1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Solved: Problem with WinANtivirus 2007 and others

Discussion in 'Virus & Other Malware Removal' started by chris.b, Jul 30, 2007.

Thread Status:
Not open for further replies.
Advertisement
  1. chris.b

    chris.b Thread Starter

    Joined:
    Jul 30, 2007
    Messages:
    13
    Hi to all ;) - Im new and infected and pissed! I deactivated my Panda because of inteference to my network connection with printer - anyway - i get opened sites like :recross.com, broadcasting.com, errorsafe, winantivirus pro 2007 and very often signs that im infected and that i have to download winantivirus 2007 (n) - can someone helpp!!! :eek: thanx!



    Logfile of HijackThis v1.99.1
    Scan saved at 9:16:59 μμ, on 30/7/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\SYSTEM32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
    C:\WINDOWS\system32\drivers\CIR.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Documents and Settings\user\Επιφάνεια εργασίας\hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.gr/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Συνδέσεις
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [EOUApp] "C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe"
    O4 - HKLM\..\Run: [CIR] C:\WINDOWS\system32\drivers\CIR.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [RunOnStartup] 
    O4 - HKLM\..\Run: [PrintCovers] 
    O4 - HKLM\..\Run: [Servers] http://server.printeranywhere.com/
    O4 - HKLM\..\Run: [CloseToTrayConfirm] 
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [MemoryManager] rundll32.exe "C:\WINDOWS\system32\scswbeqr.dll",sitypnow
    O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O4 - Global Startup: Logitech SetPoint.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
    O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01_5.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe (file missing)
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
     
  2. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    If you have vundofix, remove it and get the current version

    Please download http://www.atribune.org/ccount/click.php?id=4 to C:\
    Double-click VundoFix.exe to run it.
    click the Scan for Vundo button.
    Once it's done scanning, click the Remove Vundo button.
    You will receive a prompt asking if you want to remove the files, click YES.
    Once you click yes, your desktop will go blank as it starts removing Vundo.
    When completed, it will prompt that it will shutdown your computer, click OK.
    Turn your computer back on.
    Please post the contents of C:\vundofix.txt – Even if it does not find anything.
    Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears at reboot.

    Please let Vundo finish its thing, sometimes it can take multiple passes
    ====================
    Download Superantispyware (SAS)

    http://www.superantispyware.com/superantispywarefreevspro.html

    Install it and double-click the icon on your desktop to run it.
    · It will ask if you want to update the program definitions, click Yes.
    · Under Configuration and Preferences, click the Preferences button.
    · Click the Scanning Control tab.
    · Under Scanner Options make sure the following are checked:
    o Close browsers before scanning
    o Scan for tracking cookies
    o Terminate memory threats before quarantining.
    o Please leave the others unchecked.
    o Click the Close button to leave the control center screen.
    · On the main screen, under Scan for Harmful Software click Scan your computer.
    · On the left check C:\Fixed Drive.
    · On the right, under Complete Scan, choose Perform Complete Scan.
    · Click Next to start the scan. Please be patient while it scans your computer.
    · After the scan is complete a summary box will appear. Click OK.
    · Make sure everything in the white box has a check next to it, then click Next.
    · It will quarantine what it found and if it asks if you want to reboot, click Yes.
    · To retrieve the removal information for me please do the following:
    o After reboot, double-click the SUPERAntispyware icon on your desktop.
    o Click Preferences. Click the Statistics/Logs tab.
    o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    o It will open in your default text editor (such as Notepad/Wordpad).
    o Please highlight everything in the notepad, then right-click and choose copy.
    · Click close and close again to exit the program.
    · Please paste that information here for me with a new HijackThis log.

    This can take a while!
     
  3. chris.b

    chris.b Thread Starter

    Joined:
    Jul 30, 2007
    Messages:
    13
    thanx for ur time - i hope we kill the bug!!!

    i followed the instructions

    1-----------------------------------------------------------------
    VundoFix V6.5.6

    Checking Java version...

    Java version is 1.5.0.4
    Old versions of java are exploitable and should be removed.

    Scan started at 10:07:24 μμ 30/7/2007

    Listing files found while scanning....

    C:\WINDOWS\system32\accdd.bak1
    C:\WINDOWS\system32\accdd.bak2
    C:\WINDOWS\system32\accdd.ini
    C:\WINDOWS\system32\ddcca.dll
    C:\windows\system32\vhqfoggh.dll

    Beginning removal...

    Attempting to delete C:\WINDOWS\system32\accdd.bak1
    C:\WINDOWS\system32\accdd.bak1 Has been deleted!

    Attempting to delete C:\WINDOWS\system32\accdd.bak2
    C:\WINDOWS\system32\accdd.bak2 Has been deleted!

    Attempting to delete C:\WINDOWS\system32\accdd.ini
    C:\WINDOWS\system32\accdd.ini Has been deleted!

    Attempting to delete C:\WINDOWS\system32\ddcca.dll
    C:\WINDOWS\system32\ddcca.dll Has been deleted!

    Attempting to delete C:\windows\system32\vhqfoggh.dll
    C:\windows\system32\vhqfoggh.dll Has been deleted!

    Performing Repairs to the registry.
    Done!

