1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Ran virus scan nothing comes up

Discussion in 'Malware and Virus Removal Archive' started by squishybear, 2008/09/03.

  1. 2008/09/03
    squishybear

    squishybear Inactive Thread Starter

    Joined:
    2008/09/03
    Messages:
    7
    Likes Received:
    0
    I ran a virus scan and nothing is coming up, but I am getting this voice over thing saying "You have won a $100 Walmart gift card ".
    Here is the hijackthis log
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 7:25:43 PM, on 9/3/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\ibmpmsvc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\wltrysvc.exe
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
    C:\Program Files\ZyXEL\AG-225H\NICServ.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\System32\QCONSVC.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\tp4serv.exe
    C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
    C:\WINDOWS\system32\RunDll32.exe
    C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
    C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
    C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
    C:\Program Files\Logitech\QuickCam\Quickcam.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe
    C:\Program Files\TiVo\Desktop\TiVoNotify.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\CyberDefender\AntiSpyware\cdas3.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Belkin\F5D7011\Belkinwcui.exe
    C:\Program Files\Belkin\F5D7011\ChkDev.exe
    C:\Program Files\ZyXEL\AG-225H\AG-225H.exe
    C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\TiVo\Desktop\TiVoServer.exe
    C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    c:\program files\internet explorer\iexplore.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\3sFi4wcb.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    R3 - URLSearchHook: MyIdentityDefender - {A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - C:\Documents and Settings\default\Local Settings\Application Data\CyberDefender\cdmyidd.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: MyIdentityDefender - {A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - C:\Documents and Settings\default\Local Settings\Application Data\CyberDefender\cdmyidd.dll
    O3 - Toolbar: MyIdentityDefender - {A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - C:\Documents and Settings\default\Local Settings\Application Data\CyberDefender\cdmyidd.dll
    O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
    O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
    O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
    O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
    O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe "
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe "
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe "
    O4 - HKLM\..\Run: [XRay] C:\Documents and Settings\default\Desktop\xraybeta\xray.exe -s
    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe "
    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
    O4 - HKCU\..\Run: [TivoTransfer] "C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe" /service /registry /auto:TivoTransfer
    O4 - HKCU\..\Run: [TivoNotify] "C:\Program Files\TiVo\Desktop\TiVoNotify.exe" /service /registry /auto:TivoNotify
    O4 - HKCU\..\Run: [TivoServer] "C:\Program Files\TiVo\Desktop\TiVoServer.exe" /service /registry
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [CyberDefender Early Detection Center] "C:\Program Files\CyberDefender\AntiSpyware\cdas3.exe" /minimize
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - Startup: MEMonitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Belkin Wireless Utility.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: ZyXEL AG-225H Utility.lnk = ?
    O8 - Extra context menu item: Copy to Semagic - C:\Program Files\Semagic\copy.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Semagic - C:\Program Files\Semagic\link.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.com/wizmodules/testgen/installers/TestGenXInstall.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1152716459933
    O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/downloadcontrol.cab
    O16 - DPF: {D258C7F3-415B-48FA-8FCF-9C9EE5723FB7} (RazzulAdmin Control) - http://www.razzul.com/Upgrade/RazzulAdmin.ocx
    O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: NICSer_AG225H - Unknown owner - C:\Program Files\ZyXEL\AG-225H\NICServ.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: QCONSVC - Unknown owner - C:\WINDOWS\System32\QCONSVC.EXE
    O23 - Service: TiVo Beacon (TivoBeacon2) - TiVo Inc. - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

    --
    End of file - 10249 bytes
     
  2. 2008/09/04
    squishybear

    squishybear Inactive Thread Starter

    Joined:
    2008/09/03
    Messages:
    7
    Likes Received:
    0
    Any help on this one?
     

  3. to hide this advert.

  4. 2008/09/04
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    You'll have to be patient. Lots of logs to 'work through' here.
     
    Arie,
    #3
  5. 2008/09/04
    squishybear

    squishybear Inactive Thread Starter

    Joined:
    2008/09/03
    Messages:
    7
    Likes Received:
    0
    hehe - sorry. I'm in the hospital so all I get to do is stare at the screen and wait. The virus is just more annoying than anything else, especially when you are trying to listen to a radio show or something.

    I will be more patient I promise! :)
     
  6. 2008/09/04
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi squishybear

    I don't see Anti-Virus program running on your system.

