PDA

View Full Version : virtumonde problem



gasvictim
2008-06-23, 19:43
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:32:31, on 2008-06-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
C:\Program\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program\Spybot - Search & Destroy\SpybotSD.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
C:\Program\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program\Personal\bin\Personal.exe
C:\Program\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.se/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: (no name) - {3822B20E-4BFF-44D7-9D0E-93FACC2D4A49} - C:\WINDOWS\system32\vtUkhhGA.dll (file missing)
O2 - BHO: (no name) - {4AAE5D1F-8E0F-4977-8F88-36CF7FA1C9B7} - C:\WINDOWS\system32\iifebXPf.dll (file missing)
O2 - BHO: {dd16de2d-7100-cdfb-edc4-a63c3e878c95} - {59c878e3-c36a-4cde-bfdc-0017d2ed61dd} - C:\WINDOWS\system32\ndeysnsp.dll
O2 - BHO: (no name) - {5F0D0C65-967F-4E2D-B5C4-889EE2D6008B} - C:\WINDOWS\system32\ddcDvwVl.dll (file missing)
O2 - BHO: (no name) - {62312C8E-D42B-473E-99CE-FCB9F68D55A6} - C:\WINDOWS\system32\hgGyyvwv.dll (file missing)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program\DELADE~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {973E5397-0915-4C61-891E-4C39A8022432} - C:\WINDOWS\system32\hgGawVPJ.dll (file missing)
O2 - BHO: (no name) - {9A7D16A9-9ADF-4CE7-8028-8474978484C3} - C:\WINDOWS\system32\pmnmlKaw.dll (file missing)
O2 - BHO: (no name) - {B5275768-1354-4BEE-9A81-8A7FC6DAA7D1} - C:\WINDOWS\system32\opnmLfEv.dll (file missing)
O2 - BHO: (no name) - {BF0CA4FC-6378-4062-B546-3CDE8A28B1E0} - C:\WINDOWS\system32\ddcCUOhe.dll
O2 - BHO: (no name) - {ED0A4068-28F3-465E-B563-0593D9F00882} - C:\WINDOWS\system32\efcCuvUm.dll (file missing)
O4 - HKLM\..\Run: [ccApp] C:\Program\Delade filer\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program\Spybot - Search & Destroy\SpybotSD.exe"
O4 - HKLM\..\Run: [cc25c14f] rundll32.exe "C:\WINDOWS\system32\rxbkjpxr.dll",b
O4 - HKLM\..\Run: [BMcf16f2d3] Rundll32.exe "C:\WINDOWS\system32\njwjpnuv.dll",s
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA4134] command /c del "C:\WINDOWS\system32\efcCuvUm.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4223] cmd /c del "C:\WINDOWS\system32\efcCuvUm.dll_old"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Personal.lnk = C:\Program\Personal\bin\Personal.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://dev.srtest.com/srl_bin/sysreqlab3.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1200093771437
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: ndeysnsp.dll
O20 - Winlogon Notify: ddcCUOhe - C:\WINDOWS\SYSTEM32\ddcCUOhe.dll
O21 - SSODL: hghezudo - {84d0e9b2-0951-4fa8-9662-965053e4fa73} - C:\Documents and Settings\All Users\Application Data\hghezudo.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program\Delade filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Automatisk LiveUpdate-schemaläggare - Symantec Corporation - C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program\DELADE~1\SYMANT~1\CCPD-LC\symlcsvc.exe

--
End of file - 8227 bytes

km2357
2008-06-24, 20:54
Hello and welcome to Safer Networking Forums.

My name is km2357 and I will be helping you to remove any infection(s) that you may have.

I will be giving you a series of instructions that need to be followed in the order in which I give them to you.

If for any reason you do not understand an instruction or are just unsure then please do not guess, simply post back with your questions/concerns and we will go through it again.

Please do not start another thread or topic, I will assist you at this thread until we solve your problems.

Lastly the fix may take several attempts and my replies may take some time but I will stick with it if you do the same.


I will be back as soon as possible with your first instructions!

km2357
2008-06-24, 21:06
What does "Delade filer" translate to in English?



Step # 1 Download CCleaner

Download CCleaner from here (http://www.ccleaner.com/) to clean temp files from your computer.

Double click on the ccsetup.exe file to start the installation of the program.
Select your language and click OK, then next.
Read the license agreement and click I Agree.
Click next to use the default install location.
Under Install Options, choose all the default settings except I would recommend that you unclick/untick install the Yahoo! Toolbar, unless you want it. You can also Uncheck the 'Automatically check for updates' box.
Click Install then finish to complete installation.




Step # 2 Retrieve the Installed Programs List from CCleaner

Open CCleaner if it's not already running.
In the Left Pane, click Tools
Verify that Uninstall is highlighted in color, or click on it.
In the lower Right, click Save to Text File.
Pull down the arrow at the top of the Save dialog and choose Desktop as the location.
You can leave the filename as install.txt
Click Save
Exit CCleaner by clicking on the X button in the upper right of the CCleaner window.




Step # 3: Download and Run ComboFix

We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Be sure to save ComboFix.exe to your Desktop

Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:


Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.


Click Yes to allow ComboFix to continue scanning for malware.


When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleaning the system:

CCleaner Install List
C:\ComboFix.txt
New HijackThis log.


Use multiple posts if you can't fit everything into one post.

gasvictim
2008-06-25, 20:48
First of all: Thanks for helping me out! With you guiding me there´s still hope...
To answer your first quetion: "Delade Filer" tranlated is "Shared Files". And now the files:


Ad-Aware
Adobe Flash Player ActiveX
Adobe Photoshop CS
Adobe Reader 7.0
Adobe Shockwave Player
Athlon 64 Processor Driver
Azureus Vuze
Call of Duty(R) 4 - Modern Warfare(TM)
CCleaner (remove only)
DVDFab Platinum 4.0.6.0 Beta
EA SPORTS online 2008
Emigranten 2001
EPoX Magic BIOS
Express Rip Uninstall
GfK klientprogrammet
Gothic III
HijackThis 2.0.2
ImageMixer VCD/DVD2 for OLYMPUS
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 11
Java(TM) 6 Update 3
Java(TM) 6 Update 5
LiveUpdate (Symantec Corporation)
LiveUpdate Notice (Symantec Corporation)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 1.1 Swedish Language Pack
Microsoft .NET Framework 2.0 Language Pack - SVE
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0 Swedish Language Pack
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Games for Windows - LIVE Redistributable
Microsoft Office Excel Viewer 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 6.0 Parser (KB933579)
Nero OEM
NHL® 08
Norton AntiVirus (Symantec Corporation)
NVIDIA Drivers
OLYMPUS Master
OpenAL
Personal 4.5.2
Pro Evolution Soccer 2008
Pro Evolution Soccer 6
PunkBuster Services
QuickTime
RealPlayer
Realtek AC'97 Audio
Rhapsody Player Engine
SopCast 3.0.3
Spybot - Search & Destroy
Sverigekartan version 3
Symantec Technical Support Web Controls
System Requirements Lab
TestDrive Client
The Orange Box
Tom Clancy's Rainbow Six Vegas 2
TPTEST 5.0.2
TVAnts 1.0
TVUPlayer 2.3.5.4
U.S. Robotics 56K Faxmodem USB
VideoLAN VLC media player 0.8.6d
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Player 11
Windows-drivrutinspaket - OPTO ELECTRONICS CO.,LTD (optousb) Ports (10/19/2006 1.0.3.0)
WinRAR
VobSub v2.23 (Remove Only)
Xfire (remove only)


ComboFix 08-06-20.4 - Per-Johan 2008-06-25 19:14:10.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1053.18.578 [GMT 2:00]
Running from: C:\Documents and Settings\Per-Johan\Skrivbord\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Per-Johan\Application Data\Microsoft\dtsc
C:\Documents and Settings\Per-Johan\Application Data\Microsoft\dtsc\s
C:\WINDOWS\BMcf16f2d3.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\cpan.dll
C:\WINDOWS\ctfmon32.exe
C:\WINDOWS\ctrlpan.dll
C:\WINDOWS\directx32.exe
C:\WINDOWS\dnsrelay.dll
C:\WINDOWS\editpad.exe
C:\WINDOWS\explore.exe
C:\WINDOWS\explorer32.exe
C:\WINDOWS\funniest.exe
C:\WINDOWS\funny.exe
C:\WINDOWS\gfmnaaa.dll
C:\WINDOWS\helpcvs.exe
C:\WINDOWS\inetinf.exe
C:\WINDOWS\internet.exe
C:\WINDOWS\msconfd.dll
C:\WINDOWS\msspi.dll
C:\WINDOWS\mswsc10.dll
C:\WINDOWS\mswsc20.dll
C:\WINDOWS\pskt.ini
C:\WINDOWS\qttasks.exe
C:\WINDOWS\quicken.exe
C:\WINDOWS\rundll16.exe
C:\WINDOWS\rundll32.vbe
C:\WINDOWS\searchword.dll
C:\WINDOWS\sistem.exe
C:\WINDOWS\svchost32.exe
C:\WINDOWS\svcinit.exe
C:\WINDOWS\system32\afqrtfan.ini
C:\WINDOWS\system32\AGhhkUtv.ini
C:\WINDOWS\system32\AGhhkUtv.ini2
C:\WINDOWS\system32\cqtfwxgh.dll
C:\WINDOWS\system32\ddcCUOhe.dll
C:\WINDOWS\system32\dgkehowk.ini
C:\WINDOWS\system32\dloxcxjj.ini
C:\WINDOWS\system32\fptvvsor.dll
C:\WINDOWS\system32\fPXbefii.ini
C:\WINDOWS\system32\fPXbefii.ini2
C:\WINDOWS\system32\frdkiykc.dll
C:\WINDOWS\system32\hljwugsf.bin
C:\WINDOWS\system32\JPVwaGgh.ini
C:\WINDOWS\system32\JPVwaGgh.ini2
C:\WINDOWS\system32\knuetwpm.dll
C:\WINDOWS\system32\lonwwlps.ini
C:\WINDOWS\system32\lVwvDcdd.ini
C:\WINDOWS\system32\lVwvDcdd.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mlJabYpn.dll
C:\WINDOWS\system32\mrbbkfcn.dll
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\mUvuCcfe.ini
C:\WINDOWS\system32\mUvuCcfe.ini2
C:\WINDOWS\system32\mxsfrxvs.dll
C:\WINDOWS\system32\naftrqfa.dll
C:\WINDOWS\system32\ncfkbbrm.ini
C:\WINDOWS\system32\npYbaJlm.ini
C:\WINDOWS\system32\npYbaJlm.ini2
C:\WINDOWS\system32\rosvvtpf.ini
C:\WINDOWS\system32\rxpjkbxr.ini
C:\WINDOWS\system32\splwwnol.dll
C:\WINDOWS\system32\tpqgndbt.dll
C:\WINDOWS\system32\waKlmnmp.ini
C:\WINDOWS\system32\waKlmnmp.ini2
C:\WINDOWS\system32\vEfLmnpo.ini
C:\WINDOWS\system32\vEfLmnpo.ini2
C:\WINDOWS\system32\whodvajc.dll
C:\WINDOWS\system32\vwvyyGgh.ini
C:\WINDOWS\system32\vwvyyGgh.ini2
C:\WINDOWS\system32\xungwkqf.ini
C:\WINDOWS\time.exe
C:\WINDOWS\waol.exe
C:\WINDOWS\xplugin.dll

.
((((((((((((((((((((((((( Files Created from 2008-05-25 to 2008-06-25 )))))))))))))))))))))))))))))))
.

2008-06-25 19:21 . 2008-06-25 19:21 22 --a------ C:\WINDOWS\pskt.ini
2008-06-25 19:21 . 2008-06-25 19:21 0 --a------ C:\WINDOWS\BMcf16f2d3.xml
2008-06-25 19:14 . 2008-06-25 19:14 6,736 --a------ C:\WINDOWS\system32\drivers\PROCEXP90.SYS
2008-06-25 18:04 . 2008-06-25 18:04 106,496 --a------ C:\WINDOWS\system32\lbabstrw.dll
2008-06-25 18:04 . 2008-06-25 18:04 91,136 --a------ C:\WINDOWS\system32\kcmpkcfr.dll
2008-06-25 18:04 . 2008-06-25 18:04 81,920 --a------ C:\WINDOWS\system32\kwohekgd.dll
2008-06-25 17:35 . 2008-06-25 17:35 <KAT> d-------- C:\Program\CCleaner
2008-06-23 17:16 . 2008-06-23 17:16 105,984 --a------ C:\WINDOWS\system32\ndeysnsp.dll
2008-06-23 17:16 . 2008-06-23 17:16 91,136 --a------ C:\WINDOWS\system32\njwjpnuv.dll
2008-06-23 17:13 . 2008-06-23 17:13 <KAT> d-------- C:\Program\Trend Micro
2008-06-19 19:58 . 2008-06-19 19:58 98,816 --a------ C:\WINDOWS\system32\xbpsrytx.dll
2008-06-19 19:52 . 2008-06-19 19:52 90,112 --a------ C:\WINDOWS\system32\nfhrcubp.dll
2008-06-18 20:37 . 2008-06-18 20:37 <KAT> d-------- C:\Program\Lavasoft
2008-06-18 20:37 . 2008-06-18 20:39 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-18 20:30 . 2008-06-18 20:30 <KAT> d-------- C:\Program\Delade filer\Wise Installation Wizard
2008-06-14 21:58 . 2008-06-16 21:16 <KAT> d-------- C:\Program\Spybot - Search & Destroy
2008-06-14 21:58 . 2008-06-14 22:14 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-14 15:08 . 2008-06-16 21:12 <KAT> d-------- C:\Program\uTorrent
2008-06-14 15:08 . 2008-06-14 15:08 102,400 --a------ C:\Documents and Settings\All Users\Application Data\hghezudo.dll
2008-06-14 13:44 . 2008-06-14 13:44 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-14 13:44 . 2008-06-14 13:44 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-11 12:06 . 2008-06-14 20:01 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 12:06 . 2008-06-14 20:01 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-03 21:24 . 2008-06-03 21:24 <KAT> d-------- C:\Documents and Settings\Per-Johan\Application Data\Runaware
2008-06-03 21:24 . 2008-06-03 21:24 <KAT> d-------- C:\Documents and Settings\Per-Johan\Application Data\ICAClient
2008-06-01 21:41 . 2008-06-01 21:56 <KAT> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-06-01 16:11 . 2008-06-01 16:11 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-06-01 16:08 . 2008-06-01 16:08 <KAT> d-------- C:\WINDOWS\nview
2008-06-01 14:40 . 2008-06-01 16:09 <KAT> d-------- C:\WINDOWS\nvidia icons
2008-06-01 12:36 . 2008-06-01 12:36 <KAT> d-------- C:\Program\Valvesoftware
2008-05-28 22:25 . 2008-05-28 22:25 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\Ubisoft
2008-05-28 22:24 . 2008-05-28 22:24 2,337,865 --a------ C:\WINDOWS\system32\pbsvc.exe
2008-05-28 22:24 . 2008-05-28 22:24 107,832 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-05-28 22:24 . 2008-05-28 22:24 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-05-28 22:24 . 2008-05-28 22:24 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-05-28 22:24 . 2008-05-28 22:24 22,328 --a------ C:\Documents and Settings\Per-Johan\Application Data\PnkBstrK.sys
2008-05-28 22:23 . 2007-10-12 15:14 3,734,536 --a------ C:\WINDOWS\system32\d3dx9_36.dll
2008-05-28 22:23 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2008-05-28 22:23 . 2007-10-12 15:14 1,374,232 --a------ C:\WINDOWS\system32\D3DCompiler_36.dll
2008-05-28 22:23 . 2007-07-19 18:14 1,358,192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll
2008-05-28 22:23 . 2007-10-02 09:56 444,776 --a------ C:\WINDOWS\system32\d3dx10_36.dll
2008-05-28 22:23 . 2007-07-19 18:14 444,776 --a------ C:\WINDOWS\system32\d3dx10_35.dll
2008-05-28 22:23 . 2007-10-22 03:39 267,272 --a------ C:\WINDOWS\system32\xactengine2_10.dll
2008-05-28 22:23 . 2007-07-20 00:57 267,112 --a------ C:\WINDOWS\system32\xactengine2_9.dll
2008-05-28 15:23 . 2005-10-21 07:25 13,396 --a------ C:\WINDOWS\system32\drivers\MTictwl.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-21 19:17 --------- d-----w C:\Documents and Settings\Per-Johan\Application Data\dvdcss
2008-06-16 19:17 --------- d-----w C:\Program\QuickTime
2008-06-12 16:01 --------- d-----w C:\Documents and Settings\Per-Johan\Application Data\Azureus
2008-06-02 14:09 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-06-02 14:09 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-06-02 14:09 10,671 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-06-02 14:09 --------- d-----w C:\Program\Symantec
2008-06-01 10:36 --------- d--h--w C:\Program\InstallShield Installation Information
2008-05-28 20:12 --------- d-----w C:\Program\UBISOFT
2008-05-21 20:36 --------- d-----w C:\Program\Delade filer\Symantec Shared
2008-05-13 08:07 --------- d-----w C:\Program\Hattrick Coach Professional
2008-05-11 14:43 --------- d-----w C:\Program\SopCast
2008-05-10 13:01 --------- d-----w C:\Program\Satellite TV for PC
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-03 03:46 6,554,496 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2008-04-29 09:20 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 09:19 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 09:19 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
2008-04-18 20:29 87,608 ----a-w C:\Documents and Settings\Per-Johan\Application Data\inst.exe
2008-04-18 20:29 47,360 ----a-w C:\Documents and Settings\Per-Johan\Application Data\pcouffin.sys
.

------- Sigcheck -------

2006-01-13 19:07 360448 5562cc0a47b2aef06d3417b733f3c195 C:\WINDOWS\$hf_mig$\KB913446\SP2QFE\tcpip.sys
2006-04-20 14:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 18:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2004-08-04 14:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB913446$\tcpip.sys
2006-01-13 04:28 359808 583e063fdc888ca30d05c2724b0d7ef4 C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2006-04-20 13:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2008-04-13 21:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\SoftwareDistribution\Download\602f759e47356a387e3fe197762b452c\tcpip.sys
2008-01-09 23:29 360064 482ab7f9cd41702e8f856c11cfefb02d C:\WINDOWS\system32\dllcache\TCPIP.SYS
2008-01-09 23:29 360064 482ab7f9cd41702e8f856c11cfefb02d C:\WINDOWS\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3822B20E-4BFF-44D7-9D0E-93FACC2D4A49}]
C:\WINDOWS\system32\vtUkhhGA.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4AAE5D1F-8E0F-4977-8F88-36CF7FA1C9B7}]
C:\WINDOWS\system32\iifebXPf.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5F0D0C65-967F-4E2D-B5C4-889EE2D6008B}]
C:\WINDOWS\system32\ddcDvwVl.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{62312C8E-D42B-473E-99CE-FCB9F68D55A6}]
C:\WINDOWS\system32\hgGyyvwv.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-04-15 16:40 116088 --a------ C:\Program\DELADE~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{973E5397-0915-4C61-891E-4C39A8022432}]
C:\WINDOWS\system32\hgGawVPJ.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9A7D16A9-9ADF-4CE7-8028-8474978484C3}]
C:\WINDOWS\system32\pmnmlKaw.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B5275768-1354-4BEE-9A81-8A7FC6DAA7D1}]
C:\WINDOWS\system32\opnmLfEv.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ED0A4068-28F3-465E-B563-0593D9F00882}]
C:\WINDOWS\system32\efcCuvUm.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fcd525d7-57a7-4dd2-a5cc-206f17ead7e1}]
2008-06-25 18:04 106496 --a------ C:\WINDOWS\system32\lbabstrw.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program\Delade filer\Symantec Shared\ccApp.exe" [2008-02-14 11:01 51048]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-03 05:46 13529088]
"SpybotSnD"="C:\Program\Spybot - Search & Destroy\SpybotSD.exe" [2008-01-28 11:43 5146448]
"nwiz"="nwiz.exe" [2008-05-03 05:46 1630208 C:\WINDOWS\system32\nwiz.exe]
"cc25c14f"="C:\WINDOWS\system32\kwohekgd.dll" [2008-06-25 18:04 81920]
"BMcf16f2d3"="C:\WINDOWS\system32\kcmpkcfr.dll" [2008-06-25 18:04 91136]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]
"ALUAlert"="C:\Program\Symantec\LiveUpdate\ALUNotify.exe" [2007-08-23 14:35 152952]

C:\Documents and Settings\All Users\Start-meny\Program\Autostart\
Adobe Gamma Loader.lnk - C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe [2007-02-14 16:53:50 113664]
Adobe Reader Speed Launch.lnk - C:\Program\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 05:44:06 29696]
Personal.lnk - C:\Program\Personal\bin\Personal.exe [2007-10-29 21:18:26 722728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"hghezudo"= {84d0e9b2-0951-4fa8-9662-965053e4fa73} - C:\Documents and Settings\All Users\Application Data\hghezudo.dll [2008-06-14 15:08 102400]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=ndeysnsp.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= pvmjpg21.dll
"VIDC.XFR1"= xfcodec.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program\\KONAMI\\Pro Evolution Soccer 2008\\PES2008.exe"=
"C:\\Program\\Messenger\\msmsgs.exe"=
"C:\\Program\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program\\UBISOFT\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"C:\\Program\\UBISOFT\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Launcher.exe"=

R2 ithsgt;ithsgt;C:\WINDOWS\system32\DRIVERS\ithsgt.sys [2006-03-12 21:03]
R2 lilsgt;lilsgt;C:\WINDOWS\system32\DRIVERS\lilsgt.sys [2006-03-12 21:03]
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe" /h ccCommon []
R3 Tetri5;Tetri5 driver;C:\WINDOWS\system32\Drivers\Tetri5.sys [2006-03-18 01:28]
S2 Automatisk LiveUpdate-schemaläggare;Automatisk LiveUpdate-schemaläggare;"C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-08-23 14:35]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]
S3 optousb;OPTO ELECTRONICS optousb;C:\WINDOWS\system32\DRIVERS\optousb.sys [2006-10-18 18:14]
S3 optovcm;OPTO ELECTRONICS optovcm;C:\WINDOWS\system32\DRIVERS\optovcm.sys [2006-10-19 14:46]
S3 Winacusb;Winacusb;C:\WINDOWS\system32\DRIVERS\winacusb.sys [2002-03-06 03:24]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3780051a-f416-11db-8a99-baf56642fa9d}]
\Shell\AutoRun\command - F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3780051c-f416-11db-8a99-baf56642fa9d}]
\Shell\AutoRun\command - F:\AutoRun.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-06-23 18:01:07 C:\WINDOWS\Tasks\Norton AntiVirus - Kör fullständig systemsökning - Per-Johan.job"


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:34, on 2008-06-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Personal\bin\Personal.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.se/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: (no name) - {3822B20E-4BFF-44D7-9D0E-93FACC2D4A49} - C:\WINDOWS\system32\vtUkhhGA.dll (file missing)
O2 - BHO: (no name) - {4AAE5D1F-8E0F-4977-8F88-36CF7FA1C9B7} - C:\WINDOWS\system32\iifebXPf.dll (file missing)
O2 - BHO: (no name) - {5F0D0C65-967F-4E2D-B5C4-889EE2D6008B} - C:\WINDOWS\system32\ddcDvwVl.dll (file missing)
O2 - BHO: (no name) - {62312C8E-D42B-473E-99CE-FCB9F68D55A6} - C:\WINDOWS\system32\hgGyyvwv.dll (file missing)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program\DELADE~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {973E5397-0915-4C61-891E-4C39A8022432} - C:\WINDOWS\system32\hgGawVPJ.dll (file missing)
O2 - BHO: (no name) - {9A7D16A9-9ADF-4CE7-8028-8474978484C3} - C:\WINDOWS\system32\pmnmlKaw.dll (file missing)
O2 - BHO: (no name) - {B5275768-1354-4BEE-9A81-8A7FC6DAA7D1} - C:\WINDOWS\system32\opnmLfEv.dll (file missing)
O2 - BHO: (no name) - {ED0A4068-28F3-465E-B563-0593D9F00882} - C:\WINDOWS\system32\efcCuvUm.dll (file missing)
O2 - BHO: {1e7dae71-f602-cc5a-2dd4-7a757d525dcf} - {fcd525d7-57a7-4dd2-a5cc-206f17ead7e1} - C:\WINDOWS\system32\lbabstrw.dll
O4 - HKLM\..\Run: [ccApp] C:\Program\Delade filer\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program\Spybot - Search & Destroy\SpybotSD.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [cc25c14f] rundll32.exe "C:\WINDOWS\system32\kwohekgd.dll",b
O4 - HKLM\..\Run: [BMcf16f2d3] Rundll32.exe "C:\WINDOWS\system32\kcmpkcfr.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Personal.lnk = C:\Program\Personal\bin\Personal.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://dev.srtest.com/srl_bin/sysreqlab3.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1200093771437
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O21 - SSODL: hghezudo - {84d0e9b2-0951-4fa8-9662-965053e4fa73} - C:\Documents and Settings\All Users\Application Data\hghezudo.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program\Delade filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Automatisk LiveUpdate-schemaläggare - Symantec Corporation - C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program\DELADE~1\SYMANT~1\CCPD-LC\symlcsvc.exe

--
End of file - 7692 bytes

km2357
2008-06-25, 21:53
IMPORTANT I notice there are signs of one or more P2P (Person to Person) File Sharing Programs on your computer.

Azureus Vuze

I'd like you to read the Guidelines for P2P Programs (http://spywarewarrior.com/viewtopic.php?t=26216) where we explain why it's not a good idea to have them.

Also available here (http://forum.malwareremoval.com/viewtopic.php?t=23812&sid=a609c56441d8a2e5dc8d24e3e96420cc).

My recommendation is you go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).



Step # 1: Run CFScript

Please delete the version of ComboFix you have on your computer, I need you to download the latest version of ComboFix by sUBs here (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) and save it to your Desktop.



Then, please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:


http://forums.spybot.info/showpost.php?p=206087&postcount=4

KILLALL::

File::

C:\WINDOWS\pskt.ini
C:\WINDOWS\BMcf16f2d3.xml

Collect::

C:\WINDOWS\system32\lbabstrw.dll
C:\WINDOWS\system32\kcmpkcfr.dll
C:\WINDOWS\system32\kwohekgd.dll
C:\WINDOWS\system32\ndeysnsp.dll
C:\WINDOWS\system32\njwjpnuv.dll
C:\WINDOWS\system32\xbpsrytx.dll
C:\WINDOWS\system32\nfhrcubp.dll
C:\Documents and Settings\All Users\Application Data\hghezudo.dll

Folder::

C:\Program\uTorrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus

Registry::

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3822B20E-4BFF-44D7-9D0E-93FACC2D4A49}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4AAE5D1F-8E0F-4977-8F88-36CF7FA1C9B7}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5F0D0C65-967F-4E2D-B5C4-889EE2D6008B}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{62312C8E-D42B-473E-99CE-FCB9F68D55A6}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{973E5397-0915-4C61-891E-4C39A8022432}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9A7D16A9-9ADF-4CE7-8028-8474978484C3}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B5275768-1354-4BEE-9A81-8A7FC6DAA7D1}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ED0A4068-28F3-465E-B563-0593D9F00882}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fcd525d7-57a7-4dd2-a5cc-206f17ead7e1}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cc25c14f"=-
"BMcf16f2d3"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"hghezudo"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=""


Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.




http://i266.photobucket.com/albums/ii277/sUBs_/CFScript.gif


Note: This CFScript is for use on [user's name] computer only! Do not use it on your computer.


Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

When CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture a file to submit for analysis.

Ensure you are connected to the internet and click OK on the message box. A browser will open. Simply follow the instructions to copy/paste/send the requested file.


In your next post/reply, I need to see the following:

1. ComboFix Log that appears after Step 1 has been completed
2. A fresh HiJackThis Log taken after Step 1 has been completed

Use multiple posts if you can't fit everything into one post.

gasvictim
2008-06-26, 18:35
I did as you instructed. Azareus Vuze is removed.
But when I ran CF it never open the browser so I never got any intructions to follow. It created a ZIP-file at the desktop though, named "[4]-Submit_2008-06-26@17.03". Maybe it opened the browser and I just didn´t notice cause I wasn´t around watching.
But I noticed that when running CF and that after the blue screen saying "scan typically takes 10 minutes... may take double time..." and so on, a "File can´t be found"-message appeared. Then CF continued scanning all the stages. Thought you might like to know...

Here are the logs:

ComboFix 08-06-20.4 - Per-Johan 2008-06-26 17:03:53.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1053.18.598 [GMT 2:00]
Running from: C:\Documents and Settings\Per-Johan\Skrivbord\ComboFix.exe
Command switches used :: C:\Documents and Settings\Per-Johan\Skrivbord\CFScript.txt
* Created a new restore point

FILE ::
C:\WINDOWS\BMcf16f2d3.xml
C:\WINDOWS\pskt.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\hghezudo.dll
C:\Documents and Settings\Per-Johan\Application Data\Azureus
C:\Documents and Settings\Per-Johan\Application Data\Azureus\.keystore
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\07BACDC31EF6A94E83EAE6B4EB0720139466EFB5.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\07BACDC31EF6A94E83EAE6B4EB0720139466EFB5.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\0B049DC8296A2A3820726FCCAF32AB76BA831EC9.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\0B049DC8296A2A3820726FCCAF32AB76BA831EC9.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\1B66EF02B74337642381C4CEA1EB21A36FB4BD66.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\1B66EF02B74337642381C4CEA1EB21A36FB4BD66.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\214BEF6C8344EF4E973E0EEC0DBC9B9BD2305E96.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\214BEF6C8344EF4E973E0EEC0DBC9B9BD2305E96.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\215D2DD9D8B280445B49DC7E5994334D3C50E719.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\215D2DD9D8B280445B49DC7E5994334D3C50E719.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\2F86EFA71C51AEE32C08974232E947127CB3C7D0.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\2F86EFA71C51AEE32C08974232E947127CB3C7D0.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\38753698801EB17E31F19AE0BEBF9F86CC263481.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\38753698801EB17E31F19AE0BEBF9F86CC263481.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\5F5024775C323B9150D4F083780D402D30ECA3E2.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\5F5024775C323B9150D4F083780D402D30ECA3E2.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\7DAA4B9E0814AD02663A2BCB8F76F640D8DCEBBE.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\7DAA4B9E0814AD02663A2BCB8F76F640D8DCEBBE.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\85391B3C4F4121F669FCF8CDE68CC5C9A856C2AE.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\85391B3C4F4121F669FCF8CDE68CC5C9A856C2AE.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\A544ADC822978C5CBCC3AF17F1946B605FBC520D.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\A544ADC822978C5CBCC3AF17F1946B605FBC520D.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\B7345B0275F171284081E35CF8D228CE05AD1120.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\B7345B0275F171284081E35CF8D228CE05AD1120.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\C264C2C0611487125082F2F395AD6A46BA95E75F.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\C264C2C0611487125082F2F395AD6A46BA95E75F.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\cache.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\DAD67F5CFB4153B25419E90567754A2A43F03389.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\DAD67F5CFB4153B25419E90567754A2A43F03389.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\ED15814AA205F8B3A64348F6140E8504E7410C2C.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\ED15814AA205F8B3A64348F6140E8504E7410C2C.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\azureus.config
C:\Documents and Settings\Per-Johan\Application Data\Azureus\azureus.config.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\azureus.statistics
C:\Documents and Settings\Per-Johan\Application Data\Azureus\azureus.statistics.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\banips.config
C:\Documents and Settings\Per-Johan\Application Data\Azureus\banips.config.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\dht\addresses.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\dht\contacts.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\dht\diverse.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\dht\general.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\dht\version.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\downloads.config
C:\Documents and Settings\Per-Johan\Application Data\Azureus\downloads.config.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\filters.config
C:\Documents and Settings\Per-Johan\Application Data\Azureus\ipfilter.cache
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\alerts_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\AutoSpeed_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\AutoSpeed_2.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\AutoSpeedSearchHistory_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\AutoSpeedSearchHistory_2.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\debug_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\debug_2.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\NetStatus_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\seltrace_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\seltrace_2.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\SpeedMan_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\SpeedMan_2.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\thread_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\thread_2.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\v3.ads_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\v3.CMsgr_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\v3.PMsgr_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\v3.Stream_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\net\pm_20626.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\net\pm_default.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tables.config
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tables.config.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tmp\AZU4259.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tmp\AZU4260.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tmp\AZU4261.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tmp\AZU4262.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tmp\AZU4263.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tmp\AZU4264.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tmp\AZU4265.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tmp\AZU4266.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tmp\AZU4267.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tmp\AZU4268.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\[NHLTorrents]_NHL_Match_Stanley_Cup_Game_5_-_Pittsburgh_Penguins_@_Detroit_Redwings_-_2008_06_02_-_English[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\[NHLTorrents]_NHL_Match_Stanley_Cup_Game_6_-_Detroit_Redwings_@_Pittsburgh_Penguins_-_2008_06_04_-_English[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Amy_Winehouse_-_Back_To_Black.3693362.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Audioslave_-_Revelations.3530364.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\AZU12631.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\AZU12633.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\AZU12635.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\AZU12638.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\AZU30736.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\AZU30739.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\AZU3755.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\AZU38508.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\AZU43410.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\AZU43413.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\BBC.Jane.Eyre_[2006]_1-4.DaRmEtH.3768454.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Charles_Aznavour_-_40_Chansons_D____Or_-_CD_1_et_2_-_mp3_192kbps.3670308.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Children.Of.Men.2006.SWESUB.DVDRip.Xvid-Nimol.3765082.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Coldplay_-_Viva_La_Vida_(2008)Fullus_artwork-320Kbps.4233465.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Darling.2007.DVDRip.SWEDISH.XViD-Nimol.3725915.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Die.Hard.1988.Extended.Version.INTERNAL.DVDRip.XviD-NEPTUNE_[mininova][1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Google.SketchUp.Pro.v6.4.112.Incl.Keymaker-ACME.3939947.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Memento.SWESUB.DVDRip.Xvid-Nimol.3922082.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Neil_Young_(Greatest_Hits).3688275.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Pirates.of.the.Caribbean-Dead.Mans.Chest%5B2006%5DDvDrip%5BEng%5D-aXXo_%5Bwww.NewTorrents.info%5D[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Reign_over_me.2007.DvDrip.SWESub.XviD_-_Christley.3784341.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Shrek.The.Third[2007]DvDrip.AC3[Eng]-aXXo.3884693.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Stolthet_och_F__rdom_1.3428346.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Stolthet_och_F__rdom_2.3428359.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\The.Orange.Box-DETONATiON.3903605.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Weezer_-_Weezer_(The_Red_Album)_[2008]_-_Rock_.4217965.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tracker.config
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tracker.config.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\trackers.config
C:\Documents and Settings\Per-Johan\Application Data\Azureus\unsentdata.config
C:\Documents and Settings\Per-Johan\Application Data\Azureus\unsentdata.config.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\update.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\update.properties
C:\Documents and Settings\Per-Johan\Application Data\Azureus\VuzeActivities.config
C:\Documents and Settings\Per-Johan\Application Data\Azureus\VuzeActivities.config.bak
C:\Documents and Settings\Per-Johan\Application Data\inst.exe
C:\Program\uTorrent
C:\WINDOWS\BMcf16f2d3.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\kcmpkcfr.dll
C:\WINDOWS\system32\kwohekgd.dll
C:\WINDOWS\system32\lbabstrw.dll
C:\WINDOWS\system32\ndeysnsp.dll
C:\WINDOWS\system32\nfhrcubp.dll
C:\WINDOWS\system32\njwjpnuv.dll
C:\WINDOWS\system32\xbpsrytx.dll
.
---- Previous Run -------
.
C:\Documents and Settings\Per-Johan\Application Data\Microsoft\dtsc
C:\Documents and Settings\Per-Johan\Application Data\Microsoft\dtsc\s
C:\WINDOWS\BMcf16f2d3.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\cpan.dll
C:\WINDOWS\ctfmon32.exe
C:\WINDOWS\ctrlpan.dll
C:\WINDOWS\directx32.exe
C:\WINDOWS\dnsrelay.dll
C:\WINDOWS\editpad.exe
C:\WINDOWS\explore.exe
C:\WINDOWS\explorer32.exe
C:\WINDOWS\funniest.exe
C:\WINDOWS\funny.exe
C:\WINDOWS\gfmnaaa.dll
C:\WINDOWS\helpcvs.exe
C:\WINDOWS\inetinf.exe
C:\WINDOWS\internet.exe
C:\WINDOWS\msconfd.dll
C:\WINDOWS\msspi.dll
C:\WINDOWS\mswsc10.dll
C:\WINDOWS\mswsc20.dll
C:\WINDOWS\pskt.ini
C:\WINDOWS\qttasks.exe
C:\WINDOWS\quicken.exe
C:\WINDOWS\rundll16.exe
C:\WINDOWS\rundll32.vbe
C:\WINDOWS\searchword.dll
C:\WINDOWS\sistem.exe
C:\WINDOWS\svchost32.exe
C:\WINDOWS\svcinit.exe
C:\WINDOWS\system32\afqrtfan.ini
C:\WINDOWS\system32\AGhhkUtv.ini
C:\WINDOWS\system32\AGhhkUtv.ini2
C:\WINDOWS\system32\cqtfwxgh.dll
C:\WINDOWS\system32\ddcCUOhe.dll
C:\WINDOWS\system32\dgkehowk.ini
C:\WINDOWS\system32\dloxcxjj.ini
C:\WINDOWS\system32\fptvvsor.dll
C:\WINDOWS\system32\fPXbefii.ini
C:\WINDOWS\system32\fPXbefii.ini2
C:\WINDOWS\system32\frdkiykc.dll
C:\WINDOWS\system32\hljwugsf.bin
C:\WINDOWS\system32\JPVwaGgh.ini
C:\WINDOWS\system32\JPVwaGgh.ini2
C:\WINDOWS\system32\knuetwpm.dll
C:\WINDOWS\system32\lonwwlps.ini
C:\WINDOWS\system32\lVwvDcdd.ini
C:\WINDOWS\system32\lVwvDcdd.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mlJabYpn.dll
C:\WINDOWS\system32\mrbbkfcn.dll
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\mUvuCcfe.ini
C:\WINDOWS\system32\mUvuCcfe.ini2
C:\WINDOWS\system32\mxsfrxvs.dll
C:\WINDOWS\system32\naftrqfa.dll
C:\WINDOWS\system32\ncfkbbrm.ini
C:\WINDOWS\system32\npYbaJlm.ini
C:\WINDOWS\system32\npYbaJlm.ini2
C:\WINDOWS\system32\rosvvtpf.ini
C:\WINDOWS\system32\rxpjkbxr.ini
C:\WINDOWS\system32\splwwnol.dll
C:\WINDOWS\system32\tpqgndbt.dll
C:\WINDOWS\system32\waKlmnmp.ini
C:\WINDOWS\system32\waKlmnmp.ini2
C:\WINDOWS\system32\vEfLmnpo.ini
C:\WINDOWS\system32\vEfLmnpo.ini2
C:\WINDOWS\system32\whodvajc.dll
C:\WINDOWS\system32\vwvyyGgh.ini
C:\WINDOWS\system32\vwvyyGgh.ini2
C:\WINDOWS\system32\xungwkqf.ini
C:\WINDOWS\time.exe
C:\WINDOWS\waol.exe
C:\WINDOWS\xplugin.dll

.
((((((((((((((((((((((((( Files Created from 2008-05-26 to 2008-06-26 )))))))))))))))))))))))))))))))
.

2008-06-25 19:21 . 2008-06-26 16:39 414 ---hs---- C:\WINDOWS\system32\dgkehowk.ini
2008-06-25 17:35 . 2008-06-25 17:35 <KAT> d-------- C:\Program\CCleaner
2008-06-23 17:13 . 2008-06-23 17:13 <KAT> d-------- C:\Program\Trend Micro
2008-06-18 20:37 . 2008-06-18 20:37 <KAT> d-------- C:\Program\Lavasoft
2008-06-18 20:37 . 2008-06-18 20:39 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-18 20:30 . 2008-06-18 20:30 <KAT> d-------- C:\Program\Delade filer\Wise Installation Wizard
2008-06-14 21:58 . 2008-06-16 21:16 <KAT> d-------- C:\Program\Spybot - Search & Destroy
2008-06-14 21:58 . 2008-06-14 22:14 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-14 13:44 . 2008-06-14 13:44 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-14 13:44 . 2008-06-14 13:44 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-11 12:06 . 2008-06-14 20:01 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 12:06 . 2008-06-14 20:01 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-03 21:24 . 2008-06-03 21:24 <KAT> d-------- C:\Documents and Settings\Per-Johan\Application Data\Runaware
2008-06-03 21:24 . 2008-06-03 21:24 <KAT> d-------- C:\Documents and Settings\Per-Johan\Application Data\ICAClient
2008-06-01 21:41 . 2008-06-01 21:56 <KAT> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-06-01 16:11 . 2008-06-01 16:11 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-06-01 16:08 . 2008-06-01 16:08 <KAT> d-------- C:\WINDOWS\nview
2008-06-01 14:40 . 2008-06-01 16:09 <KAT> d-------- C:\WINDOWS\nvidia icons
2008-06-01 12:36 . 2008-06-01 12:36 <KAT> d-------- C:\Program\Valvesoftware
2008-05-28 22:25 . 2008-05-28 22:25 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\Ubisoft
2008-05-28 22:24 . 2008-05-28 22:24 2,337,865 --a------ C:\WINDOWS\system32\pbsvc.exe
2008-05-28 22:24 . 2008-05-28 22:24 107,832 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-05-28 22:24 . 2008-05-28 22:24 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-05-28 22:24 . 2008-05-28 22:24 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-05-28 22:24 . 2008-05-28 22:24 22,328 --a------ C:\Documents and Settings\Per-Johan\Application Data\PnkBstrK.sys
2008-05-28 22:23 . 2007-10-12 15:14 3,734,536 --a------ C:\WINDOWS\system32\d3dx9_36.dll
2008-05-28 22:23 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2008-05-28 22:23 . 2007-10-12 15:14 1,374,232 --a------ C:\WINDOWS\system32\D3DCompiler_36.dll
2008-05-28 22:23 . 2007-07-19 18:14 1,358,192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll
2008-05-28 22:23 . 2007-10-02 09:56 444,776 --a------ C:\WINDOWS\system32\d3dx10_36.dll
2008-05-28 22:23 . 2007-07-19 18:14 444,776 --a------ C:\WINDOWS\system32\d3dx10_35.dll
2008-05-28 22:23 . 2007-10-22 03:39 267,272 --a------ C:\WINDOWS\system32\xactengine2_10.dll
2008-05-28 22:23 . 2007-07-20 00:57 267,112 --a------ C:\WINDOWS\system32\xactengine2_9.dll
2008-05-28 15:23 . 2005-10-21 07:25 13,396 --a------ C:\WINDOWS\system32\drivers\MTictwl.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-25 21:08 --------- d-----w C:\Program\Azureus
2008-06-21 19:17 --------- d-----w C:\Documents and Settings\Per-Johan\Application Data\dvdcss
2008-06-16 19:17 --------- d-----w C:\Program\QuickTime
2008-06-02 14:09 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-06-02 14:09 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-06-02 14:09 10,671 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-06-02 14:09 --------- d-----w C:\Program\Symantec
2008-06-01 10:36 --------- d--h--w C:\Program\InstallShield Installation Information
2008-05-28 20:12 --------- d-----w C:\Program\UBISOFT
2008-05-21 20:36 --------- d-----w C:\Program\Delade filer\Symantec Shared
2008-05-13 08:07 --------- d-----w C:\Program\Hattrick Coach Professional
2008-05-11 14:43 --------- d-----w C:\Program\SopCast
2008-05-10 13:01 --------- d-----w C:\Program\Satellite TV for PC
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-03 03:46 6,554,496 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2008-04-29 09:20 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 09:19 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 09:19 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
2008-04-18 20:29 47,360 ----a-w C:\Documents and Settings\Per-Johan\Application Data\pcouffin.sys
.

------- Sigcheck -------

2006-01-13 19:07 360448 5562cc0a47b2aef06d3417b733f3c195 C:\WINDOWS\$hf_mig$\KB913446\SP2QFE\tcpip.sys
2006-04-20 14:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 18:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2004-08-04 14:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB913446$\tcpip.sys
2006-01-13 04:28 359808 583e063fdc888ca30d05c2724b0d7ef4 C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2006-04-20 13:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2008-04-13 21:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\SoftwareDistribution\Download\602f759e47356a387e3fe197762b452c\tcpip.sys
2008-01-09 23:29 360064 482ab7f9cd41702e8f856c11cfefb02d C:\WINDOWS\system32\dllcache\TCPIP.SYS
2008-01-09 23:29 360064 482ab7f9cd41702e8f856c11cfefb02d C:\WINDOWS\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((( snapshot@2008-06-25_19.25.01.85 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-25 17:20:23 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-26 15:07:22 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-03-30 20:28:39 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
+ 2008-06-25 19:38:26 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-04-15 16:40 116088 --a------ C:\Program\DELADE~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program\Delade filer\Symantec Shared\ccApp.exe" [2008-02-14 11:01 51048]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-03 05:46 13529088]
"SpybotSnD"="C:\Program\Spybot - Search & Destroy\SpybotSD.exe" [2008-01-28 11:43 5146448]
"nwiz"="nwiz.exe" [2008-05-03 05:46 1630208 C:\WINDOWS\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]
"ALUAlert"="C:\Program\Symantec\LiveUpdate\ALUNotify.exe" [2007-08-23 14:35 152952]

C:\Documents and Settings\All Users\Start-meny\Program\Autostart\
Adobe Gamma Loader.lnk - C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe [2007-02-14 16:53:50 113664]
Adobe Reader Speed Launch.lnk - C:\Program\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 05:44:06 29696]
Personal.lnk - C:\Program\Personal\bin\Personal.exe [2007-10-29 21:18:26 722728]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= pvmjpg21.dll
"VIDC.XFR1"= xfcodec.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program\\KONAMI\\Pro Evolution Soccer 2008\\PES2008.exe"=
"C:\\Program\\Messenger\\msmsgs.exe"=
"C:\\Program\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program\\UBISOFT\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"C:\\Program\\UBISOFT\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Launcher.exe"=

R2 ithsgt;ithsgt;C:\WINDOWS\system32\DRIVERS\ithsgt.sys [2006-03-12 21:03]
R2 lilsgt;lilsgt;C:\WINDOWS\system32\DRIVERS\lilsgt.sys [2006-03-12 21:03]
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe" /h ccCommon []
R3 optousb;OPTO ELECTRONICS optousb;C:\WINDOWS\system32\DRIVERS\optousb.sys [2006-10-18 18:14]
R3 optovcm;OPTO ELECTRONICS optovcm;C:\WINDOWS\system32\DRIVERS\optovcm.sys [2006-10-19 14:46]
R3 Tetri5;Tetri5 driver;C:\WINDOWS\system32\Drivers\Tetri5.sys [2006-03-18 01:28]
S2 Automatisk LiveUpdate-schemaläggare;Automatisk LiveUpdate-schemaläggare;"C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-08-23 14:35]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]
S3 Winacusb;Winacusb;C:\WINDOWS\system32\DRIVERS\winacusb.sys [2002-03-06 03:24]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3780051a-f416-11db-8a99-baf56642fa9d}]
\Shell\AutoRun\command - F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3780051c-f416-11db-8a99-baf56642fa9d}]
\Shell\AutoRun\command - F:\AutoRun.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-06-23 18:01:07 C:\WINDOWS\Tasks\Norton AntiVirus - Kör fullständig systemsökning - Per-Johan.job"


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:15, on 2008-06-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Personal\bin\Personal.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.se/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program\DELADE~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [ccApp] C:\Program\Delade filer\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program\Spybot - Search & Destroy\SpybotSD.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Personal.lnk = C:\Program\Personal\bin\Personal.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://dev.srtest.com/srl_bin/sysreqlab3.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1200093771437
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program\Delade filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Automatisk LiveUpdate-schemaläggare - Symantec Corporation - C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program\DELADE~1\SYMANT~1\CCPD-LC\symlcsvc.exe

--
End of file - 6308 bytes

km2357
2008-06-26, 21:16
But I noticed that when running CF and that after the blue screen saying "scan typically takes 10 minutes... may take double time..." and so on, a "File can´t be found"-message appeared. Then CF continued scanning all the stages. Thought you might like to know...

Thanks for letting me know. It looks like CF did its job even with the message. Do you remember if it named the file that couldn't be found or if it just said "file can't be found"?



But when I ran CF it never open the browser so I never got any intructions to follow. It created a ZIP-file at the desktop though, named "[4]-Submit_2008-06-26@17.03". Maybe it opened the browser and I just didn´t notice cause I wasn´t around watching.

I'll have you submit the file manually then. :)

First, go to the following website:

http://www.bleepingcomputer.com/submit-malware.php?channel=4

In the Link to topic where this file was requested: box, put the following link:

http://forums.spybot.info/showpost.php?p=206087&postcount=4

In the Browse to the file you want to submit box, click Browse and browse to the .Zip file on your Desktop and click Open.

Then click Send File




Step # 1: Run CFScript

Please delete the version of ComboFix you have on your computer, I need you to download the latest version of ComboFix by sUBs here (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) and save it to your Desktop.

Also delete the CFScript.txt from your Desktop, you will be creating and running a new one.



Then, please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:


KILLALL::

File::

C:\WINDOWS\system32\dgkehowk.ini

Folder::

C:\Program\Azureus


Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.




http://i266.photobucket.com/albums/ii277/sUBs_/CFScript.gif


Note: This CFScript is for use on gasvictim's computer only! Do not use it on your computer.


Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.



Step # 2 Update Java

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.

Please follow these steps to remove older version Java components and update.

Updating Java:

Download the latest version of Java Runtime Environment (JRE) 6u6 (http://java.sun.com/javase/downloads/index.jsp).
Scroll down to where it says "The Java SE Runtime Environment (JRE) allows end-users to run Java applications.".
Click the "Download" button to the right.
Check the box that says: "Accept License Agreement".
The page will refresh.
Click on the link to download Windows Offline Installation and save to your desktop. Do NOT use the Sun Download Manager.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
Remove the following old versions of Java:


J2SE Runtime Environment 5.0 Update 10

J2SE Runtime Environment 5.0 Update 11

Java(TM) 6 Update 3

Java(TM) 6 Update 5


Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.

From your desktop double-click on the download to install the newest version.



Step # 3 Run CCleaner

CCleaner will remove everything from the temp/temporary folders but please note that it will not make back ups!


Before first use, select Options > Advanced and UNCHECK Only delete files in Windows Temp folder older than 48 hours
Then select the items you wish to clean up.

In the Windows Tab:

Clean all entries in the Internet Explorer section except Cookies
Clean all the entries in the Windows Explorer section
Clean all entries in the System section
Clean all entries in the Advanced section
Clean any others that you choose

In the Applications Tab:

Clean all except cookies in the Firefox/Mozilla section if you use it
Clean all in the Opera section if you use it
Clean Sun Java in the Internet Section
Clean any others that you choose

Click the Run Cleaner button.
A pop up box will appear advising this process will permanently delete files from your system.
Click OK and it will scan and clean your system.
Click exit when done.
If it asks you to reboot at the end, click NO




Step # 4 Download and Run Malwarebytes' Anti-Malware

Please download Malwarebytes' Anti-Malware (http://www.besttechie.net/tools/mbam-setup.exe) to your desktop.

Double-click mbam-setup.exe and follow the prompts to install the program.
Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Before running a scan, click the Update tab, next click Check for Updates to download any updates, if available.
Next click the Scanner tab and select Perform Quick Scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. Please save it to a convenient location.
You can also access the log by doing the following:

Click on the Malwarebytes' Anti-Malware icon to launch the program.
Click on the Logs tab.
Click on the log at the bottom of those listed to highlight it.
Click Open.



In your next post/reply, I need to see the following:

1. ComboFix Log that appears after Step 1 has been completed
2. MalwareBytes' Log
3. A fresh HiJackThis Log taken after all steps have been completed

Use multiple posts if you can't fit everything into one post.

gasvictim
2008-06-27, 00:33
No it didnt name the file not found. But everything but this message is written in english. Except this that´s written in swedish - "filen går inte att hitta" translated "file can´t be found".

The log files:

ComboFix 08-06-20.4 - Per-Johan 2008-06-26 22:37:54.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1053.18.591 [GMT 2:00]
Running from: C:\Documents and Settings\Per-Johan\Skrivbord\ComboFix.exe
Command switches used :: C:\Documents and Settings\Per-Johan\Skrivbord\CFScript.txt
* Created a new restore point

FILE ::
C:\WINDOWS\system32\dgkehowk.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program\Azureus
C:\Program\Azureus\plugins\azemp\azemp_1.9.11.jar
C:\Program\Azureus\plugins\azemp\azemp_1.9.11.zip
C:\Program\Azureus\plugins\azemp\azemp_2.0.11.jar
C:\Program\Azureus\plugins\azemp\azemp_2.0.11.zip
C:\Program\Azureus\plugins\azemp\azemp_2.0.14.jar
C:\Program\Azureus\plugins\azemp\azemp_2.0.14.zip
C:\Program\Azureus\plugins\azemp\azmplay.exe.bak
C:\Program\Azureus\plugins\azemp\cp1250-a.raw.bak
C:\Program\Azureus\plugins\azemp\cp1250-b.raw.bak
C:\Program\Azureus\plugins\azemp\font.desc.bak
C:\Program\Azureus\plugins\azemp\osd-mplayer-a.raw.bak
C:\Program\Azureus\plugins\azemp\osd-mplayer-b.raw.bak
C:\Program\Azureus\plugins\azemp\plugin.properties_1.9.11
C:\Program\Azureus\plugins\azemp\plugin.properties_2.0.11
C:\Program\Azureus\plugins\azemp\plugin.properties_2.0.14
C:\Program\Azureus\plugins\azupdater\azupdater_1.8.8.zip
C:\Program\Azureus\plugins\azupdater\azupdaterpatcher_1.8.8.jar
C:\Program\Azureus\plugins\azupdater\plugin.properties_1.8.8
C:\Program\Azureus\plugins\azupdater\Updater.jar.bak
C:\Program\Azureus\plugins\azupnpav\azupnpav_0.2.0.jar
C:\Program\Azureus\plugins\azupnpav\azupnpav_0.2.0.zip
C:\Program\Azureus\plugins\azupnpav\azupnpav_0.2.1.jar
C:\Program\Azureus\plugins\azupnpav\azupnpav_0.2.1.zip
C:\Program\Azureus\plugins\azupnpav\plugin.properties_0.2.0
C:\Program\Azureus\plugins\azupnpav\plugin.properties_0.2.1
C:\WINDOWS\system32\dgkehowk.ini
.
---- Previous Run -------
.
C:\Documents and Settings\All Users\Application Data\hghezudo.dll
C:\Documents and Settings\Per-Johan\Application Data\Azureus
C:\Documents and Settings\Per-Johan\Application Data\Azureus\.keystore
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\07BACDC31EF6A94E83EAE6B4EB0720139466EFB5.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\07BACDC31EF6A94E83EAE6B4EB0720139466EFB5.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\0B049DC8296A2A3820726FCCAF32AB76BA831EC9.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\0B049DC8296A2A3820726FCCAF32AB76BA831EC9.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\1B66EF02B74337642381C4CEA1EB21A36FB4BD66.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\1B66EF02B74337642381C4CEA1EB21A36FB4BD66.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\214BEF6C8344EF4E973E0EEC0DBC9B9BD2305E96.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\214BEF6C8344EF4E973E0EEC0DBC9B9BD2305E96.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\215D2DD9D8B280445B49DC7E5994334D3C50E719.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\215D2DD9D8B280445B49DC7E5994334D3C50E719.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\2F86EFA71C51AEE32C08974232E947127CB3C7D0.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\2F86EFA71C51AEE32C08974232E947127CB3C7D0.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\38753698801EB17E31F19AE0BEBF9F86CC263481.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\38753698801EB17E31F19AE0BEBF9F86CC263481.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\5F5024775C323B9150D4F083780D402D30ECA3E2.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\5F5024775C323B9150D4F083780D402D30ECA3E2.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\7DAA4B9E0814AD02663A2BCB8F76F640D8DCEBBE.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\7DAA4B9E0814AD02663A2BCB8F76F640D8DCEBBE.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\85391B3C4F4121F669FCF8CDE68CC5C9A856C2AE.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\85391B3C4F4121F669FCF8CDE68CC5C9A856C2AE.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\A544ADC822978C5CBCC3AF17F1946B605FBC520D.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\A544ADC822978C5CBCC3AF17F1946B605FBC520D.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\B7345B0275F171284081E35CF8D228CE05AD1120.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\B7345B0275F171284081E35CF8D228CE05AD1120.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\C264C2C0611487125082F2F395AD6A46BA95E75F.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\C264C2C0611487125082F2F395AD6A46BA95E75F.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\cache.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\DAD67F5CFB4153B25419E90567754A2A43F03389.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\DAD67F5CFB4153B25419E90567754A2A43F03389.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\ED15814AA205F8B3A64348F6140E8504E7410C2C.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\active\ED15814AA205F8B3A64348F6140E8504E7410C2C.dat.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\azureus.config
C:\Documents and Settings\Per-Johan\Application Data\Azureus\azureus.config.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\azureus.statistics
C:\Documents and Settings\Per-Johan\Application Data\Azureus\azureus.statistics.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\banips.config
C:\Documents and Settings\Per-Johan\Application Data\Azureus\banips.config.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\dht\addresses.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\dht\contacts.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\dht\diverse.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\dht\general.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\dht\version.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\downloads.config
C:\Documents and Settings\Per-Johan\Application Data\Azureus\downloads.config.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\filters.config
C:\Documents and Settings\Per-Johan\Application Data\Azureus\ipfilter.cache
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\alerts_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\AutoSpeed_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\AutoSpeed_2.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\AutoSpeedSearchHistory_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\AutoSpeedSearchHistory_2.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\debug_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\debug_2.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\NetStatus_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\seltrace_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\seltrace_2.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\SpeedMan_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\SpeedMan_2.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\thread_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\thread_2.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\v3.ads_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\v3.CMsgr_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\v3.PMsgr_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\logs\v3.Stream_1.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\net\pm_20626.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\net\pm_default.dat
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tables.config
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tables.config.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tmp\AZU4259.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tmp\AZU4260.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tmp\AZU4261.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tmp\AZU4262.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tmp\AZU4263.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tmp\AZU4264.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tmp\AZU4265.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tmp\AZU4266.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tmp\AZU4267.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tmp\AZU4268.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\[NHLTorrents]_NHL_Match_Stanley_Cup_Game_5_-_Pittsburgh_Penguins_@_Detroit_Redwings_-_2008_06_02_-_English[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\[NHLTorrents]_NHL_Match_Stanley_Cup_Game_6_-_Detroit_Redwings_@_Pittsburgh_Penguins_-_2008_06_04_-_English[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Amy_Winehouse_-_Back_To_Black.3693362.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Audioslave_-_Revelations.3530364.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\AZU12631.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\AZU12633.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\AZU12635.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\AZU12638.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\AZU30736.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\AZU30739.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\AZU3755.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\AZU38508.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\AZU43410.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\AZU43413.tmp
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\BBC.Jane.Eyre_[2006]_1-4.DaRmEtH.3768454.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Charles_Aznavour_-_40_Chansons_D____Or_-_CD_1_et_2_-_mp3_192kbps.3670308.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Children.Of.Men.2006.SWESUB.DVDRip.Xvid-Nimol.3765082.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Coldplay_-_Viva_La_Vida_(2008)Fullus_artwork-320Kbps.4233465.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Darling.2007.DVDRip.SWEDISH.XViD-Nimol.3725915.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Die.Hard.1988.Extended.Version.INTERNAL.DVDRip.XviD-NEPTUNE_[mininova][1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Google.SketchUp.Pro.v6.4.112.Incl.Keymaker-ACME.3939947.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Memento.SWESUB.DVDRip.Xvid-Nimol.3922082.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Neil_Young_(Greatest_Hits).3688275.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Pirates.of.the.Caribbean-Dead.Mans.Chest%5B2006%5DDvDrip%5BEng%5D-aXXo_%5Bwww.NewTorrents.info%5D[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Reign_over_me.2007.DvDrip.SWESub.XviD_-_Christley.3784341.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Shrek.The.Third[2007]DvDrip.AC3[Eng]-aXXo.3884693.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Stolthet_och_F__rdom_1.3428346.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Stolthet_och_F__rdom_2.3428359.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\The.Orange.Box-DETONATiON.3903605.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\torrents\Weezer_-_Weezer_(The_Red_Album)_[2008]_-_Rock_.4217965.TPB[1].torrent
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tracker.config
C:\Documents and Settings\Per-Johan\Application Data\Azureus\tracker.config.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\trackers.config
C:\Documents and Settings\Per-Johan\Application Data\Azureus\unsentdata.config
C:\Documents and Settings\Per-Johan\Application Data\Azureus\unsentdata.config.bak
C:\Documents and Settings\Per-Johan\Application Data\Azureus\update.log
C:\Documents and Settings\Per-Johan\Application Data\Azureus\update.properties
C:\Documents and Settings\Per-Johan\Application Data\Azureus\VuzeActivities.config
C:\Documents and Settings\Per-Johan\Application Data\Azureus\VuzeActivities.config.bak
C:\Documents and Settings\Per-Johan\Application Data\inst.exe
C:\Documents and Settings\Per-Johan\Application Data\Microsoft\dtsc
C:\Documents and Settings\Per-Johan\Application Data\Microsoft\dtsc\s
C:\Program\uTorrent
C:\WINDOWS\BMcf16f2d3.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\cpan.dll
C:\WINDOWS\ctfmon32.exe
C:\WINDOWS\ctrlpan.dll
C:\WINDOWS\directx32.exe
C:\WINDOWS\dnsrelay.dll
C:\WINDOWS\editpad.exe
C:\WINDOWS\explore.exe
C:\WINDOWS\explorer32.exe
C:\WINDOWS\funniest.exe
C:\WINDOWS\funny.exe
C:\WINDOWS\gfmnaaa.dll
C:\WINDOWS\helpcvs.exe
C:\WINDOWS\inetinf.exe
C:\WINDOWS\internet.exe
C:\WINDOWS\msconfd.dll
C:\WINDOWS\msspi.dll
C:\WINDOWS\mswsc10.dll
C:\WINDOWS\mswsc20.dll
C:\WINDOWS\pskt.ini
C:\WINDOWS\qttasks.exe
C:\WINDOWS\quicken.exe
C:\WINDOWS\rundll16.exe
C:\WINDOWS\rundll32.vbe
C:\WINDOWS\searchword.dll
C:\WINDOWS\sistem.exe
C:\WINDOWS\svchost32.exe
C:\WINDOWS\svcinit.exe
C:\WINDOWS\system32\afqrtfan.ini
C:\WINDOWS\system32\AGhhkUtv.ini
C:\WINDOWS\system32\AGhhkUtv.ini2
C:\WINDOWS\system32\cqtfwxgh.dll
C:\WINDOWS\system32\ddcCUOhe.dll
C:\WINDOWS\system32\dgkehowk.ini
C:\WINDOWS\system32\dloxcxjj.ini
C:\WINDOWS\system32\fptvvsor.dll
C:\WINDOWS\system32\fPXbefii.ini
C:\WINDOWS\system32\fPXbefii.ini2
C:\WINDOWS\system32\frdkiykc.dll
C:\WINDOWS\system32\hljwugsf.bin
C:\WINDOWS\system32\JPVwaGgh.ini
C:\WINDOWS\system32\JPVwaGgh.ini2
C:\WINDOWS\system32\kcmpkcfr.dll
C:\WINDOWS\system32\knuetwpm.dll
C:\WINDOWS\system32\kwohekgd.dll
C:\WINDOWS\system32\lbabstrw.dll
C:\WINDOWS\system32\lonwwlps.ini
C:\WINDOWS\system32\lVwvDcdd.ini
C:\WINDOWS\system32\lVwvDcdd.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mlJabYpn.dll
C:\WINDOWS\system32\mrbbkfcn.dll
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\mUvuCcfe.ini
C:\WINDOWS\system32\mUvuCcfe.ini2
C:\WINDOWS\system32\mxsfrxvs.dll
C:\WINDOWS\system32\naftrqfa.dll
C:\WINDOWS\system32\ncfkbbrm.ini
C:\WINDOWS\system32\ndeysnsp.dll
C:\WINDOWS\system32\nfhrcubp.dll
C:\WINDOWS\system32\njwjpnuv.dll
C:\WINDOWS\system32\npYbaJlm.ini
C:\WINDOWS\system32\npYbaJlm.ini2
C:\WINDOWS\system32\rosvvtpf.ini
C:\WINDOWS\system32\rxpjkbxr.ini
C:\WINDOWS\system32\splwwnol.dll
C:\WINDOWS\system32\tpqgndbt.dll
C:\WINDOWS\system32\waKlmnmp.ini
C:\WINDOWS\system32\waKlmnmp.ini2
C:\WINDOWS\system32\vEfLmnpo.ini
C:\WINDOWS\system32\vEfLmnpo.ini2
C:\WINDOWS\system32\whodvajc.dll
C:\WINDOWS\system32\vwvyyGgh.ini
C:\WINDOWS\system32\vwvyyGgh.ini2
C:\WINDOWS\system32\xbpsrytx.dll
C:\WINDOWS\system32\xungwkqf.ini
C:\WINDOWS\time.exe
C:\WINDOWS\waol.exe
C:\WINDOWS\xplugin.dll

.
((((((((((((((((((((((((( Files Created from 2008-05-26 to 2008-06-26 )))))))))))))))))))))))))))))))
.

2008-06-25 17:35 . 2008-06-25 17:35 <KAT> d-------- C:\Program\CCleaner
2008-06-23 17:13 . 2008-06-23 17:13 <KAT> d-------- C:\Program\Trend Micro
2008-06-18 20:37 . 2008-06-18 20:37 <KAT> d-------- C:\Program\Lavasoft
2008-06-18 20:37 . 2008-06-18 20:39 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-18 20:30 . 2008-06-18 20:30 <KAT> d-------- C:\Program\Delade filer\Wise Installation Wizard
2008-06-14 21:58 . 2008-06-16 21:16 <KAT> d-------- C:\Program\Spybot - Search & Destroy
2008-06-14 21:58 . 2008-06-14 22:14 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-14 13:44 . 2008-06-14 13:44 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-14 13:44 . 2008-06-14 13:44 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-11 12:06 . 2008-06-14 20:01 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 12:06 . 2008-06-14 20:01 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-03 21:24 . 2008-06-03 21:24 <KAT> d-------- C:\Documents and Settings\Per-Johan\Application Data\Runaware
2008-06-03 21:24 . 2008-06-03 21:24 <KAT> d-------- C:\Documents and Settings\Per-Johan\Application Data\ICAClient
2008-06-01 21:41 . 2008-06-01 21:56 <KAT> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-06-01 16:11 . 2008-06-01 16:11 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-06-01 16:08 . 2008-06-01 16:08 <KAT> d-------- C:\WINDOWS\nview
2008-06-01 14:40 . 2008-06-01 16:09 <KAT> d-------- C:\WINDOWS\nvidia icons
2008-06-01 12:36 . 2008-06-01 12:36 <KAT> d-------- C:\Program\Valvesoftware
2008-05-28 22:25 . 2008-05-28 22:25 <KAT> d-------- C:\Documents and Settings\All Users\Application Data\Ubisoft
2008-05-28 22:24 . 2008-05-28 22:24 2,337,865 --a------ C:\WINDOWS\system32\pbsvc.exe
2008-05-28 22:24 . 2008-05-28 22:24 107,832 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-05-28 22:24 . 2008-05-28 22:24 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-05-28 22:24 . 2008-05-28 22:24 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-05-28 22:24 . 2008-05-28 22:24 22,328 --a------ C:\Documents and Settings\Per-Johan\Application Data\PnkBstrK.sys
2008-05-28 22:23 . 2007-10-12 15:14 3,734,536 --a------ C:\WINDOWS\system32\d3dx9_36.dll
2008-05-28 22:23 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2008-05-28 22:23 . 2007-10-12 15:14 1,374,232 --a------ C:\WINDOWS\system32\D3DCompiler_36.dll
2008-05-28 22:23 . 2007-07-19 18:14 1,358,192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll
2008-05-28 22:23 . 2007-10-02 09:56 444,776 --a------ C:\WINDOWS\system32\d3dx10_36.dll
2008-05-28 22:23 . 2007-07-19 18:14 444,776 --a------ C:\WINDOWS\system32\d3dx10_35.dll
2008-05-28 22:23 . 2007-10-22 03:39 267,272 --a------ C:\WINDOWS\system32\xactengine2_10.dll
2008-05-28 22:23 . 2007-07-20 00:57 267,112 --a------ C:\WINDOWS\system32\xactengine2_9.dll
2008-05-28 15:23 . 2005-10-21 07:25 13,396 --a------ C:\WINDOWS\system32\drivers\MTictwl.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-21 19:17 --------- d-----w C:\Documents and Settings\Per-Johan\Application Data\dvdcss
2008-06-16 19:17 --------- d-----w C:\Program\QuickTime
2008-06-02 14:09 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-06-02 14:09 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-06-02 14:09 10,671 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-06-02 14:09 --------- d-----w C:\Program\Symantec
2008-06-01 10:36 --------- d--h--w C:\Program\InstallShield Installation Information
2008-05-28 20:12 --------- d-----w C:\Program\UBISOFT
2008-05-21 20:36 --------- d-----w C:\Program\Delade filer\Symantec Shared
2008-05-13 08:07 --------- d-----w C:\Program\Hattrick Coach Professional
2008-05-11 14:43 --------- d-----w C:\Program\SopCast
2008-05-10 13:01 --------- d-----w C:\Program\Satellite TV for PC
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-03 03:46 6,554,496 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2008-04-29 09:20 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 09:19 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 09:19 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
2008-04-18 20:29 47,360 ----a-w C:\Documents and Settings\Per-Johan\Application Data\pcouffin.sys
.

------- Sigcheck -------

2006-01-13 19:07 360448 5562cc0a47b2aef06d3417b733f3c195 C:\WINDOWS\$hf_mig$\KB913446\SP2QFE\tcpip.sys
2006-04-20 14:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 18:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2004-08-04 14:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB913446$\tcpip.sys
2006-01-13 04:28 359808 583e063fdc888ca30d05c2724b0d7ef4 C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2006-04-20 13:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2008-04-13 21:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\SoftwareDistribution\Download\602f759e47356a387e3fe197762b452c\tcpip.sys
2008-01-09 23:29 360064 482ab7f9cd41702e8f856c11cfefb02d C:\WINDOWS\system32\dllcache\TCPIP.SYS
2008-01-09 23:29 360064 482ab7f9cd41702e8f856c11cfefb02d C:\WINDOWS\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((( snapshot@2008-06-25_19.25.01.85 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-25 17:20:23 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-26 20:41:13 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-03-30 20:28:39 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
+ 2008-06-25 19:38:26 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-04-15 16:40 116088 --a------ C:\Program\DELADE~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program\Delade filer\Symantec Shared\ccApp.exe" [2008-02-14 11:01 51048]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-03 05:46 13529088]
"SpybotSnD"="C:\Program\Spybot - Search & Destroy\SpybotSD.exe" [2008-01-28 11:43 5146448]
"nwiz"="nwiz.exe" [2008-05-03 05:46 1630208 C:\WINDOWS\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]
"ALUAlert"="C:\Program\Symantec\LiveUpdate\ALUNotify.exe" [2007-08-23 14:35 152952]

C:\Documents and Settings\All Users\Start-meny\Program\Autostart\
Adobe Gamma Loader.lnk - C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe [2007-02-14 16:53:50 113664]
Adobe Reader Speed Launch.lnk - C:\Program\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 05:44:06 29696]
Personal.lnk - C:\Program\Personal\bin\Personal.exe [2007-10-29 21:18:26 722728]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= pvmjpg21.dll
"VIDC.XFR1"= xfcodec.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program\\KONAMI\\Pro Evolution Soccer 2008\\PES2008.exe"=
"C:\\Program\\Messenger\\msmsgs.exe"=
"C:\\Program\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program\\UBISOFT\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"C:\\Program\\UBISOFT\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Launcher.exe"=

R2 ithsgt;ithsgt;C:\WINDOWS\system32\DRIVERS\ithsgt.sys [2006-03-12 21:03]
R2 lilsgt;lilsgt;C:\WINDOWS\system32\DRIVERS\lilsgt.sys [2006-03-12 21:03]
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe" /h ccCommon []
R3 optousb;OPTO ELECTRONICS optousb;C:\WINDOWS\system32\DRIVERS\optousb.sys [2006-10-18 18:14]
R3 optovcm;OPTO ELECTRONICS optovcm;C:\WINDOWS\system32\DRIVERS\optovcm.sys [2006-10-19 14:46]
R3 Tetri5;Tetri5 driver;C:\WINDOWS\system32\Drivers\Tetri5.sys [2006-03-18 01:28]
S2 Automatisk LiveUpdate-schemaläggare;Automatisk LiveUpdate-schemaläggare;"C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-08-23 14:35]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]
S3 Winacusb;Winacusb;C:\WINDOWS\system32\DRIVERS\winacusb.sys [2002-03-06 03:24]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3780051a-f416-11db-8a99-baf56642fa9d}]
\Shell\AutoRun\command - F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3780051c-f416-11db-8a99-baf56642fa9d}]
\Shell\AutoRun\command - F:\AutoRun.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-06-23 18:01:07 C:\WINDOWS\Tasks\Norton AntiVirus - Kör fullständig systemsökning - Per-Johan.job"


Malwarebytes' Anti-Malware 1.18
Databasversion: 894

23:20:37 2008-06-26
mbam-log-6-26-2008 (23-20-37).txt

Skanningstyp: Snabb skanning
Antal skannade objekt: 39748
Förfluten tid: 4 minute(s), 25 second(s)

Infekterade minnesprocesser: 0
Infekterade minnesmoduler: 0
Infekterade registernycklar: 1
Infekterade registervärden: 0
Infekterade registerdataposter: 0
Infekterade mappar: 0
Infekterade filer: 1

Infekterade minnesprocesser:
(Inga illasinnade poster hittades)

Infekterade minnesmoduler:
(Inga illasinnade poster hittades)

Infekterade registernycklar:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.

Infekterade registervärden:
(Inga illasinnade poster hittades)

Infekterade registerdataposter:
(Inga illasinnade poster hittades)

Infekterade mappar:
(Inga illasinnade poster hittades)

Infekterade filer:
C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:22, on 2008-06-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Personal\bin\Personal.exe
C:\Program\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program\DELADE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Program\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.se/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program\DELADE~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [ccApp] C:\Program\Delade filer\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program\Spybot - Search & Destroy\SpybotSD.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Personal.lnk = C:\Program\Personal\bin\Personal.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://dev.srtest.com/srl_bin/sysreqlab3.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1200093771437
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program\Delade filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Automatisk LiveUpdate-schemaläggare - Symantec Corporation - C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program\DELADE~1\SYMANT~1\CCPD-LC\symlcsvc.exe

--
End of file - 6412 bytes

km2357
2008-06-27, 00:42
Step # 1: Run Kaspersky Online Scan

Please go to Kaspersky website (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html) and perform an online antivirus scan.

Read through the requirements and privacy statement and click on Accept button.
It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
When the downloads have finished, click on Settings.
Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button: Spyware, Adware, Dialers, and other potentially dangerous programs
Archives
Mail databases Click on My Computer under Scan.
Once the scan is complete, it will display the results. Click on View Scan Report.
You will see a list of infected items there. Click on Save Report As....
Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Please post this log in your next reply.


In your next post/reply, I need to see the following:

1. Kaspersky Log
2. A fresh HiJackThis Log
3. How is your computer doing, any problems?

gasvictim
2008-06-28, 09:24
1. --------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Saturday, June 28, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Friday, June 27, 2008 14:37:09
Records in database: 889796
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\

Scan statistics:
Files scanned: 59677
Threat name: 11
Infected objects: 13
Suspicious objects: 0
Duration of the scan: 03:04:14


File name / Threat name / Threats count
C:\Documents and Settings\Per-Johan\Mina dokument\Azureus Downloads\DVD Fab PLATINUM EDITION 4.0.6.0.(NEW-with serial key)\DVDFabPlatinum4060\lg.software.innovations.generic.patch.zip Infected: Trojan.Win32.Delf.bur 1
C:\Documents and Settings\Per-Johan\Mina dokument\Azureus Downloads\DVD Fab PLATINUM EDITION 4.0.6.0.(NEW-with serial key)\DVDFabPlatinum4060.rar Infected: Trojan.Win32.Delf.bur 1
C:\QooBox\Quarantine\C\WINDOWS\system32\cqtfwxgh.dll.vir Infected: Trojan.Win32.Monder.wb 1
C:\QooBox\Quarantine\C\WINDOWS\system32\ddcCUOhe.dll.vir Infected: Trojan.Win32.Monder.gen 1
C:\QooBox\Quarantine\C\WINDOWS\system32\fptvvsor.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.yzn 1
C:\QooBox\Quarantine\C\WINDOWS\system32\frdkiykc.dll.vir Infected: Trojan.Win32.Monder.uu 1
C:\QooBox\Quarantine\C\WINDOWS\system32\knuetwpm.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.yzi 1
C:\QooBox\Quarantine\C\WINDOWS\system32\mlJabYpn.dll.vir Infected: Trojan.Win32.Monder.acx 1
C:\QooBox\Quarantine\C\WINDOWS\system32\mrbbkfcn.dll.vir Infected: Trojan.Win32.Monder.qa 1
C:\QooBox\Quarantine\C\WINDOWS\system32\mxsfrxvs.dll.vir Infected: Trojan.Win32.Monder.yj 1
C:\QooBox\Quarantine\C\WINDOWS\system32\naftrqfa.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.yxx 1
C:\QooBox\Quarantine\C\WINDOWS\system32\splwwnol.dll.vir Infected: Trojan.Win32.Monder.qa 1
C:\QooBox\Quarantine\C\WINDOWS\system32\whodvajc.dll.vir Infected: Trojan.Win32.Monder.xo 1

The selected area was scanned.


2. Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:11, on 2008-06-28
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program\Java\jre1.6.0_06\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
C:\Program\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program\Personal\bin\Personal.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.se/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program\DELADE~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] C:\Program\Delade filer\Symantec Shared\ccApp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Personal.lnk = C:\Program\Personal\bin\Personal.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://dev.srtest.com/srl_bin/sysreqlab3.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1200093771437
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program\Delade filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Automatisk LiveUpdate-schemaläggare - Symantec Corporation - C:\Program\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program\Delade filer\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program\DELADE~1\SYMANT~1\CCPD-LC\symlcsvc.exe

--
End of file - 6475 bytes


3. I havent seen any more pop-up windows and the computer runs fine. Spy-Bot only reports that windows security center is disabled but maybe thats because of Norton Anti-Virus? I checked my connection speed and it was as good as before the infection. No malware taking up noticeable bandwidth. So inspite the fact that Kaspersky found a lot of entries on my computer it feels good... Newbie Good:red:...

km2357
2008-06-28, 11:21
Kaspersky found some files in the Qoobox directory which is where ComboFix keeps it quarantined files and we'll be removing those shortly.


Using Windows Explorer, delete the following folder, if found:

C:\Documents and Settings\Per-Johan\Mina dokument\Azureus Downloads

Empty your Recycle Bin.


As for Windows Security Center being disabled, have a read through this thread:

http://forums.spybot.info/showthread.php?t=6119

and this thread:

http://forums.spybot.info/showthread.php?t=5983

If you have Spybot fix that entry, it should renable Windows Security Center. :)


Let me know how everything went.

gasvictim
2008-06-28, 17:23
Everything went well.

km2357
2008-06-28, 22:23
Then you are good to go. :)

There is a newer version of Adobe Acrobat Reader available. (See Note below)


First, go to Add/Remove Programs and uninstall all previous versions.
Please go to this link Adobe Acrobat Reader Download Link (http://www.adobe.com/products/acrobat/readstep2.html)
On the right Untick Adobe Phototshop Album Starter Edition if you do not wish to include this in the installation.
Click the Continue button
Click Run, and click Run again
Next click the Install Now button and follow the on screen prompts

Note: Adobe 8 is a large program and if you prefer a smaller program you can get Foxit 2.0 instead from http://www.foxitsoftware.com/pdf/rd_intro.php



To remove ComboFix, do the following:

Go to Start > Run - type in ComboFix /u & click OK


Please take the time to read my All Clean Post.

Please follow these simple steps in order to keep your computer clean and secure:

This is a good time to clear your existing system restore points and establish a new clean restore point

Go to Start > All Programs > Accessories > System Tools > System Restore
Select Create a restore point, and Ok it.
Next, go to Start > Run and type in cleanmgr
Select the More options tab
Choose the option to clean up system restore and OK it.
This will remove all restore points except the new one you just created..

Clearing your restore points is not something you should do on a regular basis. Normally, this process only needs to be done after clearing out an infestation of malware.


Make your Internet Explorer more secure This can be done by following these simple instructions: From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub frames across different domains to Prompt When all these settings have been made, click on the OK button.
If it asks you if you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.
Set correct settings for files that should be hidden in Windows XP
Click Start > My Computer > Tools menu (at top of page) > Folder Options > View tab.
Under "Hidden files and folders" if necessary select Do not show hidden files and folders.
If unchecked please checkHide protected operating system files (Recommended)
If necessary check "Display content of system folders"
If necessary Uncheck Hide file extensions for known file types.
Click OK

Use An Antivirus Software and Keep It Updated - It is very important that your computer has an antivirus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperative that you update your antivirus software at least once a day. If you do not update your antivirus software, then it will not be able to catch any of the new variants that may come out.
Visit Microsoft's Windows Update Site Frequently It is important that you visit Microsoft Windows Update (http://www.windowsupdate.com) regularly. This will ensure your computer has the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
Install SpywareBlaster SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. An article on anti-malware products with links for this program and others can be found here:
Computer Safety on line Anti Malware (http://forum.malwareremoval.com/viewtopic.php?p=54#54)
Use the hosts file: Every version of windows has a hosts file as part of them. In a very basic sense, they are used to locate web pages. We can customize a hosts file so that it blocks certain web pages. However, it can slow down certain computers. This is why using a hosts file is optional. Download mvps hosts file (http://www.mvps.org/winhelp2002/hosts.htm) Make sure you read the instructions on how to install the hosts file. There is a good tutorial HERE (http://www.bleepingcomputer.com/forums/tutorial51.html) If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
Click the start button on the task bar at the bottom of your screen Click run In the dialog box, type services.msc hit enter, then locate dns client Highlight it, then doubleclick it. On the dropdown box, change the setting from automatic to manual. Click ok..
Use an alternative instant messenger program.Trillian (http://www.trillian.cc/) and Miranda IM (http://www.miranda-im.com/) These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)
Please read Tony Klein's excellent article: How I got Infected in the First Place (http://forums.subratam.org/index.php?showtopic=5931)
Please read Understanding Spyware, Browser Hijackers, and Dialers (http://www.bleepingcomputer.com/forums/tutorial41.html)
Please read Simple and easy ways to keep your computer safe and secure on the Internet (http://www.bleepingcomputer.com/tutorials/tutorial82.html)
If you are using Internet Explorer, please consider using an alternate browser: Mozilla's Firefox (http://www.mozilla.org/products/firefox) or
Opera (http://www.opera.com/download/).
If you decide to use either FireFox or Opera, it is very important that you keep them up to date and check frequently for updates of the browser of your choice.
Update all these programs regularly Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
If your computer was infected by a website, a program, IM, MSN, or p2p, check this site because it is Time To Fight Back (http://spyware-free.us/2006/01/time-to-fight-back.html). Follow these steps and your potential for being infected again will reduce dramatically.

Here's a good website to read about Malware prevention:

http://users.telenet.be/bluepatchy/miekiemoes/prevention.html

Good luck!


Please reply one last time so that I know you have read my post and this thread can be closed.

gasvictim
2008-06-29, 19:28
Thanks alot for all your help. I have one last question though. When I run Dxdiag a window pops up telling me "There might have been a problem last time running DirectShow. Continue without running DirectShow?" (In my language. I translated it as good as I could). Then I can chose yes or no. If I chose no Dxdiag hangs and terminates. If I chose yes it runs fine and no problems are reported until I chose "test Direct3D". Then it freezes and the computer restarts. I googled around a little on the subject and as far as I could tell it has something to do with codecs. Since I got infected via bad codec I wonder if malware i responsible for this?

km2357
2008-06-30, 00:34
It's possible that the malware/bad codec that infected your computer also messed with DirectX on your computer. Have you tried uninstaling and then reinstalling DirectX to see if that stops the window from popping up in Dxdiag?

gasvictim
2008-07-03, 15:27
No. It didnt work. I read that you cant uninstall directX. It´s a "vital part of windows". But I tried to reinstall but then my computer didnt start after that so I dont know what to do. But thanks alot for your help anyway. The Malware is gone and I will try find an answer to this problem on my own so that you can help others with malware problems. If you know the solution or have time to help me anyway then please answer. Otherwise you could close this thread. Thanks again.

km2357
2008-07-03, 21:29
Unfortunately, I don't know the answer to help solve your problem, but I do know of a few forums that you could go to for some help with your DirectX problems.

Computer Trouble here: http://forum.computertrouble.co.uk/index.php
or
TechSupportGuy here : http://forums.techguy.org/21-windows-nt-2000-xp/
or
VirtualDr here: http://discussions.virtualdr.com/forumdisplay.php?f=48
or
PCPitStop here : http://forums.pcpitstop.com/index.php?showforum=3

All may require free registration before posting for help.

Let me know when you've read this message, so I can close this thread. And I was happy to help you clear up your malware problems. :)

gasvictim
2008-07-03, 21:59
Ok. Thank you for the links. Bye (for now;)):D:.