    2-----------------------------------------------------------------

    UPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 07/30/2007 at 11:21 PM

    Application Version : 3.9.1008

    Core Rules Database Version : 3275
    Trace Rules Database Version: 1286

    Scan type : Complete Scan
    Total Scan Time : 00:43:49

    Memory items scanned : 568
    Memory threats detected : 3
    Registry items scanned : 5142
    Registry threats detected : 18
    File items scanned : 45459
    File threats detected : 263

    Adware.Vundo Variant/Resident
    C:\WINDOWS\SYSTEM32\MLJHGFG.DLL
    C:\WINDOWS\SYSTEM32\MLJHGFG.DLL

    Adware.Vundo Variant
    C:\WINDOWS\SYSTEM32\DDABX.DLL
    C:\WINDOWS\SYSTEM32\DDABX.DLL
    HKLM\Software\Classes\CLSID\{1FB63E52-4D6E-48C1-A08F-F630FE50F337}
    HKCR\CLSID\{1FB63E52-4D6E-48C1-A08F-F630FE50F337}
    HKCR\CLSID\{1FB63E52-4D6E-48C1-A08F-F630FE50F337}\InprocServer32
    HKCR\CLSID\{1FB63E52-4D6E-48C1-A08F-F630FE50F337}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{BB336348-FD61-433A-8DE1-2E437057626D}
    HKCR\CLSID\{BB336348-FD61-433A-8DE1-2E437057626D}
    HKCR\CLSID\{BB336348-FD61-433A-8DE1-2E437057626D}\InprocServer32
    HKCR\CLSID\{BB336348-FD61-433A-8DE1-2E437057626D}\InprocServer32#ThreadingModel
    C:\WINDOWS\SYSTEM32\DDCCA.DLL
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FB63E52-4D6E-48C1-A08F-F630FE50F337}
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8245B508-2577-4EFB-8DC4-BAEF14AF5689}
    HKCR\CLSID\{8245B508-2577-4EFB-8DC4-BAEF14AF5689}
    HKCR\CLSID\{8245B508-2577-4EFB-8DC4-BAEF14AF5689}\InprocServer32
    HKCR\CLSID\{8245B508-2577-4EFB-8DC4-BAEF14AF5689}\InprocServer32#ThreadingModel
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BB336348-FD61-433A-8DE1-2E437057626D}
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{1FB63E52-4D6E-48C1-A08F-F630FE50F337}
    Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\ddabx
    Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\mljhgfg
    HKCR\CLSID\{1FB63E52-4D6E-48C1-A08F-F630FE50F337}

    Trojan.Downloader-NewJuan/VM
    C:\WINDOWS\SYSTEM32\CFTGNKLC.DLL
    C:\WINDOWS\SYSTEM32\CFTGNKLC.DLL

    Adware.Tracking Cookie
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected]cassava[1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][3].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][4].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][3].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][3].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][2].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt
    C:\Documents and Settings\user\Cookies\[email protected][1].txt

    Adware.Vundo/Traff-2
    C:\DOCUMENTS AND SETTINGS\USER\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\KXARCTM7\KCEHC_EICOOC20070702[1]

    Unclassified.Unknown Origin
    C:\PROGRAM FILES\LOGITECH\SETPOINT\SETPOINTCOMWMP9.DLL

    Trace.Known Threat Sources
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\9PGUJBHP\test[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\ODIF45QJ\CA45CXCN.js
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\LMN9YODC\no[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\9PGUJBHP\scanner[1].htm
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\5H5AB7XU\arrow[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\4HQZ49IB\ico1[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\8DY3K1IR\index[2].htm
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\NH5VYA25\download2[1].htm
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\SFTZQQRD\CARY5W9R.js
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\8DY3K1IR\index[1].htm
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\NH5VYA25\CAAJQF65.js
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\KXARCTM7\top1_menu[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\ODIF45QJ\checksoft[1].js
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\JAK7JH49\top1[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\GDENKPEF\box2[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\8DY3K1IR\masiyxanidi[1]
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\8DY3K1IR\ico2[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\SFTZQQRD\CAVMW3RT.htm
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\5H5AB7XU\wav_banner[1].swf
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\LMN9YODC\tb_01[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\TD9S9QSE\img_37[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\JAK7JH49\CA234Z7O.gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\A5XABAH8\boton1[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\ODIF45QJ\img_02[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\KXARCTM7\download2[1].htm
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\NH5VYA25\img_13[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\N1EI89EU\CAX4O71D.gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\KXARCTM7\styles[1].css
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\9PGUJBHP\logo3[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\8DY3K1IR\logo[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\NH5VYA25\footer-bg[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\SFTZQQRD\tb_03[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\LMN9YODC\body_bg[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\ODIF45QJ\boxh_bg[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\N1EI89EU\top_threats[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\4HQZ49IB\CAN2GZ71.gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\4HQZ49IB\bg_rate_right[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\8DY3K1IR\ten[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\4HQZ49IB\bt_bgT[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\NH5VYA25\img_14[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\8DY3K1IR\_affvm[1]
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\SFTZQQRD\star_full[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\KY4K0QYO\pic3[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\NH5VYA25\CA0X653W.gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\TD9S9QSE\pic2[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\KY4K0QYO\bg_testi_topleft[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\LMN9YODC\index[1].htm
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\JAK7JH49\button2[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\9PGUJBHP\win1[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\NH5VYA25\2007[1].htm
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\WPEJKXEJ\img_03[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\9PGUJBHP\top_pic2[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\A5XABAH8\bg_rate_left[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\4LMFGXMF\four_plus_one[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\JAK7JH49\CAGDGHW3.js
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\KXARCTM7\img_11[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\9PGUJBHP\WinAntiVirusPro2007FreeInstall[1].exe
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\2A37PSB7\check[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\9Z73X94E\bg[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\JAK7JH49\CAY7KTIF.js
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\ODIF45QJ\img_01[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\WPEJKXEJ\icon4[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\WPEJKXEJ\img_12[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\GDENKPEF\icon5[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\KY4K0QYO\CAOD0PO7.js
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\5H5AB7XU\win2[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\9PGUJBHP\logo-bg[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\N1EI89EU\index[2].htm
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\WPEJKXEJ\ErrorSafeFreeInstallW[1].cab
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\SFTZQQRD\icon2[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\SFTZQQRD\CASJYD6P.gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\JAK7JH49\CAGHCXON.gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\N1EI89EU\icon1[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\N1EI89EU\win_fixer_banner[1].swf
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\5H5AB7XU\baba[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\9Z73X94E\box[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\4HQZ49IB\gr[1].gif
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\8DY3K1IR\download2[1].htm
    C:\Documents and Settings\user\Local Settings\Temporary Internet files\Content.IE5\9Z73X94E\CASHUN6Z.gif
     
  4. chris.b

    chris.b Thread Starter

    Joined:
    Jul 30, 2007
    Messages:
    13
    3--------------------------------------------------------------

    Logfile of HijackThis v1.99.1
    Scan saved at 11:49:34 μμ, on 30/7/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\SYSTEM32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
    C:\WINDOWS\system32\drivers\CIR.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Documents and Settings\user\Επιφάνεια εργασίας\hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.gr/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Συνδέσεις
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {5CE08366-DF53-4609-8B83-165C5962758F} - C:\WINDOWS\system32\ddabx.dll (file missing)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {C6039E6C-BDE9-4de5-BB40-768CAA584FDC} - C:\WINDOWS\system32\cftgnklc.dll (file missing)
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [EOUApp] "C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe"
    O4 - HKLM\..\Run: [CIR] C:\WINDOWS\system32\drivers\CIR.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [RunOnStartup] 
    O4 - HKLM\..\Run: [PrintCovers] 
    O4 - HKLM\..\Run: [Servers] http://server.printeranywhere.com/
    O4 - HKLM\..\Run: [CloseToTrayConfirm] 
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [MemoryManager] rundll32.exe "C:\WINDOWS\system32\scswbeqr.dll",sitypnow
    O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O4 - Global Startup: Logitech SetPoint.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
    O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01_5.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O20 - Winlogon Notify: wingdm32 - wingdm32.dll (file missing)
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe (file missing)
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
     
  5. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    I'd like to do one more thing

    NOTE: If you have downloaded ComboFix previously please delete that version and download it again!

    Download this file :

    http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
    or
    http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe

    Double click combofix.exe & follow the prompts.
    When finished, it shall produce a log for you. Post that log and a HiJack log in your next reply

    Note:
    Do not mouseclick combofix's window while its running. That may cause it to stall
     
  6. chris.b

    chris.b Thread Starter

    Joined:
    Jul 30, 2007
    Messages:
    13
    sorry for the delay - it is the hour difference and "sleep factor" , so far I havent encountered the bug yet - i think its terminated - you are very precise(y) - thank you again!:)

    1--------------------------------------------------------------------------------

    ComboFix 07-07-30.2 - "user" 2007-07-31 8:18:40.1 [GMT 3:00] - NTFS
    Microsoft Windows XP Home Edition 5.1.2600.2.1253.1.1032.18.€ΆžŸβ
    * Created a new restore point


    (((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


    C:\WINDOWS\system32\blyqmsrv.dll


    * * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


    C:\WINDOWS\system32\dretxyqc.exe
    C:\WINDOWS\system32\eesmluhk.exe
    C:\WINDOWS\system32\kfxadxwc.exe
    C:\WINDOWS\system32\pgjlrliw.exe
    C:\WINDOWS\system32\qqmajecj.exe
    C:\WINDOWS\system32\teetvjbf.exe
    C:\WINDOWS\system32\upnnheom.exe
    C:\WINDOWS\system32\yldkspow.exe


    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


    -------\LEGACY_NWSAPAGENT
    -------\NwSapAgent


    ((((((((((((((((((((((((( Files Created from 2007-06-28 to 2007-07-31 )))))))))))))))))))))))))))))))


    2007-07-31 08:16 51,200 --a------ C:\WINDOWS\nircmd.exe
    2007-07-30 22:29 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
    2007-07-30 22:27 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
    2007-07-30 22:27 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
    2007-07-30 22:27 <DIR> d-------- C:\DOCUME~1\user\APPLIC~1\SUPERAntiSpyware.com
    2007-07-30 22:16 6,466 ---hs---- C:\WINDOWS\system32\xbadd.bak1
    2007-07-30 22:07 <DIR> d-------- C:\VundoFix Backups
    2007-07-30 22:06 109,056 --a------ C:\VundoFix.exe
    2007-07-30 17:58 126,016 --a------ C:\WINDOWS\system32\scswbeqr.dll
    2007-07-30 13:24 <DIR> d-------- C:\Program Files\Enigma Software Group
    2007-07-30 00:24 4,466 --a------ C:\WINDOWS\system32\tmp.reg
    2007-07-30 00:23 53,248 --a------ C:\WINDOWS\system32\Process.exe
    2007-07-30 00:23 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
    2007-07-30 00:23 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
    2007-07-29 17:59 126,016 --a------ C:\WINDOWS\system32\jqfsqfam.dll
    2007-07-28 22:38 <DIR> d-------- C:\Program Files\PartyGaming
    2007-07-27 11:56 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
    2007-07-27 11:56 <DIR> d-------- C:\DOCUME~1\ADMINI~1\’&#152; &#946;&#154;&#154;¨&#152;*&#945; £¦¬
    2007-07-27 11:56 <DIR> d-------- C:\DOCUME~1\ADMINI~1\„§**&#945;¤&#156;*&#152; &#156;¨&#154;&#152;©&#949;&#152;&#63737;
    2007-07-27 11:41 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
    2007-07-26 14:51 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
    2007-07-23 19:41 <DIR> d-------- C:\DOCUME~1\user\APPLIC~1\PCTV4Me
    2007-07-23 19:41 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\PCTV4Me
    2007-07-12 22:10 <DIR> d-------- C:\WINDOWS\Downloaded Installations
    2007-06-03 12:59 <DIR> d-------- C:\Program Files\PrinterAnywhere
    2007-06-02 10:36 <DIR> d-------- C:\Program Files\Hp
    2007-06-02 10:34 <DIR> d-------- C:\temp\FixEngine
    2007-06-02 10:34 <DIR> d-------- C:\temp
    2007-06-02 10:14 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
    2007-06-02 10:14 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys


    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

    2007-07-30 17:55 --------- d-------- C:\Program Files\ScanPro
    2007-07-28 22:36 --------- d-------- C:\Program Files\PKR
    2007-07-17 17:55 --------- d--h----- C:\Program Files\InstallShield Installation Information
    2007-07-17 17:55 --------- d-------- C:\Program Files\Common Files\Panda Software
    2007-07-17 09:21 --------- d-------- C:\Program Files\QuickTime
    2007-07-17 09:21 --------- d-------- C:\Program Files\MSN Messenger
    2007-07-17 09:21 --------- d-------- C:\Program Files\iTunes
    2007-07-12 23:27 86116 --a------ C:\WINDOWS\system32\perfc008.dat
    2007-07-12 23:27 506234 --a------ C:\WINDOWS\system32\perfh008.dat
    2007-07-11 12:46 --------- d-------- C:\Program Files\Messenger
    2007-05-16 18:12 683520 --a------ C:\WINDOWS\system32\inetcomm.dll


    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5CE08366-DF53-4609-8B83-165C5962758F}]
    C:\WINDOWS\system32\ddabx.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C6039E6C-BDE9-4de5-BB40-768CAA584FDC}]
    C:\WINDOWS\system32\cftgnklc.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 15:43]
    "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 12:25]
    "RTHDCPL"="RTHDCPL.EXE" [2006-02-10 13:25 C:\WINDOWS\RTHDCPL.exe]
    "Alcmtr"="ALCMTR.EXE" [2005-05-03 13:43 C:\WINDOWS\Alcmtr.exe]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-16 11:32]
    "IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 13:37]
    "IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 12:41]
    "EOUApp"="C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe" [2005-11-28 12:47]
    "BluetoothAuthenticationAgent"="bthprops.cpl" [2006-03-02 15:00 C:\WINDOWS\system32\bthprops.cpl]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]
    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 10:36]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
    "RunOnStartup"="-1 (0xffffffff)" []
    "PrintCovers"="1 (0x1)" []
    "Servers"="http://server.printeranywhere.com/\0\0" []
    "CloseToTrayConfirm"="1 (0x1)" []
    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-07-19 13:03 C:\WINDOWS\KHALMNPR.Exe]
    "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
    "SpyHunter"="C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe" [2007-04-26 19:03]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 15:00]
    "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" []
    "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 13:55]
    "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]

    C:\Documents and Settings\All Users\Start Menu\¨¦&#154;¨&#945;££&#152;«&#152;\„&#901;&#901;&#949;¤&#158;©&#158;\
    InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2006-11-15 11:41:50]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "DisableRegistryTools"=0 (0x0)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wingdm32]
    wingdm32.dll

    R0 O2MDRDR;O2MDRDR;C:\WINDOWS\system32\DRIVERS\o2media.sys
    R0 O2SDRDR;O2SDRDR;C:\WINDOWS\system32\DRIVERS\o2sd.sys
    R1 SASDIFSV;SASDIFSV;\??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
    R1 SASKUTIL;SASKUTIL;\??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
    R2 BthServ;Bluetooth Support Service;C:\WINDOWS\system32\svchost.exe -k bthsvcs
    R2 MTC0301_CIR;CIR Device;C:\WINDOWS\system32\drivers\CIR.sys
    R2 s24trans;‹&#156;«&#152;*¦¨&#945; WLAN;C:\WINDOWS\system32\DRIVERS\s24trans.sys
    R3 BthEnum;¨&#950;&#154;¨&#152;££&#152; ¦›&#947;&#154;&#158;©&#158;&#63737; &#152;&#949;«&#158;©&#158;&#63737; £§&#902;¦&#901; Bluetooth;C:\WINDOWS\system32\DRIVERS\BthEnum.sys
    R3 BTHMODEM;¨&#950;&#154;¨&#152;££&#152; ¦›&#947;&#154;&#158;©&#158;&#63737; ©&#156;*¨*&#152;&#901;&#947;&#63737; &#156;§*&#901;¦*¤&#944;¤&#949;&#152;&#63737; Bluetooth;C:\WINDOWS\system32\DRIVERS\bthmodem.sys
    R3 BthPan;Bluetooth Device (Personal Area Network);C:\WINDOWS\system32\DRIVERS\bthpan.sys
    R3 BTHUSB;¨&#950;&#154;¨&#152;££&#152; ¦›&#947;&#154;&#158;©&#158;&#63737; &#159;&#951;¨&#152;&#63737; USB &#152;©&#951;¨£&#152;«¦¬ Bluetooth;C:\WINDOWS\system32\Drivers\BTHUSB.sys
    R3 E100B;Intel(R) PRO Network Connection Driver;C:\WINDOWS\system32\DRIVERS\e100b325.sys
    R3 HSF_DPV;HSF_DPV;C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
    R3 HSFHWAZL;HSFHWAZL;C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys
    R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI);C:\WINDOWS\system32\DRIVERS\rfcomm.sys
    R3 SASENUM;SASENUM;\??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
    R3 SynTP;Synaptics TouchPad Driver;C:\WINDOWS\system32\DRIVERS\SynTP.sys
    R3 w39n51;Intel(R) PRO/Wireless 3945ABG Adapter Driver;C:\WINDOWS\system32\DRIVERS\w39n51.sys
    S3 BTHPORT;¨&#950;&#154;¨&#152;££&#152; ¦›&#947;&#154;&#158;©&#158;&#63737; &#159;&#951;¨&#152;&#63737; Bluetooth;C:\WINDOWS\system32\Drivers\BTHport.sys
    S3 HidBth;Microsoft Bluetooth HID Miniport;C:\WINDOWS\system32\DRIVERS\hidbth.sys
    S3 LHidKE;SetPoint HID Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\LHidKE.Sys
    S3 LMouKE;SetPoint Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\LMouKE.Sys
    S3 PavSRK.sys;PavSRK.sys;\??\C:\WINDOWS\system32\PavSRK.sys
    S3 PavTPK.sys;PavTPK.sys;\??\C:\WINDOWS\system32\PavTPK.sys
    S3 sdbus;sdbus;C:\WINDOWS\system32\DRIVERS\sdbus.sys
    S3 UIUSys;Conexant Setup API;C:\WINDOWS\system32\DRIVERS\UIUSYS.SYS

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    bthsvcs BthServ


    **************************************************************************

    catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-07-31 08:22:23
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden registry entries ...

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cursors\Schemes]
    "\xa0\3\x391\3\x38f\3\xb5\3\x390\3\x389\3\xbb\3\xb5\3\xb3\3\x38c\3\xad\3\xbd\3\xb1\3 ?W?i?n?d?o?w?s?"="",,,,,,,,,,,,,""
    "\x9a\3\x389\3\xbd\3\x38f\3\x39d\3\x38c\3\xb5\3\xbd\3\xb1\3 ?W?i?n?d?o?w?s?"=""C:\WINDOWS\Cursors\rainbow.ani,,C:\WINDOWS\Cursors\appstart.ani,C:\WINDOWS\Cursors\hourglas.ani,C:\WINDOWS\Cursors\cross.cur,,,,C:\WINDOWS\Cursors\sizens.ani,C:\WINDOWS\Cursors\sizewe.ani,C:\WINDOWS\Cursors\sizenwse.ani,C:\WINDOWS\Cursors\sizenesw.ani,,""
    "\x2020\3\x393\3\x390\3\x391\3\x38f\3 ?3?\x201d\3"=""C:\WINDOWS\Cursors\3dwarro.cur,,C:\WINDOWS\Cursors\appstar3.ani,C:\WINDOWS\Cursors\hourgla3.ani,C:\WINDOWS\Cursors\cross.cur,,,C:\WINDOWS\Cursors\3dwno.cur,C:\WINDOWS\Cursors\3dwns.cur,C:\WINDOWS\Cursors\3dwwe.cur,C:\WINDOWS\Cursors\3dwnwse.cur,C:\WINDOWS\Cursors\3dwnesw.cur,C:\WINDOWS\Cursors\3dwmove.cur,""
    "\xa7\3\xad\3\x391\3\x389\3\xb1\3 ?1?"=""C:\WINDOWS\Cursors\harrow.cur,,C:\WINDOWS\Cursors\handapst.ani,C:\WINDOWS\Cursors\hand.ani,C:\WINDOWS\Cursors\hcross.cur,C:\WINDOWS\Cursors\hibeam.cur,,C:\WINDOWS\Cursors\hnodrop.cur,C:\WINDOWS\Cursors\hns.cur,C:\WINDOWS\Cursors\hwe.cur,C:\WINDOWS\Cursors\hnwse.cur,C:\WINDOWS\Cursors\hnesw.cur,C:\WINDOWS\Cursors\hmove.cur,""
    "\xa7\3\xad\3\x391\3\x389\3\xb1\3 ?2?"=""C:\WINDOWS\Cursors\harrow.cur,,C:\WINDOWS\Cursors\handapst.ani,C:\WINDOWS\Cursors\handwait.ani,C:\WINDOWS\Cursors\hcross.cur,C:\WINDOWS\Cursors\hibeam.cur,,C:\WINDOWS\Cursors\handno.ani,C:\WINDOWS\Cursors\handns.ani,C:\WINDOWS\Cursors\handwe.ani,C:\WINDOWS\Cursors\handnwse.ani,C:\WINDOWS\Cursors\handnesw.ani,C:\WINDOWS\Cursors\hmove.cur,""
    "\x201d\3\xb5\3\x389\3\xbd\3\x39c\3\x393\3\xb1\3\x395\3\x391\3\x38f\3\x392\3"=""C:\WINDOWS\Cursors\3dgarro.cur,,C:\WINDOWS\Cursors\dinosaur.ani,C:\WINDOWS\Cursors\dinosau2.ani,C:\WINDOWS\Cursors\cross.cur,,,C:\WINDOWS\Cursors\banana.ani,C:\WINDOWS\Cursors\3dsns.cur,C:\WINDOWS\Cursors\3dgwe.cur,C:\WINDOWS\Cursors\3dsnwse.cur,C:\WINDOWS\Cursors\3dgnesw.cur,C:\WINDOWS\Cursors\3dsmove.cur,""
    "\xa0\3\x391\3\x38f\3\xb7\3\xb3\3\x38f\3\x39d\3\x38c\3\xb5\3\xbd\3\x38f\3 ?\x38c\3\x38f\3\xbd\3\x394\3\xad\3\xbb\3\x38f\3"=""C:\WINDOWS\Cursors\harrow.cur,,C:\WINDOWS\Cursors\horse.ani,C:\WINDOWS\Cursors\barber.ani,C:\WINDOWS\Cursors\hcross.cur,C:\WINDOWS\Cursors\hibeam.cur,,C:\WINDOWS\Cursors\coin.ani,C:\WINDOWS\Cursors\3dgns.cur,C:\WINDOWS\Cursors\3dgwe.cur,C:\WINDOWS\Cursors\3dgnwse.cur,C:\WINDOWS\Cursors\3dgnesw.cur,C:\WINDOWS\Cursors\3dgmove.cur,""
    "\xa3\3\x39d\3\xbd\3\x388\3\xb5\3\x393\3\xb7\3"=""C:\WINDOWS\Cursors\harrow.cur,,C:\WINDOWS\Cursors\drum.ani,C:\WINDOWS\Cursors\metronom.ani,C:\WINDOWS\Cursors\hcross.cur,C:\WINDOWS\Cursors\hibeam.cur,,C:\WINDOWS\Cursors\piano.ani,C:\WINDOWS\Cursors\hns.cur,C:\WINDOWS\Cursors\hwe.cur,C:\WINDOWS\Cursors\hnwse.cur,C:\WINDOWS\Cursors\hnesw.cur,C:\WINDOWS\Cursors\hmove.cur,""
    "\x9c\3\xb5\3\xb3\3\xad\3\x388\3\x395\3\xbd\3\x393\3\xb7\3"=""C:\WINDOWS\Cursors\larrow.cur,,C:\WINDOWS\Cursors\lappstrt.cur,C:\WINDOWS\Cursors\lwait.cur,C:\WINDOWS\Cursors\lcross.cur,C:\WINDOWS\Cursors\libeam.cur,,C:\WINDOWS\Cursors\lnodrop.cur,C:\WINDOWS\Cursors\lns.cur,C:\WINDOWS\Cursors\lwe.cur,C:\WINDOWS\Cursors\lnwse.cur,C:\WINDOWS\Cursors\lnesw.cur,C:\WINDOWS\Cursors\lmove.cur,""
    "\xa0\3\xb1\3\x391\3\xb1\3\xbb\3\xbb\3\xb1\3\xb3\3\xad\3\x392\3"=""C:\WINDOWS\Cursors\fillitup.ani,,C:\WINDOWS\Cursors\raindrop.ani,C:\WINDOWS\Cursors\counter.ani,C:\WINDOWS\Cursors\cross.cur,,,C:\WINDOWS\Cursors\wagtail.ani,C:\WINDOWS\Cursors\sizens.ani,C:\WINDOWS\Cursors\sizewe.ani,C:\WINDOWS\Cursors\sizenwse.ani,C:\WINDOWS\Cursors\sizenesw.ani,""
    "\x9c\3\x390\3\x391\3\x38f\3\x39d\3\x394\3\xb6\3\x389\3\xbd\3\x38f\3 ?3?\x201d\3"=""C:\WINDOWS\Cursors\3dgarro.cur,,C:\WINDOWS\Cursors\appstar2.ani,C:\WINDOWS\Cursors\hourgla2.ani,C:\WINDOWS\Cursors\cross.cur,,,C:\WINDOWS\Cursors\3dgno.cur,C:\WINDOWS\Cursors\3dgns.cur,C:\WINDOWS\Cursors\3dgwe.cur,C:\WINDOWS\Cursors\3dgnwse.cur,C:\WINDOWS\Cursors\3dgnesw.cur,C:\WINDOWS\Cursors\3dgmove.cur,""
    "\x9c\3\xb1\3\x39d\3\x391\3\xb1\3 ?W?i?n?d?o?w?s? ?"="C:\WINDOWS\cursors\arrow_r.cur,C:\WINDOWS\cursors\help_r.cur,C:\WINDOWS\cursors\wait_r.cur,C:\WINDOWS\cursors\busy_r.cur,C:\WINDOWS\cursors\cross_r.cur,C:\WINDOWS\cursors\beam_r.cur,C:\WINDOWS\cursors\pen_r.cur,C:\WINDOWS\cursors\no_r.cur,C:\WINDOWS\cursors\size4_r.cur,C:\WINDOWS\cursors\size3_r.cur,C:\WINDOWS\cursors\size2_r.cur,C:\WINDOWS\cursors\size1_r.cur,C:\WINDOWS\cursors\move_r.cur,C:\WINDOWS\cursors\up_r.cur"
    "\x9c\3\xb1\3\x39d\3\x391\3\xb1\3 ?W?i?n?d?o?w?s? ?(?\x38c\3\xb5\3\xb3\3\xac\3\xbb\3\xb1\3)?"="C:\WINDOWS\cursors\arrow_rm.cur,C:\WINDOWS\cursors\help_rm.cur,C:\WINDOWS\cursors\wait_rm.cur,C:\WINDOWS\cursors\busy_rm.cur,C:\WINDOWS\cursors\cross_rm.cur,C:\WINDOWS\cursors\beam_rm.cur,C:\WINDOWS\cursors\pen_rm.cur,C:\WINDOWS\cursors\no_rm.cur,C:\WINDOWS\cursors\size4_rm.cur,C:\WINDOWS\cursors\size3_rm.cur,C:\WINDOWS\cursors\size2_rm.cur,C:\WINDOWS\cursors\size1_rm.cur,C:\WINDOWS\cursors\move_rm.cur,C:\WINDOWS\cursors\up_rm.cur"
    "\x9c\3\xb1\3\x39d\3\x391\3\xb1\3 ?W?i?n?d?o?w?s? ?(?\x390\3\x38f\3\xbb\3\x39d\3 ?\x38c\3\xb5\3\xb3\3\xac\3\xbb\3\xb1\3)?"="C:\WINDOWS\cursors\arrow_rl.cur,C:\WINDOWS\cursors\help_rl.cur,C:\WINDOWS\cursors\wait_rl.cur,C:\WINDOWS\cursors\busy_rl.cur,C:\WINDOWS\cursors\cross_rl.cur,C:\WINDOWS\cursors\beam_rl.cur,C:\WINDOWS\cursors\pen_rl.cur,C:\WINDOWS\cursors\no_rl.cur,C:\WINDOWS\cursors\size4_rl.cur,C:\WINDOWS\cursors\size3_rl.cur,C:\WINDOWS\cursors\size2_rl.cur,C:\WINDOWS\cursors\size1_rl.cur,C:\WINDOWS\cursors\move_rl.cur,C:\WINDOWS\cursors\up_rl.cur"
    "\x2018\3\xbd\3\x394\3\xb5\3\x393\3\x394\3\x391\3\xb1\3\x38c\3\x38c\3\xad\3\xbd\3\xb1\3 ?W?i?n?d?o?w?s?"="C:\WINDOWS\cursors\arrow_i.cur,C:\WINDOWS\cursors\help_i.cur,C:\WINDOWS\cursors\wait_i.cur,C:\WINDOWS\cursors\busy_i.cur,C:\WINDOWS\cursors\cross_i.cur,C:\WINDOWS\cursors\beam_i.cur,C:\WINDOWS\cursors\pen_i.cur,C:\WINDOWS\cursors\no_i.cur,C:\WINDOWS\cursors\size4_i.cur,C:\WINDOWS\cursors\size3_i.cur,C:\WINDOWS\cursors\size2_i.cur,C:\WINDOWS\cursors\size1_i.cur,C:\WINDOWS\cursors\move_i.cur,C:\WINDOWS\cursors\up_i.cur"
    "\x2018\3\xbd\3\x394\3\xb5\3\x393\3\x394\3\x391\3\xb1\3\x38c\3\x38c\3\xad\3\xbd\3\xb1\3 ?W?i?n?d?o?w?s? ?(?\x38c\3\xb5\3\xb3\3\xac\3\xbb\3\xb1\3)?"="C:\WINDOWS\cursors\arrow_im.cur,C:\WINDOWS\cursors\help_im.cur,C:\WINDOWS\cursors\wait_im.cur,C:\WINDOWS\cursors\busy_im.cur,C:\WINDOWS\cursors\cross_im.cur,C:\WINDOWS\cursors\beam_im.cur,C:\WINDOWS\cursors\pen_im.cur,C:\WINDOWS\cursors\no_im.cur,C:\WINDOWS\cursors\size4_im.cur,C:\WINDOWS\cursors\size3_im.cur,C:\WINDOWS\cursors\size2_im.cur,C:\WINDOWS\cursors\size1_im.cur,C:\WINDOWS\cursors\move_im.cur,C:\WINDOWS\cursors\up_im.cur"
    "\x2018\3\xbd\3\x394\3\xb5\3\x393\3\x394\3\x391\3\xb1\3\x38c\3\x38c\3\xad\3\xbd\3\xb1\3 ?W?i?n?d?o?w?s? ?(?\x390\3\x38f\3\xbb\3\x39d\3 ?\x38c\3\xb5\3\xb3\3\xac\3\xbb\3\xb1\3)?"="C:\WINDOWS\cursors\arrow_il.cur,C:\WINDOWS\cursors\help_il.cur,C:\WINDOWS\cursors\wait_il.cur,C:\WINDOWS\cursors\busy_il.cur,C:\WINDOWS\cursors\cross_il.cur,C:\WINDOWS\cursors\beam_il.cur,C:\WINDOWS\cursors\pen_il.cur,C:\WINDOWS\cursors\no_il.cur,C:\WINDOWS\cursors\size4_il.cur,C:\WINDOWS\cursors\size3_il.cur,C:\WINDOWS\cursors\size2_il.cur,C:\WINDOWS\cursors\size1_il.cur,C:\WINDOWS\cursors\move_il.cur,C:\WINDOWS\cursors\up_il.cur"
    "\xa4\3\x395\3\x390\3\x389\3\x38a\3\xac\3 ?W?i?n?d?o?w?s? ?(?\x38c\3\xb5\3\xb3\3\xac\3\xbb\3\xb1\3)?"="C:\WINDOWS\cursors\arrow_m.cur,C:\WINDOWS\cursors\help_m.cur,C:\WINDOWS\cursors\wait_m.cur,C:\WINDOWS\cursors\busy_m.cur,C:\WINDOWS\cursors\cross_m.cur,C:\WINDOWS\cursors\beam_m.cur,C:\WINDOWS\cursors\pen_m.cur,C:\WINDOWS\cursors\no_m.cur,C:\WINDOWS\cursors\size4_m.cur,C:\WINDOWS\cursors\size3_m.cur,C:\WINDOWS\cursors\size2_m.cur,C:\WINDOWS\cursors\size1_m.cur,C:\WINDOWS\cursors\move_m.cur,C:\WINDOWS\cursors\up_m.cur"
    "\xa4\3\x395\3\x390\3\x389\3\x38a\3\xac\3 ?W?i?n?d?o?w?s? ?(?\x390\3\x38f\3\xbb\3\x39d\3 ?\x38c\3\xb5\3\xb3\3\xac\3\xbb\3\xb1\3)?"="C:\WINDOWS\cursors\arscanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    Completion time: 2007-07-31 8:26:20 - machine was rebooted
    C:\ComboFix-quarantined-files.txt ... 2007-07-31 08:23

    --- E O F ---


    2--------------------------------------------------------------------------------

    Logfile of HijackThis v1.99.1
    Scan saved at 8:31:49 &#960;&#956;, on 31/7/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\SYSTEM32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Documents and Settings\user\&#917;&#960;&#953;&#966;&#940;&#957;&#949;&#953;&#945; &#949;&#961;&#947;&#945;&#963;&#943;&#945;&#962;\hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.gr/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &#931;&#965;&#957;&#948;&#941;&#963;&#949;&#953;&#962;
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {5CE08366-DF53-4609-8B83-165C5962758F} - C:\WINDOWS\system32\ddabx.dll (file missing)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {C6039E6C-BDE9-4de5-BB40-768CAA584FDC} - C:\WINDOWS\system32\cftgnklc.dll (file missing)
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [EOUApp] "C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe"
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [RunOnStartup] &#63739;&#63739;&#63739;&#63739;
    O4 - HKLM\..\Run: [PrintCovers] 
    O4 - HKLM\..\Run: [Servers] http://server.printeranywhere.com/
    O4 - HKLM\..\Run: [CloseToTrayConfirm] 
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O4 - Global Startup: Logitech SetPoint.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
    O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01_5.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O20 - Winlogon Notify: wingdm32 - wingdm32.dll (file missing)
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe (file missing)
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

    -------------------------------------------------------------------------------------------
     
  7. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    Fix these with HiJackThis – mark them, close IE, click fix checked

    O2 - BHO: (no name) - {5CE08366-DF53-4609-8B83-165C5962758F} - C:\WINDOWS\system32\ddabx.dll (file missing)

    O2 - BHO: (no name) - {C6039E6C-BDE9-4de5-BB40-768CAA584FDC} - C:\WINDOWS\system32\cftgnklc.dll (file missing)

    O20 - Winlogon Notify: wingdm32 - wingdm32.dll (file missing)


    START – RUN – type in %temp% - OK - Edit – Select all – File – Delete

    Delete everything in the C:\Windows\Temp folder or C:\WINNT\temp

    Not all temp files will delete and that is normal
    Empty the recycle bin
    Boot and post a new hijack log from normal NOT safe mode

    Please give feedback on what worked/didn’t work and the current status of your system
     
  8. chris.b

    chris.b Thread Starter

    Joined:
    Jul 30, 2007
    Messages:
    13
    It seems your guidance and knowledge cleaned my system from the bug. I think everuthing is back at normal at the moment. Thank you - Efharisto!

    Logfile of HijackThis v1.99.1
    Scan saved at 5:49:37 &#956;&#956;, on 31/7/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\SYSTEM32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Documents and Settings\user\&#917;&#960;&#953;&#966;&#940;&#957;&#949;&#953;&#945; &#949;&#961;&#947;&#945;&#963;&#943;&#945;&#962;\hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.gr/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &#931;&#965;&#957;&#948;&#941;&#963;&#949;&#953;&#962;
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [EOUApp] "C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe"
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [RunOnStartup] &#63739;&#63739;&#63739;&#63739;
    O4 - HKLM\..\Run: [PrintCovers] 
    O4 - HKLM\..\Run: [Servers] http://server.printeranywhere.com/
    O4 - HKLM\..\Run: [CloseToTrayConfirm] 
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O4 - Global Startup: Logitech SetPoint.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
    O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01_5.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe (file missing)
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
     
  9. chris.b

    chris.b Thread Starter

    Joined:
    Jul 30, 2007
    Messages:
    13
    Logfile of HijackThis v1.99.1
    Scan saved at 5:56:17 &#956;&#956;, on 31/7/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\SYSTEM32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32Info.exe
    C:\Documents and Settings\user\&#917;&#960;&#953;&#966;&#940;&#957;&#949;&#953;&#945; &#949;&#961;&#947;&#945;&#963;&#943;&#945;&#962;\hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.gr/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &#931;&#965;&#957;&#948;&#941;&#963;&#949;&#953;&#962;
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [EOUApp] "C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe"
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [RunOnStartup] &#63739;&#63739;&#63739;&#63739;
    O4 - HKLM\..\Run: [PrintCovers] 
    O4 - HKLM\..\Run: [Servers] http://server.printeranywhere.com/
    O4 - HKLM\..\Run: [CloseToTrayConfirm] 
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O4 - Global Startup: Logitech SetPoint.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
    O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01_5.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe (file missing)
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
     
  10. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
  11. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/602663

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice