1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

IE7 pages turn to invalid and goes into www./// --- MY Girl is pissed!!!

Discussion in 'Virus & Other Malware Removal' started by gardnesm, Mar 10, 2008.

Thread Status:
Not open for further replies.
Advertisement
  1. gardnesm

    gardnesm Thread Starter

    Joined:
    Mar 10, 2008
    Messages:
    3
    So I decided to help out my GF's computer situation and completely backfired. She was able to view pages on IE6 but was a little slow, but not painstakingly. I install IE 7 with no problems and then decided to Install/run - Ad Ware 2007 and Spybot for the 1st time. I realized that she didn't have an up to date virus protection so I went out and installed Norton 2007 anti-virus.

    After running all of those, I have encountered several problems.

    The IE7 will go to a webpage and then within seconds say "the page is not valid" with a /// URL link.

    Anways...here is the Latest Hijackthis Log.

    I appreciate all the feed back.

    (meanwhile, I am using my other computer at my home to access all research)

    Thanks in Advance!

    BTW...I tinkered with the Hijack this a couple of times right before I post this most recent log.

    ----------------------------------------------
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:20:10 AM, on 3/10/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16608)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
    C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
    C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
    C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\ykcabjsv.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [DwlClient] c:\Program Files\Common Files\Dell\EUSW\Support.exe
    O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
    O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
    O4 - HKLM\..\Run: [BMefea52d2] Rundll32.exe "C:\WINDOWS\system32\qhodcmaw.dll",s
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: MEMonitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: Open with WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O20 - Winlogon Notify: moejtawr - C:\WINDOWS\SYSTEM32\moejtawr.dll
    O20 - Winlogon Notify: ntxqdgge - C:\WINDOWS\SYSTEM32\ntxqdgge.dll
    O20 - Winlogon Notify: ydrmekwj - C:\WINDOWS\SYSTEM32\ydrmekwj.dll
    O20 - Winlogon Notify: ykcabjsv - C:\WINDOWS\SYSTEM32\ykcabjsv.dll
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\WINDOWS\system32\windows
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

    --
    End of file - 6993 bytes
     
  2. Sponsor

  3. Cheeseball81

    Cheeseball81 Retired Moderator

    Joined:
    Mar 3, 2004
    Messages:
    84,315
  4. gardnesm

    gardnesm Thread Starter

    Joined:
    Mar 10, 2008
    Messages:
    3
    Here is the combo fix run log. It took me this long to get back to her place so now here is the log.

    Thanks





    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\check_LSA7.txt
    C:\Documents and Settings\Jennifer Gregoire\Application Data\WNSXS~1
    C:\Documents and Settings\Jennifer Gregoire\My Documents\PPATCH~1
    C:\Program Files\myglobalsearch
    C:\Temp\1cb
    C:\Temp\1cb\syscheck.log
    C:\Temp\fse
    C:\Temp\fse\tmpZTF.log
    C:\Temp\sanR24
    C:\Temp\sanR24\lDii.log
    C:\Temp\xOe
    C:\Temp\xOe\tOasF.log
    C:\WINDOWS\BMefea52d2.xml
    C:\WINDOWS\cookies.ini
    C:\WINDOWS\pskt.ini
    C:\WINDOWS\SYSTEM32\bapjnpsg.ini
    C:\WINDOWS\SYSTEM32\bbtmpixe.ini
    C:\WINDOWS\SYSTEM32\bcbeg.bak1
    C:\WINDOWS\SYSTEM32\bcbeg.ini
    C:\WINDOWS\SYSTEM32\bcbeg.ini2
    C:\WINDOWS\SYSTEM32\bcbeg.tmp
    C:\WINDOWS\SYSTEM32\bluwiqya.ini
    C:\WINDOWS\SYSTEM32\brngbmhb.ini
    C:\WINDOWS\SYSTEM32\cnxtaewt.ini
    C:\WINDOWS\system32\drivers\fad.sys
    C:\WINDOWS\system32\drivers\npf.sys
    C:\WINDOWS\SYSTEM32\dwuqkpie.ini
    C:\WINDOWS\SYSTEM32\eftfxfqt.ini
    C:\WINDOWS\SYSTEM32\eofjlcrs.ini
    C:\WINDOWS\system32\ephfxlmw.dll
    C:\WINDOWS\system32\exipmtbb.dll
    C:\WINDOWS\SYSTEM32\exkbmewp.ini
    C:\WINDOWS\SYSTEM32\eydcyybk.ini
    C:\WINDOWS\SYSTEM32\fpbuseah.ini
    C:\WINDOWS\SYSTEM32\gaxpyxmp.ini
    C:\WINDOWS\system32\gkbelyix.dll
    C:\WINDOWS\system32\grvqbrwi.dll
    C:\WINDOWS\system32\gtbppvew.dll
    C:\WINDOWS\system32\hqixwvgd.dll
    C:\WINDOWS\system32\iDlo01
    C:\WINDOWS\SYSTEM32\irqcyaal.ini
    C:\WINDOWS\system32\laaycqri.dll
    C:\WINDOWS\system32\moejtawr.dll
    C:\WINDOWS\SYSTEM32\mpolguiw.ini
    C:\WINDOWS\system32\nbpuvgpi.dll
    C:\WINDOWS\system32\ntxqdgge.dll
    C:\WINDOWS\system32\ouaqwnxg.dll
    C:\WINDOWS\system32\oxnfarbj.dll
    C:\WINDOWS\system32\pac.txt
    C:\WINDOWS\system32\packet.dll
    C:\WINDOWS\SYSTEM32\pqstv.ini
    C:\WINDOWS\SYSTEM32\pqstv.ini2
    C:\WINDOWS\system32\pthreadVC.dll
    C:\WINDOWS\SYSTEM32\rsvywlum.ini
    C:\WINDOWS\SYSTEM32\rtstv.bak1
    C:\WINDOWS\SYSTEM32\rtstv.bak2
    C:\WINDOWS\SYSTEM32\rtstv.ini
    C:\WINDOWS\SYSTEM32\rtstv.ini2
    C:\WINDOWS\SYSTEM32\rtstv.tmp
    C:\WINDOWS\system32\sks~1
    C:\WINDOWS\SYSTEM32\swlnwmen.ini
    C:\WINDOWS\SYSTEM32\trgdscxd.ini
    C:\WINDOWS\SYSTEM32\uerrvnxk.ini
    C:\WINDOWS\SYSTEM32\vvvwa.bak1
    C:\WINDOWS\SYSTEM32\vvvwa.bak2
    C:\WINDOWS\SYSTEM32\vvvwa.ini
    C:\WINDOWS\SYSTEM32\vvvwa.ini2
    C:\WINDOWS\SYSTEM32\vvvwa.tmp
    C:\WINDOWS\system32\wanpacket.dll
    C:\WINDOWS\system32\windows
    C:\WINDOWS\system32\wpcap.dll
    C:\WINDOWS\SYSTEM32\wycdd.bak1
    C:\WINDOWS\SYSTEM32\wycdd.bak2
    C:\WINDOWS\SYSTEM32\wycdd.ini
    C:\WINDOWS\SYSTEM32\wycdd.ini2
    C:\WINDOWS\SYSTEM32\wycdd.tmp
    C:\WINDOWS\SYSTEM32\wyluykqe.ini
    C:\WINDOWS\system32\ydrmekwj.dll
    C:\WINDOWS\system32\ykcabjsv.dll

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\NPF


    ((((((((((((((((((((((((( Files Created from 2008-02-15 to 2008-03-15 )))))))))))))))))))))))))))))))
    .

    2008-03-09 23:50 . 2008-03-09 23:50 <DIR> d-------- C:\Program Files\Trend Micro
    2008-03-09 20:44 . 2008-03-10 01:28 10,740 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.CAT
    2008-03-09 20:44 . 2008-03-10 01:28 805 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.INF
    2008-03-09 14:25 . 2008-03-10 01:05 <DIR> d-------- C:\Program Files\Norton AntiVirus
    2008-03-09 14:18 . 2008-03-10 01:28 123,952 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS
    2008-03-09 14:18 . 2008-03-10 01:28 60,800 --a------ C:\WINDOWS\SYSTEM32\S32EVNT1.DLL
    2008-03-09 13:58 . 2008-03-10 01:28 <DIR> d-------- C:\Program Files\Symantec
    2008-03-09 12:20 . 2008-03-14 20:24 21,542 ---hs---- C:\WINDOWS\SYSTEM32\ntxqdgge.dllbox
    2008-03-08 11:03 . 2008-03-14 19:50 28,898 ---hs---- C:\WINDOWS\SYSTEM32\moejtawr.dllbox
    2008-03-07 11:06 . 2008-03-14 20:31 21,292 --ahs---- C:\WINDOWS\SYSTEM32\ykcabjsv.dllbox
    2008-03-06 11:02 . 2008-03-12 10:05 22,170 ---hs---- C:\WINDOWS\SYSTEM32\ydrmekwj.dllbox
    2008-02-29 11:56 . 2008-02-29 12:09 242,491 --ahs---- C:\WINDOWS\SYSTEM32\aybeg.tmp
    2008-02-29 01:10 . 2008-02-29 01:10 9,662 --a------ C:\WINDOWS\SYSTEM32\ZoneAlarmIconUS.ico
    2008-02-28 13:39 . 2008-02-28 12:08 294 --ahs---- C:\WINDOWS\SYSTEM32\yxuwqwlk.ini
    2008-02-27 20:33 . 2008-02-27 20:33 1,246,747 --ahs---- C:\WINDOWS\SYSTEM32\yxuwqwlk.tmp
    2008-02-27 16:46 . 2008-03-10 01:38 20,612 ---hs---- C:\WINDOWS\SYSTEM32\nhlwamzm.dllbox
    2008-02-19 11:15 . 2004-08-04 04:56 21,504 --a------ C:\WINDOWS\SYSTEM32\hidserv.dll
    2008-02-19 11:15 . 2004-08-04 04:56 21,504 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\hidserv.dll
    2008-02-19 11:15 . 2004-08-04 02:58 14,848 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\kbdhid.sys
    2008-02-19 11:15 . 2004-08-04 02:58 14,848 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\kbdhid.sys
    2008-02-19 11:15 . 2001-08-17 14:48 12,160 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mouhid.sys
    2008-02-19 11:15 . 2001-08-17 14:48 12,160 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\mouhid.sys
    2008-02-17 02:20 . 2008-02-17 02:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
    2008-02-17 01:27 . 2007-12-06 22:21 6,066,176 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
    2008-02-17 01:27 . 2007-06-30 23:31 2,455,488 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dat
    2008-02-17 01:27 . 2007-06-30 23:36 991,232 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll.mui
    2008-02-17 01:27 . 2007-12-06 22:21 459,264 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll
    2008-02-17 01:27 . 2007-12-06 22:21 383,488 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll
    2008-02-17 01:27 . 2007-12-06 22:21 267,776 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll
    2008-02-17 01:27 . 2007-12-06 22:21 63,488 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\icardie.dll
    2008-02-17 01:27 . 2007-12-06 22:21 52,224 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll
    2008-02-17 01:27 . 2007-12-06 07:00 13,824 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-03-14 23:36 --------- d-----w C:\Documents and Settings\Jennifer Gregoire\Application Data\U3
    2008-03-14 03:29 --------- d-----w C:\Program Files\Common Files\Symantec Shared
    2008-03-10 06:45 --------- d-----w C:\Program Files\Google
    2008-03-10 05:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
    2008-03-06 02:54 12,092 ----a-w C:\Documents and Settings\Jennifer Gregoire\Application Data\wklnhst.dat
    2008-03-06 02:48 --------- d-----w C:\Program Files\FileZilla
    2008-03-06 02:41 --------- d-----w C:\Program Files\Lavasoft
    2008-03-06 02:33 --------- d-----w C:\Program Files\Spybot - Search & Destroy
    2008-03-06 02:33 --------- d-----w C:\Program Files\Common Files\AOL
    2008-03-06 02:33 --------- d-----w C:\Program Files\AIM
    2008-03-06 02:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-03-06 02:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
    2008-02-17 07:17 --------- d-----w C:\Program Files\BearShare
    2008-02-17 06:45 --------- d-----w C:\Documents and Settings\Kyle Gregoire\Application Data\Lavasoft
    2008-01-23 23:49 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-01-23 23:49 --------- d-----w C:\Program Files\LG Electronics
    2008-01-23 23:48 --------- d-----w C:\Program Files\Verizon Wireless
    2007-11-22 02:02 82,424 ----a-w C:\Documents and Settings\Jennifer Gregoire\Application Data\GDIPFONTCACHEV1.DAT
    2007-08-23 12:48 246 ----a-w C:\Program Files\Common Files\laxu303
    2007-07-28 09:06 135 ----a-w C:\Program Files\Common Files\prohdy.html
    2007-03-09 11:42 106 ----a-w C:\Documents and Settings\Jennifer Gregoire\Application Data\MTC-savedfolder.dat
    2007-02-27 22:07 34 ----a-w C:\Documents and Settings\Jennifer Gregoire\Application Data\MTC-savedinstructor.dat
    2006-11-03 17:16 13,904 -c--a-w C:\Documents and Settings\Kyle Gregoire\Application Data\wklnhst.dat
    2005-01-14 15:38 59,344 -c--a-w C:\Documents and Settings\Kyle Gregoire\Application Data\GDIPFONTCACHEV1.DAT
    2007-04-09 23:32 88 --sh--r C:\WINDOWS\SYSTEM32\A5D44B3F19.sys
    2007-10-10 21:37 717,104 --sha-w C:\WINDOWS\SYSTEM32\aycdd.bak1
    2007-10-12 09:37 716,969 --sha-w C:\WINDOWS\SYSTEM32\aycdd.bak2
    2007-10-12 18:41 722,425 --sha-w C:\WINDOWS\SYSTEM32\aycdd.ini2
    2007-04-09 23:33 2,516 --sha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
    2007-08-23 11:23 6,513 --sha-w C:\WINDOWS\SYSTEM32\ttutv.bak1
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-19 08:59 155648]
    "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-19 08:59 126976]
    "IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 21:12 221184]
    "PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2003-08-26 20:47 204800]
    "dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-03-15 02:04 122933]
    "UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 02:01 110592]
    "DwlClient"="c:\Program Files\Common Files\Dell\EUSW\Support.exe" [2005-10-13 23:26 69632]
    "Dell AIO Printer A940"="C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe" [2003-02-17 18:00 86102]
    "Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-12-05 23:08 50688]
    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-08-24 19:57 180269]
    "REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 23:32 53248]
    "QuickFinder Scheduler"="C:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE" [2006-04-06 00:55 77892]
    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-31 18:44 271672]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24 286720]
    "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-03-04 22:54 84640]
    "osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2008-03-04 22:45 26248]

    C:\Documents and Settings\Jennifer Gregoire\Start Menu\Programs\Startup\
    MEMonitor.lnk - C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe [2008-01-23 19:48:14 947544]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
    Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\moejtawr]
    moejtawr.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\AIM\\aim.exe"=
    "C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "C:\\Program Files\\iTunes\\iTunes.exe"=

    S3 MSControlService;Microsoft cache control;C:\WINDOWS\system32\windows []
    S3 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2005-10-14 03:53]
    S4 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
    \Shell\AutoRun\command - E:\LaunchU3.exe -a

    .
    Contents of the 'Scheduled Tasks' folder
    "2008-03-13 22:21:35 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    "2008-03-15 00:18:43 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Jennifer Gregoire.job"
    - C:\PROGRA~1\NORTON~1\Navw32.exeh/TASK:
    .
    **************************************************************************

    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-03-14 21:08:25
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MSControlService]
    "ImagePath"="C:\WINDOWS\system32\windows"
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
    C:\Program Files\iPod\bin\iPodService.exe
    .
    **************************************************************************
    .
    Completion time: 2008-03-14 21:18:19 - machine was rebooted [Jennifer Gregoire]
    ComboFix-quarantined-files.txt 2008-03-15 01:18:12
    .
    2008-03-13 07:05:28 --- E O F ---
     
  5. gardnesm

    gardnesm Thread Starter

    Joined:
    Mar 10, 2008
    Messages:
    3
    And here is the latest hijack this log for the records.

    The computer seems to be running fine now, but this is just a precaution on what else I need to remove. Thanks




    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 9:44:15 PM, on 3/14/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16608)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [DwlClient] c:\Program Files\Common Files\Dell\EUSW\Support.exe
    O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
    O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: MEMonitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: Open with WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O20 - Winlogon Notify: moejtawr - moejtawr.dll (file missing)
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\WINDOWS\system32\windows (file missing)
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

    --
    End of file - 6609 bytes
     
  6. Cheeseball81

    Cheeseball81 Retired Moderator

    Joined:
    Mar 3, 2004
    Messages:
    84,315
    Next step

    Download the Trial version of Superantispyware Pro (SAS):
    http://www.superantispyware.com/superantispyware.html?rid=3132


    Install it and double-click the icon on your desktop to run it.
    · It will ask if you want to update the program definitions, click Yes.
    · Under Configuration and Preferences, click the Preferences button.
    · Click the Scanning Control tab.
    · Under Scanner Options make sure the following are checked:
    o Close browsers before scanning
    o Scan for tracking cookies
    o Terminate memory threats before quarantining.
    o Please leave the others unchecked.
    o Click the Close button to leave the control center screen.
    · On the main screen, under Scan for Harmful Software click Scan your computer.
    · On the left check C:\Fixed Drive.
    · On the right, under Complete Scan, choose Perform Complete Scan.
    · Click Next to start the scan. Please be patient while it scans your computer.
    · After the scan is complete a summary box will appear. Click OK.
    · Make sure everything in the white box has a check next to it, then click Next.
    · It will quarantine what it found and if it asks if you want to reboot, click Yes.
    · To retrieve the removal information for me please do the following:
    o After reboot, double-click the SUPERAntispyware icon on your desktop.
    o Click Preferences. Click the Statistics/Logs tab.
    o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    o It will open in your default text editor (such as Notepad/Wordpad).
    o Please highlight everything in the notepad, then right-click and choose copy.
    · Click close and close again to exit the program.
    · Please paste that information here for me with a new Hijack This log.
     
  7. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/691855