    One of your first defenses against infections is an Anti-virus.
    This is a Must Have to help keep you protected in today’s Internet world.
    Here are some good ones and the best part, they are Free!

    Please Download only 1 AV .

    Anti-Virus
    AVGFree
    Avast


    Download, Update and scan your computer with the AV. Quarantine/Delete anything it finds.
    Check for updates at the least once a week and do regular scans. Most AV’s can be scheduled to scan at a given time, this is also recommended.


    After doing the above then do this.

    Download ComboFix from Here to your Desktop.

    It's best to disable realtime protection applications as they sometimes interfere with the tool.
    Check this link for any applicable programs you may have.
    • Close all open programs and windows
    • Double click combofix.exe and follow the prompts.
    • Vista users right click Combofix.exe and select Run As Administrator.
    • When finished, it shall produce a log for you. Post the Combofix log
    Note: Do not mouseclick combofix's window while its running. That may cause it to stall

    Note - ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.

    Note - Combofix makes some changes when run to prevent autorun/autoplay of ALL CDs, floppies and USB devices, to assist with malware removal & increase security. If this is an issue or makes it difficult for you to use those devices, please ask how to reset it.

    Please post the Combofix log.

    Thanks
    Geri
     
    Geri,
    #5
  7. 2008/09/08
    squishybear

    squishybear Inactive Thread Starter

    Joined:
    2008/09/03
    Messages:
    7
    Likes Received:
    0
    the cyberdefender thing is my anti-virus and I have a firewall too.

    here is the log from combofix - any help would be appreciated! Thanks

    ComboFix 08-09-05.09 - default 2008-09-08 20:12:47.1 - NTFSx86
    Running from: C:\Documents and Settings\default\Desktop\ComboFix.exe
    * Created a new restore point

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008
    C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk
    C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk
    C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
    C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk
    C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk
    C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk
    C:\Documents and Settings\default\Desktop\Download programs.url
    C:\Documents and Settings\default\Desktop\Games.url
    C:\Documents and Settings\default\Desktop\Translator.url
    C:\Documents and Settings\default\Desktop\Videos.url
    C:\Documents and Settings\default\Favorites\Download programs.url
    C:\Documents and Settings\default\Favorites\Games.url
    C:\Documents and Settings\default\Favorites\Translator.url
    C:\Documents and Settings\default\Favorites\Videos.url
    C:\Documents and Settings\default\Start Menu\Programs\Download programs.url
    C:\Documents and Settings\default\Start Menu\Programs\Games.url
    C:\Documents and Settings\default\Start Menu\Programs\Translator.url
    C:\Documents and Settings\default\Start Menu\Programs\Videos.url
    C:\Documents and Settings\Guest\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk
    C:\Documents and Settings\NetworkService\Cookies\system@trafficmp[2].txt
    C:\Documents and Settings\NetworkService\Cookies\system@wat.contextweb[2].txt
    C:\Documents and Settings\NetworkService\Cookies\system@zedo[2].txt
    C:\WINDOWS\system32\a.exe

    .
    ((((((((((((((((((((((((( Files Created from 2008-08-09 to 2008-09-09 )))))))))))))))))))))))))))))))
    .

    2008-09-04 08:04 . 2008-09-07 13:44 54,156 --ah----- C:\WINDOWS\QTFont.qfn
    2008-09-04 08:04 . 2008-09-04 08:04 1,409 --a------ C:\WINDOWS\QTFont.for
    2008-09-03 19:15 . 2008-09-03 19:15 <DIR> d-------- C:\Program Files\Trend Micro
    2008-09-03 18:21 . 2006-12-31 07:57 7,208 --------- C:\WINDOWS\system32\secupd.sig
    2008-09-03 18:21 . 2006-12-31 07:57 7,208 --a------ C:\WINDOWS\system32\dllcache\secupd.sig
    2008-09-03 18:21 . 2006-12-31 07:57 4,569 --------- C:\WINDOWS\system32\secupd.dat
    2008-09-03 18:21 . 2006-12-31 07:57 4,569 --a------ C:\WINDOWS\system32\dllcache\secupd.dat
    2008-09-03 15:52 . 2008-09-04 12:58 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
    2008-09-03 11:00 . 2008-09-03 11:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
    2008-09-03 10:57 . 2008-09-03 10:58 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
    2008-09-03 10:57 . 2008-09-03 10:57 <DIR> d-------- C:\Documents and Settings\default\Application Data\SUPERAntiSpyware.com
    2008-08-15 14:32 . 2008-08-15 14:32 0 --a------ C:\WINDOWS\system32\3sFi4wcb.exe.a_a
    2008-08-15 12:31 . 2008-09-08 17:58 83,458 --a------ C:\WINDOWS\system32\3sFi4wcb.exe
    2008-08-15 12:16 . 2008-08-15 12:15 29,760 --a------ C:\WINDOWS\system32\87mws61n.exe
    2008-08-15 12:16 . 2008-08-15 12:16 0 --a------ C:\WINDOWS\system32\87mws61n.exe.a_a
    2008-08-14 06:22 . 2008-08-14 06:22 197 --a------ C:\WINDOWS\system32\MRT.INI
    2008-08-13 13:48 . 2008-05-01 10:30 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-09-07 18:22 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
    2008-09-02 11:52 --------- d-----w C:\Program Files\Semagic
    2008-07-13 15:42 --------- d-----w C:\Program Files\V CAST Music with Rhapsody
    2008-07-13 15:24 --------- d-----w C:\Program Files\Real
    2008-07-12 00:39 --------- d-----w C:\Program Files\CyberDefender
    2008-07-11 18:32 67,424 ----a-w C:\WINDOWS\system32\drivers\CDAVFS.sys
    2008-07-10 20:00 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
    2008-07-09 02:00 --------- d-----w C:\Documents and Settings\default\Application Data\CoreFTP
    2007-07-22 14:55 632 ----a-w C:\Program Files\Shortcut to AudioVideo_To_Exe(English).lnk
    2007-07-22 14:43 3,484,160 ----a-w C:\Program Files\AudioVideo_To_Exe(English).exe
    2007-06-07 03:03 3,655,608 ----a-w C:\Program Files\FLV PlayerRCATSetup.exe
    2007-06-07 03:02 25,990,392 ----a-w C:\Program Files\FLV PlayerRCSetup.exe
    2007-04-30 18:04 723 ----a-w C:\Program Files\INSTALL.LOG
    2006-05-03 10:06 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
    2007-02-21 11:47 31,744 --sh--r C:\WINDOWS\system32\msfDX.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} "= "C:\Documents and Settings\default\Local Settings\Application Data\CyberDefender\cdmyidd.dll" [2008-08-25 3790152]

    [HKEY_CLASSES_ROOT\clsid\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6}]
    [HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar.1]
    [HKEY_CLASSES_ROOT\TypeLib\{CD24EB02-9831-4838-99D0-726D411B1328}]
    [HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6}]
    2008-08-25 11:40 3790152 --a------ C:\Documents and Settings\default\Local Settings\Application Data\CyberDefender\cdmyidd.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} "= "C:\Documents and Settings\default\Local Settings\Application Data\CyberDefender\cdmyidd.dll" [2008-08-25 3790152]

    [HKEY_CLASSES_ROOT\clsid\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6}]
    [HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar.1]
    [HKEY_CLASSES_ROOT\TypeLib\{CD24EB02-9831-4838-99D0-726D411B1328}]
    [HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} "= "C:\Documents and Settings\default\Local Settings\Application Data\CyberDefender\cdmyidd.dll" [2008-08-25 3790152]

    [HKEY_CLASSES_ROOT\clsid\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6}]
    [HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar.1]
    [HKEY_CLASSES_ROOT\TypeLib\{CD24EB02-9831-4838-99D0-726D411B1328}]
    [HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "= "C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
    "CyberDefender Early Detection Center "= "C:\Program Files\CyberDefender\AntiSpyware\cdas3.exe" [2008-08-26 619848]
    "SUPERAntiSpyware "= "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-08-19 1576176]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "QCWLICON "= "C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE" [2002-07-15 49152]
    "BMMGAG "= "C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2002-06-28 64000]
    "TPHOTKEY "= "C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [2002-06-28 86016]
    "Adobe Photo Downloader "= "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344]
    "SunJavaUpdateSched "= "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
    "TkBellExe "= "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-04-30 151597]
    "QuickTime Task "= "C:\Program Files\QuickTime\qttask.exe" [2007-06-29 286720]
    "iTunesHelper "= "C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-10 270648]
    "LogitechCommunicationsManager "= "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 563984]
    "LogitechQuickCamRibbon "= "C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 2027792]
    "TrackPointSrv "= "tp4serv.exe" [2002-06-19 C:\WINDOWS\system32\tp4serv.exe]
    "TP4EX "= "tp4ex.exe" [2002-02-22 C:\WINDOWS\system32\TP4EX.exe]
    "AGRSMMSG "= "AGRSMMSG.exe" [2003-06-27 C:\WINDOWS\AGRSMMSG.exe]

    C:\Documents and Settings\default\Start Menu\Programs\Startup\
    MEMonitor.lnk - C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe [2008-05-24 951640]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-03-30 113664]
    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
    Belkin Wireless Utility.lnk - C:\Program Files\Belkin\F5D7011\Belkinwcui.exe [2007-03-25 1572864]
    Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
    ZyXEL AG-225H Utility.lnk - C:\Program Files\ZyXEL\AG-225H\AG-225H.exe [2008-04-11 2026496]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} "= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "VIDC.I420 "= i420vfw.dll
    "vidc.yv12 "= yv12vfw.dll
    "vidc.tscc "= tsccvid.dll 0

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride "=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe "=
    "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe "=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe "=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe "=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe "=
    "C:\\Program Files\\LimeWire\\LimeWire.exe "=
    "C:\\Program Files\\Mozilla Firefox\\firefox.exe "=
    "C:\\Program Files\\iTunes\\iTunes.exe "=
    "C:\\PROGRA~1\\TESTOUT\\cmi\\Navigator.exe "=
    "C:\\WINDOWS\\system32\\dpvsetup.exe "=
    "C:\\Program Files\\TESTOUT\\CMI\\NAVIGATOR.EXE "= C:\\Program Files\\TESTOUT\\cmi\\Navigator.exe
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "C:\\Program Files\\Real\\RealPlayer\\realplay.exe "=
    "C:\\Program Files\\Java\\jre1.6.0_02\\bin\\javaw.exe "=
    "C:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaw.exe "=
    "C:\\Program Files\\V CAST Music with Rhapsody\\rhapsody.exe "=
    "C:\\Program Files\\CyberDefender\\AntiSpyware\\cdas3.exe "=

    R1 IBMTPCHK;IBMTPCHK;C:\WINDOWS\system32\drivers\IBMBLDID.SYS [2002-07-15 2295]
    R1 TPPWR;TPPWR;C:\WINDOWS\system32\drivers\Tppwr.sys [2002-06-28 12288]
    R3 CDAVFS;CDAVFS;C:\WINDOWS\system32\DRIVERS\CDAVFS.sys [2008-07-11 67424]
    R3 Tp4Track;IBM PS/2 TrackPoint Driver;C:\WINDOWS\system32\DRIVERS\tp4track.sys [2002-06-19 14096]
    R3 ZDA211U(ZyXEL);ZyXEL AG-225H 802.11a/b/g Wi-Fi Finder & USB Adapter Driver(ZyXEL);C:\WINDOWS\system32\DRIVERS\zdA211u.sys [2005-10-04 360448]

    *Newly Created Service* - PROCEXP90
    .
    Contents of the 'Scheduled Tasks' folder
    .
    - - - - ORPHANS REMOVED - - - -

    HKLM-Run-XRay - C:\Documents and Settings\default\Desktop\xraybeta\xray.exe
    HKLM-Run-UC_SMB - (no file)


    .
    ------- Supplementary Scan -------
    .
    FireFox -: Profile - C:\Documents and Settings\default\Application Data\Mozilla\Firefox\Profiles\d4bc9vug.default\
    FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/
    FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
    FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npagent.dll
    FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npitunes.dll
    FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npsnapfish.dll
    FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
    FF -: plugin - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
    FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
    FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
    .
    .
    ------- File Associations (Beta) -------
    .
    .

    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-09-08 20:29:40
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2008-09-08 20:40:58
    ComboFix-quarantined-files.txt 2008-09-09 00:40:45

    Pre-Run: 19,095,904,256 bytes free
    Post-Run: 20,506,050,560 bytes free

    195 --- E O F --- 2008-09-04 16:59:31
     
  8. 2008/09/08
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi

    Please do this.

