • When download is complete, click on My Computer to start the scan
    • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report


    Come back here and post a new HijackThis log along with the logs from the Ewido and Panda scans.
     
  6. cogent

    cogent Thread Starter

    Joined:
    Jul 31, 2006
    Messages:
    20
    ---------------------------------------------------------
    ewido anti-spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 9:25:33 PM 7/31/2006

    + Scan result:



    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063498.exe -> Adware.Agent : No action taken.
    C:\FOUND.000\FILE0078.CHK -> Adware.CommAd : No action taken.
    C:\FOUND.000\FILE0080.CHK -> Adware.CommAd : No action taken.
    HKLM\SOFTWARE\Classes\CLSID\{873eb32d-ae1a-4183-89bd-45a77f761be4} -> Adware.Generic : No action taken.
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{873eb32d-ae1a-4183-89bd-45a77f761be4} -> Adware.Generic : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063479.exe -> Adware.MediaMotor : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063546.exe -> Adware.MediaTicket : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063507.exe -> Adware.MediaTickets : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063483.dll -> Adware.Mirar : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063484.dll -> Adware.Mirar : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063486.exe -> Adware.Mirar : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063505.dll -> Adware.Mirar : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063485.exe -> Adware.NetNucleus : No action taken.
    C:\FOUND.000\FILE0092.CHK -> Adware.PurityScan : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063500.exe -> Adware.SearchAssistant : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063502.exe -> Adware.SearchAssistant : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063515.exe -> Adware.SearchAssistant : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063520.exe -> Adware.SearchAssistant : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063565.exe -> Adware.SearchAssistant : No action taken.
    C:\WINDOWS\system32afdaqd3.exe -> Adware.SearchAssistant : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063697.dll -> Adware.Softomate : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063499.exe -> Adware.Suggestor : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063501.exe -> Adware.Suggestor : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063504.exe -> Adware.Suggestor : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063506.exe -> Adware.Suggestor : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063513.exe -> Adware.Suggestor : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063521.exe -> Adware.Suggestor : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063523.dll -> Adware.Suggestor : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063724.exe -> Adware.Suggestor : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063726.dll -> Adware.Suggestor : No action taken.
    C:\WINDOWS\SYSTEM32\y3aqsoepa.exe -> Adware.Suggestor : No action taken.
    C:\FOUND.000\FILE0055.CHK -> Adware.SurfSide : No action taken.
    C:\Documents and Settings\sobrado.AOA1\Local Settings\Temp\temp.frA5B6\Programs\__delete_on_reboot__webhdll.dll -> Adware.WebHancer : No action taken.
    C:\FOUND.000\FILE0026.CHK -> Adware.WebHancer : No action taken.
    C:\FOUND.000\FILE0027.CHK -> Adware.WebHancer : No action taken.
    C:\FOUND.000\FILE0028.CHK -> Adware.WebHancer : No action taken.
    C:\FOUND.000\FILE0030.CHK -> Adware.WebHancer : No action taken.
    C:\FOUND.000\FILE0031.CHK -> Adware.WebHancer : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063438.exe -> Adware.WebHancer : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063441.dll -> Adware.WebHancer : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063444.dll -> Adware.WebHancer : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063458.exe -> Adware.WebHancer : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063477.dll -> Adware.WebHancer : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063488.exe/WhAgent.exe -> Adware.WebHancer : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063495.exe -> Adware.WebHancer : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063518.dll -> Adware.WebHancer : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063412.exe -> Backdoor.Small : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063413.exe -> Backdoor.Small : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063587.exe -> Downloader.Adload.de : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063700.exe -> Downloader.Adload.de : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063522.dll -> Downloader.Agent.agw : No action taken.
