Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Redirecting Virus Angers ME!!!
   
BullGuard Antivirus Forum > Virus > Virus Questions > Redirecting Virus Angers ME!!!  
Forum Quick Jump
 
New Topic Locked Topic Printable version of : Redirecting Virus Angers ME!!!
[ << Previous Thread | Next Thread >> ]

Tyler4590
New Member


Date Joined Sep 2008
Total Posts : 7
 
   Posted 9-23-2008 7:06 (GMT +1)    Quote: Redirecting Virus Angers ME!!!Alert an admin about: Redirecting Virus Angers ME!!!
Recently I have got something that redirects me to an ad page when I click on any link in IE, Firefox, or Google Chrome, and I was wondering if I oculd get some help with that.
Here is my logfile. Please Help, Im having to search web with My Computer hahaha.
 
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:59:02 AM, on 9/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\DISC\DISCover.exe
C:\Program Files\DISC\DiscUpdMgr.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\-BLITZ-\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\program files\steam\steam.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\DISC\DiscStreamHub.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Xfire\Xfire.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Windows Live Toolbar\msn_sl.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=63&bd=PAVILION&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PAVILION&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=63&bd=PAVILION&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: The Pirate Bay Toolbar - {a33fa729-d155-4b23-842b-2c665ecabdb6} - C:\Program Files\The_Pirate_Bay\tbThe1.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: The Pirate Bay Toolbar - {a33fa729-d155-4b23-842b-2c665ecabdb6} - C:\Program Files\The_Pirate_Bay\tbThe1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe
O4 - HKLM\..\Run: [DiscUpdateManager] C:\Program Files\DISC\DiscUpdMgr.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" -start
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ALLTEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [lphc9a0j0ea3t] C:\WINDOWS\system32\lphc9a0j0ea3t.exe
O4 - HKLM\..\Run: [SMshcea0j0ea3t] C:\Program Files\shcea0j0ea3t\shcea0j0ea3t.exe
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [inrhcca0j0ea3t] C:\Documents and Settings\TLM.HPSL\Local Settings\Temp\.ttBE.tmp.exe /CR=E378D6B80573F693830D714814CC3DF8D8D351B12EE6DC1D4784A9E36E64036B41C3B800AEAD1B8FD69993875563B756FEECC7D50F3BCA48C96C6DF394C58B6B44646BD2F5CCA3F93FF274CBD765C2EBF9
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\-BLITZ-\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O4 - Global Startup: Windstream Broadband Check-up Center.lnk = C:\Program Files\ALLTEL DSL Check-up Center\bin\matcli.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://80.126.181.68/activex/AMC.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
--
End of file - 12457 bytes
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13812
 
   Posted 9-23-2008 7:19 (GMT +1)    Quote: Redirecting Virus Angers ME!!!Alert an admin about: Redirecting Virus Angers ME!!!
Hello scool
 
 
 
Click here - >> Before posting a log 
 
 
 After You have run the scan tools -
 
Reboot normally
 
Post Hijackthis log along with SuperAntiSpyware log, , C: combofix TXT  in this topic
 
Please copy and paste your log. DO NOT add it as an attachment
Kindly do not annotate or format the log with color or font changes.
 
NB. If you are using any P2P (file sharing) programs, please remove them before we clean your computer.. We do not clean logs that have P2P applications installed as this can cause reinfection during your cleaning.


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

Tyler4590
New Member


Date Joined Sep 2008
Total Posts : 7
 
   Posted 9-23-2008 7:23 (GMT +1)    Quote: Redirecting Virus Angers ME!!!Alert an admin about: Redirecting Virus Angers ME!!!
1 question first, would Bittorrent be considered p2p by your standards?
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13812
 
   Posted 9-23-2008 7:55 (GMT +1)    Quote: Redirecting Virus Angers ME!!!Alert an admin about: Redirecting Virus Angers ME!!!
Absolutely ;-)  


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

Tyler4590
New Member


Date Joined Sep 2008
Total Posts : 7
 
   Posted 9-23-2008 9:58 (GMT +1)    Quote: Redirecting Virus Angers ME!!!Alert an admin about: Redirecting Virus Angers ME!!!
Ive spent hours doing what the "Before posting a log" thread says, and I ran ComboFix and I think it fixed the problem I think. And on that note, do you have any information on an icon that randomly appears on desktop named "Casino". Ill just be glad when this is taken care of cry and also should i post my log here or in the place stated on "before you post your log".