    Highlight and copy the contents of the code box below and paste it into a blank Notepad, then save it to your desktop as;

    Filename: CFScript.txt
    Save As Type: All Files (*.*)

    Close all other windows and programs. Now drag the CFScript.txt onto ComboFix.exe and drop it, using the left mouse button.
    Click here to see how to use CFScript.txt
    Combofix should run and may reboot the computer when it's done. A log will open when it's complete. Post the contents of that log and another fresh HijackThis log.

    Please do not click on the ComboFix window while it is running a scan. This can cause it to stall.

    Code:
    File::
    C:\WINDOWS\system32\3sFi4wcb.exe.a_a
    C:\WINDOWS\system32\3sFi4wcb.exe
    C:\WINDOWS\system32\87mws61n.exe.a_a
    C:\WINDOWS\system32\87mws61n.exe 
    Please post the Combofix log.

    Thanks
    Geri
     
    Geri,
    #7
  9. 2008/09/19
    squishybear

    squishybear Inactive Thread Starter

    Joined:
    2008/09/03
    Messages:
    7
    Likes Received:
    0
    Ok done.

    here is the combofix log

    ComboFix 08-09-05.09 - default 2008-09-19 18:54:16.2 - NTFSx86
    Running from: C:\Documents and Settings\default\Desktop\ComboFix.exe
    Command switches used :: C:\Documents and Settings\default\Desktop\CFScript.txt
    * Created a new restore point

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .
    - REDUCED FUNCTIONALITY MODE -
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\WINDOWS\system32\3sFi4wcb.exe
    C:\WINDOWS\system32\3sFi4wcb.exe.a_a
    C:\WINDOWS\system32\87mws61n.exe
    C:\WINDOWS\system32\87mws61n.exe.a_a

    .
    ((((((((((((((((((((((((( Files Created from 2008-08-19 to 2008-09-19 )))))))))))))))))))))))))))))))
    .

    2008-09-18 13:17 . 2008-09-18 13:17 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\SUPERAntiSpyware.com
    2008-09-04 08:04 . 2008-09-19 18:40 54,156 --ah----- C:\WINDOWS\QTFont.qfn
    2008-09-04 08:04 . 2008-09-04 08:04 1,409 --a------ C:\WINDOWS\QTFont.for
    2008-09-03 19:15 . 2008-09-03 19:15 <DIR> d-------- C:\Program Files\Trend Micro
    2008-09-03 18:21 . 2006-12-31 07:57 7,208 --------- C:\WINDOWS\system32\secupd.sig
    2008-09-03 18:21 . 2006-12-31 07:57 7,208 --a------ C:\WINDOWS\system32\dllcache\secupd.sig
    2008-09-03 18:21 . 2006-12-31 07:57 4,569 --------- C:\WINDOWS\system32\secupd.dat
    2008-09-03 18:21 . 2006-12-31 07:57 4,569 --a------ C:\WINDOWS\system32\dllcache\secupd.dat
    2008-09-03 15:52 . 2008-09-04 12:58 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
    2008-09-03 11:00 . 2008-09-03 11:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
    2008-09-03 10:57 . 2008-09-03 10:58 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
    2008-09-03 10:57 . 2008-09-03 10:57 <DIR> d-------- C:\Documents and Settings\default\Application Data\SUPERAntiSpyware.com

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-09-07 18:22 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
    2008-09-02 11:52 --------- d-----w C:\Program Files\Semagic
    2007-07-22 14:55 632 ----a-w C:\Program Files\Shortcut to AudioVideo_To_Exe(English).lnk
    2007-07-22 14:43 3,484,160 ----a-w C:\Program Files\AudioVideo_To_Exe(English).exe
    2007-06-07 03:03 3,655,608 ----a-w C:\Program Files\FLV PlayerRCATSetup.exe
    2007-06-07 03:02 25,990,392 ----a-w C:\Program Files\FLV PlayerRCSetup.exe
    2007-04-30 18:04 723 ----a-w C:\Program Files\INSTALL.LOG
    2006-05-03 10:06 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
    2007-02-21 11:47 31,744 --sh--r C:\WINDOWS\system32\msfDX.dll
    .