    C:\!KillBox\fym9bvo.exe -> Downloader.Agent.ala : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063508.exe -> Downloader.Agent.ala : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063592.exe -> Downloader.Agent.ala : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063489.exe -> Downloader.Dyfuca.ei : No action taken.
    C:\Documents and Settings\Stephanie\Local Settings\Application Data\0a6300b7.exe -> Downloader.Obfuscated.a : No action taken.
    C:\Documents and Settings\sobrado.AOA1\Local Settings\Application Data\0a6300b7.exe -> Downloader.Obfuscated.a : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063422.exe -> Downloader.Obfuscated.a : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063450.exe -> Downloader.Obfuscated.a : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063524.exe -> Downloader.Obfuscated.a : No action taken.
    C:\WINDOWS\SYSTEM32\0a6300b7.exe -> Downloader.Obfuscated.a : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063549.exe -> Downloader.PurityScan.cq : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063411.exe -> Downloader.Qoologic.at : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063519.dll -> Downloader.Qoologic.bj : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063535.EXE -> Downloader.Qoologic.bj : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063685.exe -> Downloader.Qoologic.bj : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063696.exe -> Downloader.Small.ajc : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063492.exe -> Downloader.Small.buy : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063482.dll -> Downloader.Small.ctp : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063493.exe -> Downloader.TSUpdate.o : No action taken.
    C:\FOUND.000\FILE0071.CHK -> Downloader.VB.aga : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063414.exe -> Downloader.VB.aga : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063487.exe -> Downloader.VB.nw : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063511.exe -> Downloader.VB.tw : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063497.exe -> Downloader.VB.wz : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063593.exe -> Dropper.Agent.aie : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063686.EXE -> Dropper.Agent.aie : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063490.exe -> Dropper.Small.qn : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063755.dll -> Hijacker.Agent.ct : No action taken.
    HKLM\SOFTWARE\Classes\CLSID\{D4DFC1D8-2D2E-4962-B0D0-389FBA0F76B5} -> Hijacker.Generic : No action taken.
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4DFC1D8-2D2E-4962-B0D0-389FBA0F76B5} -> Hijacker.Generic : No action taken.
    C:\FOUND.000\FILE0060.CHK -> Hijacker.Small : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063690.exe -> Hijacker.Small : No action taken.
    C:\FOUND.000\FILE0004.CHK -> Hijacker.Small.jf : No action taken.
    C:\FOUND.000\FILE0005.CHK -> Hijacker.Small.jf : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063480.exe -> Hijacker.VB.ij : No action taken.
    C:\!KillBox\dfndrfg_7.exe -> Hijacker.VB.ly : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063588.exe -> Hijacker.VB.ly : No action taken.
    C:\FOUND.000\FILE0024.CHK -> Not-A-Virus.Downloader.Win32.WinFixer.l : No action taken.
    C:\FOUND.000\FILE0025.CHK -> Not-A-Virus.Downloader.Win32.WinFixer.l : No action taken.
    C:\FOUND.000\FILE0079.CHK -> Not-A-Virus.Downloader.Win32.WinFixer.l : No action taken.
    C:\FOUND.000\FILE0087.CHK -> Not-A-Virus.Downloader.Win32.WinFixer.l : No action taken.
    C:\Documents and Settings\sobrado.AOA1\Application Data\winantiviruspro2006freeinstall[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
    C:\FOUND.000\FILE0000.CHK -> Not-A-Virus.Hoax.Win32.Renos.dw : No action taken.
    C:\FOUND.000\FILE0051.CHK -> Not-A-Virus.Hoax.Win32.Renos.dw : No action taken.
    C:\FOUND.000\FILE0083.CHK -> Not-A-Virus.Monitor.Win32.NetMon.a : No action taken.
    C:\Documents and Settings\sobrado.AOA1\Cookies\[email protected][2].txt -> TrackingCookie.Statcounter : No action taken.
    C:\Documents and Settings\sobrado.AOA1\Local Settings\Temporary Internet Files\Content.IE5\8TEVCLMV\bgates[1].exe -> Trojan.Dialer.pz : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063509.exe -> Trojan.Qoologic : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063728.exe -> Trojan.Starter.65 : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063503.exe -> Trojan.VB.tg : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063510.exe -> Trojan.VB.tg : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063512.exe -> Trojan.VB.tg : No action taken.
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063514.exe -> Trojan.VB.tg : No action taken.