Post Edited (Tyler4590) : 23-09-2008 09:29:38 GMT

Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13812
 
   Posted 9-23-2008 10:37 (GMT +1)    Quote: Redirecting Virus Angers ME!!!Alert an admin about: Redirecting Virus Angers ME!!!
Post the logs in this topic, as written in my first reply ;-)


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

Tyler4590
New Member


Date Joined Sep 2008
Total Posts : 7
 
   Posted 9-23-2008 11:51 (GMT +1)    Quote: Redirecting Virus Angers ME!!!Alert an admin about: Redirecting Virus Angers ME!!!
ComboFix 08-09-20.05 - -BLITZ- 2008-09-23 5:05:40.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.542 [GMT -4:00]
Running from: C:\Documents and Settings\-BLITZ-\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\Donna\Cookies\donna@secure1.healthierwaytogo.txt
C:\Documents and Settings\Games\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\HP_Administrator\Application Data\CROSOF~1
C:\Documents and Settings\HP_Administrator\Application Data\CROSOF~1\??crosoft\
C:\Documents and Settings\HP_Administrator\cookies\hp_administrator@games
.txt
C:\Documents and Settings\TLM\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Program Files\Insider
C:\Program Files\mcroso~1.net
C:\Program Files\outlook
C:\Program Files\WinAble
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\abW9
C:\Temp\abW9\tPho.log
C:\temp\tn3
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\IA
C:\WINDOWS\system32\dbxDgrevCheck.dll
C:\WINDOWS\system32\tdssadw.dll
C:\WINDOWS\system32\tdssinit.dll
C:\WINDOWS\system32\tdssl.dll
C:\WINDOWS\system32\tdsslog.dll
C:\WINDOWS\system32\tdssmain.dll
C:\WINDOWS\system32\tdsspopup.dll
C:\WINDOWS\system32\tdsspopup1.url
C:\WINDOWS\system32\tdsspopup2.url
C:\WINDOWS\system32\tdsspopup3.url
C:\WINDOWS\system32\tdssservers.dat
C:\WINDOWS\system32\windows_update.exe
C:\x.dat
C:\z.dat
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_SYSREST.SYS


((((((((((((((((((((((((( Files Created from 2008-08-23 to 2008-09-23 )))))))))))))))))))))))))))))))
.

2008-09-23 02:36 . 2008-09-23 04:51 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-09-23 02:36 . 2008-09-23 02:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-09-23 02:36 . 2008-09-23 04:52 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\SUPERAntiSpyware.com
2008-09-23 02:31 . 2008-09-23 02:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-09-23 02:30 . 2008-09-23 02:30 <DIR> dr-h----- C:\Documents and Settings\-BLITZ-\Recent
2008-09-23 01:58 . 2008-09-23 01:58 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-23 01:10 . 2008-09-23 01:13 <DIR> d-------- C:\Program Files\Cain
2008-09-23 00:59 . 2008-09-23 01:10 <DIR> d-------- C:\Program Files\WinPcap
2008-09-22 00:10 . 2008-09-22 00:10 152,892 --a------ C:\enigma!!!!!!.JPG
2008-09-22 00:06 . 2008-09-22 00:06 941 --a------ C:\Shortcut to eNiGMa.lnk
2008-09-21 05:12 . 2006-04-08 21:11 33,684 --a------ C:\Documents and Settings\DOSBoxByAalaap.exe
2008-09-21 05:12 . 2006-04-08 15:44 2,978 --a------ C:\Documents and Settings\DOS Box by Aalaap - Sample.gif
2008-09-21 05:09 . 2008-09-21 05:03 23,928 --a------ C:\Documents and Settings\dosbox(www
.customizetalk.com).zip
2008-09-20 02:51 . 2008-09-20 02:51 <DIR> d-------- C:\5808daa94ad93176ef
2008-09-20 00:19 . 2008-09-22 19:54 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 9.0
2008-09-20 00:19 . 2008-09-20 00:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-20 00:18 . 2008-09-20 00:18 <DIR> d-------- C:\Program Files\Microsoft SDKs
2008-09-20 00:16 . 2008-09-20 00:16 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-09-20 00:16 . 2008-09-20 00:16 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-09-20 00:16 . 2008-09-20 00:16 <DIR> d-------- C:\Program Files\MSBuild
2008-09-20 00:15 . 2008-09-20 00:15 <DIR> d-------- C:\c557b304674f856ee0b7be760f1d
2008-09-20 00:15 . 2008-07-06 08:06 1,676,288 --------- C:\WINDOWS\system32\xpssvcs.dll
2008-09-20 00:15 . 2008-07-06 08:06 1,676,288 --------- C:\WINDOWS\system32\dllcache\xpssvcs.dll
2008-09-20 00:15 . 2008-07-06 06:50 597,504 --------- C:\WINDOWS\system32\dllcache\printfilterpipelinesvc.exe
2008-09-20 00:15 . 2008-07-06 08:06 575,488 --------- C:\WINDOWS\system32\xpsshhdr.dll
2008-09-20 00:15 . 2008-07-06 08:06 575,488 --------- C:\WINDOWS\system32\dllcache\xpsshhdr.dll
2008-09-20 00:15 . 2008-07-06 08:06 117,760 --------- C:\WINDOWS\system32\prntvpt.dll
2008-09-20 00:15 . 2008-07-06 08:06 89,088 --------- C:\WINDOWS\system32\dllcache\filterpipelineprintproc.dll
2008-09-20 00:12 . 2008-09-20 00:12 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-09-20 00:02 . 2008-09-20 00:02 <DIR> d-------- C:\868eb10a3b82ce3966105d6531eec2
2008-09-19 03:43 . 2008-09-19 03:43 <DIR> d-------- C:\Program Files\Axis Communications
2008-09-19 03:18 . 2008-09-19 03:18 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Sun
2008-09-19 00:36 . 2008-09-19 00:38 <DIR> d-------- C:\Program Files\TeaTimer
2008-09-18 01:20 . 2008-09-18 01:20 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\AdobeUM
2008-09-17 20:46 . 2008-09-17 20:46 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\MSNInstaller
2008-09-17 20:43 . 2008-09-17 20:43 <DIR> d--h----- C:\Documents and Settings\-BLITZ-\InstallAnywhere
2008-09-17 20:41 . 2008-09-17 20:41 42,320 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-09-17 18:13 . 2008-09-17 18:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-13 01:50 . 2008-09-13 01:50 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\WinRAR
2008-09-10 22:36 . 2008-09-10 22:36 <DIR> d---s---- C:\Documents and Settings\-BLITZ-\UserData
2008-09-10 18:33 . 2008-09-11 23:21 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Google
2008-09-10 18:33 . 2008-09-18 00:25 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Adobe
2008-09-10 18:18 . 2008-09-10 18:18 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Thunderbird
2008-09-10 18:14 . 2008-09-22 19:32 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Xfire
2008-09-10 18:14 . 2008-09-17 21:56 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Ventrilo
2008-09-10 18:13 . 2008-09-10 21:47 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Mozilla
2008-09-10 18:09 . 2008-09-10 18:09 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Logitech
2008-09-10 18:08 . 2006-05-24 22:26 <DIR> d-------- C:\Documents and Settings\-BLITZ-\WINDOWS
2008-09-10 18:08 . 2005-11-14 21:04 <DIR> d--h----- C:\Documents and Settings\-BLITZ-\Templates
2008-09-10 18:08 . 2007-11-20 02:32 <DIR> dr------- C:\Documents and Settings\-BLITZ-\Start Menu
2008-09-10 18:08 . 2007-11-20 02:32 <DIR> dr-h----- C:\Documents and Settings\-BLITZ-\SendTo
2008-09-10 18:08 . 2005-11-11 18:56 <DIR> d--h----- C:\Documents and Settings\-BLITZ-\PrintHood
2008-09-10 18:08 . 2005-11-11 18:56 <DIR> d--h----- C:\Documents and Settings\-BLITZ-\NetHood
2008-09-10 18:08 . 2008-09-22 21:14 <DIR> dr------- C:\Documents and Settings\-BLITZ-\My Documents
2008-09-10 18:08 . 2008-09-23 01:41 <DIR> d--h----- C:\Documents and Settings\-BLITZ-\Local Settings
2008-09-10 18:08 . 2008-09-10 18:09 <DIR> dr------- C:\Documents and Settings\-BLITZ-\Favorites
2008-09-10 18:08 . 2008-09-23 05:04 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Desktop
2008-09-10 18:08 . 2008-09-23 05:04 <DIR> d---s---- C:\Documents and Settings\-BLITZ-\Cookies
2008-09-10 18:08 . 2008-09-18 01:20 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Real
2008-09-10 18:08 . 2008-09-17 23:35 <DIR> d---s---- C:\Documents and Settings\-BLITZ-\Application Data\Microsoft
2008-09-10 18:08 . 2008-08-06 18:11 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Macromedia
2008-09-10 18:08 . 2006-05-24 22:29 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Intuit
2008-09-10 18:08 . 2005-11-14 21:04 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Identities
2008-09-10 18:08 . 2008-09-23 02:36 <DIR> dr-h----- C:\Documents and Settings\-BLITZ-\Application Data
2008-09-10 18:08 . 2008-09-23 05:14 <DIR> d-------- C:\Documents and Settings\-BLITZ-
2008-09-10 18:08 . 2008-09-23 05:14 2,359,296 --ah----- C:\Documents and Settings\-BLITZ-\NTUSER.DAT
2008-09-10 15:07 . 2008-09-10 15:07 <DIR> d-------- C:\Program Files\Alwil Software
2008-09-06 02:48 . 2008-09-06 02:48 <DIR> d-------- C:\Program Files\Technitium
2008-08-31 22:07 . 2008-08-31 22:07 <DIR> d-------- C:\Program Files\Elaborate Bytes
2008-08-30 21:26 . 2008-09-01 22:16 <DIR> d-------- C:\Program Files\World of Warcraft Trial
2008-08-28 11:07 . 2008-08-28 11:07 <DIR> d-------- C:\Program Files\WoW-2.3.0.7561-enUS
2008-08-24 16:53 . 2008-08-30 21:26 <DIR> d-------- C:\Program Files\Common Files\Blizzard Entertainment

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-23 09:16 --------- d-----w C:\Program Files\Steam
2008-09-23 08:51 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-09-23 08:30 --------- d-----w C:\Program Files\Xfire
2008-09-23 08:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-23 06:25 --------- d-----w C:\Program Files\Yahoo!
2008-09-23 06:11 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-09-22 17:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-09-19 20:25 --------- d-----w C:\Program Files\HyCam2
2008-09-18 00:47 --------- d-----w C:\Program Files\HP Games
2008-09-18 00:44 --------- d-----w C:\Program Files\Britannica 2006
2008-09-12 00:23 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-11 00:14 --------- d-----w C:\Program Files\PCFriendly
2008-09-10 20:28 --------- d-----w C:\Program Files\music_now
2008-09-10 19:38 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\WinTouch
2008-09-09 05:35 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-08-30 19:22 --------- d-----w C:\Program Files\DNA
2008-08-29 22:01 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-26 21:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-08-26 15:18 --------- d-----w C:\Program Files\mIRC
2008-08-25 02:14 --------- d-----w C:\Program Files\SpeedFan
2008-08-23 06:00 --------- d-----w C:\Program Files\Google
2008-08-07 23:03 --------- d-----w C:\Program Files\XAimer
2008-08-03 21:32 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Thunderbird
2008-08-01 15:19 --------- d-----w C:\Program Files\Sun
2008-08-01 15:19 --------- d-----w C:\Program Files\Java
2008-07-27 23:36 --------- d-----w C:\Program Files\VentSrv
2008-06-24 17:41 472 ----a-w C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
2007-11-20 03:31 0 ----a-w C:\Documents and Settings\TLM\x.dat
2007-11-20 03:30 0 ----a-w C:\Documents and Settings\TLM\z.dat
2007-11-20 02:46 0 ----a-w C:\Documents and Settings\HP_Administrator\z.dat
2007-11-20 02:46 0 ----a-w C:\Documents and Settings\HP_Administrator\x.dat
.

------- Sigcheck -------

2008-04-13 20:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
2008-09-10 14:37 502272 9b1bd82bd0761b5ba986af66d2809c30 C:\WINDOWS\system32\winlogon.exe
2004-08-10 00:00 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\dllcache\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a33fa729-d155-4b23-842b-2c665ecabdb6}]
2008-07-03 03:30 1569304 --a------ C:\Program Files\The_Pirate_Bay\tbThe1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{a33fa729-d155-4b23-842b-2c665ecabdb6}"= "C:\Program Files\The_Pirate_Bay\tbThe1.dll" [2008-07-03 1569304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A33FA729-D155-4B23-842B-2C665ECABDB6}"= "C:\Program Files\The_Pirate_Bay\tbThe1.dll" [2008-07-03 1569304]

[HKEY_CLASSES_ROOT\clsid\{a33fa729-d155-4b23-842b-2c665ecabdb6}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-23 68856]
"Google Update"="C:\Documents and Settings\-BLITZ-\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-10 133104]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
"Steam"="c:\program files\steam\steam.exe" [2008-08-26 1271032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-30 67584]
"DISCover"="C:\Program Files\DISC\DISCover.exe" [2006-03-16 1077248]
"DiscUpdateManager"="C:\Program Files\DISC\DiscUpdMgr.exe" [2006-03-16 61440]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 249856]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-05-24 180269]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-14 282624]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-28 221184]
"ISUSScheduler"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" [2004-08-09 81920]
"Motive SmartBridge"="C:\PROGRA~1\ALLTEL~1\SMARTB~1\MotiveSB.exe" [2004-11-09 393216]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2008-03-14 233472]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 C:\WINDOWS\arpwrmsg.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 C:\WINDOWS\KHALMNPR.Exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 C:\WINDOWS\KHALMNPR.Exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-06-06 67128]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-06-06 805392]
Updates From HP.lnk - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe [2006-05-24 36903]
Windstream Broadband Check-up Center.lnk - C:\Program Files\ALLTEL DSL Check-up Center\bin\matcli.exe [2008-05-08 217088]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 02:42 72208 c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"VIDC.XFR1"= xfcodec.dll
"VIDC.JDCT"= jl_jdct.drv
"vidc.yv12"= yv12vfw.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TDSSserv.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\DISC\\DISCover.exe"=
"C:\\Program Files\\DISC\\DiscStreamHub.exe"=
"C:\\Program Files\\DISC\\myFTP.exe"=
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"C:\\Program Files\\Steam\\SteamApps\\blitzkrieg4590\\day of defeat source\\hl2.exe"=
"C:\\Program Files\\Steam\\SteamApps\\blitzkrieg4590\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Steam\\SteamApps\\tyler_mitchell4590\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\America's Army\\System\\ArmyOps.exe"=
"C:\\Program Files\\Steam\\steam.exe"=
"C:\\Program Files\\Steam\\SteamApps\\blitzkrieg4590\\source sdk base\\hl2.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"C:\\Program Files\\Ubisoft\\Demo\\Tom Clancy's Splinter Cell Double Agent Demo\\SCDA-Offline\\System\\SplinterCell4.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8097:TCP"= 8097:TCP:EarthLink UHP Modem Support

