oxrock
2008-07-30, 13:23
Done anything I could think of to get rid of it, ran hijack and here's the info:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:18:04 AM, on 7/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.att.net
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O3 - Toolbar: fdkowvbp - {E82E9D76-F0A8-4286-ADB5-52FFE3E79868} - C:\WINDOWS\fdkowvbp.dll (file missing)
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Antivirus] C:\Program Files\VAV\vav.exe
O4 - HKLM\..\Run: [lanmanwrk.exe clean] C:\WINDOWS\System32\lanmanwrk.exe clean
O4 - HKLM\..\Run: [KernelDrv.exe clean] C:\WINDOWS\System32\KernelDrv.exe clean
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA7548] command /c del "C:\Program Files\VAV\vav.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8712] cmd /c del "C:\Program Files\VAV\vav.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA688] command /c del "C:\Program Files\VAV\vav0.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3106] cmd /c del "C:\Program Files\VAV\vav0.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2279] command /c del "C:\Program Files\VAV\vav1.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5319] cmd /c del "C:\Program Files\VAV\vav1.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4178] command /c del "C:\WINDOWS\system32\hgGAsTJd.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3153] cmd /c del "C:\WINDOWS\system32\hgGAsTJd.dll"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\RunOnce: [SpybotDeletingB590] command /c del "C:\Program Files\VAV\vav.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3849] cmd /c del "C:\Program Files\VAV\vav.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9362] command /c del "C:\Program Files\VAV\vav0.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1888] cmd /c del "C:\Program Files\VAV\vav0.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1478] command /c del "C:\Program Files\VAV\vav1.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2717] cmd /c del "C:\Program Files\VAV\vav1.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8119] command /c del "C:\WINDOWS\system32\hgGAsTJd.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2065] cmd /c del "C:\WINDOWS\system32\hgGAsTJd.dll"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra button: (no name) - {20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - C:\WINDOWS\system32\mscoree.DLL
O9 - Extra 'Tools' menuitem: Tri&xie Options... - {20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - C:\WINDOWS\system32\mscoree.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.att.net
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1153361539921
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1153361526140
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: FAH@C:+Program Files+Folding@Home Windows SMP Client V1.01+fah.exe - Unknown owner - C:\Program Files\Folding@Home Windows SMP Client V1.01\fah.exe
O23 - Service: FAH@C:+WINDOWS+system32+fah.exe - Unknown owner - C:\WINDOWS\system32\fah.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MPICH2 Process Manager, Argonne National Lab (mpich2_smpd) - Unknown owner - C:\Program Files\Folding@Home Windows SMP Client V1.01\smpd.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 5503 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:18:04 AM, on 7/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.att.net
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O3 - Toolbar: fdkowvbp - {E82E9D76-F0A8-4286-ADB5-52FFE3E79868} - C:\WINDOWS\fdkowvbp.dll (file missing)
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Antivirus] C:\Program Files\VAV\vav.exe
O4 - HKLM\..\Run: [lanmanwrk.exe clean] C:\WINDOWS\System32\lanmanwrk.exe clean
O4 - HKLM\..\Run: [KernelDrv.exe clean] C:\WINDOWS\System32\KernelDrv.exe clean
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA7548] command /c del "C:\Program Files\VAV\vav.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8712] cmd /c del "C:\Program Files\VAV\vav.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA688] command /c del "C:\Program Files\VAV\vav0.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3106] cmd /c del "C:\Program Files\VAV\vav0.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2279] command /c del "C:\Program Files\VAV\vav1.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5319] cmd /c del "C:\Program Files\VAV\vav1.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4178] command /c del "C:\WINDOWS\system32\hgGAsTJd.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3153] cmd /c del "C:\WINDOWS\system32\hgGAsTJd.dll"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\RunOnce: [SpybotDeletingB590] command /c del "C:\Program Files\VAV\vav.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3849] cmd /c del "C:\Program Files\VAV\vav.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9362] command /c del "C:\Program Files\VAV\vav0.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1888] cmd /c del "C:\Program Files\VAV\vav0.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1478] command /c del "C:\Program Files\VAV\vav1.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2717] cmd /c del "C:\Program Files\VAV\vav1.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8119] command /c del "C:\WINDOWS\system32\hgGAsTJd.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2065] cmd /c del "C:\WINDOWS\system32\hgGAsTJd.dll"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra button: (no name) - {20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - C:\WINDOWS\system32\mscoree.DLL
O9 - Extra 'Tools' menuitem: Tri&xie Options... - {20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - C:\WINDOWS\system32\mscoree.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.att.net
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1153361539921
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1153361526140
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: FAH@C:+Program Files+Folding@Home Windows SMP Client V1.01+fah.exe - Unknown owner - C:\Program Files\Folding@Home Windows SMP Client V1.01\fah.exe
O23 - Service: FAH@C:+WINDOWS+system32+fah.exe - Unknown owner - C:\WINDOWS\system32\fah.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MPICH2 Process Manager, Argonne National Lab (mpich2_smpd) - Unknown owner - C:\Program Files\Folding@Home Windows SMP Client V1.01\smpd.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 5503 bytes