    ::Report end

    -------------------------------------------------------------------------------------------
    Panda scan:




    Incident Status Location

    Adware:adware/ncase Not disinfected c:\temp\salm_kyf.dat
    Adware:adware/mediatickets Not disinfected C:\WINDOWS\system32\oins.exe
    Adware:adware/bravesentry Not disinfected c:\windows\wallpap.exe
    Dialer:dialer generic Not disinfected c:\program files\dialers
    Adware:adware/imgiant Not disinfected c:\program files\joystick networks
    Spyware:spyware/betterinet Not disinfected Windows Registry
    Adware:adware/miamore Not disinfected Windows Registry
    Adware:adware/commad Not disinfected Windows Registry
    Adware:adware/clicker.b Not disinfected Windows Registry
    Adware:adware/transponder Not disinfected Windows Registry
    Adware:adware/exact.bargainbuddy Not disinfected Windows Registry
    Adware:adware/dyfuca Not disinfected Windows Registry
    Adware:adware/ist.sidefind Not disinfected Windows Registry
    Adware:adware/webhancer Not disinfected Windows Registry
    Adware:adware/ist.istbar Not disinfected Windows Registry
    Spyware:spyware/media-motor Not disinfected Windows Registry
    Spyware:spyware/adclicker Not disinfected Windows Registry
    Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\SYSTEM32\Process.exe
    Adware:Adware/SystemDoctor Not disinfected C:\WINDOWS\SYSTEM32\0a6300b7.exe
    Dialer:Dialer.HLD Not disinfected C:\WINDOWS\SYSTEM32\cool.exe
    Adware:Adware/SystemDoctor Not disinfected C:\WINDOWS\SYSTEM32\cea7f071.exe
    Spyware:Spyware/Virtumonde Not disinfected C:\Program Files\Common Files\{0B3B16EB-0709-1033-0806-031127030001}\services.dll
    Spyware:Spyware/SafeSurf Not disinfected C:\Program Files\EvilLyrics\updateEL.exe[²=\ExtractDLL.dll]



    -------------------------------------------------------------------------------------------
    New HJT logfile

    Logfile of HijackThis v1.99.1
    Scan saved at 10:16:51 PM, on 8/1/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    f:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\WINDOWS\System32\nvsvc32.exe
    f:\Program Files\Spyware Doctor\sdhelp.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ASUS\Probe\AsusProb.exe
    C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    C:\WINDOWS\MXOALDR.EXE
    F:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
    F:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Documents and Settings\sobrado.AOA1\My Documents\hijack this\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
    O4 - HKLM\..\Run: [ASUS Probe] "C:\Program Files\ASUS\Probe\AsusProb.exe"
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\clbcatix.dll (file missing)
    O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
    O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
    O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {00000000-0000-0000-0000-100005000004} - http://code.jcash.biz/l/a4a1cd41c1dcd03d49961b6dc58a6cd9_13.exe
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by106fd.bay106.hotmail.msn.com/resources/MsnPUpld.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - f:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
    O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - f:\Program Files\Spyware Doctor\sdhelp.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
     
  7. Cookiegal

    Cookiegal Administrator Malware Specialist Coordinator

    Joined:
    Aug 27, 2003
    Messages:
    112,034
    Run Ewido again and follow the instructions posted carefully so that it quarantines the items found and then post the new scan log please.
     
  8. cogent

    cogent Thread Starter

    Joined:
    Jul 31, 2006
    Messages:
    20
    ---------------------------------------------------------
    ewido anti-spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 8:55:00 PM 8/3/2006

    + Scan result:



    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063498.exe -> Adware.Agent : Cleaned with backup (quarantined).
    C:\FOUND.000\FILE0078.CHK -> Adware.CommAd : Cleaned with backup (quarantined).
    C:\FOUND.000\FILE0080.CHK -> Adware.CommAd : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\CLSID\{873eb32d-ae1a-4183-89bd-45a77f761be4} -> Adware.Generic : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{873eb32d-ae1a-4183-89bd-45a77f761be4} -> Adware.Generic : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063479.exe -> Adware.MediaMotor : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063546.exe -> Adware.MediaTicket : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063507.exe -> Adware.MediaTickets : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063483.dll -> Adware.Mirar : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063484.dll -> Adware.Mirar : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063486.exe -> Adware.Mirar : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063505.dll -> Adware.Mirar : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063485.exe -> Adware.NetNucleus : Cleaned with backup (quarantined).
    C:\FOUND.000\FILE0092.CHK -> Adware.PurityScan : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063500.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063502.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063515.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063520.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063565.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
    C:\WINDOWS\system32afdaqd3.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063697.dll -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063499.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063501.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063504.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063506.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063513.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063521.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063523.dll -> Adware.Suggestor : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063724.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063726.dll -> Adware.Suggestor : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\y3aqsoepa.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
    C:\FOUND.000\FILE0055.CHK -> Adware.SurfSide : Cleaned with backup (quarantined).
    C:\FOUND.000\FILE0026.CHK -> Adware.WebHancer : Cleaned with backup (quarantined).
    C:\FOUND.000\FILE0028.CHK -> Adware.WebHancer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063438.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063441.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063444.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063458.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063477.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063488.exe/WhAgent.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063495.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063518.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063412.exe -> Backdoor.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063413.exe -> Backdoor.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063587.exe -> Downloader.Adload.de : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063700.exe -> Downloader.Adload.de : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063522.dll -> Downloader.Agent.agw : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063508.exe -> Downloader.Agent.ala : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063592.exe -> Downloader.Agent.ala : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0065784.exe -> Downloader.Agent.ala : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063489.exe -> Downloader.Dyfuca.ei : Cleaned with backup (quarantined).
    C:\Documents and Settings\sobrado.AOA1\Local Settings\Application Data\0a6300b7.exe -> Downloader.Obfuscated.a : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063422.exe -> Downloader.Obfuscated.a : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063450.exe -> Downloader.Obfuscated.a : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063524.exe -> Downloader.Obfuscated.a : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0064781.exe -> Downloader.Obfuscated.a : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\0a6300b7.exe -> Downloader.Obfuscated.a : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063549.exe -> Downloader.PurityScan.cq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063411.exe -> Downloader.Qoologic.at : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063519.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063535.EXE -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063685.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063696.exe -> Downloader.Small.ajc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063492.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
    C:\Documents and Settings\Stephanie\Local Settings\Temp\Rar$EX00.703\patch.exe -> Downloader.Small.bwy : Cleaned with backup (quarantined).
    C:\Documents and Settings\Stephanie\Local Settings\Temporary Internet Files\Content.IE5\2NYZEBOL\Spyware Doctor 4[1].0.rar/patch.exe -> Downloader.Small.bwy : Cleaned with backup (quarantined).