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 McciCMService;McciCMService;C:\Program Files\Common Files\Motive\McciCMService.exe [2007-11-16 303104]
R3 SCREAMINGBDRIVER;Screaming Bee Audio;C:\WINDOWS\system32\drivers\ScreamingBAudio.sys [2008-05-15 21920]
S3 JL2005C;Dual Mode Camera;C:\WINDOWS\system32\Drivers\jl2005c.sys [2007-02-14 68922]
S3 MREMP50;MREMP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [2007-11-16 19712]
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [ ]
S3 MRESP50;MRESP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [2007-11-16 18304]
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [ ]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-11-06 34064]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-lphc9a0j0ea3t - C:\WINDOWS\system32\lphc9a0j0ea3t.exe
HKLM-Run-SMshcea0j0ea3t - C:\Program Files\shcea0j0ea3t\shcea0j0ea3t.exe
HKLM-Run-DMAScheduler - c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
HKLM-Run-inrhcca0j0ea3t - C:\Documents and Settings\TLM.HPSL\Local Settings\Temp\.ttBE.tmp.exe
HKLM-Run-PCDrProfiler - (no file)


.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=63&bd=PAVILION&pf=desktop
R0 -: HKCU-Main,Search Page = hxxp://www.google.com
R0 -: HKCU-Main,Default_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PAVILION&pf=desktop
R0 -: HKCU-Main,Search Bar = hxxp://www.google.com/ie
R0 -: HKLM-Main,Default_Search_URL = hxxp://www.google.com/ie
R0 -: HKLM-Main,Start Page = hxxp://www.yahoo.com/
R0 -: HKLM-Main,Search Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R0 -: HKCU-Search,SearchAssistant = hxxp://www.google.com/ie
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
R0 -: HKLM-Search,SearchAssistant = hxxp://www.google.com/ie
O8 -: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 -: &Translate English Word - C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 -: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 -: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 -: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 -: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 -: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 -: Translate Page into English - C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O18 -: Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd

O16 -: {745395C8-D0E1-4227-8586-624CA9A10A8D} - hxxp://80.126.181.68/activex/AMC.cab
C:\WINDOWS\Downloaded Program Files\setup.inf
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-23 05:16:57
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\Program Files\DISC\DiscStreamHub.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-09-23 5:24:54 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-23 09:24:47

Pre-Run: 100,318,740,480 bytes free
Post-Run: 100,622,008,320 bytes free

340 --- E O F --- 2008-09-21 07:01:03



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:50:58 PM, on 9/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\DISC\DISCover.exe
C:\Program Files\DISC\DiscUpdMgr.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\-BLITZ-\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\program files\steam\steam.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\DISC\DiscStreamHub.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\Program Files\Xfire\xfire.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PAVILION&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=63&bd=PAVILION&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: The Pirate Bay Toolbar - {a33fa729-d155-4b23-842b-2c665ecabdb6} - C:\Program Files\The_Pirate_Bay\tbThe1.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: The Pirate Bay Toolbar - {a33fa729-d155-4b23-842b-2c665ecabdb6} - C:\Program Files\The_Pirate_Bay\tbThe1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe
O4 - HKLM\..\Run: [DiscUpdateManager] C:\Program Files\DISC\DiscUpdMgr.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" -start
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ALLTEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\-BLITZ-\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O4 - Global Startup: Windstream Broadband Check-up Center.lnk = C:\Program Files\ALLTEL DSL Check-up Center\bin\matcli.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://80.126.181.68/activex/AMC.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe

--
End of file - 12177 bytes


There you go :)

Post Edited (Touch) : 24-09-2008 04:34:29 GMT

Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13812
 
   Posted 9-24-2008 5:52 (GMT +1)    Quote: Redirecting Virus Angers ME!!!Alert an admin about: Redirecting Virus Angers ME!!!
Please upload and  have this file scanned:
 
C:\WINDOWS\system32\winlogon.exe
Here:
 
 
 
 
Post back the results
 


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

Tyler4590
New Member


Date Joined Sep 2008
Total Posts : 7
 
   Posted 9-24-2008 8:08 (GMT +1)    Quote: Redirecting Virus Angers ME!!!Alert an admin about: Redirecting Virus Angers ME!!!
I wasnt quite sure od what you wanted me to post back to you so I took the liberty of posting the 2 differnet results that it
showed after I uploaded. Oh and by the way, I appreciate the trouble your going through by helping me out with this.


A-Squared
Found nothing
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found Application.WLHack.A
ClamAV
Found nothing
CPsecure
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found nothing
Ikarus
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Sophos Antivirus
Found Troj/WLhack-F
VirusBuster
Found nothing
VBA32
Found nothing

________________________________________________

Scanner Malware name
A-Squared X
AntiVir X
ArcaVir Heur.W32
Avast X
AVG Antivirus X
BitDefender X
ClamAV X
CPsecure Generic.W32
Dr.Web X
F-Prot Antivirus X
F-Secure Anti-Virus Type_Win32
Ikarus X
Kaspersky Anti-Virus Type_Win32
NOD32 X
Norman Virus Control X
Panda Antivirus X
Sophos Antivirus X
VirusBuster X
VBA32 X
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13812
 
   Posted 9-24-2008 8:24 (GMT +1)    Quote: Redirecting Virus Angers ME!!!Alert an admin about: Redirecting Virus Angers ME!!!
It seems to be infected.
 
 
Open notepad and copy/paste the text in the quotebox below into it:


Quote:
 
Killall::
 
Snapshot::
 
 
 
FCOPY::
C:\WINDOWS\system32\dllcache\winlogon.exe| C:\WINDOWS\system32\winlogon.exe
 
 
Save this as:
CFScript
 
Refering to the picture above, drag CFScript into ComboFix.exe

Then post fresh combofix  log.
 
 


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

Tyler4590
New Member


Date Joined Sep 2008
Total Posts : 7
 
   Posted 9-24-2008 9:24 (GMT +1)    Quote: Redirecting Virus Angers ME!!!Alert an admin about: Redirecting Virus Angers ME!!!
ComboFix 08-09-20.05 - -BLITZ- 2008-09-24 4:05:04.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.550 [GMT -4:00]
Running from: C:\Documents and Settings\-BLITZ-\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\-BLITZ-\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
--------------- FCopy ---------------

C:\WINDOWS\system32\dllcache\winlogon.exe --> C:\WINDOWS\system32\winlogon.exe
.
((((((((((((((((((((((((( Files Created from 2008-08-24 to 2008-09-24 )))))))))))))))))))))))))))))))
.

