PDA

View Full Version : MSN Virus: PIC006.JPG-live.messenger.com



Bumblebee77
2008-03-03, 20:19
Greetings, I have been so mindless and click a link from a friend on MSN Messenger this Saturday. The name of it was PIC006.JPG-live.messenger.com. Not before it was too late, did I realise it was a virus. :sad:

I may have been a bad girl in trying to remove it on my own, :oops: instead of coming to you directly. I will try to explain the steps I have taken myself here.

First I ran scans with AVG Free, Spybot - S&D and ClamWin. Neither found anything. Then I uninstalled MSN Messenger and everything (or at least I think everthing) connected to it. I then ran all 3 programs again with no result. Then I was sad and it was late, so I went to bed leaving the PC on. Then when I returned to the PC sunday morning it appeared that TeaTimer (it is TeaTimer that little thing by the clock in the bottom right corner that asks if I want to accept or deny changes stuff wants to make to the registry, right?) had found it and asked me if I wanted to accept or deny it. I denied. (I probably should mention that when I clicked the link saturday and before I realised it was a virus it had popped up and I had accepted *DOH*) Then I opened the AVG Free Virus Vault and it seemed it was in there too. I then removed it along with everything else in there. It called it a "back up" so I'm not sure if it removed the original or just a back up. Then I deleted that version of AVG Free and got a newer one, scanned again and it found... *surpriseee* Nothing. Then I thought my day was made... But low and behold, not 5 mins passed and TeaTimer again popped up asking me if I wanted to accept or deny that file to change in the registry. Then I went searching forums, and found a few with the same name of virus as "mine". I then did a foolish thing *sowwy* :sad: and did what one of them had adviced the user to do. I downloaded MsnCleaner and rebooted to safe mode and ran it. It found a file (which I can't remember the name off except it was somethingWINDOWSsomething) and I told it to remove that file. I rebooted to normal mode and again TeaTimer popped up asking me if I wanted to allow or deny. I denied again. And here is where my stupidity ends (Or so I'd like to hope) and I am writing to you. I have followed all the steps in your "Before you post" and "Before you post a log", so I have both a Kaspersky log and a HijackThis log for you.

I haven't installed MSN Messenger again and I've not logged in to anything requiring a password including my WoW *miiiiiiiss iiiiit :red:* Even here I've used a username and a password nowhere near what I normally use. I'm so scared the virus contains a keylogger.

I am looking very much forward to hearing from you and I promise, cross my heart, only to do what you tell me to do from now on.

*Bows gracefully*

Shaba
2008-03-04, 15:17
Hi Bumblebee77

Please post those logs next :)

Bumblebee77
2008-03-04, 15:44
Here is the HijackThis log :)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:52:08, on 03-03-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Programmer\Fælles filer\Logitech\Bluetooth\LBTSERV.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Programmer\Logitech\Easy Synchronization\servicestub.exe
C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe
C:\Programmer\Fælles filer\Logitech\G-series Software\LGDCore.exe
C:\Programmer\Logitech\SetPoint\LBTWiz.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\DAEMON Tools\daemon.exe
C:\Programmer\DNA\btdna.exe
C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Programmer\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Programmer\Logitech\SetPoint\SetPoint.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Programmer\OpenOffice.org 2.2\program\soffice.exe
C:\Programmer\OpenOffice.org 2.2\program\soffice.BIN
C:\Programmer\Fælles filer\Logishrd\KHAL2\KHALMNPR.EXE
C:\Programmer\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://netbank.danskebank.dk/html/index.html?site=DBNB
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.zitech.dk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmer\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: CVirtualDNSObj Object - {86C510E9-97EF-4749-914F-0280247BE3A6} - C:\WINDOWS\VirtualDNS.dll (file missing)
O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programmer\AVG\AVG8\avgtoolbar.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Programmer\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programmer\AVG\AVG8\avgtoolbar.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Easy Synchronization] C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Programmer\Fælles filer\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Bluetooth Connection Assistant] LBTWIZ.EXE -silent
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [ClamWin] "C:\Programmer\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [MSN Messenger] live.messenger.com
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\RunOnce: [Easy Synchronization] C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe --ports
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Programmer\DNA\btdna.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.2.lnk = C:\Programmer\OpenOffice.org 2.2\program\quickstart.exe
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: &Search - ?p=ZJfox000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.zitech.dk
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmer\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FLLESF~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmer\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Programmer\Canon\CAL\CALMAIN.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Programmer\Fælles filer\Logitech\Bluetooth\LBTSERV.EXE
O23 - Service: Logitech Easy Synchronization - Unknown owner - C:\Programmer\Logitech\Easy Synchronization\servicestub.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmer\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 9265 bytes

Bumblebee77
2008-03-04, 15:46
Aaaand here is the Kaspersky log :) Thank you for your swift reply :D

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, March 03, 2008 7:25:14 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 3/03/2008
Kaspersky Anti-Virus database records: 594525
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 92184
Number of viruses found: 0
Number of infected objects: 0
Number of suspicious objects: 0
Duration of the scan process: 01:21:47

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg8\AvgAm\avgam.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\emc\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgam.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgcore.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avglng.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgns.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgrs.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgui.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgwd.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgwdsvc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Lokale indstillinger\Oversigt\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Lokale indstillinger\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Lokale indstillinger\Temp\Oversigt\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Lokale indstillinger\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Lokale indstillinger\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Tanja\Application Data\Mozilla\Firefox\Profiles\egstgt4b.default\cert8.db Object is locked skipped
C:\Documents and Settings\Tanja\Application Data\Mozilla\Firefox\Profiles\egstgt4b.default\history.dat Object is locked skipped
C:\Documents and Settings\Tanja\Application Data\Mozilla\Firefox\Profiles\egstgt4b.default\key3.db Object is locked skipped
C:\Documents and Settings\Tanja\Application Data\Mozilla\Firefox\Profiles\egstgt4b.default\parent.lock Object is locked skipped
C:\Documents and Settings\Tanja\Application Data\Mozilla\Firefox\Profiles\egstgt4b.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Tanja\Application Data\Mozilla\Firefox\Profiles\egstgt4b.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Tanja\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Tanja\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Tanja\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Tanja\Lokale indstillinger\Application Data\Mozilla\Firefox\Profiles\egstgt4b.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Tanja\Lokale indstillinger\Application Data\Mozilla\Firefox\Profiles\egstgt4b.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Tanja\Lokale indstillinger\Application Data\Mozilla\Firefox\Profiles\egstgt4b.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Tanja\Lokale indstillinger\Application Data\Mozilla\Firefox\Profiles\egstgt4b.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Tanja\Lokale indstillinger\Oversigt\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Tanja\Lokale indstillinger\Oversigt\History.IE5\MSHist012008030320080304\index.dat Object is locked skipped
C:\Documents and Settings\Tanja\Lokale indstillinger\Temp\ClamWin1.log Object is locked skipped
C:\Documents and Settings\Tanja\Lokale indstillinger\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Tanja\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Tanja\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{06B16ED4-AB0D-4ED0-919C-9D613D487F9C}\RP513\A0255412.dll Object is locked skipped
C:\System Volume Information\_restore{06B16ED4-AB0D-4ED0-919C-9D613D487F9C}\RP515\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.

Shaba
2008-03-04, 15:52
Hi

We need first to disable TeaTimer that it doesn't interfere with fixes. You can re-enable it when you're clean again:

1. Run Spybot-S&D in Advanced Mode.
2. If it is not already set to do this Go to the Mode menu select "Advanced Mode"
3. On the left hand side, Click on Tools
4. Then click on the Resident Icon in the List
5. Uncheck "Resident TeaTimer" and OK any prompts.
6. Restart your computer.

Open HijackThis, click do a system scan only and checkmark this:

O4 - HKLM\..\Run: [MSN Messenger] live.messenger.com

Close all windows including browser and press fix checked.

Reboot.

Download SDFix (http://downloads.andymanchesta.com/RemovalTools/SDFix.exe) and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, the Advanced Options Menu should appear;
Select the first option, to run Windows in Safe Mode, then press Enter.
Choose your usual account.

Open the extracted SDFix folder and double click RunThis.bat to start the script.
Type Y to begin the cleanup process.
It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
Press any Key and it will restart the PC.
When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).
Finally paste the contents of the Report.txt back on the forum with a new HijackThis log


Also tell me if this is your preferred home page:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com

Bumblebee77
2008-03-04, 16:52
SDFix report


SDFix: Version 1.152

Run by Tanja on 04-03-2008 at 16:22

Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\admintxt.txt - Deleted
C:\WINDOWS\system32\drivers\etc\BackupHosts.bak - Deleted





Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-04 16:36:42
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ESENT]
"EventMessageFile"=str(2):"c:\windows\system32\ESENT.dll"
"CategoryMessageFile"=str(2):"c:\windows\system32\ESENT.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Programmer\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:48,7f,67,72,30,af,00,98,b0,72,72,21,ef,4c,e9,77,67,bc,e4,f0,0e,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,96,32,20,86,7f,6d,47,8f,82,0c,aa,bc,86,fb,3a,6d,58,..
"khjeh"=hex:b4,d3,48,e5,35,06,86,a9,97,cd,99,52,65,08,58,f1,05,af,cb,6b,c3,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:8f,28,af,95,60,7e,41,44,45,17,69,5d,5e,2e,a9,b8,9a,41,4d,cd,55,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Programmer\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:48,7f,67,72,30,af,00,98,b0,72,72,21,ef,4c,e9,77,67,bc,e4,f0,0e,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,96,32,20,86,7f,6d,47,8f,82,0c,aa,bc,86,fb,3a,6d,58,..
"khjeh"=hex:b4,d3,48,e5,35,06,86,a9,97,cd,99,52,65,08,58,f1,05,af,cb,6b,c3,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:8f,28,af,95,60,7e,41,44,45,17,69,5d,5e,2e,a9,b8,9a,41,4d,cd,55,..

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Games\\World of Warcraft\\WoW-1.12.0-enGB-downloader.exe"="C:\\Games\\World of Warcraft\\WoW-1.12.0-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Programmer\\Grisoft\\AVG Free\\avginet.exe"="C:\\Programmer\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Programmer\\Grisoft\\AVG Free\\avgemc.exe"="C:\\Programmer\\Grisoft\\AVG Free\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Programmer\\VentSrv\\ventrilo_srv.exe"="C:\\Programmer\\VentSrv\\ventrilo_srv.exe:*:Enabled:ventrilo_srv"
"C:\\Programmer\\Shareaza\\Shareaza.exe"="C:\\Programmer\\Shareaza\\Shareaza.exe:*:Enabled:Shareaza Ultimate File Sharing"
"C:\\Games\\World of Warcraft\\WoW-1.12.0.5595-to-1.12.1.5875-enGB-downloader.exe"="C:\\Games\\World of Warcraft\\WoW-1.12.0.5595-to-1.12.1.5875-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Games\\World of Warcraft\\BackgroundDownloader.exe"="C:\\Games\\World of Warcraft\\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Programmer\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"="C:\\Programmer\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe:*:Enabled:DarkCrusade"
"F:\\Dawn of War\\W40k.exe"="F:\\Dawn of War\\W40k.exe:*:Enabled:W40k"
"C:\\Games\\World of Warcraft\\WoW-2.0.3-enGB-downloader.exe"="C:\\Games\\World of Warcraft\\WoW-2.0.3-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Games\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.5.6320-enGB-downloader.exe"="C:\\Games\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.5.6320-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Games\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enGB-downloader.exe"="C:\\Games\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"F:\\Dawn of War\\W40kWA.exe"="F:\\Dawn of War\\W40kWA.exe:*:Enabled:W40kWA"
"C:\\Games\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enGB-downloader.exe"="C:\\Games\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Programmer\\Grisoft\\AVG7\\avginet.exe"="C:\\Programmer\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Programmer\\Grisoft\\AVG7\\avgcc.exe"="C:\\Programmer\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Programmer\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Programmer\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Programmer\\eMule\\emule.exe"="C:\\Programmer\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Games\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enGB-downloader.exe"="C:\\Games\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Programmer\\F‘lles filer\\AOL\\Loader\\aolload.exe"="C:\\Programmer\\F‘lles filer\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Programmer\\F‘lles filer\\AOL\\1183328871\\ee\\aolsoftware.exe"="C:\\Programmer\\F‘lles filer\\AOL\\1183328871\\ee\\aolsoftware.exe:*:Enabled:AOL Services"
"C:\\Programmer\\F‘lles filer\\AOL\\1183328871\\ee\\aim6.exe"="C:\\Programmer\\F‘lles filer\\AOL\\1183328871\\ee\\aim6.exe:*:Enabled:AIM"
"C:\\Programmer\\Xfire\\xfire.exe"="C:\\Programmer\\Xfire\\xfire.exe:*:Enabled:Xfire"
"C:\\Programmer\\uTorrent\\uTorrent.exe"="C:\\Programmer\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"C:\\Games\\Titan Quest\\Titan Quest.exe"="C:\\Games\\Titan Quest\\Titan Quest.exe:*:Disabled:Titan Quest"
"C:\\Programmer\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Programmer\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"C:\\Programmer\\BitTorrent_DNA\\dna.exe"="C:\\Programmer\\BitTorrent_DNA\\dna.exe:*:Enabled:BitTorrent DNA"
"C:\\Programmer\\BitTorrent\\bittorrent.exe"="C:\\Programmer\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\Programmer\\FlashGet\\flashget.exe"="C:\\Programmer\\FlashGet\\flashget.exe:*:Enabled:Flashget"
"C:\\Games\\Sacred Underworld\\sacred.exe"="C:\\Games\\Sacred Underworld\\sacred.exe:*:Enabled:Sacred"
"C:\\Games\\Sacred Underworld\\gameserver.exe"="C:\\Games\\Sacred Underworld\\gameserver.exe:*:Enabled:Sacred Gameserver"
"C:\\Programmer\\DNA\\btdna.exe"="C:\\Programmer\\DNA\\btdna.exe:*:Enabled:DNA"
"C:\\Programmer\\Veoh Networks\\Veoh\\VeohClient.exe"="C:\\Programmer\\Veoh Networks\\Veoh\\VeohClient.exe:*:Enabled:Veoh Client"
"C:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Programmer\\Windows Live\\Messenger\\livecall.exe"="C:\\Programmer\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Programmer\\Skype\\Phone\\Skype.exe"="C:\\Programmer\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Programmer\\AVG\\AVG8\\avgupd.exe"="C:\\Programmer\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Programmer\\AVG\\AVG8\\avgemc.exe"="C:\\Programmer\\AVG\\AVG8\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Programmer\\AVG\\AVG8\\avgnsx.exe"="C:\\Programmer\\AVG\\AVG8\\avgnsx.exe:*:Enabled:avgnsx.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Programmer\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Programmer\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"C:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Programmer\\Windows Live\\Messenger\\livecall.exe"="C:\\Programmer\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Programmer\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Programmer\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe"
Sun 11 Jan 2004 22,016 A..H. --- "C:\Fra gammel harddisk (Home C)\Misc\Private Eyes Only\~WRL0001.tmp"
Wed 4 Feb 2004 23,040 A..H. --- "C:\Fra gammel harddisk (Home C)\Misc\Private Eyes Only\~WRL1067.tmp"
Wed 30 Mar 2005 28,672 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Dansk, SVW\~WRL0003.tmp"
Fri 25 Mar 2005 24,576 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Dansk, SVW\~WRL0130.tmp"
Fri 15 Apr 2005 19,968 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Engelsk, JCL\~WRL0003.tmp"
Fri 15 Apr 2005 24,576 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Engelsk, JCL\~WRL0483.tmp"
Fri 15 Apr 2005 25,088 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Engelsk, JCL\~WRL0579.tmp"
Fri 15 Apr 2005 24,576 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Engelsk, JCL\~WRL1247.tmp"
Fri 15 Apr 2005 24,064 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Engelsk, JCL\~WRL2505.tmp"
Fri 15 Apr 2005 25,088 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Engelsk, JCL\~WRL2814.tmp"
Fri 15 Apr 2005 24,064 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Engelsk, JCL\~WRL3000.tmp"
Fri 15 Apr 2005 25,088 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Engelsk, JCL\~WRL3682.tmp"
Fri 15 Apr 2005 25,600 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Engelsk, JCL\~WRL3818.tmp"
Sun 19 Sep 2004 25,088 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\S&S, FK\~WRL0001.tmp"
Fri 15 Oct 2004 24,064 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\S&S, FK\~WRL2421.tmp"
Sat 13 Nov 2004 37,376 A..H. --- "C:\Programmer\F‘lles filer\Adobe\ESD\DLMCleanup.exe"
Wed 23 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\f7db876e78b88fd8276fd7d29cb7e4eb\BIT1.tmp"
Sun 27 Feb 2005 25,088 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Engelsk\~WRL0002.tmp"
Fri 15 Apr 2005 19,968 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Engelsk\~WRL0003.tmp"
Tue 1 Mar 2005 27,648 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Engelsk\~WRL0004.tmp"
Fri 15 Apr 2005 24,576 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Engelsk\~WRL0483.tmp"
Fri 15 Apr 2005 25,088 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Engelsk\~WRL0579.tmp"
Fri 15 Apr 2005 24,576 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Engelsk\~WRL1247.tmp"
Fri 15 Apr 2005 24,064 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Engelsk\~WRL2505.tmp"
Fri 15 Apr 2005 25,088 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Engelsk\~WRL2814.tmp"
Fri 15 Apr 2005 24,064 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Engelsk\~WRL3000.tmp"
Fri 15 Apr 2005 25,088 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Engelsk\~WRL3682.tmp"
Fri 15 Apr 2005 25,600 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Engelsk\~WRL3818.tmp"
Sun 19 Sep 2004 25,088 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\~WRL0001.tmp"
Fri 15 Oct 2004 24,064 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\~WRL2421.tmp"
Fri 18 Mar 2005 74,752 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Tysk\~WRL0156.tmp"
Fri 18 Mar 2005 131,072 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Tysk\~WRL0721.tmp"
Fri 18 Mar 2005 29,696 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Tysk\~WRL1510.tmp"
Fri 18 Mar 2005 131,072 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Tysk\~WRL2060.tmp"
Fri 18 Mar 2005 86,528 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Tysk\~WRL2554.tmp"
Fri 18 Mar 2005 37,376 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Tysk\~WRL3325.tmp"
Fri 18 Mar 2005 131,072 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Tysk\~WRL3536.tmp"
Fri 18 Mar 2005 38,912 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Tysk\~WRL3547.tmp"
Fri 18 Mar 2005 177,152 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Tysk\~WRL3691.tmp"
Fri 18 Mar 2005 38,912 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Tysk\~WRL3933.tmp"
Fri 18 Mar 2005 74,752 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Tysk\~WRL4013.tmp"
Sun 22 May 2005 30,208 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\VOF\~WRL0001.tmp"
Mon 30 May 2005 39,424 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\IT\Til fremlaegningen\~WRL0001.tmp"
Tue 31 May 2005 40,448 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\IT\Til fremlaegningen\~WRL0004.tmp"
Tue 31 May 2005 40,960 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\IT\Til fremlaegningen\~WRL0327.tmp"
Tue 31 May 2005 42,496 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\IT\Til fremlaegningen\~WRL0916.tmp"
Tue 31 May 2005 41,472 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\IT\Til fremlaegningen\~WRL1122.tmp"
Tue 31 May 2005 41,984 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\IT\Til fremlaegningen\~WRL1515.tmp"
Tue 31 May 2005 40,448 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\IT\Til fremlaegningen\~WRL1732.tmp"
Tue 31 May 2005 40,448 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\IT\Til fremlaegningen\~WRL1976.tmp"
Tue 31 May 2005 41,472 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\IT\Til fremlaegningen\~WRL3387.tmp"
Sat 23 Apr 2005 57,344 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0020.tmp"
Sat 23 Apr 2005 60,416 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0037.tmp"
Sat 23 Apr 2005 57,344 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0101.tmp"
Sat 23 Apr 2005 57,856 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0145.tmp"
Sat 23 Apr 2005 56,832 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0309.tmp"
Sat 23 Apr 2005 57,344 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0505.tmp"

Bumblebee77
2008-03-04, 16:53
Sat 23 Apr 2005 59,904 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0536.tmp"
Sat 23 Apr 2005 58,368 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0615.tmp"
Sat 23 Apr 2005 55,296 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0670.tmp"
Sat 23 Apr 2005 60,928 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0699.tmp"
Fri 22 Apr 2005 54,272 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0785.tmp"
Sat 23 Apr 2005 60,416 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0853.tmp"
Sat 23 Apr 2005 56,832 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0876.tmp"
Sat 23 Apr 2005 57,856 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0995.tmp"
Sat 23 Apr 2005 57,856 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL1008.tmp"
Sat 23 Apr 2005 59,392 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL1069.tmp"
Sat 23 Apr 2005 60,928 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL1426.tmp"
Sat 23 Apr 2005 58,880 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL1697.tmp"
Sat 23 Apr 2005 60,928 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL1872.tmp"
Sat 23 Apr 2005 56,832 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL1988.tmp"
Sat 23 Apr 2005 56,832 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2052.tmp"
Sat 23 Apr 2005 58,880 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2053.tmp"
Sat 23 Apr 2005 56,832 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2063.tmp"
Sat 23 Apr 2005 60,928 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2169.tmp"
Sat 23 Apr 2005 57,856 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2177.tmp"
Sat 23 Apr 2005 57,856 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2221.tmp"
Sat 23 Apr 2005 58,880 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2351.tmp"
Sat 23 Apr 2005 55,808 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2456.tmp"
Sat 23 Apr 2005 55,808 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2474.tmp"
Sat 23 Apr 2005 26,624 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2567.tmp"
Sat 23 Apr 2005 56,320 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2713.tmp"
Sat 23 Apr 2005 57,856 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2749.tmp"
Sat 23 Apr 2005 59,904 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2756.tmp"
Sat 23 Apr 2005 55,808 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2769.tmp"
Sat 23 Apr 2005 57,344 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2881.tmp"
Sat 23 Apr 2005 60,928 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2916.tmp"
Sat 23 Apr 2005 26,624 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3015.tmp"
Sat 23 Apr 2005 60,928 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3150.tmp"
Sat 23 Apr 2005 56,832 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3207.tmp"
Sat 23 Apr 2005 55,808 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3290.tmp"
Sat 23 Apr 2005 60,928 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3326.tmp"
Sat 23 Apr 2005 60,416 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3369.tmp"
Sat 23 Apr 2005 60,928 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3518.tmp"
Sat 23 Apr 2005 57,856 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3870.tmp"
Sat 23 Apr 2005 57,856 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3871.tmp"
Sat 23 Apr 2005 59,392 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3872.tmp"
Sat 23 Apr 2005 55,296 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3906.tmp"
Sat 23 Apr 2005 60,416 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3978.tmp"
Sat 23 Apr 2005 60,416 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3979.tmp"
Sat 23 Apr 2005 60,928 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL4061.tmp"
Sat 23 Apr 2005 55,808 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL4074.tmp"
Sat 23 Apr 2005 55,808 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL4094.tmp"

Finished!

Bumblebee77
2008-03-04, 16:54
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:44:46, on 04-03-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Programmer\Fælles filer\Logitech\Bluetooth\LBTSERV.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Programmer\Logitech\Easy Synchronization\servicestub.exe
C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe
C:\Programmer\Fælles filer\Logitech\G-series Software\LGDCore.exe
C:\Programmer\Logitech\SetPoint\LBTWiz.exe
C:\Programmer\ClamWin\bin\ClamTray.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\DAEMON Tools\daemon.exe
C:\Programmer\DNA\btdna.exe
C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Programmer\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Programmer\Logitech\SetPoint\SetPoint.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Programmer\OpenOffice.org 2.2\program\soffice.exe
C:\Programmer\OpenOffice.org 2.2\program\soffice.BIN
C:\Programmer\Fælles filer\Logishrd\KHAL2\KHALMNPR.EXE
C:\Programmer\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://netbank.danskebank.dk/html/index.html?site=DBNB
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.zitech.dk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmer\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: CVirtualDNSObj Object - {86C510E9-97EF-4749-914F-0280247BE3A6} - C:\WINDOWS\VirtualDNS.dll (file missing)
O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programmer\AVG\AVG8\avgtoolbar.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Programmer\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programmer\AVG\AVG8\avgtoolbar.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Easy Synchronization] C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Programmer\Fælles filer\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Bluetooth Connection Assistant] LBTWIZ.EXE -silent
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [ClamWin] "C:\Programmer\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\RunOnce: [Easy Synchronization] C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe --ports
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Programmer\DNA\btdna.exe"
O4 - HKCU\..\Run: [LDM] C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.2.lnk = C:\Programmer\OpenOffice.org 2.2\program\quickstart.exe
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: &Search - ?p=ZJfox000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.zitech.dk
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmer\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FLLESF~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmer\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Programmer\Canon\CAL\CALMAIN.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Programmer\Fælles filer\Logitech\Bluetooth\LBTSERV.EXE
O23 - Service: Logitech Easy Synchronization - Unknown owner - C:\Programmer\Logitech\Easy Synchronization\servicestub.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmer\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 9304 bytes

Bumblebee77
2008-03-04, 16:58
To answer your question about my preferred home page I have to say I'm a bit baffled. I use Mozilla Firefox as my regular browser, where I have a personalized Google.com as my home page. I do have IE installed and use it for net banking. And the home page of my bank is my start up page in IE. That link/site it mentions... I don't know anything about it.

My PC has for a reeeheeeally long time randomly crashed to a blue screen with a lot of nonsense info on it... Could that have something to do with that link/site you're asking about?

Shaba
2008-03-04, 17:13
Hi

"To answer your question about my preferred home page I have to say I'm a bit baffled. I use Mozilla Firefox as my regular browser, where I have a personalized Google.com as my home page. I do have IE installed and use it for net banking. And the home page of my bank is my start up page in IE. That link/site it mentions... I don't know anything about it.
"

Thanks for the info.

"My PC has for a reeeheeeally long time randomly crashed to a blue screen with a lot of nonsense info on it... Could that have something to do with that link/site you're asking about?"

Likely a hardware issue. What is the temperature of your CPU?

Open HijackThis, click do a system scan only and checkmark these:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: CVirtualDNSObj Object - {86C510E9-97EF-4749-914F-0280247BE3A6} - C:\WINDOWS\VirtualDNS.dll (file missing)
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

Close all windows includiung browser and press fix checked.

Reboot.

Post back a fresh HijackThis log.

Bumblebee77
2008-03-04, 17:22
I don't have a computer thermometer. How do I check the temperature of my CPU? :red:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:44:46, on 04-03-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Programmer\Fælles filer\Logitech\Bluetooth\LBTSERV.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Programmer\Logitech\Easy Synchronization\servicestub.exe
C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe
C:\Programmer\Fælles filer\Logitech\G-series Software\LGDCore.exe
C:\Programmer\Logitech\SetPoint\LBTWiz.exe
C:\Programmer\ClamWin\bin\ClamTray.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\DAEMON Tools\daemon.exe
C:\Programmer\DNA\btdna.exe
C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Programmer\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Programmer\Logitech\SetPoint\SetPoint.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Programmer\OpenOffice.org 2.2\program\soffice.exe
C:\Programmer\OpenOffice.org 2.2\program\soffice.BIN
C:\Programmer\Fælles filer\Logishrd\KHAL2\KHALMNPR.EXE
C:\Programmer\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://netbank.danskebank.dk/html/index.html?site=DBNB
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.zitech.dk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmer\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: CVirtualDNSObj Object - {86C510E9-97EF-4749-914F-0280247BE3A6} - C:\WINDOWS\VirtualDNS.dll (file missing)
O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programmer\AVG\AVG8\avgtoolbar.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Programmer\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programmer\AVG\AVG8\avgtoolbar.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Easy Synchronization] C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Programmer\Fælles filer\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Bluetooth Connection Assistant] LBTWIZ.EXE -silent
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [ClamWin] "C:\Programmer\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\RunOnce: [Easy Synchronization] C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe --ports
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Programmer\DNA\btdna.exe"
O4 - HKCU\..\Run: [LDM] C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.2.lnk = C:\Programmer\OpenOffice.org 2.2\program\quickstart.exe
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: &Search - ?p=ZJfox000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.zitech.dk
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmer\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FLLESF~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmer\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Programmer\Canon\CAL\CALMAIN.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Programmer\Fælles filer\Logitech\Bluetooth\LBTSERV.EXE
O23 - Service: Logitech Easy Synchronization - Unknown owner - C:\Programmer\Logitech\Easy Synchronization\servicestub.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmer\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 9304 bytes

Bumblebee77
2008-03-04, 17:32
Oh dear. Wrong HijackThis log. Sorry. :red:

Will have the right one for you in a sec.

Bumblebee77
2008-03-04, 17:34
Again.... I'm so so sorry. :sad:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:32:06, on 04-03-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Programmer\Fælles filer\Logitech\Bluetooth\LBTSERV.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Programmer\Logitech\Easy Synchronization\servicestub.exe
C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe
C:\Programmer\Fælles filer\Logitech\G-series Software\LGDCore.exe
C:\Programmer\Logitech\SetPoint\LBTWiz.exe
C:\Programmer\ClamWin\bin\ClamTray.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\DAEMON Tools\daemon.exe
C:\Programmer\DNA\btdna.exe
C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Programmer\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Programmer\Logitech\SetPoint\SetPoint.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Programmer\OpenOffice.org 2.2\program\soffice.exe
C:\Programmer\OpenOffice.org 2.2\program\soffice.BIN
C:\Programmer\Fælles filer\Logishrd\KHAL2\KHALMNPR.EXE
C:\Programmer\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://netbank.danskebank.dk/html/index.html?site=DBNB
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.zitech.dk
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmer\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programmer\AVG\AVG8\avgtoolbar.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Programmer\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programmer\AVG\AVG8\avgtoolbar.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Easy Synchronization] C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Programmer\Fælles filer\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Bluetooth Connection Assistant] LBTWIZ.EXE -silent
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [ClamWin] "C:\Programmer\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\RunOnce: [Easy Synchronization] C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe --ports
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Programmer\DNA\btdna.exe"
O4 - HKCU\..\Run: [LDM] C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.2.lnk = C:\Programmer\OpenOffice.org 2.2\program\quickstart.exe
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: &Search - ?p=ZJfox000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.zitech.dk
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmer\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FLLESF~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmer\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Programmer\Canon\CAL\CALMAIN.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Programmer\Fælles filer\Logitech\Bluetooth\LBTSERV.EXE
O23 - Service: Logitech Easy Synchronization - Unknown owner - C:\Programmer\Logitech\Easy Synchronization\servicestub.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programmer\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 8930 bytes

Shaba
2008-03-04, 18:40
Hi

Use everest (http://www.majorgeeks.com/download4181.html)
for that, please.

Bumblebee77
2008-03-04, 18:48
Not sure how to use it. I see no download link and on the site you linked it says: "Limitations: Lavalys has discontinued the free edition. This is unsupported."

Is my PC free of the MSN virus now? I can safely log on to games, sites etc? And can I safely re-install MSN Messenger again?

Shaba
2008-03-04, 18:49
Hi

Download links are below:

Free Downloads From

"Is my PC free of the MSN virus now? I can safely log on to games, sites etc? And can I safely re-install MSN Messenger again?"

Should be yes unless you have other symptoms than blue screen left?

Bumblebee77
2008-03-04, 18:53
Good grief, you must be annoyed with me by now. You may spank me :devil:

It says that my GPU temp is 56 C / 133 F and HDT722516DLA380 temp is 40 C / 104 F.

(It does say Gpu and not Cpu... not sure if that's the temp you're looking for.)

Bumblebee77
2008-03-04, 18:56
No, no other symptoms than the blue screen. Thank you so much for all your help and patience. You and your colleagues to an amazing job. Thank you! :heart:

Shaba
2008-03-04, 18:56
Hi

Well GPU usually means graphics card.

Anyway, it's too much.

Have you lately opened computer case and taken off dust?

Bumblebee77
2008-03-04, 19:04
:red: .... No...

Shaba
2008-03-04, 19:09
Hi

So please do that (shutdown computer first of course and be gentle when removing dust) and let me know if it helped.

If you're unsure about procedure, of course you can let some computer store do it :)

Bumblebee77
2008-03-04, 19:12
Thank you. I think I'd better let a professional do that. I'm kinda too nervous to be poking around in there. But thank you for the advice. I'll get it done asap.

You truly are a gem for all you have done for me. I'd give you a big smack kiss on the lips if I could reach Finland from here, hehe ;)

Take care and blessed be. :heart:

Shaba
2008-03-04, 19:15
Hi

Ok :)

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Looking over your log, it seems you don't have any evidence of a third party firewall.

As the term conveys, a firewall is an extra layer of security installed onto computers, which restricts access to systems from the outside world. Firewalls protect against hackers and malicious intruders. I want you to download a free firewall NOW from one of these excellent vendors:

1) Comodo (http://www.personalfirewall.comodo.com/)
2) Online Armor (http://www.tallemu.com/online_armor_free.html)
3) Sunbelt/Kerio (http://www.sunbelt-software.com/Kerio-Download.cfm)
4) Agnitum (http://www.agnitum.com/products/outpostfree/download.php)
5) ZoneAlarm (http://www.zonelabs.com/store/content/catalog/products/sku_list_za.jsp?dc=12bms&ctry=US&lang=en&lid=nav_za) (uncheck ZoneAlarm Spy Blocker during installation if you choose this one)

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. A malicious site could render Java content under older, vulnerable versions of Sun's software if the user has not removed them. Please follow these steps to remove older version Java components and update: Download the latest version of Java Runtime Environment (JRE) 6 Update 4 (http://java.sun.com/javase/downloads/index.jsp) and save it to your desktop.
Scroll down to where it saysThe J2SE Runtime Environment (JRE) allows end-users to run Java applications.
Click the Download button to the right.
Select Windows on platform combobox and check the box that says:
Accept License Agreement. Click continue.
The page will refresh.
Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u4-windows-i586-p.exe to install the newest version.

Next we remove all used tools.

Please download OTMoveIt2 (http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe) and save it to desktop.

Double-click OTMoveIt2.exe.
Click the CleanUp! button.
Select Yes when the "Begin cleanup Process?" prompt appears.
If you are prompted to Reboot during the cleanup, select Yes.
The tool will delete itself once it finishes, if not delete it by yourself.


Note: If you receive a warning from your firewall or other security programs regarding OTMoveIt2 attempting to contact the internet, please allow it to do so.

Disable and Enable System Restore. - If you are using Windows XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide (http://www.bleepingcomputer.com/forums/tutorial56.html)

Re-enable system restore with instructions from tutorial above

Make your Internet Explorer more secure - This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt

Change the Download unsigned ActiveX controls to Disable

Change the Initialize and script ActiveX controls not marked as safe to Disable

Change the Installation of desktop items to Prompt

Change the Launching programs and files in an IFRAME to Prompt

Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.

If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.


Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com (http://www.windowsupdate.com) regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware (http://www.bleepingcomputer.com/tutorials/tutorial49.html)


Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Here are some additional utilities that will enhance your safety

MVPS Hosts file (http://mvps.org/winhelp2002/hosts.htm) <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
Google Toolbar (http://toolbar.google.com/) <= Get the free google toolbar to help stop pop up windows.
Comodo BOCLEAN (http://www.comodo.com/boclean/boclean.html) <= Stop identity thieves from getting personal information. Instantly detects well over 1,000,000 unique, variant and repack malware in total. And it's free.
Winpatrol (http://www.winpatrol.com/) <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
Using Winpatrol to protect your computer from malicious software (http://www.winpatrol.com/features.html)

Stand Up and Be Counted ---> Malware Complaints (http://www.malwarecomplaints.info/index.php) <--- where you can make difference!

The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

Also, please read this great article by Tony Klein So How Did I Get Infected In First Place (http://castlecops.com/postlite7736-.html)

Happy surfing and stay clean! :bigthumb:

Shaba
2008-03-06, 11:12
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

Note: If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.