PDA

View Full Version : Command Service Help



gabe23
2006-09-07, 20:09
keep getting tons of popups. I have tried spybot and adware with normal boot and safe mode. It keep coming up with command service but cannot fix it because its in memory. Here is the log. Thanks

Logfile of HijackThis v1.99.1
Scan saved at 12:46:37 PM, on 9/7/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\r_server.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe
C:\kybrdff_16.exe
C:\dfndrff_16.exe
C:\WINNT\win32093128865464.exe
C:\WINNT\Duce6.exe
C:\WINNT\wjzmppoA.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
C:\Program Files\WinZip\WZQKPICK.EXE
c:\winnt\system32\ojdsregj.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Allen.LeCuyer.nwoodswhitebear.000\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=userinit.exe
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [key2] C:\WINNT\system32\winlog.exe
O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" -start
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_16.exe
O4 - HKLM\..\Run: [defender] C:\\dfndrff_16.exe
O4 - HKLM\..\Run: [win32093128865464] C:\WINNT\win32093128865464.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINNT\Duce6.exe
O4 - HKLM\..\Run: [wjzmppoA] C:\WINNT\wjzmppoA.exe
O4 - HKLM\..\Run: [yrc1dbfe] RUNDLL32.EXE w213b800.dll,n 0041dbfa00000003213b800
O4 - HKLM\..\Run: [sys028865464312] C:\WINNT\sys028865464312.exe
O4 - HKLM\..\Run: [ntdll.dll] c:\winnt\system32\ojdsregj.exe GEN001
O4 - HKLM\..\Run: [{F4-4F-F3-33-ZN}] c:\winnt\system32\ojdsregj.exe GEN001
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINNT\system32\swinkpex.exe GEN001
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [key2] C:\WINNT\system32\winlog.exe
O4 - HKCU\..\Run: [german.exe] C:\WINNT\system32\wintems.exe
O4 - HKCU\..\Run: [CMFibula] "C:\Program Files\CMFibula\CMFibula.exe"
O4 - HKCU\..\Run: [quqo] C:\PROGRA~1\COMMON~1\quqo\quqom.exe
O4 - Startup: TA_Start.lnk = C:\WINNT\system32\dwdsregt.exe
O4 - Startup: Think-Adz.lnk = C:\WINNT\system32\swinkpex.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\GameClient.exe
O16 - DPF: {2564B8E6-7D84-11D4-A689-30475BC10000} (Tkweb Control) - http://toolkitcma.com/tkweb/tkweb.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/162ae3397f6729e6f116/netzip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1124234828578
O16 - DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} (VaPgCtrl Class) - http://192.168.0.104/plugin/h263ctrl.cab
O16 - DPF: {D1ACD2D8-7312-4D06-BECD-90EB094D2277} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = nwoodswhitebear.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = nwoodswhitebear.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = nwoodswhitebear.local
O18 - Filter: text/html - {994D478A-45D0-4DB4-AE27-738B1E346F99} - C:\Program Files\Batty2\Batty2.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINNT\system32\r_server.exe" /service (file missing)

Rawe
2006-09-08, 17:03
Hello and welcome... :)

Lets get started.

Please get the free version of AVG (http://www.grisoft.com/us/us_dwnl_free.php).

Download & install it, configure it how you wish, update it. Next, run a scan with it (set it to scan everything it can). Remove/quarantine everything found. Reboot. Make sure you keep using it - Anti-virus client is very important to be run at all times.

----

Please download VundoFix.exe (http://www.atribune.org/ccount/click.php?id=4) to your desktop.
Double-click VundoFix.exe to run it.
Click the Scan for Vundo button.
Once it's done scanning, click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will reboot your computer, click OK.
Please post the contents of C:\vundofix.txt in your next reply.


Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

----

Finally:

Please download Combofix (http://download.bleepingcomputer.com/sUBs/combofix.exe) to your desktop:
Double-click combofix.exe & follow the prompts.
When finished, it shall produce a log for you. Post that log in your next reply along with the contents of the C:\vundofix.txt log. :bigthumb:

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

gabe23
2006-09-11, 21:19
Thanks for the help. Here are the log files.

allen.lecuyer - Mon 09/11/2006 14:16:58.95
ComboFix 06.09.11B - Running from: C:\Documents and Settings\Allen.LeCuyer.nwoodswhitebear.000\Desktop

Microsoft Windows 2000 [Version 5.00.2195]

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINNT\Duce6.exe
C:\deskbar3.exe
C:\Program Files\batty2
C:\Program Files\cmfibula
C:\Program Files\PSLister


((((((((((((((((((((((((((((((( Files Created from 2006-08-11 to 2006-09-11 ))))))))))))))))))))))))))))))))))


2006-09-11 11:25 53,248 --a------ C:\WINNT\system32\Process.exe
2006-09-11 11:25 40,960 --a------ C:\WINNT\system32\swsc.exe
2006-09-11 11:25 288,417 --a------ C:\WINNT\system32\SrchSTS.exe
2006-09-11 11:25 135,168 --a------ C:\WINNT\system32\swreg.exe
2006-09-07 11:36 499,712 --a------ C:\WINNT\system32\msvcp71.dll
2006-09-07 11:36 348,160 --a------ C:\WINNT\system32\msvcr71.dll
2006-09-07 00:18 163,840 --a------ C:\WINNT\win320764312886542006.exe
2006-09-06 17:55 208,896 --a------ C:\WINNT\system32\wmpns.dll
2006-09-06 15:40 928 --a------ C:\WINNT\system32\winpfg32.sys
2006-09-06 15:39 52,224 --a------ C:\WINNT\Duce6.exe
2006-09-06 15:39 186,223 --a------ C:\WINNT\srvabegcnq.exe
2006-09-06 15:39 1,233 --a------ C:\WINNT\system32\yrc1dbfe.sys
2006-09-06 15:37 163,840 --a------ C:\WINNT\win32093128865464.exe


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-09-11 13:18 76560 --a------ C:\WINNT\system32\drivers\tmcomm.sys
2006-09-11 13:18 -------- d-------- C:\Program Files\Internet Explorer
2006-09-11 11:59 777472 --a------ C:\WINNT\system32\drivers\avg7core.sys
2006-09-11 11:59 4288 --a------ C:\WINNT\system32\drivers\avg7rsw.sys
2006-09-11 11:59 27904 --a------ C:\WINNT\system32\drivers\avg7rsxp.sys
2006-09-11 11:59 26912 --a------ C:\WINNT\system32\drivers\avg7rsnt.sys
2006-09-11 11:59 23424 --a------ C:\WINNT\system32\drivers\avgmfrs.sys
2006-09-11 11:59 -------- d-------- C:\Program Files\Grisoft
2006-09-11 11:59 -------- d-------- C:\Documents and Settings\Allen.LeCuyer.nwoodswhitebear.000\Application Data\AVG7
2006-09-11 11:46 44288 --a------ C:\WINNT\system32\drivers\cdr4_2k.sys
2006-09-11 10:34 -------- d-a------ C:\Program Files\ewido anti-spyware 4.0
2006-09-08 14:34 -------- d-------- C:\Documents and Settings\Allen.LeCuyer.nwoodswhitebear.000\Application Data\AdobeUM
2006-09-07 13:48 -------- d-------- C:\Program Files\Common Files\Adaptec Shared
2006-09-07 11:05 -------- d-------- C:\Program Files\Accessories
2006-09-07 10:57 -------- d-------- C:\Program Files\Lavasoft
2006-09-07 10:57 -------- d-------- C:\Documents and Settings\Allen.LeCuyer.nwoodswhitebear.000\Application Data\Lavasoft
2006-09-06 17:55 -------- d-------- C:\Program Files\Windows Media Player
2006-09-06 17:55 -------- d-------- C:\Program Files\Outlook Express
2006-09-06 17:55 -------- d-------- C:\Program Files\Common Files\System
2006-09-06 17:18 -------- d-------- C:\Program Files\Common Files\quqo
2006-09-06 17:12 -------- d-------- C:\Program Files\SG2
2006-09-06 15:38 -------- d-------- C:\Program Files\Common Files
2006-08-30 12:53 11827 --a------ C:\Documents and Settings\Allen.LeCuyer.nwoodswhitebear.000\Application Data\Comma Separated Values (Windows).CAL
2006-07-27 11:54 -------- d-------- C:\Documents and Settings\Allen.LeCuyer.nwoodswhitebear.000\Application Data\Google
2006-07-25 00:08 840976 --a------ C:\WINNT\system32\mmcndmgr.dll
2006-07-21 10:08 72704 --a------ C:\WINNT\system32\hlink.dll
2006-07-06 11:52 613648 --a------ C:\WINNT\system32\mmc.exe
2006-07-06 06:45 96528 --a------ C:\WINNT\system32\dnsrslvr.dll
2006-06-21 01:52 54544 --a------ C:\WINNT\system32\mpr.dll
2006-06-16 02:05 1713536 --a------ C:\WINNT\system32\NTKRNLPA.EXE
2006-06-16 02:04 1690880 --a------ C:\WINNT\system32\NTOSKRNL.EXE


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="ctfmon.exe"
"key2"="C:\\WINNT\\system32\\winlog.exe"
"CMFibula"="\"C:\\Program Files\\CMFibula\\CMFibula.exe\""
"quqo"="C:\\PROGRA~1\\COMMON~1\\quqo\\quqom.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe /logon"
"EM_EXEC"="C:\\PROGRA~1\\Logitech\\MOUSEW~1\\SYSTEM\\EM_EXEC.EXE"
"CreateCD50"="\"C:\\Program Files\\Common Files\\Adaptec Shared\\CreateCD\\CreateCD50.exe\" -r"
"AdaptecDirectCD"="\"C:\\Program Files\\Roxio\\Easy CD Creator 5\\DirectCD\\DirectCD.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"ISUSPM Startup"="C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\ISUSPM.exe -startup"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"key2"="C:\\WINNT\\system32\\winlog.exe"
"StatusClient 2.6"="C:\\Program Files\\Hewlett-Packard\\Toolbox\\StatusClient\\StatusClient.exe /auto"
"TomcatStartup 2.5"="C:\\Program Files\\Hewlett-Packard\\Toolbox\\hpbpsttp.exe"
"ISUSScheduler"="\"C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\issch.exe\" -start"
"win32093128865464"="C:\\WINNT\\win32093128865464.exe"
"yrc1dbfe"="RUNDLL32.EXE w213b800.dll,n 0041dbfa00000003213b800"
"sys028865464312"="C:\\WINNT\\sys028865464312.exe"
"{F4-4F-F3-33-ZN}"="c:\\winnt\\system32\\ojdsregj.exe GEN001"
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"TheMonitor"="C:\\WINNT\\Duce6.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000003
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="C:\\Program Files\\Windows Media Player\\pogofud.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,e8,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="C:\\Program Files\\Outlook Express\\medecibow.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,ea,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\2]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e4,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,c0
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,10,03,00,00,1f,00,00,00,e0,00,00,00,d6,00,\
00,00,01,00,00,00

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonce]
"^SetupICWDesktop"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"DisableRegistryTools"=dword:00000000

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000095
"CDRAutoRun"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoWelcomeScreen"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000095

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"Network.ConnectionTray"="{7007ACCF-3202-11D1-AAD2-00805FC1270E}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


Contents of the 'Scheduled Tasks' folder
C:\WINNT\tasks\Backup.job

Completion time: Mon 2006-09-11 14:19:16.28
ComboFix.txt





VundoFix V6.1.4

Checking Java version...

Java version is 1.5.0.6

Scan started at 1:19:55 PM 9/7/2006

Listing files found while scanning....

No infected files were found.


VundoFix V6.1.4

Checking Java version...

Java version is 1.5.0.6

Scan started at 2:12:09 PM 9/11/2006

Listing files found while scanning....

No infected files were found.

Rawe
2006-09-12, 11:07
Hmm... Please rename your HijackThis.exe to hjt.exe. Make sure you use this renamed file next time when posting a fresh log.

Then lets run an online scanner also:

Please run the F-Secure Online Scanner (http://support.f-secure.com/enu/home/ols3.shtml#)

Note: This scanner is for internet explorer only!
Follow the instructions here (http://support.f-secure.com/enu/home/ols3.shtml) for installation.
Accept the License Agreement.
Once the ActiveX installs, click Full System Scan
Once the download completes, the scan will begin automatically.
The scan will take some time to finish, so please be patient.
When the scan completes, click the Automatic cleaning (recommended) button.
Click the Show Report button and copy & paste the entire report in your next reply along with a fresh HijackThis log. :bigthumb:

tashi
2006-09-17, 20:33
gabe23, still with us?

tashi
2006-09-22, 23:05
This topic has been archived due to lack of a response.
If you need it re-opened please send me a private message (pm) and provide a link to the thread.

Applies only to the original topic starter.