2008-09-23 21:44 . 2008-09-23 21:44 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-09-23 21:44 . 2008-09-23 21:44 1,409 --a------ C:\WINDOWS\QTFont.for
2008-09-23 15:27 . 2008-09-23 17:38 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\Xfire
2008-09-23 02:36 . 2008-09-23 04:51 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-09-23 02:36 . 2008-09-23 02:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-09-23 02:36 . 2008-09-23 04:52 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\SUPERAntiSpyware.com
2008-09-23 02:31 . 2008-09-23 02:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-09-23 02:30 . 2008-09-24 04:03 <DIR> dr-h----- C:\Documents and Settings\-BLITZ-\Recent
2008-09-23 01:58 . 2008-09-23 01:58 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-23 01:10 . 2008-09-23 01:13 <DIR> d-------- C:\Program Files\Cain
2008-09-23 00:59 . 2008-09-23 01:10 <DIR> d-------- C:\Program Files\WinPcap
2008-09-22 00:10 . 2008-09-22 00:10 152,892 --a------ C:\enigma!!!!!!.JPG
2008-09-22 00:06 . 2008-09-22 00:06 941 --a------ C:\Shortcut to eNiGMa.lnk
2008-09-21 05:12 . 2006-04-08 21:11 33,684 --a------ C:\Documents and Settings\DOSBoxByAalaap.exe
2008-09-21 05:12 . 2006-04-08 15:44 2,978 --a------ C:\Documents and Settings\DOS Box by Aalaap - Sample.gif
2008-09-21 05:09 . 2008-09-21 05:03 23,928 --a------ C:\Documents and Settings\dosbox(www.customizetalk.com).zip
2008-09-20 02:51 . 2008-09-20 02:51 <DIR> d-------- C:\5808daa94ad93176ef
2008-09-20 00:19 . 2008-09-22 19:54 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 9.0
2008-09-20 00:19 . 2008-09-20 00:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-20 00:18 . 2008-09-20 00:18 <DIR> d-------- C:\Program Files\Microsoft SDKs
2008-09-20 00:16 . 2008-09-20 00:16 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-09-20 00:16 . 2008-09-20 00:16 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-09-20 00:16 . 2008-09-20 00:16 <DIR> d-------- C:\Program Files\MSBuild
2008-09-20 00:15 . 2008-09-20 00:15 <DIR> d-------- C:\c557b304674f856ee0b7be760f1d
2008-09-20 00:15 . 2008-07-06 08:06 1,676,288 --------- C:\WINDOWS\system32\xpssvcs.dll
2008-09-20 00:15 . 2008-07-06 08:06 1,676,288 --------- C:\WINDOWS\system32\dllcache\xpssvcs.dll
2008-09-20 00:15 . 2008-07-06 06:50 597,504 --------- C:\WINDOWS\system32\dllcache\printfilterpipelinesvc.exe
2008-09-20 00:15 . 2008-07-06 08:06 575,488 --------- C:\WINDOWS\system32\xpsshhdr.dll
2008-09-20 00:15 . 2008-07-06 08:06 575,488 --------- C:\WINDOWS\system32\dllcache\xpsshhdr.dll
2008-09-20 00:15 . 2008-07-06 08:06 117,760 --------- C:\WINDOWS\system32\prntvpt.dll
2008-09-20 00:15 . 2008-07-06 08:06 89,088 --------- C:\WINDOWS\system32\dllcache\filterpipelineprintproc.dll
2008-09-20 00:12 . 2008-09-20 00:12 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-09-20 00:02 . 2008-09-20 00:02 <DIR> d-------- C:\868eb10a3b82ce3966105d6531eec2
2008-09-19 03:43 . 2008-09-19 03:43 <DIR> d-------- C:\Program Files\Axis Communications
2008-09-19 03:18 . 2008-09-19 03:18 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Sun
2008-09-19 00:36 . 2008-09-19 00:38 <DIR> d-------- C:\Program Files\TeaTimer
2008-09-18 01:20 . 2008-09-18 01:20 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\AdobeUM
2008-09-17 20:46 . 2008-09-17 20:46 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\MSNInstaller
2008-09-17 20:43 . 2008-09-17 20:43 <DIR> d--h----- C:\Documents and Settings\-BLITZ-\InstallAnywhere
2008-09-17 20:41 . 2008-09-17 20:41 42,320 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-09-17 18:13 . 2008-09-17 18:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-13 01:50 . 2008-09-13 01:50 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\WinRAR
2008-09-10 22:36 . 2008-09-10 22:36 <DIR> d---s---- C:\Documents and Settings\-BLITZ-\UserData
2008-09-10 18:33 . 2008-09-11 23:21 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Google
2008-09-10 18:33 . 2008-09-18 00:25 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Adobe
2008-09-10 18:18 . 2008-09-10 18:18 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Thunderbird
2008-09-10 18:14 . 2008-09-22 19:32 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Xfire
2008-09-10 18:14 . 2008-09-17 21:56 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Ventrilo
2008-09-10 18:13 . 2008-09-23 05:37 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Mozilla
2008-09-10 18:09 . 2008-09-10 18:09 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Logitech
2008-09-10 18:08 . 2006-05-24 22:26 <DIR> d-------- C:\Documents and Settings\-BLITZ-\WINDOWS
2008-09-10 18:08 . 2005-11-14 21:04 <DIR> d--h----- C:\Documents and Settings\-BLITZ-\Templates
2008-09-10 18:08 . 2007-11-20 02:32 <DIR> dr------- C:\Documents and Settings\-BLITZ-\Start Menu
2008-09-10 18:08 . 2007-11-20 02:32 <DIR> dr-h----- C:\Documents and Settings\-BLITZ-\SendTo
2008-09-10 18:08 . 2005-11-11 18:56 <DIR> d--h----- C:\Documents and Settings\-BLITZ-\PrintHood
2008-09-10 18:08 . 2005-11-11 18:56 <DIR> d--h----- C:\Documents and Settings\-BLITZ-\NetHood
2008-09-10 18:08 . 2008-09-23 05:52 <DIR> dr------- C:\Documents and Settings\-BLITZ-\My Documents
2008-09-10 18:08 . 2008-09-24 04:10 <DIR> d--h----- C:\Documents and Settings\-BLITZ-\Local Settings
2008-09-10 18:08 . 2008-09-10 18:09 <DIR> dr------- C:\Documents and Settings\-BLITZ-\Favorites
2008-09-10 18:08 . 2008-09-24 04:04 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Desktop
2008-09-10 18:08 . 2008-09-24 00:08 <DIR> d---s---- C:\Documents and Settings\-BLITZ-\Cookies
2008-09-10 18:08 . 2008-09-18 01:20 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Real
2008-09-10 18:08 . 2008-09-17 23:35 <DIR> d---s---- C:\Documents and Settings\-BLITZ-\Application Data\Microsoft
2008-09-10 18:08 . 2008-08-06 18:11 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Macromedia
2008-09-10 18:08 . 2006-05-24 22:29 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Intuit
2008-09-10 18:08 . 2005-11-14 21:04 <DIR> d-------- C:\Documents and Settings\-BLITZ-\Application Data\Identities
2008-09-10 18:08 . 2008-09-23 02:36 <DIR> dr-h----- C:\Documents and Settings\-BLITZ-\Application Data
2008-09-10 18:08 . 2008-09-23 05:14 <DIR> d-------- C:\Documents and Settings\-BLITZ-
2008-09-10 18:08 . 2008-09-24 04:10 2,359,296 --ah----- C:\Documents and Settings\-BLITZ-\NTUSER.DAT
2008-09-10 15:07 . 2008-09-10 15:07 <DIR> d-------- C:\Program Files\Alwil Software
2008-09-06 02:48 . 2008-09-06 02:48 <DIR> d-------- C:\Program Files\Technitium
2008-08-31 22:07 . 2008-08-31 22:07 <DIR> d-------- C:\Program Files\Elaborate Bytes
2008-08-30 21:26 . 2008-09-01 22:16 <DIR> d-------- C:\Program Files\World of Warcraft Trial
2008-08-28 11:07 . 2008-08-28 11:07 <DIR> d-------- C:\Program Files\WoW-2.3.0.7561-enUS
2008-08-24 16:53 . 2008-08-30 21:26 <DIR> d-------- C:\Program Files\Common Files\Blizzard Entertainment

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-24 08:13 --------- d-----w C:\Program Files\Steam
2008-09-24 02:04 --------- d-----w C:\Program Files\Xfire
2008-09-24 01:35 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-09-23 18:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-09-23 08:51 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-09-23 08:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-23 06:25 --------- d-----w C:\Program Files\Yahoo!
2008-09-19 20:25 --------- d-----w C:\Program Files\HyCam2
2008-09-18 00:47 --------- d-----w C:\Program Files\HP Games
2008-09-18 00:44 --------- d-----w C:\Program Files\Britannica 2006
2008-09-12 00:23 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-11 00:14 --------- d-----w C:\Program Files\PCFriendly
2008-09-10 20:28 --------- d-----w C:\Program Files\music_now
2008-09-10 19:38 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\WinTouch
2008-09-09 05:35 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-08-30 19:22 --------- d-----w C:\Program Files\DNA
2008-08-29 22:01 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-26 21:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-08-26 15:18 --------- d-----w C:\Program Files\mIRC
2008-08-25 02:14 --------- d-----w C:\Program Files\SpeedFan
2008-08-23 06:00 --------- d-----w C:\Program Files\Google
2008-08-07 23:03 --------- d-----w C:\Program Files\XAimer
2008-08-03 21:32 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Thunderbird
2008-08-01 15:19 --------- d-----w C:\Program Files\Sun
2008-08-01 15:19 --------- d-----w C:\Program Files\Java
2008-07-27 23:36 --------- d-----w C:\Program Files\VentSrv
2008-06-24 17:41 472 ----a-w C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
2007-11-20 03:31 0 ----a-w C:\Documents and Settings\TLM\x.dat
2007-11-20 03:30 0 ----a-w C:\Documents and Settings\TLM\z.dat
2007-11-20 02:46 0 ----a-w C:\Documents and Settings\HP_Administrator\z.dat
2007-11-20 02:46 0 ----a-w C:\Documents and Settings\HP_Administrator\x.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a33fa729-d155-4b23-842b-2c665ecabdb6}]
2008-07-03 03:30 1569304 --a------ C:\Program Files\The_Pirate_Bay\tbThe1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{a33fa729-d155-4b23-842b-2c665ecabdb6}"= "C:\Program Files\The_Pirate_Bay\tbThe1.dll" [2008-07-03 1569304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A33FA729-D155-4B23-842B-2C665ECABDB6}"= "C:\Program Files\The_Pirate_Bay\tbThe1.dll" [2008-07-03 1569304]

[HKEY_CLASSES_ROOT\clsid\{a33fa729-d155-4b23-842b-2c665ecabdb6}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-23 68856]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
"Steam"="c:\program files\steam\steam.exe" [2008-08-26 1271032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-30 67584]
"DISCover"="C:\Program Files\DISC\DISCover.exe" [2006-03-16 1077248]
"DiscUpdateManager"="C:\Program Files\DISC\DiscUpdMgr.exe" [2006-03-16 61440]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 249856]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-05-24 180269]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-14 282624]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-28 221184]
"ISUSScheduler"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" [2004-08-09 81920]
"Motive SmartBridge"="C:\PROGRA~1\ALLTEL~1\SMARTB~1\MotiveSB.exe" [2004-11-09 393216]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2008-03-14 233472]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 C:\WINDOWS\arpwrmsg.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 C:\WINDOWS\KHALMNPR.Exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 C:\WINDOWS\KHALMNPR.Exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-06-06 67128]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-06-06 805392]
Updates From HP.lnk - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe [2006-05-24 36903]
Windstream Broadband Check-up Center.lnk - C:\Program Files\ALLTEL DSL Check-up Center\bin\matcli.exe [2008-05-08 217088]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 02:42 72208 c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"VIDC.XFR1"= xfcodec.dll
"VIDC.JDCT"= jl_jdct.drv
"vidc.yv12"= yv12vfw.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TDSSserv.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\DISC\\DISCover.exe"=
"C:\\Program Files\\DISC\\DiscStreamHub.exe"=
"C:\\Program Files\\DISC\\myFTP.exe"=
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"C:\\Program Files\\Steam\\SteamApps\\blitzkrieg4590\\day of defeat source\\hl2.exe"=
"C:\\Program Files\\Steam\\SteamApps\\blitzkrieg4590\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Steam\\SteamApps\\tyler_mitchell4590\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\America's Army\\System\\ArmyOps.exe"=
"C:\\Program Files\\Steam\\steam.exe"=
"C:\\Program Files\\Steam\\SteamApps\\blitzkrieg4590\\source sdk base\\hl2.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Com