    ((((((((((((((((((((((((((((( snapshot@2008-09-08_20.39.31.58 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2008-08-05 18:11:01 15,888,504 ----a-w C:\WINDOWS\system32\MRT.exe
    + 2008-08-26 20:28:12 16,208,504 ----a-w C:\WINDOWS\system32\MRT.exe
    - 2006-10-19 01:47:20 295,936 ------w C:\WINDOWS\system32\wmpeffects.dll
    + 2008-06-24 22:12:58 295,936 ------w C:\WINDOWS\system32\wmpeffects.dll
    + 2008-04-15 17:54:19 1,724,416 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\GdiPlus.dll
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} "= "C:\Documents and Settings\default\Local Settings\Application Data\CyberDefender\cdmyidd.dll" [2008-08-25 3790152]

    [HKEY_CLASSES_ROOT\clsid\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6}]
    [HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar.1]
    [HKEY_CLASSES_ROOT\TypeLib\{CD24EB02-9831-4838-99D0-726D411B1328}]
    [HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6}]
    2008-08-25 11:40 3790152 --a------ C:\Documents and Settings\default\Local Settings\Application Data\CyberDefender\cdmyidd.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} "= "C:\Documents and Settings\default\Local Settings\Application Data\CyberDefender\cdmyidd.dll" [2008-08-25 3790152]

    [HKEY_CLASSES_ROOT\clsid\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6}]
    [HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar.1]
    [HKEY_CLASSES_ROOT\TypeLib\{CD24EB02-9831-4838-99D0-726D411B1328}]
    [HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} "= "C:\Documents and Settings\default\Local Settings\Application Data\CyberDefender\cdmyidd.dll" [2008-08-25 3790152]

    [HKEY_CLASSES_ROOT\clsid\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6}]
    [HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar.1]
    [HKEY_CLASSES_ROOT\TypeLib\{CD24EB02-9831-4838-99D0-726D411B1328}]
    [HKEY_CLASSES_ROOT\Cdmyidd.SecurityToolbar]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "= "C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
    "CyberDefender Early Detection Center "= "C:\Program Files\CyberDefender\AntiSpyware\cdas3.exe" [2008-08-26 619848]
    "SUPERAntiSpyware "= "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-08-19 1576176]
    "Google Update "= "C:\Documents and Settings\default\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-16 133104]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "QCWLICON "= "C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE" [2002-07-15 49152]
    "BMMGAG "= "C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2002-06-28 64000]
    "TPHOTKEY "= "C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [2002-06-28 86016]
    "Adobe Photo Downloader "= "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344]
    "SunJavaUpdateSched "= "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
    "TkBellExe "= "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-04-30 151597]
    "QuickTime Task "= "C:\Program Files\QuickTime\qttask.exe" [2007-06-29 286720]
    "iTunesHelper "= "C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-10 270648]
    "LogitechCommunicationsManager "= "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 563984]
    "LogitechQuickCamRibbon "= "C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 2027792]
    "TrackPointSrv "= "tp4serv.exe" [2002-06-19 C:\WINDOWS\system32\tp4serv.exe]
    "TP4EX "= "tp4ex.exe" [2002-02-22 C:\WINDOWS\system32\TP4EX.exe]
    "AGRSMMSG "= "AGRSMMSG.exe" [2003-06-27 C:\WINDOWS\AGRSMMSG.exe]

    C:\Documents and Settings\default\Start Menu\Programs\Startup\
    MEMonitor.lnk - C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe [2008-05-24 951640]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-03-30 113664]
    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
    Belkin Wireless Utility.lnk - C:\Program Files\Belkin\F5D7011\Belkinwcui.exe [2007-03-25 1572864]
    Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
    ZyXEL AG-225H Utility.lnk - C:\Program Files\ZyXEL\AG-225H\AG-225H.exe [2008-04-11 2026496]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} "= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "VIDC.I420 "= i420vfw.dll
    "vidc.yv12 "= yv12vfw.dll
    "vidc.tscc "= tsccvid.dll 0

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride "=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe "=
    "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe "=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe "=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe "=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe "=
    "C:\\Program Files\\LimeWire\\LimeWire.exe "=
    "C:\\Program Files\\Mozilla Firefox\\firefox.exe "=
    "C:\\Program Files\\iTunes\\iTunes.exe "=
    "C:\\PROGRA~1\\TESTOUT\\cmi\\Navigator.exe "=
    "C:\\WINDOWS\\system32\\dpvsetup.exe "=
    "C:\\Program Files\\TESTOUT\\CMI\\NAVIGATOR.EXE "= C:\\Program Files\\TESTOUT\\cmi\\Navigator.exe
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "C:\\Program Files\\Real\\RealPlayer\\realplay.exe "=
    "C:\\Program Files\\Java\\jre1.6.0_02\\bin\\javaw.exe "=
    "C:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaw.exe "=
    "C:\\Program Files\\V CAST Music with Rhapsody\\rhapsody.exe "=
    "C:\\Program Files\\CyberDefender\\AntiSpyware\\cdas3.exe "=

    R1 IBMTPCHK;IBMTPCHK;C:\WINDOWS\system32\drivers\IBMBLDID.SYS [2002-07-15 2295]
    R1 TPPWR;TPPWR;C:\WINDOWS\system32\drivers\Tppwr.sys [2002-06-28 12288]
    R2 NICSer_AG225H;NICSer_AG225H;C:\Program Files\ZyXEL\AG-225H\NICServ.exe [2005-06-15 529920]
    R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
    R3 CDAVFS;CDAVFS;C:\WINDOWS\system32\DRIVERS\CDAVFS.sys [2008-07-11 67424]
    R3 Tp4Track;IBM PS/2 TrackPoint Driver;C:\WINDOWS\system32\DRIVERS\tp4track.sys [2002-06-19 14096]
    R3 ZDA211U(ZyXEL);ZyXEL AG-225H 802.11a/b/g Wi-Fi Finder & USB Adapter Driver(ZyXEL);C:\WINDOWS\system32\DRIVERS\zdA211u.sys [2005-10-04 360448]
    .
    Contents of the 'Scheduled Tasks' folder
    .

    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-09-19 18:59:11
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2008-09-19 19:13:03
    ComboFix-quarantined-files.txt 2008-09-19 23:12:57
    ComboFix2.txt 2008-09-09 00:41:03

    Pre-Run: 21,171,445,760 bytes free
    Post-Run: 21,272,092,672 bytes free

    157 --- E O F --- 2008-09-10 23:00:26
     
  10. 2008/09/19
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi
    Why did you run combofix in safe mode?

    Please run it again in normal mode and post the log.

    Geri
     
    Geri,
    #9
  11. 2008/09/19
    squishybear

    squishybear Inactive Thread Starter

    Joined:
    2008/09/03
    Messages:
    7
    Likes Received:
    0
    Is this a setting for the combofix or are you talking about my computer? My computer is in normal mode and I did it from my desktop while signed in normally?
     
  12. 2008/09/20
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi
    OK sorry, just found out that combofix now adds this to it's log if combofix is more then 10 days old.
    "REDUCED FUNCTIONALITY MODE"

    Are you still hearing voices?

    Geri
     
  13. 2008/09/20
    squishybear

    squishybear Inactive Thread Starter

    Joined:
    2008/09/03
    Messages:
    7
    Likes Received:
    0
    NO! It seemed to work fine last night, I think you got it!

    THANK YOU SOOOOOOOOOOOOO MUCH!
     
  14. 2008/09/20
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi
    OK that's good.

    Still a couple things to do.

    Download ATF Cleaner by Atribune and save it to your Desktop.
    This is a good tool to get rid of the temporary garbage you pick up while surfing the net.
    Double click ATF-Cleaner.exe to run the program.
    Check the boxes to the left of:

    Windows Temp
    Current User Temp
    All Users Temp
    Cookies
    Temporary Internet Files
    Prefetch
    Java Cache
    Recycle bin


    The rest are optional - if you want it to remove everything check "Select All ".
    Finally, click Empty Selected. When you get the "Done Cleaning" message, click OK.

    Now lets get a on line scan.

    Please do an online scan with Kaspersky WebScanner

    Click on "Accept" If your pop "“up blocker blocks any windows from opening.

    Click Run on the window that opens.
    Windows Vista users you must open the web browser using the Run as Administrator command.
    • The program will launch and then begin downloading the latest definition files:
    • Under Scan on the left side.Click on My Computer
    • This will start the program and scan your system.
    • Click the "Scan Report" On the left side.
    • The scan will take a while so be patient and let it run.
    • Once the scan is complete it will display if your system has been infected.
      • Click the Save Report As button, and in the Browse dialog box, type a name for the scan report file that you want to create and select its type Text file. Click OK to save the file.:
    • Save the text file to your desktop.
    • Copy and paste that information in your next post.

    Please post the Kaspersky results.

    Thanks
    Geri
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.