PDA

View Full Version : Coolwebsearch and other nasties have bitten me



ATHiker95
2008-09-17, 19:42
Well, after many,many years of escaping issues, i have finally been caught. Despite running Avast (free version), Spybot Search and Destroy, Java Coolware SpywareBlaster and Zone Alarm, the damn coolwebsearch thing landed on me and has wreaked havoc on my XP Home SP2 machine. The first odd thing I noticed was that zonealarm was asking for svchost.exe to be allowed. I recognized that as a common windows file from Task Manager, so the first time I said deny and possibly the 2nd time. Then the 3rd time, I finally decided I was getting tired of seeing it and clicked ok. Probably a bad move. Then it popped up something called dhanpie.exe, which I denied. (I've been unable to find any mention of that when searching for it on the Net). Despite denying it, there it sat in my Zone Alarm program listing with 4 question marks next to - so i blocked it completely there. Then I decided I'd better run Spybot and it found CoolwebSearch - I clicked on Fix and after a bit, it said it was fixed. But I don't think so. Then suddenly a big boxed popped up which said something about Spyware on my computer and my desktop background got wiped out and was replaced with this stark white background. Icons were still there, however. The spyware box alluded to me having Win32/PrivacyRemover.M64 and Win32/Adware.virtumonde and had a button to click, which I didn't. You also couldn't close the box. So from there, I opened Firefox and tried to go to Trend Micro and other anti-spyware sites - it wouldn't let me. When I clicked on a Google Search and then clicked on the results, it would send me to strange search pages. It would load most web pages ok, but obviously it was messed up.

I ran a full Virus scan with AVG and found a few VBS.Malware-gen viruses,, one located in C:Docs and Settings\Mark\Local Settings\Temp\tt238.tmp.vbs and another in F:\Program Files\BillPStudios\WinPatrol\winpatrol.exe. I took the recommended action to move them to Avast's Chest. (it also found win32:Agent-xwt(trj))

After a bit of reading on my wife's laptop, I found out about cwshredder and downloaded it to a usb key and ran it in safe mode on my desktop - it didn't find any evidence of it.

When I tried to open My Computer or Windows Explorer, it wouldn't let me. Returned a Windows error message with app name explorer.exe and Modname a9srchas.dll. I reported those to windows. I was able to navigate into My Computer by opening a My Documents window and then clicking on My Computer in left window pane- sort of a back door way of getting in. Could not access Control Panel.

I finally wondered if spybot's removal thing had worked and perhaps I should reboot and see what happened (probably a dumb thing to do). Computer booted and brought up the desktop, but again the big Spy thing appeared and my desktop background was white and then the computer froze solid. Not good. So I cold rebooted and went into safe mode. Since I run this desktop wirelessly, I couldn't use safe mode with networking. Things appeared to work ok in safe mode, except when running more virus scans there , the screen would periodically go to BSOD's and post messages like Kmode-exception not handled or Sysinternals_Great_Site or Bad_Pool_Header and would say it was rebooting and would go to the Windows rebooting screen with the little scrolling bar. I didn't think it was really rebooting so hit my safemode key again (F5 on my computer) and it brought me right back up again to my virus scanner doing it's thing. That made me think these were most likely fake BSOD's - could that be? Seems like the very first messages I saw had some really goofy names for errors in there, one being a porn name even, if I recall correctly -they didn't stay on the screen long enough for me to get them all down, because it would return to the reboot screen.

I am concerned about my backed up information. I have two external drives but haven't backed them up recently as I have gotten lazy using Carbonite, an online backup service. I'm not sure if these viruses/trojans could get backed up to Carbonite's services or if they have some way of checking before stuff hits their servers - I'm awaiting answer on that. I have been running out of room on my Desktop (have a 100GB hard drive which I foolishly partitioned with a 7GB C: drive some 5 years ago - down to about 350mb on C - not good - system restore was turned off due to needing more space - also not good), so I have put things on my external drive that are not on my desktop. I have even installed programs on there since my F:\Programs drive was getting full. I ran a virus scan on this K:drive (external) and it found a trojan (Win32:Trojan-gen(other), VPS version 080915-0, 09/15/2008) in my Internet downloads directory. I tried to move it to the Chest, but Avast couldn't connect to the Chest (I think it needs online access to do this), so it couldn't move the item to the chest - rather dumb, me thinks. So I have a patch.exe file in there that has a trojan - that one looked familiar and I thought I had put it in the Virus Vault a long time ago, but I transferred my Internet Download files from my Desktop to that K drive sometime ago - maybe it reappeared?

So, now the question - what to do? I've downloaded HiJack This on to a usb key from my wife's laptop. I plan to use that to run a log on my desktop in safe mode.Once I do that, is it safe to put it back in my wife's laptop, so I can post a report here? If I virus scan the key before taking it out of my desktop using Avast and it says it is ok, can I trust that? Sure don't want to infect my wife's laptop (death would be imminent).

Also - would it be save to back up in safe mode my H drive (photos) and my G: Drive (which includes My Documents) to my external drive? All my Programs are loaded on F: - not sure if I should back them up or not. Don't want to back up C: for obvious reasons.

Should I try the repair or delete options in Avast ? I was thinking that might be dangerous to do - the recommended action was to move them to the Chest (which I can't do at the moment). Or should I pay for something like Webroot's Spysweeper and run it, figuring the paid version would at least make an attempt to repair this stuff.

Ok, I've probably irritated everyone with my constant blathering, so I'll shut up and let you advance me some suggestions. I live on my computer, so this is freaking me out(obviously). Incidentally, I use Roboform for passwords and do a lot of online banking,etc. Would it be advisable to change all of those banking passwords immediately?

Thanks again,
Mark

ATHiker95
2008-09-21, 23:28
http://forums.spybot.info/showthread.php?t=34289

I posted 4 days ago for help, but at the time, had not yet run a HiJack Log - since then I have, which is below. Thanks so much for helping out with this - like most folks, I have critical stuff on my computer that I would like to protect.

Here's my HiJack log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:31:00 PM, on 9/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Mark\Application Data\U3\000015E96A612DE3\LaunchPad.exe
C:\WINDOWS\system32\ctfmon.exe
F:\Internet Downloads\HiJackThis 2.02\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
R3 - URLSearchHook: Answers.com Toolbar - {6341761b-babe-406d-b0d6-8d99b81c2ee5} - C:\Program Files\Answers.com\tbAnsw.dll
O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - F:\Program Files\IEPro\iepro.dll
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - F:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Ask Search Assistant BHO - {0A94B111-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
O2 - BHO: bxNewFolder - {51C8BCA8-2524-4523-BF09-738C4EEBFC58} - F:\PROGRA~1\BXNEWF~1\BXNEWF~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - F:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll (file missing)
O2 - BHO: Powermarks - {6172E460-FAE3-11D2-B494-004005A47AAA} - F:\PROGRA~1\POWERM~1.5\iec.dll
O2 - BHO: Answers.com Toolbar - {6341761b-babe-406d-b0d6-8d99b81c2ee5} - C:\Program Files\Answers.com\tbAnsw.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - F:\Program Files\Adobe\Acrobat6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
O2 - BHO: InlineSearchHandleHotKey - {B6FFE2AE-4D12-451F-B457-FE6125FFB1CF} - F:\Program Files\IEForge\Inline Search\InlineSearch.dll
O2 - BHO: (no name) - {BBE59AF5-EE22-4A3A-AB26-3F774D1B4216} - F:\PROGRA~1\FOLDER~1\FOLDER~1.DLL
O2 - BHO: &Google Notebook - {CCCCCCD3-666F-4F81-8B69-745DE9F6D897} - C:\Program Files\Google\Google Notebook\gnotes1.0.2.19-1093068710.dll
O2 - BHO: PicLens plug-in for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\PicLens.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: FireShot - {6E6E744E-4D20-4ce3-9A7A-26DFFFE22F68} - C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\zvye194z.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\library\fsaddin-0.55.dll (file missing)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O3 - Toolbar: Answers.com Toolbar - {6341761b-babe-406d-b0d6-8d99b81c2ee5} - C:\Program Files\Answers.com\tbAnsw.dll
O4 - HKLM\..\Run: [GWMDMpi] C:\WINDOWS\GWMDMpi.exe
O4 - HKLM\..\Run: [IMONTRAY] F:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MaxtorOneTouch] F:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast!] F:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [zBrowser Launcher] F:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "F:\program files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [lphctnfj0eefl] C:\WINDOWS\system32\lphctnfj0eefl.exe
O4 - HKCU\..\Run: [Clipomatic] F:\Program Files\Clipomatic\Clipomatic.exe
O4 - HKCU\..\Run: [CursorXP] F:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [MSGTAG] "F:\Program Files\MSGTAG Status\MSGTAGStatus.exe" /startup
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\3.14.0.44\PlaxoHelper_en.exe -a
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue Quick Access] "F:\Program Files\Uniblue\ProcessLibrary\qaccess.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Mark\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Mark\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Copernic Desktop Search 2] "F:\Program Files\Copernic Desktop Search\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [PlaxoSysTray] C:\Program Files\Plaxo\3.14.0.44\PlaxoSysTray.exe
O4 - HKCU\..\Run: [xrt_Shell] C:\Documents and Settings\Mark\xrt_yftw.exe
O4 - HKCU\..\RunOnce: [FFTI] C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\zvye194z.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\ffti.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /DestPath="C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles/zvye194z.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: AlarmApp.exe.lnk = F:\Program Files\Handspring\AlarmApp.exe
O4 - Startup: Google Talk, Labs Edition.lnk = C:\Documents and Settings\Mark\Local Settings\Application Data\Google\Google Talk, Labs Edition\GoogleTalkLabsEdition.exe
O4 - Startup: RTM Tool.lnk = ?
O4 - Global Startup: 1-Click Answers.lnk = C:\Program Files\1-Click Answers\answers.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: APC UPS Status.lnk = F:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
O4 - Global Startup: Audible Download Manager.lnk = C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O8 - Extra context menu item: Answers... - file://C:\Program Files\1-Click Answers\Html\atiemenu.htm
O8 - Extra context menu item: Call 3d Traceroute - res://C:\WINDOWS\d3triehelper.exe/HTML.HTA
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://F:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://F:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://F:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Note this (Google Notebook) - res://C:\Program Files\Google\Google Notebook\gnotes1.0.2.19-1093068710.dll/gn_menu1.html
O8 - Extra context menu item: Note this item (Google Notebook) - res://C:\Program Files\Google\Google Notebook\gnotes1.0.2.19-1093068710.dll/gn_menu2.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - F:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - F:\Program Files\IEPro\iepro.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Internet Radio by Endicosoft.com - {1F958B09-3312-7f0e-9723-4C1324C57B20} - F:\Program Files\Internet Radio\Radio.exe
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: FireShot menu - {A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - F:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - F:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.bestbuy.msn.com
O16 - DPF: ChatSpace Full Java Client 2.1.0.84 - http://about.chatspace.com/Java/cs4fs084.cab
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
O16 - DPF: Yahoo! Chat - http://cs5.chat.sc5.yahoo.com/c381/chat.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20020713/qtinstall.info.apple.com/samantha/us/win/QuickTimeInstaller.exe
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
O16 - DPF: {51045741-8C4E-4EAC-8F03-08E43A6FBB29} - http://aft.ancestry.com/aftfiles/files/install/AncestryFamilyTree.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/06c5345dd0ead5cee321/netzip/RdxIE2.cab
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/en/deleon/1.1.57-deleon/GoogleNav.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1163259859265
O16 - DPF: {8CE3BAE6-AB66-40B6-9019-41E5282FF1E2} (QuickBooks Online Edition Utilities Class v8) - https://accounting.quickbooks.com/c5/v14.223/qboax8.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {A57B79D8-9501-42B7-BA9B-B961454712F2} (WLANinfo.WLANX) - https://www.jiwire.com/activeX/wlaninfo.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/53/install/gtdownls.cab
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O18 - Protocol: asksam - {F9FF9EDA-4916-11D1-B6C1-002018305A61} - F:\Program Files\askSam\SurfSaver\AS_AIPP.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - F:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - F:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - F:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - F:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - F:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CarboniteService - Carbonite, Inc. (www.carbonite.com) - C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
O23 - Service: Diskeeper - Diskeeper Corporation - F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Folder Size (FolderSize) - Brio - F:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel(R) Active Monitor (imonNT) - Intel Corp. - F:\Program Files\Intel\Intel(R) Active Monitor\imonnt.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Retrospect Helper - Dantz Development Corporation - F:\Program Files\Dantz\Retrospect\rthlpsvc.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - F:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
O23 - Service: CLCV0 (UTSCSI) - Unknown owner - C:\WINDOWS\system32\UTSCSI.EXE
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WUSB54GSv2SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
O24 - Desktop Component 1: MSNBC Weather - HTTP://www.msnbc.com/modules/weather/ie4weather.htm

--
End of file - 18259 bytes

Blade81
2008-09-22, 19:20
Hi

Do following steps in normal mode if possible.

Disable Spybot's TeaTimer
Run Spybot-S&D in Advanced Mode
If it is not already set to do this, go to the Mode menu
select
Advanced Mode

On the left hand side, click on Tools
Then click on the Resident icon in the list
Uncheck
Resident TeaTimer
and OK any prompts.
Restart your computer


Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:


Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link (http://www.bleepingcomputer.com/forums/topic114351.html)
Remember to re-enable them afterwards.


Click Yes to allow ComboFix to continue scanning for malware.


When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New HijackThis log.

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.

ATHiker95
2008-09-23, 01:02
Before starting this procedure of using Combofix, I should mention that i tried to install SuperAntiSpyware and BitDefender in the hopes that maybe they would clean up my mess. But the system refused to allow either to be installed - "system administrator has set policies to prevent this installation". I assume that was another sneaky thing these Trojans have done. Is there something I need to do to fix that before trying ComboFix?

Thanks!
Mark

ATHiker95
2008-09-23, 01:29
In addition to the above question, since I only have 350mb of space left on my C: drive, will I be able to install the Recovery Console ? Wasn't sure how much space it used. Also - I don't have my computer set up to use restore points, because I am so low on space on C: - will that affect anything?

Also - since I don't have Internet access on the infected machine, can I download combofix to a usb key using my wife's computer and then transfer it to the desktop on the affected computer? Will that still work? (same goes for the download of the recovery console).

Thanks - sorry for all these secondary questions, but thought they might be important (or not).

Mark

ATHiker95
2008-09-23, 07:03
well i forged ahead and put combofix and the recovery console on a usb key and then moved them to the desktop on the infected machine. (did this while in safe mode). This was after rebooting my machine and finding it would only come up with a black screen and no icons in safe mode - had to reboot into safe mode with networking to see icons - don't know what's up with that.
So, while in safe mode, I drug the recovery console icon on top of combofix.exe and a little blue bar ran across and then i got a message saying it had found a rootkit and needed to reboot. I hesitated as it didn't say anything about installing the recovery console. Would you reboot or try to run combofix before rebooting? I saw someone on the net suggest that one could look at C:\combofix.exe to see if it had produced a log, but there is nothing there like that, although there is a file called bug.txt which looks to have been produced very recently. I'm a bit afraid to open that, even though it is a txt file - can a malware product masquerade itself as a .txt file?

Anyway, thought I'd wait for your advice!
Thanks again!
Mark

Blade81
2008-09-23, 07:19
it had found a rootkit and needed to reboot.
Hi

Please reboot.

ATHiker95
2008-09-23, 14:21
one last dumb question - do you reboot into Safe Mode or should one let it reboot into normal mode?

Thanks,
Mark

Blade81
2008-09-23, 18:22
Normal mode if possible :)

ATHiker95
2008-09-25, 06:04
Here are my combofix.txt log and Hijack log

ComboFix 08-09-20.05 - Mark 2008-09-24 22:34:31.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.590 [GMT -4:00]
Running from: C:\Documents and Settings\Mark\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mark\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.
The following files were disabled during the run:
F:\Program Files\TuneUp Utilities 2006\WinStylerThemeHelper.dll


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Janet\Cookies\janet@2o7[2].txt
C:\Documents and Settings\Mark\Cookies\mark@9aacff40cbe9d4950377995da355ea2c.img.pheedo[1].txt
C:\Documents and Settings\Mark\Cookies\mark@e3229a726baa605a13495ac1160ff208.img.pheedo[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg.hitbox[2].txt
C:\WINDOWS\Downloaded Program Files\Quarantine
C:\WINDOWS\Downloaded Program Files\Temp
C:\WINDOWS\system32\blphctnfj0eefl.scr
C:\WINDOWS\system32\lphctnfj0eefl.exe
C:\WINDOWS\system32\phctnfj0eefl.bmp
C:\WINDOWS\system32\tdssadw.dll
C:\WINDOWS\system32\tdssinit.dll
C:\WINDOWS\system32\tdssl.dll
C:\WINDOWS\system32\tdsslog.dll
C:\WINDOWS\system32\tdssmain.dll
C:\WINDOWS\system32\tdssserf.dll
C:\WINDOWS\system32\tdssservers.dat
C:\WINDOWS\temp\perflib_perfdata_1cc.dat

.
((((((((((((((((((((((((( Files Created from 2008-08-25 to 2008-09-25 )))))))))))))))))))))))))))))))
.

2008-09-15 21:09 . 2008-09-16 00:48 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-09-15 07:19 . 2008-09-22 23:06 1,324 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-09-15 07:18 . 2008-09-15 07:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\IEPro
2008-09-15 07:16 . 2008-09-15 07:16 39,424 --a------ C:\Documents and Settings\Mark\xrt_yftw.exe
2008-08-31 19:25 . 2008-09-04 20:59 <DIR> d-------- C:\Documents and Settings\Mark\Application Data\OpenOffice.org2

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-25 02:29 --------- d-----w C:\Program Files\Plaxo
2008-09-21 02:37 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-09-17 17:59 20,252,664 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2008_09_17_13_51_36_full.dmp.zip
2008-09-17 17:54 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-16 05:03 --------- d-----w C:\Documents and Settings\Mark\Application Data\U3
2008-09-15 17:17 --------- d-----w C:\Documents and Settings\Mark\Application Data\MSGTAG
2008-09-15 11:16 502,272 ----a-w C:\WINDOWS\system32\winlogon.exe
2008-09-15 11:16 295,424 ----a-w C:\WINDOWS\system32\termsrv.dll
2008-09-15 11:06 24,856,608 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-14 15:01 1,819,921 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-09-14 15:00 288,836 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-13 20:40 --------- d-----w C:\Program Files\Java
2008-08-31 21:07 --------- d-----w C:\Documents and Settings\Mark\Application Data\uTorrent
2008-08-21 17:31 --------- d-----w C:\Program Files\Conduit
2008-08-21 17:31 --------- d-----w C:\Program Files\Answers.com
2008-08-21 17:31 --------- d-----w C:\Program Files\1-Click Answers
2008-08-20 00:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-15 01:49 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-12 00:54 --------- d-----w C:\Program Files\Apple Software Update
2008-08-03 23:35 --------- d-----w C:\Program Files\iPod
2008-08-03 22:59 --------- d-----w C:\Program Files\Bonjour
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-19 02:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-19 02:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 02:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-09 13:05 75,248 ----a-w C:\WINDOWS\zllsputility.exe
2008-07-09 13:05 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:32 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2007-12-31 02:09 846,504 -c--a-w C:\Documents and Settings\Mark\JNativeCpp.dll
2006-01-16 19:30 18,410 -c--a-w C:\Program Files\irunin.ini
2006-01-16 19:29 8,154 -c--a-w C:\Program Files\irunin.bmp
2006-01-16 19:29 26,267 -c--a-w C:\Program Files\irunin.dat
2006-01-16 19:29 15,938 -c--a-w C:\Program Files\irunin.lng
2002-10-19 21:00 606 -c-h--w C:\Documents and Settings\Mark\links.dat
2008-03-07 05:09 23 --sha-w C:\WINDOWS\system32\afafcf2_z.dll
.

------- Sigcheck -------

2004-05-26 21:38 483328 e7f9d2e4e4a94a6f58014e5ffa16a65e C:\WINDOWS\$hf_mig$\KB840987\SP1QFE\winlogon.exe
2004-05-26 21:38 483328 e7f9d2e4e4a94a6f58014e5ffa16a65e C:\WINDOWS\$hf_mig$\KB841533\SP1QFE\winlogon.exe
2004-08-04 00:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2008-09-15 07:16 502272 9b1bd82bd0761b5ba986af66d2809c30 C:\WINDOWS\system32\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0A94B116-4504-4e26-AB05-E61E474AA38B}"= "C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL" [2008-02-17 61440]
"{6341761b-babe-406d-b0d6-8d99b81c2ee5}"= "C:\Program Files\Answers.com\tbAnsw.dll" [2008-08-05 1610264]

[HKEY_CLASSES_ROOT\clsid\{0a94b116-4504-4e26-ab05-e61e474aa38b}]

[HKEY_CLASSES_ROOT\clsid\{6341761b-babe-406d-b0d6-8d99b81c2ee5}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6341761b-babe-406d-b0d6-8d99b81c2ee5}]
2008-08-05 02:13 1610264 --a------ C:\Program Files\Answers.com\tbAnsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{6341761b-babe-406d-b0d6-8d99b81c2ee5}"= "C:\Program Files\Answers.com\tbAnsw.dll" [2008-08-05 1610264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{6341761B-BABE-406D-B0D6-8D99B81C2EE5}"= "C:\Program Files\Answers.com\tbAnsw.dll" [2008-08-05 1610264]

[HKEY_CLASSES_ROOT\clsid\{6341761b-babe-406d-b0d6-8d99b81c2ee5}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Blue]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2008-06-13 23:19 527296 -ra------ C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2008-06-13 23:19 527296 -ra------ C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Blue]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2008-06-13 23:19 527296 -ra------ C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Red]
@="{01CCCC8C-1D50-4b13-B96D-4B922DD3128B}"
[HKEY_CLASSES_ROOT\CLSID\{01CCCC8C-1D50-4b13-B96D-4B922DD3128B}]
2008-06-13 23:19 527296 -ra------ C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2008-06-13 23:19 527296 -ra------ C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Clipomatic"="F:\Program Files\Clipomatic\Clipomatic.exe" [1999-05-15 65536]
"CursorXP"="F:\Program Files\CursorXP\CursorXP.exe" [2005-01-19 128000]
"MSGTAG"="F:\Program Files\MSGTAG Status\MSGTAGStatus.exe" [2007-07-10 1820160]
"PlaxoUpdate"="C:\Program Files\Plaxo\3.14.0.44\PlaxoHelper_en.exe" [2008-07-24 363591]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"Uniblue Quick Access"="F:\Program Files\Uniblue\ProcessLibrary\qaccess.exe" [2006-09-14 225280]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-01 68856]
"cdloader"="C:\Documents and Settings\Mark\Application Data\mjusbsp\cdloader2.exe" [2007-12-21 50520]
"Google Update"="C:\Documents and Settings\Mark\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-08-29 133104]
"Copernic Desktop Search 2"="F:\Program Files\Copernic Desktop Search\Copernic Desktop Search 2\DesktopSearchService.exe" [2008-03-03 1583624]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-07-13 160592]
"PlaxoSysTray"="C:\Program Files\Plaxo\3.14.0.44\PlaxoSysTray.exe" [2008-07-24 20480]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"FFTI"="C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\zvye194z.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\ffti.exe" [2007-03-30 2526784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GWMDMpi"="C:\WINDOWS\GWMDMpi.exe" [2001-10-31 40960]
"IMONTRAY"="F:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe" [2004-03-10 32768]
"MaxtorOneTouch"="F:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe" [2003-05-21 45056]
"MXO Auto Loader"="C:\WINDOWS\MXOALDR.EXE" [2003-04-07 118784]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2004-03-24 46080]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-03-24 3309568]
"avast!"="F:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"zBrowser Launcher"="F:\Program Files\Logitech\iTouch\iTouch.exe" [2004-03-18 892928]
"ZoneAlarm Client"="F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"Carbonite Backup"="C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2008-06-13 600000]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040]
"QuickTime Task"="F:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="F:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"SunJavaUpdateSched"="F:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2005-09-26 169984]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 C:\WINDOWS\LOGI_MWX.EXE]
"nwiz"="nwiz.exe" [2004-03-24 C:\WINDOWS\system32\nwiz.exe]
"GWMDMMSG"="GWMDMMSG.exe" [2001-10-31 C:\WINDOWS\GWMDMMSG.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 C:\WINDOWS\system32\narrator.exe]

C:\Documents and Settings\Janet\Start Menu\Programs\Startup\
Powermarks.lnk - F:\Program Files\Powermarks 3.5\pm.exe [2002-07-09 614400]

C:\Documents and Settings\Mark\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2002-09-17 113664]
AlarmApp.exe.lnk - F:\Program Files\Handspring\AlarmApp.exe [2005-09-19 274432]
Google Talk, Labs Edition.lnk - C:\Documents and Settings\Mark\Local Settings\Application Data\Google\Google Talk, Labs Edition\GoogleTalkLabsEdition.exe [2008-05-08 94704]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
1-Click Answers.lnk - C:\Program Files\1-Click Answers\answers.exe [2005-05-07 806912]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
APC UPS Status.lnk - F:\Program Files\APC\APC PowerChute Personal Edition\Display.exe [2004-09-01 221247]
Audible Download Manager.lnk - C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe [2006-08-24 714344]
DataViz Inc Messenger.lnk - C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe [2006-01-15 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= ctwdm32.dll

[HKLM\~\startupfolder\C:^Documents and Settings^Mark^Start Menu^Programs^Startup^MailWasherPro.lnk]
path=C:\Documents and Settings\Mark\Start Menu\Programs\Startup\MailWasherPro.lnk
backup=C:\WINDOWS\pss\MailWasherPro.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Mark^Start Menu^Programs^Startup^RTM Tool.lnk]
path=C:\Documents and Settings\Mark\Start Menu\Programs\Startup\RTM Tool.lnk
backup=C:\WINDOWS\pss\RTM Tool.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gcasServ

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-08-18 18:41 1832272 F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a--c--- 2006-12-11 10:53 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xrt_Shell]
--a------ 2008-09-15 07:16 39424 C:\Documents and Settings\Mark\xrt_yftw.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"Skype"="F:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
"StartGuard"=f:\program files\interapple\@start\StartGuard.exe
"Spyware Doctor"=F:\PROGRA~1\SPYWAR~2\swdoctor.exe /Q

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="F:\program files\QuickTime\qttask.exe" -atboottime
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
"iTunesHelper"=f:\program files\itunes\ituneshelper.exe
"bxAutoZipOE"=C:\Program Files\Common Files\BAxBEx\bxOE\bxOEPluginAR.exe
"Microsoft Works Portfolio"=C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
"Microsoft Works Update Detection"=C:\Program Files\Microsoft Works\WkDetect.exe
"WinPatrol"="f:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe"
"WorksFUD"=C:\Program Files\Microsoft Works\wkfud.exe
"zBrowser Launcher"=C:\Program Files\Logitech\iTouch\iTouch.exe
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"UpdReg"=C:\WINDOWS\Updreg.exe
"SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"F:\\Program Files\\Trillian\\trillian.exe"=
"F:\\Program Files\\Handspring\\Hotsync.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"G:\\Mark's Documents\\Internet Downloads\\UTorrent\\utorrent.exe"=
"F:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\IEPro\\MiniDM.exe"=
"F:\\Program Files\\IEPro\\MiniDM.exe"=
"C:\\Documents and Settings\\Mark\\Local Settings\\Application Data\\Google\\Google Talk, Labs Edition\\GoogleTalkLabsEdition.exe"=
"C:\\Documents and Settings\\Mark\\Application Data\\mjusbsp\\magicJack.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"F:\\Program Files\\iTunes\\iTunes.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 ousbehci;NEC PCI to USB Enhanced Host Controller;C:\WINDOWS\system32\Drivers\ousbehci.sys [2002-04-01 29696]
R2 WUSB54GSv2SVC;WUSB54GSv2SVC;C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe WUSB54GSv2.exe [ ]
R3 ousb2hub;OrangeWare USB 2.0 Hub Support;C:\WINDOWS\system32\DRIVERS\ousb2hub.sys [2002-04-01 43648]
S3 hwi4857;Duo Digital Media Player;C:\WINDOWS\system32\Drivers\hwi4857.sys [2001-12-20 10532]
S3 Otis;Audible Otis Service;C:\WINDOWS\system32\Drivers\OtisPlay.sys [2003-07-14 9472]
S3 PortRst;BaromTec HMS30C6001 Reset Driver;C:\WINDOWS\system32\DRIVERS\PortRst.sys [2001-08-06 12721]
S3 ptiusbf;PTI USB Filter;C:\WINDOWS\system32\DRIVERS\PTIUSBF.SYS [2001-04-14 22474]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
\Shell\AutoRun\command - L:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{da20412e-b688-11dc-a39a-0016b6977199}]
\Shell\AutoRun\command - L:\autorun.exe
\Shell\phone\command - L:\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{da204130-b688-11dc-a39a-0016b6977199}]
\Shell\AutoRun\command - M:\magicJack\autorun.exe
\Shell\phone\command - M:\magicJack\autorun.exe

*Newly Created Service* - CATCHME
*Newly Created Service* - GTNDIS5
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{6E6E744E-4D20-4ce3-9A7A-26DFFFE22F68} - C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\zvye194z.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\library\fsaddin-0.55.dll
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
MSConfigStartUp-ISTray - F:\Program Files\Spyware Doctor\pctsTray.exe
MSConfigStartUp-lphctnfj0eefl - C:\WINDOWS\system32\lphctnfj0eefl.exe


.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\zvye194z.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/ig?hl=en
FF -: plugin - C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\zvye194z.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp07061050.dll
FF -: plugin - C:\Documents and Settings\Mark\Local Settings\Application Data\Google\Update\1.2.131.11\npGoogleOneClick5.dll
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\Microsoft Silverlight\2.0.30523.8\npctrl.dll
FF -: plugin - c:\program files\real\rhapsodyplayerengine\nprhapengine.dll
FF -: plugin - F:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - F:\Program Files\Java\jre1.6.0_05\bin\npjava11.dll
FF -: plugin - F:\Program Files\Java\jre1.6.0_05\bin\npjava12.dll
FF -: plugin - F:\Program Files\Java\jre1.6.0_05\bin\npjava13.dll
FF -: plugin - F:\Program Files\Java\jre1.6.0_05\bin\npjava14.dll
FF -: plugin - F:\Program Files\Java\jre1.6.0_05\bin\npjava32.dll
FF -: plugin - F:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
FF -: plugin - F:\Program Files\Java\jre1.6.0_05\bin\npoji610.dll
FF -: plugin - F:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
FF -: plugin - F:\Program Files\Mozilla Firefox\plugins\npLegitCheckPlugin.dll
FF -: plugin - F:\Program Files\Mozilla Firefox\plugins\npnul32.dll
FF -: plugin - F:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
FF -: plugin - F:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
FF -: plugin - F:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
FF -: plugin - F:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
FF -: plugin - F:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
FF -: plugin - F:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
FF -: plugin - F:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
FF -: plugin - F:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
FF -: plugin - F:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
FF -: plugin - F:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
FF -: plugin - F:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
FF -: plugin - F:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll
FF -: plugin - F:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll
FF -: plugin - F:\Program Files\Mozilla Firefox\plugins\NPZoneSB.dll
FF -: plugin - F:\program files\QuickTime\Plugins\npqtplugin.dll
FF -: plugin - F:\program files\QuickTime\Plugins\npqtplugin2.dll
FF -: plugin - F:\program files\QuickTime\Plugins\npqtplugin3.dll
FF -: plugin - F:\program files\QuickTime\Plugins\npqtplugin4.dll
FF -: plugin - F:\program files\QuickTime\Plugins\npqtplugin5.dll
FF -: plugin - F:\program files\QuickTime\Plugins\npqtplugin6.dll
FF -: plugin - F:\program files\QuickTime\Plugins\npqtplugin7.dll
FF -: plugin - F:\Program Files\Real\RealOnePlayer\Netscape6\nppl3260.dll
FF -: plugin - F:\Program Files\Real\RealOnePlayer\Netscape6\nprjplug.dll
FF -: plugin - F:\Program Files\Real\RealOnePlayer\Netscape6\nprpjplug.dll
.

**************************************************************************

and My Hijack log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:00:40 PM, on 9/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
F:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
F:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
F:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
F:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
C:\WINDOWS\System32\cisvc.exe
F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
F:\Program Files\FolderSize\FolderSizeSvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UTSCSI.EXE
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GSv2.exe
F:\Program Files\Intel\Intel(R) Active Monitor\imonnt.exe
C:\WINDOWS\System32\alg.exe
F:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe
F:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\MXOALDR.EXE
C:\WINDOWS\system32\devldr32.exe
F:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\GWMDMMSG.exe
F:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
F:\Program Files\iTunes\iTunesHelper.exe
F:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\wuauclt.exe
F:\Program Files\CursorXP\CursorXP.exe
F:\Program Files\MSGTAG Status\MSGTAGStatus.exe
C:\Program Files\Plaxo\3.14.0.44\PlaxoHelper_en.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\Mark\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
F:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\WINDOWS\system32\cidaemon.exe
F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
F:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
F:\Program Files\Alwil Software\Avast4\ashWebSv.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
F:\PROGRA~1\BXNEWF~1\bxExpHelper.exe
C:\Documents and Settings\Mark\Desktop\HiJackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
R3 - URLSearchHook: Answers.com Toolbar - {6341761b-babe-406d-b0d6-8d99b81c2ee5} - C:\Program Files\Answers.com\tbAnsw.dll
O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - F:\Program Files\IEPro\iepro.dll
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - F:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Ask Search Assistant BHO - {0A94B111-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
O2 - BHO: bxNewFolder - {51C8BCA8-2524-4523-BF09-738C4EEBFC58} - F:\PROGRA~1\BXNEWF~1\BXNEWF~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - F:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll (file missing)
O2 - BHO: Powermarks - {6172E460-FAE3-11D2-B494-004005A47AAA} - F:\PROGRA~1\POWERM~1.5\iec.dll
O2 - BHO: Answers.com Toolbar - {6341761b-babe-406d-b0d6-8d99b81c2ee5} - C:\Program Files\Answers.com\tbAnsw.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - F:\Program Files\Adobe\Acrobat6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
O2 - BHO: InlineSearchHandleHotKey - {B6FFE2AE-4D12-451F-B457-FE6125FFB1CF} - F:\Program Files\IEForge\Inline Search\InlineSearch.dll
O2 - BHO: (no name) - {BBE59AF5-EE22-4A3A-AB26-3F774D1B4216} - F:\PROGRA~1\FOLDER~1\FOLDER~1.DLL
O2 - BHO: &Google Notebook - {CCCCCCD3-666F-4F81-8B69-745DE9F6D897} - C:\Program Files\Google\Google Notebook\gnotes1.0.2.19-1093068710.dll
O2 - BHO: PicLens plug-in for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\PicLens.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O3 - Toolbar: Answers.com Toolbar - {6341761b-babe-406d-b0d6-8d99b81c2ee5} - C:\Program Files\Answers.com\tbAnsw.dll
O4 - HKLM\..\Run: [GWMDMpi] C:\WINDOWS\GWMDMpi.exe
O4 - HKLM\..\Run: [IMONTRAY] F:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MaxtorOneTouch] F:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast!] F:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [zBrowser Launcher] F:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "F:\program files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [Clipomatic] F:\Program Files\Clipomatic\Clipomatic.exe
O4 - HKCU\..\Run: [CursorXP] F:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [MSGTAG] "F:\Program Files\MSGTAG Status\MSGTAGStatus.exe" /startup
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\3.14.0.44\PlaxoHelper_en.exe -a
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue Quick Access] "F:\Program Files\Uniblue\ProcessLibrary\qaccess.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Mark\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Mark\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Copernic Desktop Search 2] "F:\Program Files\Copernic Desktop Search\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [PlaxoSysTray] C:\Program Files\Plaxo\3.14.0.44\PlaxoSysTray.exe
O4 - HKCU\..\RunOnce: [FFTI] C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\zvye194z.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\ffti.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /DestPath="C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles/zvye194z.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: AlarmApp.exe.lnk = F:\Program Files\Handspring\AlarmApp.exe
O4 - Startup: Google Talk, Labs Edition.lnk = C:\Documents and Settings\Mark\Local Settings\Application Data\Google\Google Talk, Labs Edition\GoogleTalkLabsEdition.exe
O4 - Global Startup: 1-Click Answers.lnk = C:\Program Files\1-Click Answers\answers.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: APC UPS Status.lnk = F:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
O4 - Global Startup: Audible Download Manager.lnk = C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O8 - Extra context menu item: Answers... - file://C:\Program Files\1-Click Answers\Html\atiemenu.htm
O8 - Extra context menu item: Call 3d Traceroute - res://C:\WINDOWS\d3triehelper.exe/HTML.HTA
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://F:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://F:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://F:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Note this (Google Notebook) - res://C:\Program Files\Google\Google Notebook\gnotes1.0.2.19-1093068710.dll/gn_menu1.html
O8 - Extra context menu item: Note this item (Google Notebook) - res://C:\Program Files\Google\Google Notebook\gnotes1.0.2.19-1093068710.dll/gn_menu2.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - F:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - F:\Program Files\IEPro\iepro.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Internet Radio by Endicosoft.com - {1F958B09-3312-7f0e-9723-4C1324C57B20} - F:\Program Files\Internet Radio\Radio.exe
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: FireShot menu - {A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - F:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - F:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.bestbuy.msn.com
O16 - DPF: ChatSpace Full Java Client 2.1.0.84 - http://about.chatspace.com/Java/cs4fs084.cab
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
O16 - DPF: Yahoo! Chat - http://cs5.chat.sc5.yahoo.com/c381/chat.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20020713/qtinstall.info.apple.com/samantha/us/win/QuickTimeInstaller.exe
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
O16 - DPF: {51045741-8C4E-4EAC-8F03-08E43A6FBB29} - http://aft.ancestry.com/aftfiles/files/install/AncestryFamilyTree.cab
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/en/deleon/1.1.57-deleon/GoogleNav.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1163259859265
O16 - DPF: {8CE3BAE6-AB66-40B6-9019-41E5282FF1E2} (QuickBooks Online Edition Utilities Class v8) - https://accounting.quickbooks.com/c5/v14.223/qboax8.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {A57B79D8-9501-42B7-BA9B-B961454712F2} (WLANinfo.WLANX) - https://www.jiwire.com/activeX/wlaninfo.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/53/install/gtdownls.cab
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O18 - Protocol: asksam - {F9FF9EDA-4916-11D1-B6C1-002018305A61} - F:\Program Files\askSam\SurfSaver\AS_AIPP.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - F:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - F:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - F:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - F:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - F:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CarboniteService - Carbonite, Inc. (www.carbonite.com) - C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
O23 - Service: Diskeeper - Diskeeper Corporation - F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Folder Size (FolderSize) - Brio - F:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel(R) Active Monitor (imonNT) - Intel Corp. - F:\Program Files\Intel\Intel(R) Active Monitor\imonnt.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Retrospect Helper - Dantz Development Corporation - F:\Program Files\Dantz\Retrospect\rthlpsvc.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - F:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
O23 - Service: CLCV0 (UTSCSI) - Unknown owner - C:\WINDOWS\system32\UTSCSI.EXE
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WUSB54GSv2SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
O24 - Desktop Component 1: MSNBC Weather - HTTP://www.msnbc.com/modules/weather/ie4weather.htm

--
End of file - 20005 bytes

Hope this helps! System seems better already, but I will wait to hear from you on what to do next before getting too carried away.

P.S. I do notice that dhanpbie.exe is still listed in the program listing in Zone Alarm - at the moment, I have set it to be completely blocked. Not sure what that is.
Thanks again so much for your help!
Mark

ATHiker95
2008-09-25, 06:38
In addition to the combofix log and hijack log above, i noticed after reboot that teatimer is listed as running as a Process when I pull up TaskManager. Yet I had unchecked it in MSCONFIG (and it is still unchecked there) before running combofix. I'm running Spybot 1.5 and under Tools, the Resident box is unchecked but I don't see any specific Teatimer setting. Should I delete this process in TaskManager or? I don't understand how it can be running if it is unchecked in MSCONFIG.

Thanks,
Mark

Blade81
2008-09-25, 09:27
P.S. I do notice that dhanpbie.exe is still listed in the program listing in Zone Alarm - at the moment, I have set it to be completely blocked. Not sure what that is.


Hi

Delete that dhanpbie.exe file (search for its location if needed).


IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

µTorrent


I'd like you to read the this thread (http://forums.spybot.info/showthread.php?t=282).

Please go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).

Delete these folders afterwards:

C:\Documents and Settings\Mark\Application Data\uTorrent
G:\Mark's Documents\Internet Downloads\UTorrent

Empty Recycle Bin.

After that:



Upload following files to http://www.virustotal.com and post back the results:
C:\Program Files\irunin.ini
C:\Program Files\irunin.dat
C:\Documents and Settings\Mark\links.dat



Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

Updating Java:

Download the latest version of Java Runtime Environment (JRE) 6 Update 7 (http://java.sun.com/javase/downloads/index.jsp).
Scroll down to where it says
The J2SE Runtime Environment (JRE) allows end-users to run Java applications.

Click the
Download
button to the right.
Select Windows on platform combobox and check the box that says:
Accept License Agreement. Click continue.

The page will refresh.
Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
Check any item with Java Runtime Environment (JRE or J2SE) in the name.
Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u7-windows-i586-p.exe to install the newest version.


Uninstall old Adobe Reader and get the latest one here (http://www.filehippo.com/download_adobe_reader/) or get Foxit Reader here (http://www.foxitsoftware.com/pdf/reader_2/down_reader.htm).


Kill TeaTimer process thru task manager.


Open notepad and copy/paste the text in the quotebox below into it:



KILLALL::

File::
C:\Documents and Settings\Mark\xrt_yftw.exe

Folder::
C:\Documents and Settings\Mark\Application Data\uTorrent
G:\Mark's Documents\Internet Downloads\UTorrent

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xrt_Shell]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"G:\\Mark's Documents\\Internet Downloads\\UTorrent\\utorrent.exe"=-



Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.


Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.


Download ATF (Atribune Temp File) Cleaner© by Atribune (http://www.atribune.org/ccount/click.php?id=1) to your desktop.

Double-click ATF Cleaner.exe to open it

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache
*The other boxes are optional*
Then click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.


Please run an online scan with Kaspersky Online Scanner (http://www.kaspersky.com/virusscanner) as instructed in the screenshot here (http://i275.photobucket.com/albums/jj285/Bleeping/KAS/KAS9.gif).


Post back its report, a fresh hjt log and above mentioned ComboFix resultant log.

ATHiker95
2008-09-26, 04:06
Didn't find UTorrent in Add/Remove Programs, so I'm guessing ComboFix removed it. I removed the directories you mentioned


File irunin.ini received on 09.26.2008 01:42:33 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 0/36 (0%)

File irunin.dat received on 09.26.2008 01:47:09 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 0/36 (0%)

File links.dat received on 09.26.2008 01:50:46 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 0/36 (0%)

I removed Java through Add/Remove Programs , rebooted - noticed that message popped up saying I was starting to run low on space on C: drive. Thought that was odd since I had just uninstalled Java. So before installing new Java, went ahead and deleted Adobe Reader and rebooted. Thought that would free up more room, but was puzzled when it didn't, so decided to uninstall my copy of Adobe Professional. Still the low space message (down to 170mb at the moment) and then it dawned on me that ComboFix had set a restore point and must have somehow turned system restore back on so that each time i uninstalled a program and rebooted , it created a new restore point. I checked C:\system volume information and the restore points are taking up 600mb! If I install Java now, it may take me perilously close to running completely out of space. (This is why I had originally turned system restore off because it sucked up too much space on C: and I was running out of space after a number of years and all those windows updates).

I know you can't delete individual restore points - so realize if I turn system restore off and then back on, i will wipe out all restore points including the combofix one that it initially set. The system is definitely better than it was before, so I wondering if that would be so bad to do? Perhaps turn them off and then reduce the amount of space system restore is set for (12% in this case which is about 800mb - perhaps knock it back to 8%?) and then turn it back on?

Think I'll await your advice before proceeding - not sure what happens when a system runs entirely out of space - probably not pretty.

Thanks!
Mark

ATHiker95
2008-09-26, 05:10
Just as a followup to the above, suddenly about 200mb of system restore points freed themselves up - probably because the amt of disk space on C: dropped below 200 mb, so it went back and wiped out the first restore point, which was of course Combofix's initial restore point. Oh well, guess that is not a concern now. Back up to about 370mb of space now. That should be enough to install java and finish your script and run the logs again.

Mark

ATHiker95
2008-09-26, 05:51
OK, I despite to forge ahead. Installed Java, and then drug the cfscript to ComboFix. Resulting log is here:

ComboFix 08-09-25.03 - Mark 2008-09-25 22:25:45.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.656 [GMT -4:00]
Running from: C:\Documents and Settings\Mark\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mark\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\Documents and Settings\Mark\xrt_yftw.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Mark\xrt_yftw.exe

.
((((((((((((((((((((((((( Files Created from 2008-08-26 to 2008-09-26 )))))))))))))))))))))))))))))))
.

2008-09-25 22:12 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-09-25 22:11 . 2008-09-25 22:11 <DIR> d-------- C:\Program Files\Common Files\Java
2008-09-15 21:09 . 2008-09-16 00:48 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-09-15 07:19 . 2008-09-22 23:06 1,324 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-09-15 07:18 . 2008-09-15 07:18 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\IEPro
2008-08-31 19:25 . 2008-09-04 20:59 <DIR> d-------- C:\Documents and Settings\Mark\Application Data\OpenOffice.org2

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-26 02:12 --------- d-----w C:\Program Files\Java
2008-09-26 00:31 --------- d-----w C:\Program Files\Plaxo
2008-09-25 02:47 --------- d-----w C:\Documents and Settings\Mark\Application Data\MSGTAG
2008-09-25 02:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-21 02:37 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-09-17 17:59 20,252,664 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2008_09_17_13_51_36_full.dmp.zip
2008-09-17 17:54 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-16 05:03 --------- d-----w C:\Documents and Settings\Mark\Application Data\U3
2008-09-15 11:16 502,272 ----a-w C:\WINDOWS\system32\winlogon.exe
2008-09-15 11:16 295,424 ----a-w C:\WINDOWS\system32\termsrv.dll
2008-09-15 11:06 24,856,608 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-14 15:01 1,819,921 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-09-14 15:00 288,836 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-08-21 17:31 --------- d-----w C:\Program Files\Conduit
2008-08-21 17:31 --------- d-----w C:\Program Files\Answers.com
2008-08-21 17:31 --------- d-----w C:\Program Files\1-Click Answers
2008-08-20 00:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-15 01:49 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-12 00:54 --------- d-----w C:\Program Files\Apple Software Update
2008-08-03 23:35 --------- d-----w C:\Program Files\iPod
2008-08-03 22:59 --------- d-----w C:\Program Files\Bonjour
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-19 02:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-19 02:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 02:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-09 13:05 75,248 ----a-w C:\WINDOWS\zllsputility.exe
2008-07-09 13:05 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:32 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2007-12-31 02:09 846,504 -c--a-w C:\Documents and Settings\Mark\JNativeCpp.dll
2006-01-16 19:30 18,410 -c--a-w C:\Program Files\irunin.ini
2006-01-16 19:29 8,154 -c--a-w C:\Program Files\irunin.bmp
2006-01-16 19:29 26,267 -c--a-w C:\Program Files\irunin.dat
2006-01-16 19:29 15,938 -c--a-w C:\Program Files\irunin.lng
2002-10-19 21:00 606 -c-h--w C:\Documents and Settings\Mark\links.dat
2008-03-07 05:09 23 --sha-w C:\WINDOWS\system32\afafcf2_z.dll
.

------- Sigcheck -------

2004-05-26 21:38 483328 e7f9d2e4e4a94a6f58014e5ffa16a65e C:\WINDOWS\$hf_mig$\KB840987\SP1QFE\winlogon.exe
2004-05-26 21:38 483328 e7f9d2e4e4a94a6f58014e5ffa16a65e C:\WINDOWS\$hf_mig$\KB841533\SP1QFE\winlogon.exe
2004-08-04 00:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2008-09-15 07:16 502272 9b1bd82bd0761b5ba986af66d2809c30 C:\WINDOWS\system32\winlogon.exe
.
((((((((((((((((((((((((((((( snapshot@2008-09-24_22.38.44.57 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-09-02 20:57:27 391,184 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-09-26 00:28:57 390,384 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
- 2008-02-22 05:23:35 135,168 ----a-w C:\WINDOWS\system32\java.exe
+ 2008-06-10 05:21:01 135,168 ----a-w C:\WINDOWS\system32\java.exe
- 2008-02-22 05:23:39 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2008-06-10 05:21:04 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
- 2008-02-22 06:33:32 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2008-06-10 06:32:34 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2008-09-26 02:28:51 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_138.dat
+ 2008-09-26 02:29:06 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_4d0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0A94B116-4504-4e26-AB05-E61E474AA38B}"= "C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL" [2008-02-17 61440]
"{6341761b-babe-406d-b0d6-8d99b81c2ee5}"= "C:\Program Files\Answers.com\tbAnsw.dll" [2008-08-05 1610264]

[HKEY_CLASSES_ROOT\clsid\{0a94b116-4504-4e26-ab05-e61e474aa38b}]

[HKEY_CLASSES_ROOT\clsid\{6341761b-babe-406d-b0d6-8d99b81c2ee5}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6341761b-babe-406d-b0d6-8d99b81c2ee5}]
2008-08-05 02:13 1610264 --a------ C:\Program Files\Answers.com\tbAnsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{6341761b-babe-406d-b0d6-8d99b81c2ee5}"= "C:\Program Files\Answers.com\tbAnsw.dll" [2008-08-05 1610264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{6341761B-BABE-406D-B0D6-8D99B81C2EE5}"= "C:\Program Files\Answers.com\tbAnsw.dll" [2008-08-05 1610264]

[HKEY_CLASSES_ROOT\clsid\{6341761b-babe-406d-b0d6-8d99b81c2ee5}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Blue]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2008-06-13 23:19 527296 -ra------ C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2008-06-13 23:19 527296 -ra------ C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Blue]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2008-06-13 23:19 527296 -ra------ C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Red]
@="{01CCCC8C-1D50-4b13-B96D-4B922DD3128B}"
[HKEY_CLASSES_ROOT\CLSID\{01CCCC8C-1D50-4b13-B96D-4B922DD3128B}]
2008-06-13 23:19 527296 -ra------ C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2008-06-13 23:19 527296 -ra------ C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Clipomatic"="F:\Program Files\Clipomatic\Clipomatic.exe" [1999-05-15 65536]
"CursorXP"="F:\Program Files\CursorXP\CursorXP.exe" [2005-01-19 128000]
"MSGTAG"="F:\Program Files\MSGTAG Status\MSGTAGStatus.exe" [2007-07-10 1820160]
"PlaxoUpdate"="C:\Program Files\Plaxo\3.14.0.44\PlaxoHelper_en.exe" [2008-07-24 363591]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"Uniblue Quick Access"="F:\Program Files\Uniblue\ProcessLibrary\qaccess.exe" [2006-09-14 225280]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-01 68856]
"cdloader"="C:\Documents and Settings\Mark\Application Data\mjusbsp\cdloader2.exe" [2007-12-21 50520]
"Google Update"="C:\Documents and Settings\Mark\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-08-29 133104]
"Copernic Desktop Search 2"="F:\Program Files\Copernic Desktop Search\Copernic Desktop Search 2\DesktopSearchService.exe" [2008-03-03 1583624]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-07-13 160592]
"PlaxoSysTray"="C:\Program Files\Plaxo\3.14.0.44\PlaxoSysTray.exe" [2008-07-24 20480]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"FFTI"="C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\zvye194z.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\ffti.exe" [2007-03-30 2526784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GWMDMpi"="C:\WINDOWS\GWMDMpi.exe" [2001-10-31 40960]
"IMONTRAY"="F:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe" [2004-03-10 32768]
"MaxtorOneTouch"="F:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe" [2003-05-21 45056]
"MXO Auto Loader"="C:\WINDOWS\MXOALDR.EXE" [2003-04-07 118784]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2004-03-24 46080]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-03-24 3309568]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"zBrowser Launcher"="F:\Program Files\Logitech\iTouch\iTouch.exe" [2004-03-18 892928]
"ZoneAlarm Client"="F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"Carbonite Backup"="C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2008-06-13 600000]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040]
"QuickTime Task"="F:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="F:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2005-09-26 169984]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 C:\WINDOWS\LOGI_MWX.EXE]
"nwiz"="nwiz.exe" [2004-03-24 C:\WINDOWS\system32\nwiz.exe]
"GWMDMMSG"="GWMDMMSG.exe" [2001-10-31 C:\WINDOWS\GWMDMMSG.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 C:\WINDOWS\system32\narrator.exe]

C:\Documents and Settings\Janet\Start Menu\Programs\Startup\
Powermarks.lnk - F:\Program Files\Powermarks 3.5\pm.exe [2002-07-09 614400]

C:\Documents and Settings\Mark\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2002-09-17 113664]
AlarmApp.exe.lnk - F:\Program Files\Handspring\AlarmApp.exe [2005-09-19 274432]
Google Talk, Labs Edition.lnk - C:\Documents and Settings\Mark\Local Settings\Application Data\Google\Google Talk, Labs Edition\GoogleTalkLabsEdition.exe [2008-05-08 94704]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
1-Click Answers.lnk - C:\Program Files\1-Click Answers\answers.exe [2005-05-07 806912]
APC UPS Status.lnk - F:\Program Files\APC\APC PowerChute Personal Edition\Display.exe [2004-09-01 221247]
Audible Download Manager.lnk - C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe [2006-08-24 714344]
DataViz Inc Messenger.lnk - C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe [2006-01-15 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= ctwdm32.dll

[HKLM\~\startupfolder\C:^Documents and Settings^Mark^Start Menu^Programs^Startup^MailWasherPro.lnk]
path=C:\Documents and Settings\Mark\Start Menu\Programs\Startup\MailWasherPro.lnk
backup=C:\WINDOWS\pss\MailWasherPro.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Mark^Start Menu^Programs^Startup^RTM Tool.lnk]
path=C:\Documents and Settings\Mark\Start Menu\Programs\Startup\RTM Tool.lnk
backup=C:\WINDOWS\pss\RTM Tool.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gcasServ

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-08-18 18:41 1832272 F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a--c--- 2006-12-11 10:53 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"Skype"="F:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
"StartGuard"=f:\program files\interapple\@start\StartGuard.exe
"Spyware Doctor"=F:\PROGRA~1\SPYWAR~2\swdoctor.exe /Q

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="F:\program files\QuickTime\qttask.exe" -atboottime
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
"iTunesHelper"=f:\program files\itunes\ituneshelper.exe
"bxAutoZipOE"=C:\Program Files\Common Files\BAxBEx\bxOE\bxOEPluginAR.exe
"Microsoft Works Portfolio"=C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
"Microsoft Works Update Detection"=C:\Program Files\Microsoft Works\WkDetect.exe
"WinPatrol"="f:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe"
"WorksFUD"=C:\Program Files\Microsoft Works\wkfud.exe
"zBrowser Launcher"=C:\Program Files\Logitech\iTouch\iTouch.exe
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"UpdReg"=C:\WINDOWS\Updreg.exe
"SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"F:\\Program Files\\Trillian\\trillian.exe"=
"F:\\Program Files\\Handspring\\Hotsync.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"F:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\IEPro\\MiniDM.exe"=
"F:\\Program Files\\IEPro\\MiniDM.exe"=
"C:\\Documents and Settings\\Mark\\Local Settings\\Application Data\\Google\\Google Talk, Labs Edition\\GoogleTalkLabsEdition.exe"=
"C:\\Documents and Settings\\Mark\\Application Data\\mjusbsp\\magicJack.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"F:\\Program Files\\iTunes\\iTunes.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 ousbehci;NEC PCI to USB Enhanced Host Controller;C:\WINDOWS\system32\Drivers\ousbehci.sys [2002-04-01 29696]
R3 ousb2hub;OrangeWare USB 2.0 Hub Support;C:\WINDOWS\system32\DRIVERS\ousb2hub.sys [2002-04-01 43648]
S3 hwi4857;Duo Digital Media Player;C:\WINDOWS\system32\Drivers\hwi4857.sys [2001-12-20 10532]
S3 Otis;Audible Otis Service;C:\WINDOWS\system32\Drivers\OtisPlay.sys [2003-07-14 9472]
S3 PortRst;BaromTec HMS30C6001 Reset Driver;C:\WINDOWS\system32\DRIVERS\PortRst.sys [2001-08-06 12721]
S3 ptiusbf;PTI USB Filter;C:\WINDOWS\system32\DRIVERS\PTIUSBF.SYS [2001-04-14 22474]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
\Shell\AutoRun\command - L:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b90788bc-220e-11dc-acd6-0016b6977199}]
\Shell\AutoRun\command - L:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{da20412e-b688-11dc-a39a-0016b6977199}]
\Shell\AutoRun\command - L:\autorun.exe
\Shell\phone\command - L:\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{da204130-b688-11dc-a39a-0016b6977199}]
\Shell\AutoRun\command - M:\magicJack\autorun.exe
\Shell\phone\command - M:\magicJack\autorun.exe
.
Contents of the 'Scheduled Tasks' folder
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-25 22:31:10
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\C:\WINDOWS\TEMP\mc21.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> F:\Program Files\TuneUp Utilities 2006\WinStylerThemeHelper.dll

PROCESS: C:\WINDOWS\system32\lsass.exe
-> F:\Program Files\TuneUp Utilities 2006\WinStylerThemeHelper.dll

PROCESS: C:\WINDOWS\explorer.exe
-> F:\Program Files\TuneUp Utilities 2006\WinStylerThemeHelper.dll

PROCESS: C:\WINDOWS\system32\csrss.exe
-> F:\Program Files\TuneUp Utilities 2006\WinStylerThemeHelper.dll
.
------------------------ Other Running Processes ------------------------
.
F:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
F:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
F:\Program Files\Alwil Software\Avast4\ashServ.exe
F:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe
F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
F:\Program Files\FolderSize\FolderSizeSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\UTSCSI.EXE
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GSv2.exe
F:\Program Files\Intel\Intel(R) Active Monitor\imonNT.exe
F:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
F:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\devldr32.exe
F:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE
C:\Program Files\iPod\bin\iPodService.exe
F:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\PROGRA~1\1-CLIC~1\agtserv.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-09-25 22:39:34 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-26 02:39:19
ComboFix2.txt 2008-09-25 02:40:31

Pre-Run: 166,264,832 bytes free
Post-Run: 146,710,528 bytes free

311 --- E O F --- 2008-09-14 14:19:02


I'll be back with the other logs shortly.

Mark

ATHiker95
2008-09-26, 18:50
Here is the copy of the full scan with Kaspersky:
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Friday, September 26, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Friday, September 26, 2008 04:32:43
Records in database: 1262259
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\

Scan statistics:
Files scanned: 278725
Threat name: 9
Infected objects: 10
Suspicious objects: 9
Duration of the scan: 09:01:51


File name / Threat name / Threats count
C:\Documents and Settings\Mark\Application Data\Opera\Opera\Mail\store\account5\2007\01\18\63.mbs Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\lphctnfj0eefl.exe.vir Infected: Backdoor.Win32.Frauder.fk 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\tdssadw.dll.vir Infected: Rootkit.Win32.Clbd.jy 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\tdssl.dll.vir Infected: Backdoor.Win32.UltimateDefender.gen 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\tdsslog.dll.vir Infected: Backdoor.Win32.Agent.rfv 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\tdssmain.dll.vir Infected: Backdoor.Win32.Agent.rfw 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\tdssserf.dll.vir Infected: Trojan-Downloader.Win32.FraudLoad.vbxt 1
G:\Mark's Documents\My Outlook Express Messages\Inbox.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 1
G:\Mark's Documents\My Outlook Express Messages\Inbox.dbx Infected: Trojan-Spy.HTML.Bankfraud.cw 1
G:\Mark's Documents\My Outlook Express Messages\PayPal Receipts,etc.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 2
G:\Mark's Documents\My Outlook Express Messages\PayPal Receipts,etc.dbx Infected: Trojan-Spy.HTML.Paylap.hs 1
G:\Mark's Documents\Thunderbird Mail Profile\gdlqv9rl.default\Mail\Local Folders\Junk Suspicious: Trojan-Spy.HTML.Fraud.gen 1
K:\Backup of G Folder after Virus Infection 9-15-08\Critical Data (G)\Mark's Documents\My Outlook Express Messages\Inbox.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 1
K:\Backup of G Folder after Virus Infection 9-15-08\Critical Data (G)\Mark's Documents\My Outlook Express Messages\Inbox.dbx Infected: Trojan-Spy.HTML.Bankfraud.cw 1
K:\Backup of G Folder after Virus Infection 9-15-08\Critical Data (G)\Mark's Documents\My Outlook Express Messages\PayPal Receipts,etc.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 2
K:\Backup of G Folder after Virus Infection 9-15-08\Critical Data (G)\Mark's Documents\My Outlook Express Messages\PayPal Receipts,etc.dbx Infected: Trojan-Spy.HTML.Paylap.hs 1
K:\Backup of G Folder after Virus Infection 9-15-08\Critical Data (G)\Mark's Documents\Thunderbird Mail Profile\gdlqv9rl.default\Mail\Local Folders\Junk Suspicious: Trojan-Spy.HTML.Fraud.gen 1

The selected area was scanned.


Just so you know - K: is my external backup drive where I was trying to back up my data before attempting all the fixes we have been doing. Will wait for you to tell me about above issues before submitting another HiJack log.

Thanks again!
Mark

Blade81
2008-09-26, 18:56
I know you can't delete individual restore points - so realize if I turn system restore off and then back on, i will wipe out all restore points including the combofix one that it initially set. The system is definitely better than it was before, so I wondering if that would be so bad to do? Perhaps turn them off and then reduce the amount of space system restore is set for (12% in this case which is about 800mb - perhaps knock it back to 8%?) and then turn it back on?
Hi

I recommend you keep free space available so that system restore (the smallest percentage is better than no system restore enabled at all) can be enabled. You might want to purchase external hard drive to store things if your internal hard drive doesn't have enough space to store all your contents.


Delete C:\Documents and Settings\Mark\Application Data\Opera\Opera\Mail\store\account5\2007\01\18\63.mbs file

Then delete all suspicious emails thru Outlook Express. After that it's recommended to delete those backups Kaspersky found on K: drive.

After above things are done please post a fresh hjt log and tell how the system is running.

ATHiker95
2008-09-27, 02:46
attached is latest Hijack log. Computer seems to be running well. Will wait to see what you have to say about this latest log. Would also be interested in your opinions on anti-spyware,virus,malware programs, should you wish to share. I'm a bit puzzled why Avast caught none of this, Zone Alarm didn't help much and Spybot didn't seem to find much of this stuff either. Is Kaspersky the way to go? Spyware Doctor 6.0? Bit Defender? I read reviews of all of these and all are rated differently based on the reviewer, which doesn't help a whole lot.

In the log below, I notice ctfmon.exe running - is that spyware? Also what is AskpBar?

Thanks for all the help you're providing. You're saving me!
Mark

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:35:38 PM, on 9/26/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
F:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
F:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
F:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
F:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
F:\Program Files\FolderSize\FolderSizeSvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UTSCSI.EXE
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GSv2.exe
F:\Program Files\Intel\Intel(R) Active Monitor\imonnt.exe
F:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
F:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
F:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe
C:\WINDOWS\system32\devldr32.exe
F:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\WINDOWS\MXOALDR.EXE
C:\WINDOWS\GWMDMMSG.exe
F:\Program Files\Logitech\MouseWare\system\em_exec.exe
F:\Program Files\Logitech\iTouch\iTouch.exe
F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
F:\program files\QuickTime\qttask.exe
F:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
F:\Program Files\Clipomatic\Clipomatic.exe
F:\Program Files\CursorXP\CursorXP.exe
C:\WINDOWS\system32\ctfmon.exe
F:\Program Files\MSGTAG Status\MSGTAGStatus.exe
C:\Program Files\Plaxo\3.14.0.44\PlaxoHelper_en.exe
F:\Program Files\Uniblue\ProcessLibrary\qaccess.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\Mark\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\1-Click Answers\answers.exe
C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
F:\Program Files\Handspring\AlarmApp.exe
F:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\PROGRA~1\1-CLIC~1\agtserv.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
F:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Mark\Local Settings\temp\jkos-Mark\binaries\ScanningProcess.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Mark\Desktop\HiJackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
R3 - URLSearchHook: Answers.com Toolbar - {6341761b-babe-406d-b0d6-8d99b81c2ee5} - C:\Program Files\Answers.com\tbAnsw.dll
O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - F:\Program Files\IEPro\iepro.dll
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - F:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Ask Search Assistant BHO - {0A94B111-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
O2 - BHO: bxNewFolder - {51C8BCA8-2524-4523-BF09-738C4EEBFC58} - F:\PROGRA~1\BXNEWF~1\BXNEWF~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - F:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll (file missing)
O2 - BHO: Powermarks - {6172E460-FAE3-11D2-B494-004005A47AAA} - F:\PROGRA~1\POWERM~1.5\iec.dll
O2 - BHO: Answers.com Toolbar - {6341761b-babe-406d-b0d6-8d99b81c2ee5} - C:\Program Files\Answers.com\tbAnsw.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
O2 - BHO: InlineSearchHandleHotKey - {B6FFE2AE-4D12-451F-B457-FE6125FFB1CF} - F:\Program Files\IEForge\Inline Search\InlineSearch.dll
O2 - BHO: (no name) - {BBE59AF5-EE22-4A3A-AB26-3F774D1B4216} - F:\PROGRA~1\FOLDER~1\FOLDER~1.DLL
O2 - BHO: &Google Notebook - {CCCCCCD3-666F-4F81-8B69-745DE9F6D897} - C:\Program Files\Google\Google Notebook\gnotes1.0.2.19-1093068710.dll
O2 - BHO: PicLens plug-in for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\PicLens.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O3 - Toolbar: Answers.com Toolbar - {6341761b-babe-406d-b0d6-8d99b81c2ee5} - C:\Program Files\Answers.com\tbAnsw.dll
O4 - HKLM\..\Run: [GWMDMpi] C:\WINDOWS\GWMDMpi.exe
O4 - HKLM\..\Run: [IMONTRAY] F:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MaxtorOneTouch] F:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [zBrowser Launcher] F:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "F:\program files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [Clipomatic] F:\Program Files\Clipomatic\Clipomatic.exe
O4 - HKCU\..\Run: [CursorXP] F:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [MSGTAG] "F:\Program Files\MSGTAG Status\MSGTAGStatus.exe" /startup
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\3.14.0.44\PlaxoHelper_en.exe -a
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue Quick Access] "F:\Program Files\Uniblue\ProcessLibrary\qaccess.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Mark\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Mark\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Copernic Desktop Search 2] "F:\Program Files\Copernic Desktop Search\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [PlaxoSysTray] C:\Program Files\Plaxo\3.14.0.44\PlaxoSysTray.exe
O4 - HKCU\..\RunOnce: [FFTI] C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles\zvye194z.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\ffti.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /DestPath="C:\Documents and Settings\Mark\Application Data\Mozilla\Firefox\Profiles/zvye194z.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: AlarmApp.exe.lnk = F:\Program Files\Handspring\AlarmApp.exe
O4 - Startup: Google Talk, Labs Edition.lnk = C:\Documents and Settings\Mark\Local Settings\Application Data\Google\Google Talk, Labs Edition\GoogleTalkLabsEdition.exe
O4 - Global Startup: 1-Click Answers.lnk = C:\Program Files\1-Click Answers\answers.exe
O4 - Global Startup: APC UPS Status.lnk = F:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
O4 - Global Startup: Audible Download Manager.lnk = C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O8 - Extra context menu item: Answers... - file://C:\Program Files\1-Click Answers\Html\atiemenu.htm
O8 - Extra context menu item: Call 3d Traceroute - res://C:\WINDOWS\d3triehelper.exe/HTML.HTA
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://F:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://F:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://F:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Note this (Google Notebook) - res://C:\Program Files\Google\Google Notebook\gnotes1.0.2.19-1093068710.dll/gn_menu1.html
O8 - Extra context menu item: Note this item (Google Notebook) - res://C:\Program Files\Google\Google Notebook\gnotes1.0.2.19-1093068710.dll/gn_menu2.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - F:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - F:\Program Files\IEPro\iepro.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Internet Radio by Endicosoft.com - {1F958B09-3312-7f0e-9723-4C1324C57B20} - F:\Program Files\Internet Radio\Radio.exe
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: FireShot menu - {A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - F:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - F:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.bestbuy.msn.com
O16 - DPF: ChatSpace Full Java Client 2.1.0.84 - http://about.chatspace.com/Java/cs4fs084.cab
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
O16 - DPF: Yahoo! Chat - http://cs5.chat.sc5.yahoo.com/c381/chat.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20020713/qtinstall.info.apple.com/samantha/us/win/QuickTimeInstaller.exe
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
O16 - DPF: {51045741-8C4E-4EAC-8F03-08E43A6FBB29} - http://aft.ancestry.com/aftfiles/files/install/AncestryFamilyTree.cab
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/en/deleon/1.1.57-deleon/GoogleNav.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1163259859265
O16 - DPF: {8CE3BAE6-AB66-40B6-9019-41E5282FF1E2} (QuickBooks Online Edition Utilities Class v8) - https://accounting.quickbooks.com/c5/v14.223/qboax8.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {A57B79D8-9501-42B7-BA9B-B961454712F2} (WLANinfo.WLANX) - https://www.jiwire.com/activeX/wlaninfo.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/53/install/gtdownls.cab
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O18 - Protocol: asksam - {F9FF9EDA-4916-11D1-B6C1-002018305A61} - F:\Program Files\askSam\SurfSaver\AS_AIPP.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - F:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - F:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - F:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - F:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - F:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CarboniteService - Carbonite, Inc. (www.carbonite.com) - C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
O23 - Service: Diskeeper - Diskeeper Corporation - F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Folder Size (FolderSize) - Brio - F:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel(R) Active Monitor (imonNT) - Intel Corp. - F:\Program Files\Intel\Intel(R) Active Monitor\imonnt.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Retrospect Helper - Dantz Development Corporation - F:\Program Files\Dantz\Retrospect\rthlpsvc.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - F:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
O23 - Service: CLCV0 (UTSCSI) - Unknown owner - C:\WINDOWS\system32\UTSCSI.EXE
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WUSB54GSv2SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
O24 - Desktop Component 1: MSNBC Weather - HTTP://www.msnbc.com/modules/weather/ie4weather.htm

--
End of file - 19770 bytes

ATHiker95
2008-09-27, 07:13
In addition to the hijack log above, I updated my virus definitions in Avast and ran a full scan on my C: drive. It found 8 issues - 7 of which were in C:\Qoobox\Quarantine\C\Windows\system 32. Avast set off an alarm for all of those and offered to move them to the Avast Chest. I assumed these were ok to ignore as I figured ComboFix put them in this particular directory and they are safe? I just clicked continue and didn't move them to Avast's Chest. One that was left still hanging around was the one in C:\Windows\Internet logs (the last one below). I moved it to Avast's Chest. The log of found issues is below: My question is - is it better to delete these from the Quarantine folder and from Avast's Chest rather than having them sitting around or is there danger in attempting to delete these type of files? It is annoying when you go to bed running a full scan in Avast only to find that it has stopped because it has seen one of these bad files, even though it is in a Quarantine folder.

Thanks again!

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AzeSearch.zip\sbRecovery.reg [E] Archive is password protected. (42056)
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AzeSearch.zip\sbRecovery.ini [E] Archive is password protected. (42056)
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSvchost.zip\sbRecovery.reg [E] Archive is password protected. (42056)
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSvchost.zip\sbRecovery.ini [E] Archive is password protected. (42056)
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSvchost1.zip\svchost.exe [E] Archive is password protected. (42056)
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSvchost1.zip\sbRecovery.ini [E] Archive is password protected. (42056)
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\COSMI.zip\sbRecovery.reg [E] Archive is password protected. (42056)
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\COSMI.zip\sbRecovery.ini [E] Archive is password protected. (42056)
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\COSMI1.zip\sbRecovery.reg [E] Archive is password protected. (42056)
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\COSMI1.zip\sbRecovery.ini [E] Archive is password protected. (42056)
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\COSMI2.zip\sbRecovery.reg [E] Archive is password protected. (42056)
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\COSMI2.zip\sbRecovery.ini [E] Archive is password protected. (42056)
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\COSMI3.zip\sbRecovery.reg [E] Archive is password protected. (42056)
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\COSMI3.zip\sbRecovery.ini [E] Archive is password protected. (42056)
C:\Qoobox\Quarantine\C\WINDOWS\system32\blphctnfj0eefl.scr.vir [L] Win32:Trojan-gen {Other} (0)
C:\Qoobox\Quarantine\C\WINDOWS\system32\lphctnfj0eefl.exe.vir [L] Win32:Frauder-E [Trj] (0)
C:\Qoobox\Quarantine\C\WINDOWS\system32\tdssadw.dll.vir [L] Win32:Bravix-B [Drp] (0)
C:\Qoobox\Quarantine\C\WINDOWS\system32\tdssl.dll.vir [L] Win32:Bravix-B [Drp] (0)
C:\Qoobox\Quarantine\C\WINDOWS\system32\tdsslog.dll.vir [L] Win32:Bravix [Drp] (0)
C:\Qoobox\Quarantine\C\WINDOWS\system32\tdssmain.dll.vir [L] Win32:Bravix [Drp] (0)
C:\Qoobox\Quarantine\C\WINDOWS\system32\tdssserf.dll.vir [L] Win32:Bravix [Drp] (0)
C:\WINDOWS\Internet Logs\vsmon_on_demand_2008_09_17_13_51_36_full.dmp.zip\vsmon_on_demand_2008_09_17_13_51_36_full.dmp [L] Win32:DNSChanger-VJ [Trj] (0)
File was successfully moved to chest...

ATHiker95
2008-09-27, 08:11
I am having one rather strange problem . My C: drive just keeps shrinking - i look in C:\system volume information and under the hidden restore folder, I have a folder called RP7 - in that folder are lots of .rdb files, each 1624kb in size and appearing every few minutes, with the end result that my c: drive has now dropped under 100mb and is continuing to drop. The type of file is called a Retrospect Disk Backup Set (I have that program on this computer, but haven't used it in ages). Any idea what is happening?

I checked system restore - I have only 1 checkpoint which is a system checkpoint from 9/26.

Blade81
2008-09-27, 13:51
I'm a bit puzzled why Avast caught none of this, Zone Alarm didn't help much and Spybot didn't seem to find much of this stuff either. Is Kaspersky the way to go? Spyware Doctor 6.0? Bit Defender? I read reviews of all of these and all are rated differently based on the reviewer, which doesn't help a whole lot.

Hi

The truth is that there isn't universal antivirus program that would detect all possible threats. Some other antivirus might had caught the infection that Avast didn't see but Avast might catch something that some other antivirus program doesn't detect. In my opinion Avast is very good program.


I notice ctfmon.exe running - is that spyware? Also what is AskpBar?
C:\WINDOWS\system32\ctfmon.exe is Windows own process and completely legal one. AskpBar you've probably installed with Zonealarm. You may try to uninstall it thru add/remove programs.


My question is - is it better to delete these from the Quarantine folder and from Avast's Chest rather than having them sitting around or is there danger in attempting to delete these type of files?
It's not dangerous to move those in the Avast's chest. However, you may clear those in Spybot's recovery thru Spybot as well. ComboFix quarantine items will be cleared by uninstallation of ComboFix. Instructions for that below.


Well congrats, it appears your system is all clean Are you still noticing any problems? If not, it's time to secure your system to prevent against further intrusions.


THESE STEPS ARE VERY IMPORTANT

Let's reset system restore
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points.

1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.
NOTE: only do this ONCE,NOT on a regular basis



Now lets uninstall ComboFix:

Click START then RUN
Now type Combofix /u in the runbox and click OK



UPDATING WINDOWS AND INTERNET EXPLORER

IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site (http://windowsupdate.microsoft.com/) to get the critical updates.

If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.


Make your Internet Explorer more secure

This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.



The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.


Download SpywareBlaster
Spyware blaster is a program that stops known malicious activex controls from installing on your computer. It works by changing settings in your registry. It makes
kill bits
in the registry, so that certain activex controls can't install.
If you don't know what activex controls are, see here (http://www.webopedia.com/TERM/A/ActiveX_control.html)
You can download SpywareBlaster here here (http://majorgeeks.com/downloadget.php?id=2859&file=11&evp=61b0e8ad41924a03c37615f4682b4cef)
SpywareBlaster tutorial (http://www.bleepingcomputer.com/forums/tutorial49.html)


hosts file:
Every version of windows has a hosts file as part of them. In a very basic sense, they are used to locate webpages. We can customize a hosts file so that it blocks certain webpages. However, it can slow down certain computers. This is why using a hosts file is optional!!
Download it here (http://www.mvps.org/winhelp2002/hosts.htm). Make sure you read the instructions on how to install the hosts file. There is a good tutorial here (http://www.bleepingcomputer.com/forums/tutorial51.html)
If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
Click the start button (at the lower left hand corner of your screen) Click run In the dialog box, type services.msc hit enter, then locate dns client Highlight it, then double-click it. On the dropdown box, change the setting from automatic to manual. Click ok



Just a final reminder for you. I am trying to stress these two points.
UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
Make sure all of your security programs are up to date.
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.



Once again, please post and tell me how things are going with your system... problems etc.

Have a great day,
Blade :cool:

ATHiker95
2008-09-27, 16:20
Blade,
Thanks so much for the help. I think once I get the System Restore thing worked out - I'll be ok. I don't know if you noticed my comment about these 1624kb .rdb files appearing every 5 minutes in c:\system volume information. In doing a bit of searching I stumbled across this thread - http://forum.zonelabs.org/zonelabs/board/message?board.id=gen&message.id=45374. If I don't fix this problem quickly, my c: drive will go straight to 0.

This seems to be what is happening to me. I'm wondering, if in addition to resetting System Restore, if maybe I should uninstall Zone Alarm as well and download a new version? Or find a different firewall such as Comodo? (http://www.personalfirewall.comodo.com/overview.html)

Thanks,
Mark

Blade81
2008-09-27, 16:27
Hi

Yes, you may uninstall ZA and get the latest version or then replace ZA with some other firewall (like you said with Comodo for example). For firewall I recommend either Online Armor Free (http://www.tallemu.com/free-firewall-protection-software.html) or Comodo Firewall Pro (http://download.comodo.com/cfp/download/setups/CFP_Setup_3.0.25.378_XP_Vista_x32.exe) (don't install SurfSafe toolbar if you choose Comodo).

ATHiker95
2008-09-28, 03:19
Blade,
So far so good - did everything you told me. Got my C: drive back up to about 580mb . Uninstalled Zone Alarm and installed Online Armor Free. It may have saved me already. I decided to uninstall Spybot and install a new version. I right clicked and uninstalled it in Start/Programs. I then looked in Add/Remove programs and noticed that it was gone, but one other small version of Spybot Search and Destroy 1.52 claiming to occupy 2MB was still there, albeit with the wrong icon. I started to uninstall it through Add/Remove but when I clicked on it to remove it, Online Armor popped up asking me if I wanted to run c:\Windows\unins000.exe Since I didn't recognize that and thought it looked a bit strange, I blocked it and then went and uploaded that file to VirusTotal where two of the scanning engines (GData and Ikarus) thought it was Trojan-Downloader.Win32.Agent.vur. What would you do in this case? (I also noticed that there was a unins000.dat file as well, which I also uploaded to VirusTotal, but nothing was found on that one).

Other than that, so far so good, me thinks. I updated my Spyware Blaster and things seem to be running better. This has been quite an informative event, to say the least.

Thanks once again - you don't know how much!
Mark

Blade81
2008-09-28, 12:20
Hi

Those findings are most likely false positives. I'd let c:\Windows\unins000.exe run :)

ATHiker95
2008-09-28, 16:52
I selected to do so, but once I clicked on it, Online Armor popped up a red box that said it was trying to access _iu14D2n.tmp in C:\Docs and Settings\Mark\Local Settings\temp and that this tmp file contained the same content as unins000.exe. Said the program was suspicious and that I should take extreme care. It recommended that I block it. It said that it would be unusual for a program to use this trick, unless it is an auto-update program or an installer. I uploaded that .tmp file to VirusTotal and it analyzed it as if it were unins000.exe. You think this little program in Add/Remove is some sort of auto-update or installer? Rather strange that this is associated with a Spybot uninstall routine (actually the right click in Start/Programs to uninstall Spybot didn't touch this thing and the fact that it has the icon for my Copernic Search program,rather than Spybot is a bit strange - isn't it true that Add/Remove can sometimes turn a bit goofy?

As you can see, I have now joined the ranks of the truly paranoid. :)

Thanks,
Mark

Blade81
2008-09-28, 18:16
You think this little program in Add/Remove is some sort of auto-update or installer?
Hi

That's uninstaller and completely safe to let run :)

ATHiker95
2008-09-28, 18:25
ok, I allow that one .

I downloaded SuperAntiSpyware to see what it produced while scanning my C: Drive. Below is the log. I uploaded that curl.exe file, which it was claiming was a Trojan.Dropper.gen - VirusTotal didn't find a thing. I suspect if I quarantine it, that program won't run, so best to ignore? I submitted a possible False Positive report to Super Antispyware.

Also - not sure about the two desktop wallpaper items in the registry - what would you do with those?

Sorry to keep pestering you, but I do want to make sure this thing is truly cleaned out (if that is ever possible).

Thanks again,
Mark
(I deleted all the tracking cookies from the report listed below as there were 100+ and didn't serve any purpose here)

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/28/2008 at 11:04 AM

Application Version : 4.21.1004

Core Rules Database Version : 3581
Trace Rules Database Version: 1569

Scan type : Complete Scan
Total Scan Time : 00:48:37

Memory items scanned : 498
Memory threats detected : 0
Registry items scanned : 6533
Registry threats detected : 4
File items scanned : 17953
File threats detected : 114

Adware.ZToolbar
HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\{A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB}
HKLM\Software\Microsoft\Internet Explorer\Extensions\{A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB}


Trojan.FakeAlert/Desktop
HKU\S-1-5-21-2911765694-1194005503-2939561921-1008\CONTROL PANEL\DESKTOP#CONVERTEDWALLPAPER
HKU\S-1-5-21-2911765694-1194005503-2939561921-1008\CONTROL PANEL\DESKTOP#ORIGINALWALLPAPER

Trojan.Dropper/Gen
C:\DOCUMENTS AND SETTINGS\MARK\LOCAL SETTINGS\APPLICATION DATA\YAHOO\WIDGET ENGINE\WIDGET DATA\ITUNES COMPANION\CURL.EXE

Blade81
2008-09-28, 18:32
I downloaded SuperAntiSpyware to see what it produced while scanning my C: Drive. Below is the log. I uploaded that curl.exe file, which it was claiming was a Trojan.Dropper.gen - VirusTotal didn't find a thing. I suspect if I quarantine it, that program won't run, so best to ignore? I submitted a possible False Positive report to Super Antispyware.
Yes, seems to be a false positive.


Also - not sure about the two desktop wallpaper items in the registry - what would you do with those?
Let SuperAntiSpyware fix those.


Sorry to keep pestering you, but I do want to make sure this thing is truly cleaned out (if that is ever possible).
You're not pestering me :)

ATHiker95
2008-09-28, 22:34
Blade,
Just one more question before I think I'm finally done. Do you have an opinion on running Registry Cleaners? I use jvPowerTools16 2008 and just did a registry scan - which found quite a few errors. I've used this in the past to clean up the registry without issues, but wondered after all we went through to clean up my machine, whether this was a safe process (naturally, I would create a backup of the registry before proceeding).

Thanks!
Mark

Blade81
2008-09-28, 23:07
Hi Mark,

I don't personally recommend using any registry cleaners. Those can easily cause damage if used wrongly.

ATHiker95
2008-09-29, 04:59
Blade,
No doubt good advice. I've run it in the past and have been lucky, but as even jvPowerTools16 says in its manual - this is an Axe, so wield it carefully!

I'm good to go on this end - thanks once again for all your help and saving me for another day! I'll pass along the good word.

Mark

Blade81
2008-09-29, 07:23
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help. :)

Note:If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send me or MOD a private message (pm). A valid, working link to the closed topic is required.