    C:\Documents and Settings\Stephanie\Local Settings\Temporary Internet Files\Content.IE5\S9E74PIR\13[1].exe -> Downloader.Small.bwy : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063482.dll -> Downloader.Small.ctp : Cleaned with backup (quarantined).
    C:\Documents and Settings\Stephanie\Local Settings\Temp\Rar$EX00.703\keygen.exe -> Downloader.Small.dib : Cleaned with backup (quarantined).
    C:\Documents and Settings\Stephanie\Local Settings\Temporary Internet Files\Content.IE5\2NYZEBOL\Spyware Doctor 4[1].0.rar/keygen.exe -> Downloader.Small.dib : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063493.exe -> Downloader.TSUpdate.o : Cleaned with backup (quarantined).
    C:\FOUND.000\FILE0071.CHK -> Downloader.VB.aga : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063414.exe -> Downloader.VB.aga : Cleaned with backup (quarantined).
    C:\Documents and Settings\Stephanie\Local Settings\Temp\Rar$EX00.703\crack.exe -> Downloader.VB.aiw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Stephanie\Local Settings\Temporary Internet Files\Content.IE5\2NYZEBOL\Spyware Doctor 4[1].0.rar/crack.exe -> Downloader.VB.aiw : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063487.exe -> Downloader.VB.nw : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063511.exe -> Downloader.VB.tw : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063497.exe -> Downloader.VB.wz : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063418.exe -> Downloader.Zlob.abj : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063432.exe -> Downloader.Zlob.abj : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063448.exe -> Downloader.Zlob.abj : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063532.exe -> Downloader.Zlob.abj : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063542.exe -> Downloader.Zlob.abj : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063577.exe -> Downloader.Zlob.abj : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063600.exe -> Downloader.Zlob.abj : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063639.exe -> Downloader.Zlob.abj : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063640.exe -> Downloader.Zlob.abj : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063593.exe -> Dropper.Agent.aie : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063686.EXE -> Dropper.Agent.aie : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063490.exe -> Dropper.Small.qn : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063755.dll -> Hijacker.Agent.ct : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\CLSID\{D4DFC1D8-2D2E-4962-B0D0-389FBA0F76B5} -> Hijacker.Generic : Cleaned with backup (quarantined).
    C:\FOUND.000\FILE0060.CHK -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063690.exe -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\FOUND.000\FILE0004.CHK -> Hijacker.Small.jf : Cleaned with backup (quarantined).
    C:\FOUND.000\FILE0005.CHK -> Hijacker.Small.jf : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063480.exe -> Hijacker.VB.ij : Cleaned with backup (quarantined).
    C:\!KillBox\dfndrfg_7.exe -> Hijacker.VB.ly : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063588.exe -> Hijacker.VB.ly : Cleaned with backup (quarantined).
    C:\FOUND.000\FILE0024.CHK -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
    C:\FOUND.000\FILE0025.CHK -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
    C:\FOUND.000\FILE0079.CHK -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
    C:\FOUND.000\FILE0087.CHK -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0065783.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0065781.exe -> Not-A-Virus.Hoax.Win32.Renos.bw : Cleaned with backup (quarantined).
    C:\FOUND.000\FILE0000.CHK -> Not-A-Virus.Hoax.Win32.Renos.dw : Cleaned with backup (quarantined).
    C:\FOUND.000\FILE0051.CHK -> Not-A-Virus.Hoax.Win32.Renos.dw : Cleaned with backup (quarantined).
    C:\FOUND.000\FILE0083.CHK -> Not-A-Virus.Monitor.Win32.NetMon.a : Cleaned with backup (quarantined).
    C:\Documents and Settings\sobrado.AOA1\Cookies\[email protected][2].txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    C:\Documents and Settings\sobrado.AOA1\Cookies\[email protected][2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
    C:\Documents and Settings\sobrado.AOA1\Cookies\[email protected][1].txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
    C:\Documents and Settings\sobrado.AOA1\Cookies\[email protected][2].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    C:\Documents and Settings\sobrado.AOA1\Cookies\[email protected][2].txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063624.exe -> Trojan.Dialer.qs : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063683.exe -> Trojan.Dialer.qs : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063721.exe -> Trojan.Dialer.qs : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\cool.exe -> Trojan.Dialer.qs : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063509.exe -> Trojan.Qoologic : Cleaned with backup (quarantined).
    C:\Documents and Settings\Stephanie\Local Settings\Temporary Internet Files\Content.IE5\S9E74PIR\cavhgzwsyt[1].txt -> Trojan.Sinowal.ae : Cleaned with backup (quarantined).
    C:\whcrk.exe -> Trojan.Sinowal.ae : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0065780.exe -> Trojan.Sinowal.ai : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063728.exe -> Trojan.Starter.65 : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063503.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063510.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063512.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{66444101-8415-4B39-A0BE-8EA0C351F312}\RP469\A0063514.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).


    ::Report end




    Logfile of HijackThis v1.99.1
    Scan saved at 9:46:24 PM, on 8/3/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    f:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\nvsvc32.exe
    f:\Program Files\Spyware Doctor\sdhelp.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\ASUS\Probe\AsusProb.exe
    C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    C:\WINDOWS\MXOALDR.EXE
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\system32\rundll32.exe
    F:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    F:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Documents and Settings\sobrado.AOA1\My Documents\hijack this\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
    O4 - HKLM\..\Run: [ASUS Probe] "C:\Program Files\ASUS\Probe\AsusProb.exe"
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\clbcatix.dll (file missing)
    O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
    O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
    O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {00000000-0000-0000-0000-100005000004} - http://code.jcash.biz/l/a4a1cd41c1dcd03d49961b6dc58a6cd9_13.exe
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by106fd.bay106.hotmail.msn.com/resources/MsnPUpld.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - f:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
    O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - f:\Program Files\Spyware Doctor\sdhelp.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
     
  9. Cookiegal

    Cookiegal Administrator Malware Specialist Coordinator

    Joined:
    Aug 27, 2003
    Messages:
    112,034
    • Click Start - Control Panel - Add/Remove Programs
    • In the list of installed software, look for PuritySCAN By OIN, Cowabanga, OuterInfo, OIN or similar
    • If you find it:
      • Click on it and click Remove.
      • Reboot and delete the folder C:\Program Files\PurityScan (if it's still there).
    • If not:




    Please download Brute Force Uninstaller to your desktop.
    • Right click the BFU folder on your desktop, and choose Extract All
    • Click "Next"
    • In the box to choose where to extract the files to,
    • Click "Browse"
    • Click on the + sign next to "My Computer"
    • Click on "Local Disk (C: or whatever your primary drive is)
    • Click "Make New Folder"
    • Type in BFU
    • Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".
    RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target As") in order to download Alcra PLUS Remover.
    Save it in the same folder you made earlier (c:\BFU).

    Do not do anything with this yet!

    Reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping F8 until a menu appears. Highlight Safe Mode and hit enter.


    Then, please go to Start > My Computer and navigate to the C:\BFU folder.
    • Start the Brute Force Uninstaller by doubleclicking BFU.exe
    • Behind the scriptline to execute field click the folder icon [​IMG] and select alcanshorty.bfu
    • Press Execute and let the program do its job. (You ought to see a progress bar if you did this correctly.)
    • Wait for the complete script execution box to pop up and press OK.
    • Press exit to terminate the BFU program.
    Reboot into normal windows.


    Reboot and post a new HijackThis log please.
     
  10. cogent

    cogent Thread Starter

    Joined:
    Jul 31, 2006
    Messages:
    20
    Logfile of HijackThis v1.99.1
    Scan saved at 6:25:23 PM, on 8/4/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    f:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ASUS\Probe\AsusProb.exe
    C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\MXOALDR.EXE
    F:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
    F:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
    C:\Documents and Settings\sobrado.AOA1\My Documents\hijack this\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
    O4 - HKLM\..\Run: [ASUS Probe] "C:\Program Files\ASUS\Probe\AsusProb.exe"
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
    O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
    O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - f:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
     
  11. cogent

    cogent Thread Starter

    Joined:
    Jul 31, 2006
    Messages:
    20
    what is wuauclt.exe and how do I get rid of it?
     
  12. cogent

    cogent Thread Starter

    Joined:
    Jul 31, 2006
    Messages:
    20
    Logfile of HijackThis v1.99.1
    Scan saved at 1:40:19 AM, on 8/5/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    f:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\WINDOWS\system32\rundll32.exe
    F:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
    F:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
    C:\Documents and Settings\sobrado.AOA1\My Documents\hijack this\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: (no name) - {A4F94C0C-54A7-4DB1-9AF3-B22E63D00310} - C:\WINDOWS\system32\compstuid.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - f:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe


    Does it look ok now?
     
  13. Cookiegal

    Cookiegal Administrator Malware Specialist Coordinator

    Joined:
    Aug 27, 2003
    Messages:
    112,034
    Download win32delfkil.exe.
    Save it on your desktop.

    Double click on win32delfkil.exe and install it. This creates a new folder on your desktop: win32delfkil.

    Close all windows then open the win32delfkil folder and double click on fix.bat. The computer will reboot automatically.

    Post the contents of the log file c:\windelf.txt, along with a new HijackThis log.
     
  14. cogent

    cogent Thread Starter

    Joined:
    Jul 31, 2006
    Messages:
    20
    ************************
    * WIN32DELFKIL LOGFILE *
    ************************
    by Marckie


    BEFORE RUNNING WIN32DELFKIL
    ***************************

    File(s) found in Windows directory
    ----------------------------------

    File(s) found in system32 folder
    --------------------------------
    compstuid.dll

    Export SharedTaskScheduler key
    ------------------------------
    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
    "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"



    Notify key
    ----------



    AFTER RUNNING WIN32DELFKIL
    **************************

    File(s) found in Windows directory
    ----------------------------------

    File(s) found in system32 folder
    --------------------------------
    Export SharedTaskScheduler key
    ------------------------------
    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
    "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"



    Notify key
    ----------


    Logfile of HijackThis v1.99.1
    Scan saved at 9:18:52 PM, on 8/5/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    f:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\WINDOWS\Explorer.EXE
    F:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Winamp\winampa.exe
    F:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Documents and Settings\sobrado.AOA1\My Documents\hijack this\HijackThis.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Webroot\Spy Sweeper\SSU.EXE

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - f:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
     
  15. Cookiegal

    Cookiegal Administrator Malware Specialist Coordinator

    Joined:
    Aug 27, 2003
    Messages:
    112,034
    The HijackThis log looks fine but there are some files that were found by Panda that need to be deleted so please do this:


    Click Here and download Killbox and save it to your desktop but don’t run it yet.


    Then boot to safe mode:


    How to restart to safe mode


    Double-click on Killbox.exe to run it.
    • Put a tick by Standard File Kill.
    • In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time:

      c:\temp\salm_kyf.dat

      C:\WINDOWS\system32\oins.exe

      c:\windows\wallpap.exe

      c:\program files\dialers

      c:\program files\joystick networks

      C:\WINDOWS\SYSTEM32\0a6300b7.exe

      C:\WINDOWS\SYSTEM32\cool.exe

      C:\WINDOWS\SYSTEM32\cea7f071.exe

      C:\Program Files\Common Files\{0B3B16EB-0709-1033-0806-031127030001}

      C:\Program Files\EvilLyrics\updateEL.exe


    • Click on the button that has the red circle with the X in the middle after you enter each file.
    • It will ask for confirmation to delete the file.
    • Click Yes.
    • Continue with that procedure until you have pasted all of these in the "Paste Full Path of File to Delete" box.
    • Killbox may tell you that one or more files do not exist.
    • If that happens, just continue on with all the files. Be sure you don't miss any.
    • Next in Killbox go to Tools > Delete Temp Files
    • In the window that pops up, put a check by ALL the options there except these three:
      • XP Prefetch
      • Recent
      • History
    • Now click the Delete Selected Temp Files button.
    • Exit the Killbox.


    Also, to be thorough, I'd like to see a WinpFind log please.

    Download WinPFind
    • Right Click the Zip Folder and Select "Extract All"
    • Extract it somewhere you will remember like the Desktop
    • Don’t do anything with it yet!


    Click here for info on how to boot to safe mode if you don't already know how.


    Reboot into Safe Mode.


    Double click WinPFind.exe
    • Click "Start Scan"
    • It will scan the entire System, so please be patient and let it complete.


    Reboot back to Normal Mode!


    • Go to the WinPFind folder
    • Locate WinPFind.txt
    • Copy and paste WinPFind.txt in your next post here please.
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/488003

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice