PDA

View Full Version : Spyware/Virus Removal help pls: Yihazuso.dll removal (?)



gorzul
2009-01-28, 09:33
Hi,

I tend to write way toooo much...so I'll try to keep it short and simple. Anything you need/want to know just ask.

Original scenario:
- working before going to work.
- came back: unable to do anything on pc (30 - 45 mins just for user names to come up) and certainly couldn't do anything online.

Steps taken:
- removed hdd, installed as slave on another pc
- ran antispyware and antivirus software
- reinstalled hdd as master
- ran HJT 1.99 -> carefully/selectivly used "Fix checked" button on items I could not identify after extensive research (line by line, file by file online and cross-referencing programs installed & files in install locations)

Current status:
- Bootup: prior to users listed and up until initial startup complete -> all exe (and dll's?) produce error as below:

<filename> - Bad Image.
The application or DLL C:\WINDOWS\system32\yihazuso.dll is not a valid Windows image. Please check this against your installation diskette. <OK button>

- the programs still run despite message
- I can find no yhiazuso.dll file anywhere
- I have installed AVG, SUPERAntispysweeper, Malwarebytes' Anti-Malware
- I have run BitDefender and Housecall online
- System is cleaned every night now...before found 100's of infections, now nightly 20 or less...but they can't seem to be cleaned properly.
- after 15 - 30 mins internet usage...no internet functionaly (no browser, no email client, chat client, ping, etc)
- after longer times, max 5 (approx) tasks at once can be done (not due to speed)...eg. can't open My Computer if too many windows open (4?).

Here's the HJT log requested. I'll answer any questions you have (I do have logs of HJT before/after scans & changes). Please help:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:45:53 AM, on 1/28/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\PrevxCSI\prevxcsi.exe
E:\Nero Ultra 8.3.2.1\Nero\Nero8\InCD\InCDsrv.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
F:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
E:\Nero Ultra 8.3.2.1\Nero\Nero8\Nero BackItUp\NBService.exe
E:\Nero Ultra 8.3.2.1\Nero\Nero8\InCD\NBHRegInCDSrv.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
F:\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe
C:\Program Files\PrevxCSI\prevxcsi.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\WINDOWS\system32\RUNDLL32.EXE
E:\Nero Ultra 8.3.2.1\Nero\Nero8\InCD\NBHGui.exe
E:\Nero Ultra 8.3.2.1\Nero\Nero8\InCD\InCD.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\V0420Mon.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
D:\CyberLink\PowerDVD\PDVDServ.exe
E:\PowerISO\PWRISOVM.EXE
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\713xRMT.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
F:\Cyberlink\Multimedia Launcher\PowerBar.exe
C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
C:\Program Files\Creative\Shared Files\CTSched.exe
C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\PROGRA~1\MICROS~4\wcescomm.exe
C:\Program Files\LG Soft India\forteManager\bin\Monitor.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
C:\Program Files\Common Files\Symantec Shared\SecurityStatusSDK\SSDK02.exe
C:\Program Files\TV Expert\ADTVScheduleAgent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://teamtutorials.com/windows-tutorials-retrieving-xp-key-from-the-registry
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {A3DB05B0-5655-47E0-B547-0E59B0AFF584} - C:\WINDOWS\system32\geBrpnLb.dll (file missing)
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] E:\Nero Ultra 8.3.2.1\Nero\Nero8\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] E:\Nero Ultra 8.3.2.1\Nero\Nero8\InCD\InCD.exe
O4 - HKLM\..\Run: [NBKeyScan] "E:\Nero Ultra 8.3.2.1\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [V0420Mon.exe] C:\WINDOWS\V0420Mon.exe
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [RemoteControl] D:\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] E:\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [LanguageShortcut] D:\CyberLink\PowerDVD\Language\Language.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [TV Card Remote Control Device Monitor] C:\WINDOWS\713xRMT.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PowerBar] "F:\Cyberlink\Multimedia Launcher\PowerBar.exe" /AtBootTime
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CreativeTaskScheduler] "C:\Program Files\Creative\Shared Files\CTSched.exe" /logon
O4 - HKCU\..\Run: [Creative Live! Cam Manager] "C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MICROS~4\wcescomm.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [_Sym_MI_] "C:\Program Files\SAV\SAVSetup\setup.exe" /qn /z /nosp (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [_Sym_MI_] "C:\Program Files\SAV\SAVSetup\setup.exe" /qn /z /nosp (User 'Default user')
O4 - S-1-5-18 Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: forteManager.lnk = ?
O4 - Global Startup: PC Alert 4.lnk = C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
O4 - Global Startup: TV Expert Schedule Agent.lnk = C:\Program Files\TV Expert\ADTVScheduleAgent.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: Rogers Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: rwbihq.dll,jwgcxd.dll,C:\WINDOWS\system32\yihazuso.dll,wddpyd.dll,vhhmah.dll,zdzwqx.dll,llhkat.dll,extawj.dll,avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: yayaAsTm - yayaAsTm.dll (file missing)
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: CSIScanner - Prevx - C:\Program Files\PrevxCSI\prevxcsi.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - E:\Nero Ultra 8.3.2.1\Nero\Nero8\InCD\InCDsrv.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - E:\Nero Ultra 8.3.2.1\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Nero AG - E:\Nero Ultra 8.3.2.1\Nero\Nero8\InCD\NBHRegInCDSrv.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - F:\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

--
End of file - 14685 bytes

peku006
2009-01-30, 17:39
Hello and welcome to Safer Networking.

My name is peku006 and I will be helping you to remove any infection(s) that you may have.
I will be giving you a series of instructions that need to be followed in the order in which I give them to you.

Please observe these rules while we work:

If you don't know, stop and ask! Don't keep going on.
Please reply to this thread. Do not start a new topic.
Please continue to respond until I give you the "All Clear"

If you follow these instructions, everything should go smoothly.

1 - Scan With ComboFix

We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

How to Temporarily Disable Anti-virus (http://www.bleepingcomputer.com/forums/topic114351.html)

Please include the C:\ComboFix.txt in your next reply for further review.

2 - Run Hijackthis
Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad

3 - Status Check
Please reply with


1. the ComboFix log(C:\ComboFix.txt)
2. a fresh HijackThis log

Thanks peku006

gorzul
2009-02-02, 09:27
Hi Peku...

...and just like that my stress is removed? :eek: :) :bigthumb: :D:


I got a sigh of relief when I saw combofix had a line that said deleting C:\Windows\System32\yihazuso.dll ...the file I kept searching for there (even in hidden files) and could not find to delete.

Here's the requested C:\ComboFix.txt and updated HJT logs:

ComboFix 09-02-01.01 - Carlos 2009-02-02 2:08:47.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3071.2435 [GMT -5:00]
Running from: e:\bit torrent\Finished Downloads\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\SAV
c:\program files\SAV\_ISNAVNT.ULG
c:\program files\SAV\clt-inst\Webinst\brnotsup.htm
c:\program files\SAV\clt-inst\Webinst\default.htm
c:\program files\SAV\clt-inst\Webinst\intro.htm
c:\program files\SAV\clt-inst\Webinst\logo.jpg
c:\program files\SAV\clt-inst\Webinst\oscheck.htm
c:\program files\SAV\clt-inst\Webinst\plnotsup.htm
c:\program files\SAV\clt-inst\Webinst\readme.htm
c:\program files\SAV\clt-inst\Webinst\start.htm
c:\program files\SAV\clt-inst\Webinst\webinst.cab
c:\program files\SAV\clt-inst\Webinst\webinst\files.ini
c:\program files\SAV\clt-inst\Win32\GRC.DAT
c:\program files\SAV\clt-inst\Win32\Setup.exe
c:\program files\SAV\defloc.dat
c:\program files\SAV\GRC.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\CATALOG.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\LIC.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\NAVENG.EXP
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\NAVENG.NLM
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\NAVENG.SYS
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\NAVENG.VXD
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\NAVENG16.DLL
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\NAVENG32.DLL
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\NAVEX15.EXP
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\NAVEX15.NLM
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\NAVEX15.SYS
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\NAVEX15.VXD
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\NAVEX16A.DLL
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\NAVEX32A.DLL
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\NAVLIC.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\NCSACERT.TXT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\SCRAUTH.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\SYMAVENG.CAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\SYMAVENG.INF
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\TECHNOTE.TXT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\TINF.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\TINFIDX.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\TINFL.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\TSCAN1.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\TSCAN1HD.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\UPDATE.TXT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\VIRSCAN.INF
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\VIRSCAN1.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\VIRSCAN2.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\VIRSCAN3.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\VIRSCAN4.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\VIRSCAN5.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\VIRSCAN6.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\VIRSCAN7.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\VIRSCAN8.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\VIRSCAN9.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\WHATSNEW.TXT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\WILD\BIGVSCAN.INF
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\WILD\IS.DIS
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\WILD\NAVEX15.EXP
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\WILD\NAVUPLIN.DIS
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\WILD\NAVUPSOL.DIS
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\WILD\VIRSCAN1.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\WILD\VIRSCAN2.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\WILD\VIRSCAN3.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\WILD\VIRSCAN4.DAT
c:\program files\SAV\I2_LDVP.VDB\VD11A605.VDB\ZDONE.DAT
c:\program files\SAV\Logon\vpscan16.bat
c:\program files\SAV\SAVSetup\AMS2\0x0409.ini
c:\program files\SAV\SAVSetup\AMS2\AMS Server.msi
c:\program files\SAV\SAVSetup\AMS2\Amsremote.dat
c:\program files\SAV\SAVSetup\AMS2\amsremote.exe
c:\program files\SAV\SAVSetup\AMS2\Data1.cab
c:\program files\SAV\SAVSetup\AMS2\instmsia.exe
c:\program files\SAV\SAVSetup\AMS2\instmsiw.exe
c:\program files\SAV\SAVSetup\AMS2\isscript.msi
c:\program files\SAV\SAVSetup\AMS2\setup.exe
c:\program files\SAV\SAVSetup\AMS2\Setup.ini
c:\program files\SAV\SAVSetup\AMS2\Setup.iss
c:\program files\SAV\SAVSetup\SETTINGS.INI
c:\program files\SAV\SAVSetup\Setup.exe
c:\program files\SAV\SAVSetup\Setup.wis
c:\program files\SAV\SAVSetup\Vpremote.dat
c:\program files\SAV\SAVSetup\Vpremote.exe
c:\program files\SAV\settings.ini
c:\program files\SAV\vpdebug.log
c:\windows\mainms.vpi
c:\windows\megavid.cdt
c:\windows\muotr.so
c:\windows\system32\adbqhymq.ini
c:\windows\system32\aleyalok.ini
c:\windows\system32\bhmbpjvq.ini
c:\windows\system32\bLnprBeg.ini
c:\windows\system32\bLnprBeg.ini2
c:\windows\system32\cwcwwlsq.ini
c:\windows\system32\eopuyjwx.ini
c:\windows\system32\eresuwad.ini
c:\windows\system32\hljwugsf.bin
c:\windows\system32\ijehehiv.ini
c:\windows\system32\jcafjphy.ini
c:\windows\system32\maoasfjs.ini
c:\windows\system32\oyekuveb.ini
c:\windows\system32\qewblqjl.ini
c:\windows\system32\qndmcyus.ini
c:\windows\system32\siewymmh.ini
c:\windows\system32\urmwdlin.ini
c:\windows\system32\usahoyuv.ini
c:\windows\system32\vaclfiml.ini
c:\windows\system32\vfgiqvwo.ini
c:\windows\system32\vinltnrn.ini
c:\windows\system32\yelwpess.ini
c:\windows\system32\ygrhggij.ini
c:\windows\system32\yihazuso.dll
c:\windows\Temp\tmp3.tmp

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_TDSSSERV.SYS


((((((((((((((((((((((((( Files Created from 2009-01-02 to 2009-02-02 )))))))))))))))))))))))))))))))
.

2009-01-31 22:34 . 2009-01-31 22:35 <DIR> d-------- c:\program files\Rogers
2009-01-30 22:34 . 2009-01-30 22:34 21,512 --a------ c:\windows\system32\drivers\pxscan.sys
2009-01-30 22:34 . 2009-01-30 22:34 65 --a------ c:\windows\wininit.ini
2009-01-28 01:45 . 2009-01-28 01:45 <DIR> d-------- c:\program files\Trend Micro
2009-01-28 01:35 . 2009-01-28 01:36 <DIR> d-------- c:\program files\ERUNT
2009-01-27 14:30 . 2009-01-27 14:31 <DIR> d-------- c:\windows\system32\drivers\UMDF
2009-01-27 14:28 . 2008-05-26 21:08 466,944 -ra------ c:\windows\713xRMT.exe
2009-01-27 14:27 . 2009-01-27 14:27 <DIR> d-------- c:\windows\MyInstall
2009-01-27 14:27 . 2009-01-27 14:27 <DIR> d-------- c:\program files\TV Expert
2009-01-27 01:33 . 2009-01-27 01:33 <DIR> d-------- c:\documents and settings\Carlos\.housecall6.6
2009-01-27 01:28 . 2009-01-27 07:26 <DIR> d-------- c:\windows\BDOSCAN8
2009-01-26 09:07 . 2009-02-02 01:20 <DIR> d--h----- C:\$AVG8.VAULT$
2009-01-25 11:54 . 2009-02-02 01:31 <DIR> d-------- c:\windows\system32\drivers\Avg
2009-01-25 11:54 . 2009-01-25 12:19 <DIR> d-------- c:\documents and settings\Carlos\Application Data\AVGTOOLBAR
2009-01-25 11:54 . 2009-01-31 08:48 325,128 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-01-25 11:54 . 2009-01-31 08:48 107,272 --a------ c:\windows\system32\drivers\avgtdix.sys
2009-01-25 11:54 . 2009-01-31 08:48 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-01-25 11:53 . 2009-01-25 11:53 <DIR> d-------- c:\program files\AVG
2009-01-25 11:53 . 2009-01-31 08:49 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2009-01-25 10:54 . 2009-01-25 10:54 <DIR> d-------- c:\program files\Common Files\scanner
2009-01-25 10:54 . 2009-01-27 07:57 <DIR> d-------- c:\program files\CA Yahoo! Anti-Spy
2009-01-25 10:54 . 2009-01-25 11:01 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-01-24 22:39 . 2009-01-24 22:39 <DIR> d-------- c:\program files\pocketGEAR
2009-01-24 05:24 . 2009-01-24 05:24 <DIR> d-------- c:\program files\Astraware
2009-01-23 23:13 . 2009-01-23 23:13 <DIR> d-------- c:\program files\Palm
2009-01-23 22:16 . 2005-10-20 20:47 30,592 --------- c:\windows\system32\drivers\rndismpx.sys
2009-01-23 22:16 . 2005-10-20 20:47 12,800 --------- c:\windows\system32\drivers\usb8023x.sys
2009-01-20 23:14 . 2009-01-20 23:14 54,156 --ah----- c:\windows\QTFont.qfn
2009-01-20 23:14 . 2009-01-20 23:14 1,409 --a------ c:\windows\QTFont.for
2009-01-20 23:03 . 2009-01-29 23:43 <DIR> d-------- c:\documents and settings\Carlos\Application Data\gtk-2.0
2009-01-20 23:03 . 2009-01-20 23:03 <DIR> d-------- c:\documents and settings\Carlos\.thumbnails
2009-01-20 22:56 . 2009-01-29 23:46 <DIR> d-------- c:\documents and settings\Carlos\.gimp-2.6
2009-01-20 22:55 . 2009-01-20 22:55 <DIR> d-------- c:\program files\GIMP-2.0
2009-01-20 22:55 . 2009-01-20 22:56 <DIR> d-------- c:\documents and settings\Carlos\.gegl-0.0
2009-01-18 10:37 . 2009-01-18 14:03 <DIR> d-------- C:\ST_Temp
2009-01-17 00:49 . 2009-01-17 00:49 197 --a------ c:\windows\system32\MRT.INI
2009-01-17 00:43 . 2009-01-20 09:28 <DIR> d-------- c:\program files\SUPERAntiSpyware
2009-01-17 00:43 . 2009-01-17 00:43 <DIR> d-------- c:\documents and settings\Carlos\Application Data\SUPERAntiSpyware.com
2009-01-17 00:43 . 2009-01-17 00:43 <DIR> d-------- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-01-09 21:31 . 2009-01-09 21:31 <DIR> d-------- c:\program files\PrevxCSI
2009-01-09 21:30 . 2009-01-30 23:52 <DIR> d-------- c:\documents and settings\All Users\Application Data\PrevxCSI
2009-01-07 22:48 . 2004-08-03 23:10 15,360 --a------ c:\windows\system32\drivers\MPE.sys
2009-01-07 22:48 . 2004-08-03 23:10 15,360 --a--c--- c:\windows\system32\dllcache\mpe.sys
2009-01-07 22:44 . 2009-01-07 22:46 <DIR> d-------- C:\antispy

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-01 07:03 37,912 ----a-w c:\documents and settings\Carlos\Application Data\GDIPFONTCACHEV1.DAT
2009-01-28 12:24 --------- d-----w c:\documents and settings\Carlos\Application Data\mIRC
2009-01-27 19:27 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-25 15:54 --------- d-----w c:\program files\Yahoo!
2009-01-25 15:54 --------- d-----w c:\documents and settings\Carlos\Application Data\Yahoo!
2009-01-24 03:15 --------- d-----w c:\program files\Microsoft ActiveSync
2009-01-18 07:26 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-17 10:06 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2009-01-17 10:00 --------- d-----w c:\program files\Symantec
2009-01-17 05:42 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-01-17 05:41 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-01-14 21:11 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-14 21:11 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-01-10 03:55 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-01-10 03:55 123,952 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-10 03:55 10,652 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-10 03:50 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2008-12-20 14:12 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-12-20 14:12 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2008-12-20 03:46 --------- d-----w c:\program files\Common Files\Motorola Shared
2008-12-11 11:57 333,184 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-07 19:56 43,528 ------w c:\windows\system32\drivers\pxhelp20.sys
2008-12-01 18:58 508 ----a-w c:\program files\Shortcut to Mozilla Firefox.lnk
2008-04-01 17:00 81,920 ----a-w c:\documents and settings\Carlos\Application Data\ezpinst.exe
2008-04-01 17:00 47,360 ----a-w c:\documents and settings\Carlos\Application Data\pcouffin.sys
2005-04-01 02:17 40,960 ----a-w c:\program files\Uninstall_CDS.exe
2008-06-30 17:44 324,976 ----a-w c:\program files\mozilla firefox\components\coFFPlgn.dll
2009-01-08 05:51 67,688 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2009-01-08 05:51 54,368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2009-01-08 05:51 34,944 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2009-01-08 05:51 46,712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2009-01-08 05:51 172,136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\NBHShellExt]
@="{8D2223A2-B3C6-4e32-B096-CDD11F628C60}"
[HKEY_CLASSES_ROOT\CLSID\{8D2223A2-B3C6-4e32-B096-CDD11F628C60}]
2008-02-28 12:04 97064 --a------ e:\nero ultra 8.3.2.1\Nero\Nero8\InCD\NBHShx.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"PowerBar"="f:\cyberlink\Multimedia Launcher\PowerBar.exe" [2004-04-21 86016]
"Nero PhotoShow Media Manager"="c:\progra~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe" [2006-05-10 249856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"CreativeTaskScheduler"="c:\program files\Creative\Shared Files\CTSched.exe" [2006-11-17 53341]
"Creative Live! Cam Manager"="c:\program files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe" [2007-06-07 155648]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-20 1830128]
"H/PC Connection Agent"="c:\progra~1\MICROS~4\wcescomm.exe" [2006-06-20 1207080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2006-07-07 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-20 213936]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-03-27 81920]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-03-27 8425472]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-02-28 570664]
"SecurDisc"="e:\nero ultra 8.3.2.1\Nero\Nero8\InCD\NBHGui.exe" [2008-02-28 2049320]
"InCD"="e:\nero ultra 8.3.2.1\Nero\Nero8\InCD\InCD.exe" [2008-02-28 1083176]
"NBKeyScan"="e:\nero ultra 8.3.2.1\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-09-11 67488]
"YOP"="c:\progra~1\Yahoo!\YOP\yop.exe" [2008-06-03 509224]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-08-28 51048]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-08-08 98304]
"V0420Mon.exe"="c:\windows\V0420Mon.exe" [2007-04-29 32768]
"RemoteControl"="d:\cyberlink\PowerDVD\PDVDServ.exe" [2007-02-07 71216]
"PWRISOVM.EXE"="e:\poweriso\PWRISOVM.EXE" [2007-04-09 200704]
"PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2004-03-10 406016]
"LanguageShortcut"="d:\cyberlink\PowerDVD\Language\Language.exe" [2007-02-07 54832]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2006-06-29 49152]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-31 1601304]
"TV Card Remote Control Device Monitor"="c:\windows\713xRMT.exe" [2008-05-26 466944]
"Rogers SHS"="c:\program files\Rogers\SelfHealing\shs.exe" [2008-05-16 2733416]
"nwiz"="nwiz.exe" [2007-03-27 c:\windows\system32\nwiz.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 c:\windows\RTHDCPL.exe]

c:\documents and settings\Carlos\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
forteManager.lnk - c:\program files\LG Soft India\forteManager\bin\Monitor.exe [2008-11-15 1097728]
PC Alert 4.lnk - c:\program files\MSI\PC Alert 4\PCAlert4.exe [2007-08-05 552960]
TV Expert Schedule Agent.lnk - c:\program files\TV Expert\ADTVScheduleAgent.exe [2009-01-27 32256]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-31 08:48 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= ffdshow.ax
"vidc.tscc"= tsccvid.dll 0

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NBService"=3 (0x3)
"LiveUpdate Notice Service"=2 (0x2)
"LiveUpdate Notice Ex"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"f:\\Pinnacle\\programs\\RM.exe"=
"f:\\Pinnacle\\programs\\Studio.exe"=
"f:\\Pinnacle\\programs\\PMSRegisterFile.exe"=
"f:\\Pinnacle\\programs\\umi.exe"=
"e:\\Bit Torrent\\bittorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqnrs08.exe"=
"f:\\PROGRAM FILES\\TESTOUT\\Cmi\\Navigator.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\SUPERAntiSpyware\\SUPERANTISPYWARE.EXE"=
"c:\\Program Files\\SUPERAntiSpyware\\RUNSAS.EXE"=
"c:\\Program Files\\AVG\\AVG8\\avgtray.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgui.exe"=
"f:\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\Yahoo!\\YOP\\yop.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [2009-01-30 21512]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-01-25 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-01-25 107272]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2008-12-22 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2008-12-22 55024]
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};d:\cyberlink\PowerDVD\000.fcl [2006-11-02 15:51:58 13560]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 124832]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-25 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-25 298264]
R2 CSIScanner;CSIScanner;c:\program files\PrevxCSI\prevxcsi.exe [2009-01-09 4107832]
R2 NeroRegInCDSrv;Nero Registry InCD Service;e:\nero ultra 8.3.2.1\Nero\Nero8\InCD\NBHRegInCDSrv.exe [2008-02-28 53032]
R2 RogersSelfHelpService;Rogers SHS Service;c:\program files\Rogers\SelfHealing\RogersSelfHelpService.exe [2008-05-16 140648]
R2 RogersUpdateManager;Rogers Update Manager;c:\program files\Rogers\Update Manager\RogersUpdateManager.exe [2008-04-22 163840]
R3 3xHybrid;SAA713x TV Card Service;c:\windows\system32\drivers\3xHybrid.sys [2009-01-07 906368]
R3 LGDDCDevice;LGDDCDevice;c:\program files\LG Soft India\forteManager\bin\I2CDriver.sys [2008-11-15 14336]
R3 N5SG;Airlink101 SuperG Wireless Network Adapter Service;c:\windows\system32\drivers\N5SG.sys [2006-11-03 467040]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-22 7408]
R3 V0420VID;Live! Cam Vista IM (VF0420);c:\windows\system32\drivers\V0420Vid.sys [2008-10-03 99648]
S3 DualCoreCenter;DualCoreCenter;c:\program files\MSI\DualCoreCenter\NTGLM7X.sys [2007-08-05 28160]
S3 LGII2CDevice;LGII2CDevice;c:\program files\LG Soft India\forteManager\bin\PII2CDriver.sys [2008-11-15 13312]
S3 RushTopDevice2;RushTopDevice2;c:\program files\MSI\DualCoreCenter\RushTop.sys [2007-08-05 44544]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - NVR0DEV
*NewlyCreated* - PCALERTDRIVER
*Deregistered* - PCAlertDriver

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8be1595f-e575-11dd-91f4-00180242ba5c}]
\Shell\AutoRun\command - K:\setup.exe
.
Contents of the 'Scheduled Tasks' folder

2009-02-02 c:\windows\Tasks\fkyhkpbt.job
- c:\windows\system32\pmnkHXnN.dll []
.
- - - - ORPHANS REMOVED - - - -

BHO-{A3DB05B0-5655-47E0-B547-0E59B0AFF584} - c:\windows\system32\geBrpnLb.dll
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
HKLM-Run-NWEReboot - (no file)
HKU-Default-RunOnce-_Sym_MI_ - c:\program files\SAV\SAVSetup\setup.exe
Notify-WgaLogon - (no file)
Notify-yayaAsTm - yayaAsTm.dll


.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://teamtutorials.com/windows-tutorials-retrieving-xp-key-from-the-registry
uInternet Connection Wizard,ShellNext = iexplore
FF - ProfilePath - c:\documents and settings\Carlos\Application Data\Mozilla\Firefox\Profiles\xvsejsb0.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.neopets.com
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - component: c:\program files\Mozilla Firefox\components\coFFPlgn.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-02 02:15:55
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\d:\cyberlink\PowerDVD\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,f2,a6,b8,bb,09,
e6,cc,28,e2,63,26,f1,3f,c8,ff,68,94,c1,37,69,92,09,2f,8e,e2,63,26,f1,3f,c8,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:46,47,15,b0,92,4b,c7,ef,da,9e,c8,12,9e,
e2,45,65,6a,9c,d6,61,af,45,84,18,18,00,20,76,0d,d7,41,7f,6a,9c,d6,61,af,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:7a,45,05,fd,91,e8,6f,31,a8,66,f5,a6,9e,
d8,38,38,ff,7c,85,e0,43,d4,0e,fe,dd,23,c2,a7,17,c8,55,8f,ff,7c,85,e0,43,d4,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:6b,65,49,6a,7e,99,74,f7,37,e7,03,bf,68,
bd,45,55,86,8c,21,01,be,91,eb,e7,e6,94,0f,05,8c,17,18,54,86,8c,21,01,be,91,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:e9,02,6c,fa,fb,1d,47,57,92,b5,2a,ad,0b,
2d,9c,0c,f5,1d,4d,73,a8,13,5c,05,7f,63,f1,cc,a4,00,2c,2c,f5,1d,4d,73,a8,13,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,d4,ea,13,48,73,
93,b0,4a,df,20,58,62,78,6b,cf,c8,59,c6,ac,25,68,da,d4,f0,df,20,58,62,78,6b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,d1,26,c3,45,39,
74,77,44,fb,a7,78,e6,12,2f,9a,ea,63,86,6f,a2,cb,50,bb,6c,fb,a7,78,e6,12,2f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,0b,eb,0a,d3,b9,
51,4b,8f,01,3a,48,fc,e8,04,4a,f1,12,8c,55,c4,54,9c,ae,01,01,3a,48,fc,e8,04,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,c9,f6,3b,c1,30,
ab,55,ac,f6,0f,4e,58,98,5b,89,c9,e3,df,56,b9,89,71,d1,bf,f6,0f,4e,58,98,5b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,51,96,a0,13,92,
df,f7,39,3d,ce,ea,26,2d,45,aa,78,b2,57,1f,02,69,65,0f,fb,3d,ce,ea,26,2d,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,77,26,c1,71,04,
0d,ab,ff,2a,b7,cc,b5,b9,7f,41,e7,39,64,54,a8,be,3c,99,11,2a,b7,cc,b5,b9,7f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,ee,a9,23,2f,37,
6d,57,43,6c,43,2d,1e,aa,22,2f,9c,b6,ca,14,6e,19,18,10,ac,6c,43,2d,1e,aa,22,\

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(912)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\program files\Bonjour\mDNSResponder.exe
e:\nero ultra 8.3.2.1\Nero\Nero8\InCD\InCDsrv.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
f:\program files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\rundll32.exe
e:\nero ultra 8.3.2.1\Nero\Nero8\Nero BackItUp\NBService.exe
c:\program files\Yahoo!\YOP\yop.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\system32\HPZipm12.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\progra~1\MICROS~4\rapimgr.exe
c:\progra~1\Yahoo!\browser\ycommon.exe
f:\pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe
c:\program files\Common Files\Symantec Shared\SecurityStatusSDK\SSDK02.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-02-02 2:19:14 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-02 07:19:11

Pre-Run: 1,229,725,696 bytes free
Post-Run: 2,286,333,952 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

506 --- E O F --- 2009-01-17 09:47:26




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:20:49 AM, on 2/2/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\PrevxCSI\prevxcsi.exe
E:\Nero Ultra 8.3.2.1\Nero\Nero8\InCD\InCDsrv.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
F:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\PrevxCSI\prevxcsi.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\WINDOWS\system32\RUNDLL32.EXE
E:\Nero Ultra 8.3.2.1\Nero\Nero8\InCD\NBHGui.exe
E:\Nero Ultra 8.3.2.1\Nero\Nero8\InCD\InCD.exe
E:\Nero Ultra 8.3.2.1\Nero\Nero8\Nero BackItUp\NBService.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\V0420Mon.exe
C:\WINDOWS\RTHDCPL.EXE
D:\CyberLink\PowerDVD\PDVDServ.exe
E:\PowerISO\PWRISOVM.EXE
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\713xRMT.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
F:\Cyberlink\Multimedia Launcher\PowerBar.exe
C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
E:\Nero Ultra 8.3.2.1\Nero\Nero8\InCD\NBHRegInCDSrv.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Creative\Shared Files\CTSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Rogers\SelfHealing\RogersSelfHelpService.exe
C:\PROGRA~1\MICROS~4\wcescomm.exe
C:\Program Files\Rogers\Update Manager\RogersUpdateManager.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\Program Files\LG Soft India\forteManager\bin\Monitor.exe
C:\Program Files\TV Expert\ADTVScheduleAgent.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
F:\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe
C:\Program Files\Common Files\Symantec Shared\SecurityStatusSDK\SSDK02.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://teamtutorials.com/windows-tutorials-retrieving-xp-key-from-the-registry
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] E:\Nero Ultra 8.3.2.1\Nero\Nero8\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] E:\Nero Ultra 8.3.2.1\Nero\Nero8\InCD\InCD.exe
O4 - HKLM\..\Run: [NBKeyScan] "E:\Nero Ultra 8.3.2.1\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [V0420Mon.exe] C:\WINDOWS\V0420Mon.exe
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [RemoteControl] D:\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] E:\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [LanguageShortcut] D:\CyberLink\PowerDVD\Language\Language.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [TV Card Remote Control Device Monitor] C:\WINDOWS\713xRMT.exe
O4 - HKLM\..\Run: [Rogers SHS] C:\Program Files\Rogers\SelfHealing\shs.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PowerBar] "F:\Cyberlink\Multimedia Launcher\PowerBar.exe" /AtBootTime
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CreativeTaskScheduler] "C:\Program Files\Creative\Shared Files\CTSched.exe" /logon
O4 - HKCU\..\Run: [Creative Live! Cam Manager] "C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MICROS~4\wcescomm.exe"
O4 - S-1-5-18 Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: forteManager.lnk = ?
O4 - Global Startup: PC Alert 4.lnk = C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
O4 - Global Startup: TV Expert Schedule Agent.lnk = C:\Program Files\TV Expert\ADTVScheduleAgent.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: Rogers Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: CSIScanner - Prevx - C:\Program Files\PrevxCSI\prevxcsi.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - E:\Nero Ultra 8.3.2.1\Nero\Nero8\InCD\InCDsrv.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - E:\Nero Ultra 8.3.2.1\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Nero AG - E:\Nero Ultra 8.3.2.1\Nero\Nero8\InCD\NBHRegInCDSrv.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - F:\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Rogers SHS Service (RogersSelfHelpService) - Rogers Cable Communications - C:\Program Files\Rogers\SelfHealing\RogersSelfHelpService.exe
O23 - Service: Rogers Update Manager (RogersUpdateManager) - Rogers Cable Communications - C:\Program Files\Rogers\Update Manager\RogersUpdateManager.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

--
End of file - 14234 bytes

peku006
2009-02-02, 12:07
Hi gorzul

which Symantec software you are using?

1 - Download and Run Malwarebytes' Anti-Malware
Please download Malwarebytes Anti-Malware (http://www.besttechie.net/tools/mbam-setup.exe) and save it to your desktop.
alternate download link 1 (http://malwarebytes.gt500.org/mbam-setup.exe)
alternate download link 2 (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html)

Double-click on Download_mbam-setup.exe to install the application.
When the installation begins, follow the prompts and do not make any changes to default settings.
When installation has finished, make sure you leave both of these checked:
Update Malwarebytes' Anti-Malware
Launch Malwarebytes' Anti-Malware
Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
If an update is found, the program will automatically update itself.
Press the OK button to close that box and continue.
If you encounter any problems while downloading the updates, manually download them from here (http://www.malwarebytes.org/mbam/database/mbam-rules.exe) and just double-click on mbam-rules.exe to install.
On the Scanner tab:

Make sure the "Perform full scan" option is selected.
Then click on the Scan button.
If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button
The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:

Click on the Show Results button to see a list of any malware that was found.
Make sure that everything is checked, and click Remove Selected.
When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
The log can also be found here:

C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
Copy and paste the contents of that report in your next reply and exit MBAM.

Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

2 - Status Check
Please reply with

1. the Malwarebytes' Anti-Malware Log

Thanks peku006