1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Solved: Pop-up and trojan problems

Discussion in 'Virus & Other Malware Removal' started by planegray, Aug 10, 2007.

Thread Status:
Not open for further replies.
Advertisement
  1. planegray

    planegray Thread Starter

    Joined:
    Aug 10, 2007
    Messages:
    6
    I read a couple of other post about adfcook and started to follow the steps but wasn't sure if it was a user specific fix but her is the list from Hijackthis any help would be great it's a company laptop and the database can not be lost

    FYI: Windows XP

    Logfile of HijackThis v1.99.1
    Scan saved at 4:13:05 PM, on 8/10/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
    C:\WINDOWS\system32\gqlbavwr.exe
    C:\Program Files\HP Web Jetadmin\hpwebjetd.exe
    C:\WINDOWS\System32\inetsrv\inetinfo.exe
    C:\Program Files\InterBase\Bin\ibguard.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\HP Web Jetadmin\hpwebjetd.exe
    C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
    c:\program files\winscribe\winscribe speech recognition service\purgeadaptationservice\winscribe.services.speechrecognition.purgeadaptationservice.exe
    c:\program files\winscribe\winscribe speech recognition adapter service\winscribe.services.speechrecognition.speechrecognitionadapterservice.exe
    c:\program files\verizon wireless\venturi\Client\ventc.exe
    C:\WINDOWS\system32\WSServer.exe
    c:\program files\winscribe\winscribe sr submitter\wssubmitterservice.exe
    C:\WINDOWS\System32\mqsvc.exe
    C:\WINDOWS\System32\mqtgsvc.exe
    C:\WINDOWS\System32\00THotkey.exe
    C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
    C:\WINDOWS\system32\TFNF5.exe
    C:\WINDOWS\system32\TPWRTRAY.EXE
    C:\Program Files\Apoint2K\Apoint.exe
    C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Apoint2K\Apntex.exe
    C:\WINDOWS\system32\PspContr.Exe
    C:\WINDOWS\System32\ezSP_Px.exe
    C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\InterBase\Bin\ibserver.exe
    C:\WINDOWS\System32\dllhost.exe
    C:\PVSW\Bin\W3DBSMGR.EXE
    C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    C:\Program Files\XNote Stopwatch\xnsw.exe
    \?\C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
    C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\explorer.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgwb.dat
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgvv.exe
    C:\Downloads\HijackThis.exe

    O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
    O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
    O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 20
    O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
    O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
    O4 - HKLM\..\Run: [PspContr] PspContr.Exe
    O4 - HKLM\..\Run: [PspUsbCf] PspUsbCf.exe
    O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
    O4 - HKLM\..\Run: [Drag'n Drop CD] C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe /StartUp
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\ujiyvvlb.dll",forkonce
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: D-Link AirPlus.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Pervasive.SQL Workstation Engine.lnk = C:\PVSW\Bin\W3DBSMGR.EXE
    O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    O4 - Global Startup: Stop Watch.lnk = C:\Program Files\XNote Stopwatch\xnsw.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\program files\neoteris\secure application manager\samnsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\neoteris\secure application manager\samnsp.dll
    O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://vendors.carolinas.org/dana-cached/setup/NeoterisSetup.cab
    O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://support.coastalsystems.net/Launchers/setup.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1184694856794
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1184698471780
    O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - https://cert.coastalsystems.net/Remote/msrdp.cab
    O16 - DPF: {8B29E7C6-6EE1-43B3-A909-C3E641F16C5F} - http://csi/wsnotify/setup/Winscribe Notification Service Client.cab
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield Setup Player) - http://winscribe/winscribe/setup/Typist/isetup.cab
    O16 - DPF: {A1B8A30B-8AAA-4A3E-8869-1DA509E8A011} (Crystal ActiveX Report Viewer Control 10.0) - http://210.55.18.50/eservice/reporting/viewer/activeXViewer10/activeXViewer.cab
    O16 - DPF: {A7B6FBFE-C894-4954-8377-D1CF19B4E07F} (Wapplink Control) - http://66.15.242.204/applets/OcxLink.cab
    O16 - DPF: {A922D52D-26B1-4672-B0AF-9673AB46F937} (InstallShield Setup Player 2K2) - http://laptop/winscribe/setup/Author/setup.exe
    O16 - DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} (VaPgCtrl Class) - http://66.45.99.198/plugin/h263ctrl.cab
    O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
    O16 - DPF: {C7DC40E0-6601-4530-9AFB-68506CAE2628} (InstallShield Setup Player 2K2) - http://66.15.242.204/Launchers/setup.exe
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://winscribe.webex.com/client/T22L/training/ieatgpc.cab
    O16 - DPF: {F3C7C5EE-8BBA-4B6E-8147-3B315A41B85B} - http://66.15.242.204/clientinstall/install.cab
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: DM1Service - OLYMPUS IMAGING CORP. - C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
    O23 - Service: DomainService - - C:\WINDOWS\system32\gqlbavwr.exe
    O23 - Service: HP Web Jetadmin (HPWebJetadmin) - Unknown owner - C:\Program Files\HP Web Jetadmin\hpwebjetd.exe" -k runservice (file missing)
    O23 - Service: InterBase Guardian (InterBaseGuardian) - Inprise Corporation - C:\Program Files\InterBase\Bin\ibguard.exe
    O23 - Service: InterBase Server (InterBaseServer) - Inprise Corporation - C:\Program Files\InterBase\Bin\ibserver.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: WinScribe SR Purge Adaptation Service (PurgeAdaptationService) - - c:\program files\winscribe\winscribe speech recognition service\purgeadaptationservice\winscribe.services.speechrecognition.purgeadaptationservice.exe
    O23 - Service: WinScribe Speech Recognition Adapter Service (SpeechRecognitionAdapterService) - - c:\program files\winscribe\winscribe speech recognition adapter service\winscribe.services.speechrecognition.speechrecognitionadapterservice.exe
    O23 - Service: Venturi Client (Venturi2) - Venturi Wireless - c:\program files\verizon wireless\venturi\Client\ventc.exe
    O23 - Service: WinScribe Importer (wsImporterService) - WinScribe - C:\Program Files\WinScribe\Importer\wsImporterService.exe
    O23 - Service: WinScribe Dictation (WSServer) - WinScribe Inc Limited - C:\WINDOWS\system32\WSServer.exe
    O23 - Service: WinScribe SR Submitter Service (WsSubmitterService) - - c:\program files\winscribe\winscribe sr submitter\wssubmitterservice.exe







    Thanks for any help you can offer and let me know if there is any information that i can provide.

    PS my name is Gary
     
  2. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    First you cannot put yourslf in a position that you cannot lose the BD - make backups!

    NOTE: If you have downloaded ComboFix previously please delete that version and download it again!

    Download this file :

    http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
    or
    http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe

    Double click combofix.exe & follow the prompts.
    When finished, it shall produce a log for you. Post that log and a HiJack log in your next reply

    Note:
    Do not mouseclick combofix's window while its running. That may cause it to stall

    =====================
    Download Superantispyware (SAS) free home version

    http://www.superantispyware.com/superantispywarefreevspro.html

    Install it and double-click the icon on your desktop to run it.
    · It will ask if you want to update the program definitions, click Yes.
    · Under Configuration and Preferences, click the Preferences button.
    · Click the Scanning Control tab.
    · Under Scanner Options make sure the following are checked:
    o Close browsers before scanning
    o Scan for tracking cookies
    o Terminate memory threats before quarantining.
    o Please leave the others unchecked.
    o Click the Close button to leave the control center screen.
    · On the main screen, under Scan for Harmful Software click Scan your computer.
    · On the left check C:\Fixed Drive.
    · On the right, under Complete Scan, choose Perform Complete Scan.
    · Click Next to start the scan. Please be patient while it scans your computer.
    · After the scan is complete a summary box will appear. Click OK.
    · Make sure everything in the white box has a check next to it, then click Next.
    · It will quarantine what it found and if it asks if you want to reboot, click Yes.
    · To retrieve the removal information for me please do the following:
    o After reboot, double-click the SUPERAntispyware icon on your desktop.
    o Click Preferences. Click the Statistics/Logs tab.
    o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    o It will open in your default text editor (such as Notepad/Wordpad).
    o Please highlight everything in the notepad, then right-click and choose copy.
    · Click close and close again to exit the program.
    · Please paste that information here for me with a new HijackThis log.

    This will take some time!!!!!!!!
     
  3. planegray

    planegray Thread Starter

    Joined:
    Aug 10, 2007
    Messages:
    6
    ComboFix 07-08-09.3 - "Terry" 2007-08-10 20:31:54.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.301 [GMT -4:00]
    * Created a new restore point


    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


    C:\WINDOWS\system32\aifhyhul.ini
    C:\WINDOWS\system32\blvvyiju.ini
    C:\WINDOWS\system32\dcfii.bak1
    C:\WINDOWS\system32\dcfii.bak2
    C:\WINDOWS\system32\dcfii.ini
    C:\WINDOWS\system32\dcfii.ini2
    C:\WINDOWS\system32\dcfii.tmp
    C:\WINDOWS\system32\eudrpqug.dll
    C:\WINDOWS\system32\fuvgydpi.ini
    C:\WINDOWS\system32\guqprdue.ini
    C:\WINDOWS\system32\hqvyakeq.dll
    C:\WINDOWS\system32\iifcd.dll
    C:\WINDOWS\system32\ipdygvuf.dll
    C:\WINDOWS\system32\khffcby.dll
    C:\WINDOWS\system32\kkdqtphr.ini
    C:\WINDOWS\system32\kwpgvlaq.dll
    C:\WINDOWS\system32\luhyhfia.dll
    C:\WINDOWS\system32\qalvgpwk.ini
    C:\WINDOWS\system32\qekayvqh.ini
    C:\WINDOWS\system32\rhptqdkk.dll
    C:\WINDOWS\system32\ujiyvvlb.dll
    C:\WINDOWS\system32\yutbiohw.dll


    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


    -------\LEGACY_DOMAINSERVICE
    -------\DomainService


    ((((((((((((((((((((((((( Files Created from 2007-07-11 to 2007-08-11 )))))))))))))))))))))))))))))))


    2007-08-10 20:29 75,328 --a------ C:\WINDOWS\system32\crxcnhrh.exe
    2007-08-10 20:27 51,200 --a------ C:\WINDOWS\nircmd.exe
    2007-08-10 19:41 75,328 --a------ C:\WINDOWS\system32\qenluuyl.exe
    2007-08-10 19:12 75,328 --a------ C:\WINDOWS\system32\uutcaamn.exe
    2007-08-10 16:12 75,328 --a------ C:\WINDOWS\system32\llmxjdqh.exe
    2007-08-10 16:06 75,328 --a------ C:\WINDOWS\system32\lanfagbg.exe
    2007-08-10 16:00 75,328 --a------ C:\WINDOWS\system32\urluecxb.exe
    2007-08-10 13:41 75,328 --a------ C:\WINDOWS\system32\nyyvxmqn.exe
    2007-08-10 12:47 75,328 --a------ C:\WINDOWS\system32\mvdkkdnr.exe
    2007-08-10 12:29 75,328 --a------ C:\WINDOWS\system32\wsvhlgnd.exe
    2007-08-10 11:25 75,328 --a------ C:\WINDOWS\system32\gqlbavwr.exe
    2007-08-09 10:02 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
    2007-08-09 09:15 75,328 --a------ C:\WINDOWS\system32\txbyrbsc.exe
    2007-08-01 13:02 <DIR> d-------- C:\DOCUME~1\TERRYM~1\APPLIC~1\Philips Speech
    2007-07-27 09:01 1,738,236 --ahs---- C:\WINDOWS\system32\lnnnn.bak2
    2007-07-26 09:05 6,467 --ahs---- C:\WINDOWS\system32\lnnnn.bak1
    2007-07-17 15:16 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
    2007-07-17 14:19 <DIR> d-------- C:\Program Files\Windows Media Connect 2
    2007-07-17 14:16 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
    2007-07-17 12:34 <DIR> d-------- C:\Program Files\MSXML 4.0
    2007-07-13 15:00 118,784 --a------ C:\WINDOWS\system32\nvqtwk.dll
    2007-07-13 15:00 <DIR> d-------- C:\display.temp


    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

    2007-08-08 16:41 --------- d-------- C:\DOCUME~1\TERRYM~1\APPLIC~1\AdobeUM
    2007-08-01 15:32 --------- d-------- C:\Program Files\Nortel Networks
    2007-08-01 15:04 --------- d-------- C:\Program Files\WAVpedal
    2007-08-01 12:46 --------- d-------- C:\Program Files\Philips Speech
    2007-07-26 11:42 --------- d-------- C:\Program Files\WS_FTP Pro
    2007-07-20 16:56 --------- d-------- C:\Program Files\HP Web Jetadmin
    2007-06-26 04:27 363520 -----c--- C:\WINDOWS\system32\dllcache\w3svc.dll
    2007-06-15 14:28 186443 --a------ C:\WINDOWS\system32\atasnt40.dll
    2007-05-16 11:12 86528 -----c--- C:\WINDOWS\system32\dllcache\directdb.dll
    2007-05-16 11:12 85504 -----c--- C:\WINDOWS\system32\dllcache\wabimp.dll
    2007-05-16 11:12 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
    2007-05-16 11:12 683520 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
    2007-05-16 11:12 510976 -----c--- C:\WINDOWS\system32\dllcache\wab32.dll
    2007-05-16 11:12 1314816 -----c--- C:\WINDOWS\system32\dllcache\msoe.dll
    2007-02-28 14:31 94120 --a------ C:\DOCUME~1\TERRYM~1\APPLIC~1\JuniperSetup.exe
    2005-11-23 12:44 63656 --a------ C:\DOCUME~1\TERRYM~1\APPLIC~1\GDIPFONTCACHEV1.DAT


    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1A30E56A-EFCE-4861-80BB-D753CE0BD2B9}]
    C:\WINDOWS\system32\nnnnl.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "00THotkey"="C:\WINDOWS\System32\00THotkey.exe" [2002-04-15 18:35]
    "000StTHK"="000StTHK.exe" [2001-06-23 20:28 C:\WINDOWS\system32\000StTHK.exe]
    "TFncKy"="TFncKy.exe" []
    "TFNF5"="TFNF5.exe" [2001-08-03 17:08 C:\WINDOWS\system32\TFNF5.exe]
    "Tpwrtray"="TPWRTRAY.EXE" [2002-03-19 20:38 C:\WINDOWS\system32\TPWRTRAY.EXE]
    "Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2002-07-16 00:41]
    "TouchED"="C:\Program Files\TOSHIBA\TouchED\TouchED.Exe" [2002-07-31 11:41]
    "AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-04-22 09:37]
    "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-08-09 06:03]
    "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-08-09 06:03]
    "MsmqIntCert"="regsvr32 /s mqrt.dll" []
    "PspContr"="PspContr.Exe" [2003-02-07 15:43 C:\WINDOWS\system32\pspcontr.exe]
    "PspUsbCf"="PspUsbCf.exe" [2002-10-18 08:11 C:\WINDOWS\system32\pspusbcf.exe]
    "ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-07-03 20:17]
    "Drag'n Drop CD"="C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe" [2002-07-24 20:44]
    "NvCplDaemon"="NvQTwk" []

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
    "WSNotify"="" []
    "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-26 16:13]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06]
    D-Link AirPlus.lnk - C:\Program Files\D-Link AirPlus\AirPlus.exe [2004-10-12 12:52:24]
    Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
    Pervasive.SQL Workstation Engine.lnk - C:\PVSW\Bin\W3DBSMGR.EXE [2004-12-19 09:03:21]
    Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2002-12-17 17:23:32]
    Stop Watch.lnk - C:\Program Files\XNote Stopwatch\xnsw.exe [2005-07-15 09:15:32]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ckpNotify]
    ckpNotify.dll 2003-04-08 17:45 24666 C:\WINDOWS\system32\ckpNotify.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnnl]
    C:\WINDOWS\system32\nnnnl.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
    PCANotify.dll 2003-10-31 11:01 8704 C:\WINDOWS\system32\PCANotify.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wineby32]
    wineby32.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PC Health.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PC Health.lnk
    backup=C:\WINDOWS\pss\PC Health.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SpeechMagic Startup.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SpeechMagic Startup.lnk
    backup=C:\WINDOWS\pss\SpeechMagic Startup.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VPN Client.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk
    backup=C:\WINDOWS\pss\VPN Client.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
    "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    "C:\Program Files\Messenger\msmsgs.exe" /background

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
    RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIEW]
    rundll32.exe nview.dll,nViewLoadHook

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
    nwiz.exe /installquiet /nodetect /keeploaded

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PspContr]
    PspContr.Exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    "C:\Program Files\QuickTime\qttask.exe" -atboottime

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
    "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    R0 Gernuwa;Gernuwa;C:\WINDOWS\system32\drivers\Gernuwa.sys
    R0 TVALD;Toshiba ACPI-Based Value Added Logical Device Driver;C:\WINDOWS\system32\DRIVERS\TVALD.SYS
    R0 TVALG;Toshiba Value Added Logical and General Purpose Device Driver;C:\WINDOWS\system32\DRIVERS\TVALG.SYS
    R1 NEOFLTR_530_10741;Juniper Networks TDI Filter Driver (NEOFLTR_530_10741);\??\C:\WINDOWS\system32\Drivers\NEOFLTR_530_10741.SYS
    R1 nvport;NVIDIA PORT IO Control Driver;\??\C:\WINDOWS\System32\Drivers\nvport.sys
    R2 CVPND;Cisco Systems, Inc. VPN Service;C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    R2 CVPNDRVA;Cisco Systems Inc. IPSec Driver;\??\C:\WINDOWS\System32\Drivers\CVPNDRVA.sys
    R2 HPWebJetadmin;HP Web Jetadmin;"C:\Program Files\HP Web Jetadmin\hpwebjetd.exe" -k runservice
    R2 IISADMIN;IIS Admin;C:\WINDOWS\System32\inetsrv\inetinfo.exe
    R2 InterBaseGuardian;InterBase Guardian;C:\Program Files\InterBase\Bin\ibguard.exe -s
    R2 MSMQ;Message Queuing;C:\WINDOWS\System32\mqsvc.exe
    R2 MSMQTriggers;Message Queuing Triggers;C:\WINDOWS\System32\mqtgsvc.exe
    R2 PurgeAdaptationService;WinScribe SR Purge Adaptation Service;c:\program files\winscribe\winscribe speech recognition service\purgeadaptationservice\winscribe.services.speechrecognition.purgeadaptationservice.exe
    R2 Scap;SecureClient Application Policy Module;C:\WINDOWS\system32\DRIVERS\Scap.sys
    R2 SMTPSVC;Simple Mail Transfer Protocol (SMTP);C:\WINDOWS\System32\inetsrv\inetinfo.exe
    R2 VPN-1;VPN-1 Module;C:\WINDOWS\system32\drivers\vpn.sys
    R2 WSServer;WinScribe Dictation;C:\WINDOWS\system32\WSServer.exe
    R2 WsSubmitterService;WinScribe SR Submitter Service;c:\program files\winscribe\winscribe sr submitter\wssubmitterservice.exe
    R3 DNE;Deterministic Network Enhancer Miniport;C:\WINDOWS\system32\DRIVERS\dne2000.sys
    R3 Eacfilt;Eacfilt Miniport;C:\WINDOWS\system32\DRIVERS\eacfilt.sys
    R3 FW1;SecuRemote Miniport;C:\WINDOWS\system32\DRIVERS\fw.sys
    R3 InterBaseServer;InterBase Server;C:\Program Files\InterBase\Bin\ibserver.exe -s -g
    R3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys
    R3 MQAC;Message Queuing access control;\??\C:\WINDOWS\System32\drivers\mqac.sys
    R3 RMCAST;Reliable Multicast Protocol driver;\??\C:\WINDOWS\System32\drivers\RMCast.sys
    R3 SMNDIS5;SMNDIS5 NDIS Protocol Driver;\??\C:\PROGRA~1\VERIZO~1\VZACCE~1\SMNDIS5.SYS
    R3 WDM_YAMAHAAC97;YAMAHA AC-XG Audio Device;C:\WINDOWS\system32\drivers\yacxgc.sys
    S2 IPSECEXT;Nortel Extranet Access Protocol;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys
    S2 SpeechRecognitionAdapterService;WinScribe Speech Recognition Adapter Service;c:\program files\winscribe\winscribe speech recognition adapter service\winscribe.services.speechrecognition.speechrecognitionadapterservice.exe
    S2 VPCAppSv;Virtual PC Application Services;C:\WINDOWS\system32\DRIVERS\VPCAppSv.sys
    S3 AIRPLUS;D-Link AirPlus Wireless Adapter;C:\WINDOWS\system32\DRIVERS\airplus.sys
    S3 awhost32;pcAnywhere Host Service;C:\Program Files\Symantec\pcAnywhere\awhost32.exe
    S3 CVirtA;Cisco Systems VPN Adapter;C:\WINDOWS\system32\DRIVERS\CVirtA.sys
    S3 DM_1USB;DM_1USB Device;C:\WINDOWS\system32\DRIVERS\DM_1USB.sys
    S3 DSSUSB1;DSSUSB1 Device;C:\WINDOWS\system32\DRIVERS\DSSUSB1.sys
    S3 msloop;Microsoft Loopback Adapter Driver;C:\WINDOWS\system32\DRIVERS\loop.sys
    S3 OMVA;VPN-1 SecureClient Adapter;C:\WINDOWS\system32\DRIVERS\OMVA.sys
    S3 pwi_bus;Curitel PC Card Composite Device driver (WDM);C:\WINDOWS\system32\DRIVERS\pwi_bus.sys
    S3 pwi_mdfl;Curitel PC Card Filter;C:\WINDOWS\system32\DRIVERS\pwi_mdfl.sys
    S3 pwi_mdm;Curitel PC Card Drivers;C:\WINDOWS\system32\DRIVERS\pwi_mdm.sys
    S3 pwi_oflt;Curitel PC Card OHCI Filter;C:\WINDOWS\system32\DRIVERS\pwi_oflt.sys
    S3 pwi_serd;Curitel PC Card Diagnostic Serial Port (WDM);C:\WINDOWS\system32\DRIVERS\pwi_serd.sys
    S3 usb_rndisx;USB RNDIS Adapter;C:\WINDOWS\system32\DRIVERS\usb8023x.sys
    S3 wceusbsh;Windows CE USB Serial Host Driver;C:\WINDOWS\system32\DRIVERS\wceusbsh.sys
    S3 wlluc48;Wireless LAN PC Card Driver;C:\WINDOWS\system32\DRIVERS\wlluc48.sys
    S3 wsImporterService;WinScribe Importer;C:\Program Files\WinScribe\Importer\wsImporterService.exe


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{463f5fb1-bb73-11db-b424-444553544200}]
    AutoRun\command- E:\LaunchU3.exe -a


    **************************************************************************

    catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-08-10 20:56:44
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden registry entries ...

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-854245398-1343024091-1957994488-1014\Components\\x00d01\xe8w\xff\xff\xff\xff;_\xe7w4\xb2\xd4w\2]
    "422721BB1F51BA38E46C9A718B520011"="C:\Documents and Settings\All Users\Application Data\ScanSoft\Dragon SDK Server Edition8\Data\Enx\enx_enu_office_transcription_large\"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
    "TracesProcessed"=dword:000002de

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    Completion time: 2007-08-10 21:03:00 - machine was rebooted
    C:\ComboFix-quarantined-files.txt ... 2007-08-10 21:01

    --- E O F ---



    ==============



    Logfile of HijackThis v1.99.1
    Scan saved at 9:08:38 PM, on 8/10/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
    C:\Program Files\HP Web Jetadmin\hpwebjetd.exe
    C:\WINDOWS\System32\inetsrv\inetinfo.exe
    C:\Program Files\InterBase\Bin\ibguard.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\HP Web Jetadmin\hpwebjetd.exe
    C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
    c:\program files\winscribe\winscribe speech recognition service\purgeadaptationservice\winscribe.services.speechrecognition.purgeadaptationservice.exe
    C:\WINDOWS\Explorer.EXE
    c:\program files\verizon wireless\venturi\Client\ventc.exe
    C:\WINDOWS\system32\WSServer.exe
    c:\program files\winscribe\winscribe sr submitter\wssubmitterservice.exe
    C:\WINDOWS\System32\mqsvc.exe
    C:\WINDOWS\System32\mqtgsvc.exe
    C:\WINDOWS\System32\00THotkey.exe
    C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
    C:\WINDOWS\system32\TFNF5.exe
    C:\WINDOWS\system32\TPWRTRAY.EXE
    C:\Program Files\Apoint2K\Apoint.exe
    C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\WINDOWS\system32\PspContr.Exe
    C:\Program Files\Apoint2K\Apntex.exe
    C:\WINDOWS\System32\ezSP_Px.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\PROGRA~1\MICROS~3\rapimgr.exe
    C:\PVSW\Bin\W3DBSMGR.EXE
    C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    C:\Program Files\InterBase\Bin\ibserver.exe
    C:\WINDOWS\System32\dllhost.exe
    \?\C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
    C:\Downloads\HijackThis.exe

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {1A30E56A-EFCE-4861-80BB-D753CE0BD2B9} - C:\WINDOWS\system32\nnnnl.dll (file missing)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
    O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
    O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 20
    O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
    O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
    O4 - HKLM\..\Run: [PspContr] PspContr.Exe
    O4 - HKLM\..\Run: [PspUsbCf] PspUsbCf.exe
    O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
    O4 - HKLM\..\Run: [Drag'n Drop CD] C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe /StartUp
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: D-Link AirPlus.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Pervasive.SQL Workstation Engine.lnk = C:\PVSW\Bin\W3DBSMGR.EXE
    O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    O4 - Global Startup: Stop Watch.lnk = C:\Program Files\XNote Stopwatch\xnsw.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\program files\neoteris\secure application manager\samnsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\neoteris\secure application manager\samnsp.dll
    O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://vendors.carolinas.org/dana-cached/setup/NeoterisSetup.cab
    O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://support.coastalsystems.net/Launchers/setup.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1184694856794
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1184698471780
    O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - https://cert.coastalsystems.net/Remote/msrdp.cab
    O16 - DPF: {8B29E7C6-6EE1-43B3-A909-C3E641F16C5F} - http://csi/wsnotify/setup/Winscribe Notification Service Client.cab
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield Setup Player) - http://winscribe/winscribe/setup/Typist/isetup.cab
    O16 - DPF: {A1B8A30B-8AAA-4A3E-8869-1DA509E8A011} (Crystal ActiveX Report Viewer Control 10.0) - http://210.55.18.50/eservice/reporting/viewer/activeXViewer10/activeXViewer.cab
    O16 - DPF: {A7B6FBFE-C894-4954-8377-D1CF19B4E07F} (Wapplink Control) - http://66.15.242.204/applets/OcxLink.cab
    O16 - DPF: {A922D52D-26B1-4672-B0AF-9673AB46F937} (InstallShield Setup Player 2K2) - http://laptop/winscribe/setup/Author/setup.exe
    O16 - DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} (VaPgCtrl Class) - http://66.45.99.198/plugin/h263ctrl.cab
    O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
    O16 - DPF: {C7DC40E0-6601-4530-9AFB-68506CAE2628} (InstallShield Setup Player 2K2) - http://66.15.242.204/Launchers/setup.exe
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://winscribe.webex.com/client/T22L/training/ieatgpc.cab
    O16 - DPF: {F3C7C5EE-8BBA-4B6E-8147-3B315A41B85B} - http://66.15.242.204/clientinstall/install.cab
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O20 - Winlogon Notify: ckpNotify - C:\WINDOWS\SYSTEM32\ckpNotify.dll
    O20 - Winlogon Notify: nnnnl - C:\WINDOWS\system32\nnnnl.dll (file missing)
    O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O20 - Winlogon Notify: wineby32 - wineby32.dll (file missing)
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: DM1Service - OLYMPUS IMAGING CORP. - C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
    O23 - Service: HP Web Jetadmin (HPWebJetadmin) - Unknown owner - C:\Program Files\HP Web Jetadmin\hpwebjetd.exe" -k runservice (file missing)
    O23 - Service: InterBase Guardian (InterBaseGuardian) - Inprise Corporation - C:\Program Files\InterBase\Bin\ibguard.exe
    O23 - Service: InterBase Server (InterBaseServer) - Inprise Corporation - C:\Program Files\InterBase\Bin\ibserver.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: WinScribe SR Purge Adaptation Service (PurgeAdaptationService) - - c:\program files\winscribe\winscribe speech recognition service\purgeadaptationservice\winscribe.services.speechrecognition.purgeadaptationservice.exe
    O23 - Service: WinScribe Speech Recognition Adapter Service (SpeechRecognitionAdapterService) - - c:\program files\winscribe\winscribe speech recognition adapter service\winscribe.services.speechrecognition.speechrecognitionadapterservice.exe
    O23 - Service: Venturi Client (Venturi2) - Venturi Wireless - c:\program files\verizon wireless\venturi\Client\ventc.exe
    O23 - Service: WinScribe Importer (wsImporterService) - WinScribe - C:\Program Files\WinScribe\Importer\wsImporterService.exe
    O23 - Service: WinScribe Dictation (WSServer) - WinScribe Inc Limited - C:\WINDOWS\system32\WSServer.exe
    O23 - Service: WinScribe SR Submitter Service (WsSubmitterService) - - c:\program files\winscribe\winscribe sr submitter\wssubmitterservice.exe
     
  4. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    Keep going - do the rest of my post
     
  5. planegray

    planegray Thread Starter

    Joined:
    Aug 10, 2007
    Messages:
    6
    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 08/10/2007 at 11:49 PM

    Application Version : 3.9.1008

    Core Rules Database Version : 3284
    Trace Rules Database Version: 1295

    Scan type : Complete Scan
    Total Scan Time : 02:30:35

    Memory items scanned : 635
    Memory threats detected : 0
    Registry items scanned : 7680
    Registry threats detected : 0
    File items scanned : 99516
    File threats detected : 40

    Adware.Tracking Cookie
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][2].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][2].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][2].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][3].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][2].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][3].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][2].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][2].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][2].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][3].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][2].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][2].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][2].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][2].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][2].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][2].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt
    C:\Documents and Settings\Terry Markley\Cookies\terry [email protected][1].txt

    Adware.Vundo Variant
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{8C298732-0EB3-4661-978F-B2AC3E3B8BAA}\RP1304\A0130135.DLL



    ==================


    Logfile of HijackThis v1.99.1
    Scan saved at 12:04:19 AM, on 8/11/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
    C:\Program Files\HP Web Jetadmin\hpwebjetd.exe
    C:\WINDOWS\System32\inetsrv\inetinfo.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\HP Web Jetadmin\hpwebjetd.exe
    C:\Program Files\InterBase\Bin\ibguard.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
    c:\program files\winscribe\winscribe speech recognition service\purgeadaptationservice\winscribe.services.speechrecognition.purgeadaptationservice.exe
    c:\program files\winscribe\winscribe speech recognition adapter service\winscribe.services.speechrecognition.speechrecognitionadapterservice.exe
    C:\WINDOWS\System32\00THotkey.exe
    c:\program files\verizon wireless\venturi\Client\ventc.exe
    C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
    C:\WINDOWS\system32\TFNF5.exe
    C:\WINDOWS\system32\TPWRTRAY.EXE
    C:\Program Files\Apoint2K\Apoint.exe
    C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
    C:\WINDOWS\system32\WSServer.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    c:\program files\winscribe\winscribe sr submitter\wssubmitterservice.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\WINDOWS\system32\PspContr.Exe
    C:\WINDOWS\System32\ezSP_Px.exe
    C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe
    C:\WINDOWS\System32\mqsvc.exe
    C:\Program Files\Apoint2K\Apntex.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\PROGRA~1\MICROS~3\rapimgr.exe
    C:\WINDOWS\System32\mqtgsvc.exe
    C:\Program Files\InterBase\Bin\ibserver.exe
    C:\WINDOWS\System32\wbem\wmiapsrv.exe
    C:\WINDOWS\System32\dllhost.exe
    \?\C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
    C:\PVSW\Bin\W3DBSMGR.EXE
    C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    C:\Program Files\XNote Stopwatch\xnsw.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Downloads\HijackThis.exe

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {1A30E56A-EFCE-4861-80BB-D753CE0BD2B9} - C:\WINDOWS\system32\nnnnl.dll (file missing)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
    O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
    O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 20
    O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
    O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
    O4 - HKLM\..\Run: [PspContr] PspContr.Exe
    O4 - HKLM\..\Run: [PspUsbCf] PspUsbCf.exe
    O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
    O4 - HKLM\..\Run: [Drag'n Drop CD] C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe /StartUp
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: D-Link AirPlus.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Pervasive.SQL Workstation Engine.lnk = C:\PVSW\Bin\W3DBSMGR.EXE
    O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    O4 - Global Startup: Stop Watch.lnk = C:\Program Files\XNote Stopwatch\xnsw.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\program files\neoteris\secure application manager\samnsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\neoteris\secure application manager\samnsp.dll
    O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://vendors.carolinas.org/dana-cached/setup/NeoterisSetup.cab
    O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://support.coastalsystems.net/Launchers/setup.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1184694856794
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1184698471780
    O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - https://cert.coastalsystems.net/Remote/msrdp.cab
    O16 - DPF: {8B29E7C6-6EE1-43B3-A909-C3E641F16C5F} - http://csi/wsnotify/setup/Winscribe Notification Service Client.cab
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield Setup Player) - http://winscribe/winscribe/setup/Typist/isetup.cab
    O16 - DPF: {A1B8A30B-8AAA-4A3E-8869-1DA509E8A011} (Crystal ActiveX Report Viewer Control 10.0) - http://210.55.18.50/eservice/reporting/viewer/activeXViewer10/activeXViewer.cab
    O16 - DPF: {A7B6FBFE-C894-4954-8377-D1CF19B4E07F} (Wapplink Control) - http://66.15.242.204/applets/OcxLink.cab
    O16 - DPF: {A922D52D-26B1-4672-B0AF-9673AB46F937} (InstallShield Setup Player 2K2) - http://laptop/winscribe/setup/Author/setup.exe
    O16 - DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} (VaPgCtrl Class) - http://66.45.99.198/plugin/h263ctrl.cab
    O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
    O16 - DPF: {C7DC40E0-6601-4530-9AFB-68506CAE2628} (InstallShield Setup Player 2K2) - http://66.15.242.204/Launchers/setup.exe
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://winscribe.webex.com/client/T22L/training/ieatgpc.cab
    O16 - DPF: {F3C7C5EE-8BBA-4B6E-8147-3B315A41B85B} - http://66.15.242.204/clientinstall/install.cab
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: ckpNotify - C:\WINDOWS\SYSTEM32\ckpNotify.dll
    O20 - Winlogon Notify: nnnnl - C:\WINDOWS\system32\nnnnl.dll (file missing)
    O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O20 - Winlogon Notify: wineby32 - wineby32.dll (file missing)
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: DM1Service - OLYMPUS IMAGING CORP. - C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
    O23 - Service: HP Web Jetadmin (HPWebJetadmin) - Unknown owner - C:\Program Files\HP Web Jetadmin\hpwebjetd.exe" -k runservice (file missing)
    O23 - Service: InterBase Guardian (InterBaseGuardian) - Inprise Corporation - C:\Program Files\InterBase\Bin\ibguard.exe
    O23 - Service: InterBase Server (InterBaseServer) - Inprise Corporation - C:\Program Files\InterBase\Bin\ibserver.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: WinScribe SR Purge Adaptation Service (PurgeAdaptationService) - - c:\program files\winscribe\winscribe speech recognition service\purgeadaptationservice\winscribe.services.speechrecognition.purgeadaptationservice.exe
    O23 - Service: WinScribe Speech Recognition Adapter Service (SpeechRecognitionAdapterService) - - c:\program files\winscribe\winscribe speech recognition adapter service\winscribe.services.speechrecognition.speechrecognitionadapterservice.exe
    O23 - Service: Venturi Client (Venturi2) - Venturi Wireless - c:\program files\verizon wireless\venturi\Client\ventc.exe
    O23 - Service: WinScribe Importer (wsImporterService) - WinScribe - C:\Program Files\WinScribe\Importer\wsImporterService.exe
    O23 - Service: WinScribe Dictation (WSServer) - WinScribe Inc Limited - C:\WINDOWS\system32\WSServer.exe
    O23 - Service: WinScribe SR Submitter Service (WsSubmitterService) - - c:\program files\winscribe\winscribe sr submitter\wssubmitterservice.exe
     
  6. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    [​IMG] Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. Beware it is NOT supported for use in 9x or ME and probably will not install in those systems

    Ugrading Java:
    • Download the latest version of Java Runtime Environment (JRE) 6u2.
    • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
    • Click the "Download" button to the right.
    • Check the box that says: "Accept License Agreement".
    • The page will refresh.
    • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
    • Close any programs you may have running - especially your web browser.
    • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
    • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    • Click the Remove or Change/Remove button.
    • Repeat as many times as necessary to remove each Java version.
    • Reboot your computer once all Java components are removed.
    • Then from your desktop double-click on the download to install the newest version.
    ===============
    Fix these with HiJackThis – mark them, close IE, click fix checked

    O2 - BHO: (no name) - {1A30E56A-EFCE-4861-80BB-D753CE0BD2B9} - C:\WINDOWS\system32\nnnnl.dll (file missing)

    O20 - Winlogon Notify: nnnnl - C:\WINDOWS\system32\nnnnl.dll (file missing)

    O20 - Winlogon Notify: wineby32 - wineby32.dll (file missing)

    START – RUN – type in %temp% - OK - Edit – Select all – File – Delete

    Delete everything in the C:\Windows\Temp folder or C:\WINNT\temp

    Not all temp files will delete and that is normal
    Empty the recycle bin
    Boot and post a new hijack log from normal NOT safe mode

    Please give feedback on what worked/didn’t work and the current status of your system
     
  7. planegray

    planegray Thread Starter

    Joined:
    Aug 10, 2007
    Messages:
    6
    Logfile of HijackThis v1.99.1
    Scan saved at 11:42:12 AM, on 8/11/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\00THotkey.exe
    C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\WINDOWS\system32\TFNF5.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
    C:\Program Files\HP Web Jetadmin\hpwebjetd.exe
    C:\WINDOWS\system32\TPWRTRAY.EXE
    C:\WINDOWS\System32\inetsrv\inetinfo.exe
    C:\Program Files\Apoint2K\Apoint.exe
    C:\Program Files\InterBase\Bin\ibguard.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\HP Web Jetadmin\hpwebjetd.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
    C:\WINDOWS\system32\PspContr.Exe
    C:\Program Files\Apoint2K\Apntex.exe
    C:\WINDOWS\System32\ezSP_Px.exe
    C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe
    c:\program files\winscribe\winscribe speech recognition service\purgeadaptationservice\winscribe.services.speechrecognition.purgeadaptationservice.exe
    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    c:\program files\verizon wireless\venturi\Client\ventc.exe
    C:\PROGRA~1\MICROS~3\rapimgr.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\WINDOWS\system32\WSServer.exe
    c:\program files\winscribe\winscribe sr submitter\wssubmitterservice.exe
    C:\WINDOWS\System32\mqsvc.exe
    C:\WINDOWS\System32\mqtgsvc.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\InterBase\Bin\ibserver.exe
    C:\WINDOWS\System32\dllhost.exe
    \?\C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
    C:\Program Files\D-Link AirPlus\AirPlus.exe
    C:\PVSW\Bin\W3DBSMGR.EXE
    C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    C:\Program Files\XNote Stopwatch\xnsw.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Downloads\HijackThis.exe

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
    O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
    O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 20
    O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
    O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
    O4 - HKLM\..\Run: [PspContr] PspContr.Exe
    O4 - HKLM\..\Run: [PspUsbCf] PspUsbCf.exe
    O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
    O4 - HKLM\..\Run: [Drag'n Drop CD] C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe /StartUp
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: D-Link AirPlus.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Pervasive.SQL Workstation Engine.lnk = C:\PVSW\Bin\W3DBSMGR.EXE
    O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    O4 - Global Startup: Stop Watch.lnk = C:\Program Files\XNote Stopwatch\xnsw.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\program files\neoteris\secure application manager\samnsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\neoteris\secure application manager\samnsp.dll
    O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://vendors.carolinas.org/dana-cached/setup/NeoterisSetup.cab
    O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://support.coastalsystems.net/Launchers/setup.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1184694856794
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1184698471780
    O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - https://cert.coastalsystems.net/Remote/msrdp.cab
    O16 - DPF: {8B29E7C6-6EE1-43B3-A909-C3E641F16C5F} - http://csi/wsnotify/setup/Winscribe Notification Service Client.cab
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield Setup Player) - http://winscribe/winscribe/setup/Typist/isetup.cab
    O16 - DPF: {A1B8A30B-8AAA-4A3E-8869-1DA509E8A011} (Crystal ActiveX Report Viewer Control 10.0) - http://210.55.18.50/eservice/reporting/viewer/activeXViewer10/activeXViewer.cab
    O16 - DPF: {A7B6FBFE-C894-4954-8377-D1CF19B4E07F} (Wapplink Control) - http://66.15.242.204/applets/OcxLink.cab
    O16 - DPF: {A922D52D-26B1-4672-B0AF-9673AB46F937} (InstallShield Setup Player 2K2) - http://laptop/winscribe/setup/Author/setup.exe
    O16 - DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} (VaPgCtrl Class) - http://66.45.99.198/plugin/h263ctrl.cab
    O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
    O16 - DPF: {C7DC40E0-6601-4530-9AFB-68506CAE2628} (InstallShield Setup Player 2K2) - http://66.15.242.204/Launchers/setup.exe
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://winscribe.webex.com/client/T22L/training/ieatgpc.cab
    O16 - DPF: {F3C7C5EE-8BBA-4B6E-8147-3B315A41B85B} - http://66.15.242.204/clientinstall/install.cab
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: ckpNotify - C:\WINDOWS\SYSTEM32\ckpNotify.dll
    O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: DM1Service - OLYMPUS IMAGING CORP. - C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
    O23 - Service: HP Web Jetadmin (HPWebJetadmin) - Unknown owner - C:\Program Files\HP Web Jetadmin\hpwebjetd.exe" -k runservice (file missing)
    O23 - Service: InterBase Guardian (InterBaseGuardian) - Inprise Corporation - C:\Program Files\InterBase\Bin\ibguard.exe
    O23 - Service: InterBase Server (InterBaseServer) - Inprise Corporation - C:\Program Files\InterBase\Bin\ibserver.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: WinScribe SR Purge Adaptation Service (PurgeAdaptationService) - - c:\program files\winscribe\winscribe speech recognition service\purgeadaptationservice\winscribe.services.speechrecognition.purgeadaptationservice.exe
    O23 - Service: WinScribe Speech Recognition Adapter Service (SpeechRecognitionAdapterService) - - c:\program files\winscribe\winscribe speech recognition adapter service\winscribe.services.speechrecognition.speechrecognitionadapterservice.exe
    O23 - Service: Venturi Client (Venturi2) - Venturi Wireless - c:\program files\verizon wireless\venturi\Client\ventc.exe
    O23 - Service: WinScribe Importer (wsImporterService) - WinScribe - C:\Program Files\WinScribe\Importer\wsImporterService.exe
    O23 - Service: WinScribe Dictation (WSServer) - WinScribe Inc Limited - C:\WINDOWS\system32\WSServer.exe
    O23 - Service: WinScribe SR Submitter Service (WsSubmitterService) - - c:\program files\winscribe\winscribe sr submitter\wssubmitterservice.exe
     
  8. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
  9. planegray

    planegray Thread Starter

    Joined:
    Aug 10, 2007
    Messages:
    6
    YAY! Thank you so much! I felt very comfortable at the website and being replied to so fast was above my expectations. I will be sending a donation via mail. Thanks for the excellent free service!!!

    I will post feedback in the next couple of days.

    MFDnNC you couldn't be more right NC is great been here for a little more than a year and the people here are absolutely wonderful.
     
  10. planegray

    planegray Thread Starter

    Joined:
    Aug 10, 2007
    Messages:
    6
    Problem fixed no more pop ups and the alerts stating a trojan has been detected have ended.

    Thanks!
     
  11. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/607977

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice