Page 1 of 3 123 LastLast
Results 1 to 10 of 24

Thread: MSN Virus: PIC006.JPG-live.messenger.com

  1. #1
    Junior Member
    Join Date
    Mar 2008
    Posts
    16

    Default MSN Virus: PIC006.JPG-live.messenger.com

    Greetings, I have been so mindless and click a link from a friend on MSN Messenger this Saturday. The name of it was PIC006.JPG-live.messenger.com. Not before it was too late, did I realise it was a virus.

    I may have been a bad girl in trying to remove it on my own, instead of coming to you directly. I will try to explain the steps I have taken myself here.

    First I ran scans with AVG Free, Spybot - S&D and ClamWin. Neither found anything. Then I uninstalled MSN Messenger and everything (or at least I think everthing) connected to it. I then ran all 3 programs again with no result. Then I was sad and it was late, so I went to bed leaving the PC on. Then when I returned to the PC sunday morning it appeared that TeaTimer (it is TeaTimer that little thing by the clock in the bottom right corner that asks if I want to accept or deny changes stuff wants to make to the registry, right?) had found it and asked me if I wanted to accept or deny it. I denied. (I probably should mention that when I clicked the link saturday and before I realised it was a virus it had popped up and I had accepted *DOH*) Then I opened the AVG Free Virus Vault and it seemed it was in there too. I then removed it along with everything else in there. It called it a "back up" so I'm not sure if it removed the original or just a back up. Then I deleted that version of AVG Free and got a newer one, scanned again and it found... *surpriseee* Nothing. Then I thought my day was made... But low and behold, not 5 mins passed and TeaTimer again popped up asking me if I wanted to accept or deny that file to change in the registry. Then I went searching forums, and found a few with the same name of virus as "mine". I then did a foolish thing *sowwy* and did what one of them had adviced the user to do. I downloaded MsnCleaner and rebooted to safe mode and ran it. It found a file (which I can't remember the name off except it was somethingWINDOWSsomething) and I told it to remove that file. I rebooted to normal mode and again TeaTimer popped up asking me if I wanted to allow or deny. I denied again. And here is where my stupidity ends (Or so I'd like to hope) and I am writing to you. I have followed all the steps in your "Before you post" and "Before you post a log", so I have both a Kaspersky log and a HijackThis log for you.

    I haven't installed MSN Messenger again and I've not logged in to anything requiring a password including my WoW *miiiiiiiss iiiiit * Even here I've used a username and a password nowhere near what I normally use. I'm so scared the virus contains a keylogger.

    I am looking very much forward to hearing from you and I promise, cross my heart, only to do what you tell me to do from now on.

    *Bows gracefully*

  2. #2
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi Bumblebee77

    Please post those logs next
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  3. #3
    Junior Member
    Join Date
    Mar 2008
    Posts
    16

    Default

    Here is the HijackThis log

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 19:52:08, on 03-03-2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Programmer\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\Programmer\Fælles filer\Logitech\Bluetooth\LBTSERV.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Programmer\Logitech\Easy Synchronization\servicestub.exe
    C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Programmer\Canon\CAL\CALMAIN.exe
    C:\PROGRA~1\AVG\AVG8\avgam.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe
    C:\Programmer\Fælles filer\Logitech\G-series Software\LGDCore.exe
    C:\Programmer\Logitech\SetPoint\LBTWiz.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programmer\DAEMON Tools\daemon.exe
    C:\Programmer\DNA\btdna.exe
    C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
    C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Programmer\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Programmer\Logitech\SetPoint\SetPoint.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
    C:\Programmer\OpenOffice.org 2.2\program\soffice.exe
    C:\Programmer\OpenOffice.org 2.2\program\soffice.BIN
    C:\Programmer\Fælles filer\Logishrd\KHAL2\KHALMNPR.EXE
    C:\Programmer\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://netbank.danskebank.dk/html/index.html?site=DBNB
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.zitech.dk
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmer\AVG\AVG8\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: CVirtualDNSObj Object - {86C510E9-97EF-4749-914F-0280247BE3A6} - C:\WINDOWS\VirtualDNS.dll (file missing)
    O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programmer\AVG\AVG8\avgtoolbar.dll
    O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Programmer\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
    O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programmer\AVG\AVG8\avgtoolbar.dll
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Easy Synchronization] C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe
    O4 - HKLM\..\Run: [Launch LGDCore] "C:\Programmer\Fælles filer\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
    O4 - HKLM\..\Run: [Bluetooth Connection Assistant] LBTWIZ.EXE -silent
    O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
    O4 - HKLM\..\Run: [ClamWin] "C:\Programmer\ClamWin\bin\ClamTray.exe" --logon
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [MSN Messenger] live.messenger.com
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\RunOnce: [Easy Synchronization] C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe --ports
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Programmer\DNA\btdna.exe"
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: OpenOffice.org 2.2.lnk = C:\Programmer\OpenOffice.org 2.2\program\quickstart.exe
    O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Bluetooth.lnk = ?
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Logitech SetPoint.lnk = ?
    O8 - Extra context menu item: &Search - ?p=ZJfox000
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.zitech.dk
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/.../GAME_UNO1.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
    O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/a.../e-Safekey.cab
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmer\AVG\AVG8\avgpp.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FLLESF~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: avgrsstx.dll
    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmer\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Programmer\Canon\CAL\CALMAIN.exe
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Programmer\Fælles filer\Logitech\Bluetooth\LBTSERV.EXE
    O23 - Service: Logitech Easy Synchronization - Unknown owner - C:\Programmer\Logitech\Easy Synchronization\servicestub.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Programmer\PC Connectivity Solution\ServiceLayer.exe

    --
    End of file - 9265 bytes

  4. #4
    Junior Member
    Join Date
    Mar 2008
    Posts
    16

    Default

    Aaaand here is the Kaspersky log Thank you for your swift reply :D

    -------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER REPORT
    Monday, March 03, 2008 7:25:14 PM
    Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.98.0
    Kaspersky Anti-Virus database last update: 3/03/2008
    Kaspersky Anti-Virus database records: 594525
    -------------------------------------------------------------------------------

    Scan Settings:
    Scan using the following antivirus database: extended
    Scan Archives: true
    Scan Mail Bases: true

    Scan Target - My Computer:
    A:\
    C:\
    D:\
    E:\

    Scan Statistics:
    Total number of scanned objects: 92184
    Number of viruses found: 0
    Number of infected objects: 0
    Number of suspicious objects: 0
    Duration of the scan process: 01:21:47

    Infected Object Name / Virus Name / Last Action
    C:\Documents and Settings\All Users\Application Data\avg8\AvgAm\avgam.lck Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\avg8\emc\Log\emc.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\avg8\Log\avgam.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\avg8\Log\avgcore.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\avg8\Log\avglng.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\avg8\Log\avgns.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\avg8\Log\avgrs.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\avg8\Log\avgui.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\avg8\Log\avgwd.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\avg8\Log\avgwdsvc.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\LocalService\Lokale indstillinger\Oversigt\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Lokale indstillinger\Temp\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Lokale indstillinger\Temp\Oversigt\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Lokale indstillinger\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Lokale indstillinger\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\Tanja\Application Data\Mozilla\Firefox\Profiles\egstgt4b.default\cert8.db Object is locked skipped
    C:\Documents and Settings\Tanja\Application Data\Mozilla\Firefox\Profiles\egstgt4b.default\history.dat Object is locked skipped
    C:\Documents and Settings\Tanja\Application Data\Mozilla\Firefox\Profiles\egstgt4b.default\key3.db Object is locked skipped
    C:\Documents and Settings\Tanja\Application Data\Mozilla\Firefox\Profiles\egstgt4b.default\parent.lock Object is locked skipped
    C:\Documents and Settings\Tanja\Application Data\Mozilla\Firefox\Profiles\egstgt4b.default\search.sqlite Object is locked skipped
    C:\Documents and Settings\Tanja\Application Data\Mozilla\Firefox\Profiles\egstgt4b.default\urlclassifier2.sqlite Object is locked skipped
    C:\Documents and Settings\Tanja\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\Tanja\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\Tanja\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\Tanja\Lokale indstillinger\Application Data\Mozilla\Firefox\Profiles\egstgt4b.default\Cache\_CACHE_001_ Object is locked skipped
    C:\Documents and Settings\Tanja\Lokale indstillinger\Application Data\Mozilla\Firefox\Profiles\egstgt4b.default\Cache\_CACHE_002_ Object is locked skipped
    C:\Documents and Settings\Tanja\Lokale indstillinger\Application Data\Mozilla\Firefox\Profiles\egstgt4b.default\Cache\_CACHE_003_ Object is locked skipped
    C:\Documents and Settings\Tanja\Lokale indstillinger\Application Data\Mozilla\Firefox\Profiles\egstgt4b.default\Cache\_CACHE_MAP_ Object is locked skipped
    C:\Documents and Settings\Tanja\Lokale indstillinger\Oversigt\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\Tanja\Lokale indstillinger\Oversigt\History.IE5\MSHist012008030320080304\index.dat Object is locked skipped
    C:\Documents and Settings\Tanja\Lokale indstillinger\Temp\ClamWin1.log Object is locked skipped
    C:\Documents and Settings\Tanja\Lokale indstillinger\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\Tanja\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\Tanja\ntuser.dat.LOG Object is locked skipped
    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    C:\System Volume Information\_restore{06B16ED4-AB0D-4ED0-919C-9D613D487F9C}\RP513\A0255412.dll Object is locked skipped
    C:\System Volume Information\_restore{06B16ED4-AB0D-4ED0-919C-9D613D487F9C}\RP515\change.log Object is locked skipped
    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
    C:\WINDOWS\SchedLgU.Txt Object is locked skipped
    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
    C:\WINDOWS\Sti_Trace.log Object is locked skipped
    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\default Object is locked skipped
    C:\WINDOWS\system32\config\default.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SAM Object is locked skipped
    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
    C:\WINDOWS\system32\config\software Object is locked skipped
    C:\WINDOWS\system32\config\software.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\system Object is locked skipped
    C:\WINDOWS\system32\config\system.LOG Object is locked skipped
    C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
    C:\WINDOWS\system32\h323log.txt Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
    C:\WINDOWS\wiadebug.log Object is locked skipped
    C:\WINDOWS\wiaservc.log Object is locked skipped
    C:\WINDOWS\WindowsUpdate.log Object is locked skipped

    Scan process completed.

  5. #5
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    We need first to disable TeaTimer that it doesn't interfere with fixes. You can re-enable it when you're clean again:

    1. Run Spybot-S&D in Advanced Mode.
    2. If it is not already set to do this Go to the Mode menu select "Advanced Mode"
    3. On the left hand side, Click on Tools
    4. Then click on the Resident Icon in the List
    5. Uncheck "Resident TeaTimer" and OK any prompts.
    6. Restart your computer.

    Open HijackThis, click do a system scan only and checkmark this:

    O4 - HKLM\..\Run: [MSN Messenger] live.messenger.com

    Close all windows including browser and press fix checked.

    Reboot.

    Download SDFix and save it to your Desktop.

    Double click SDFix.exe and it will extract the files to %systemdrive%
    (Drive that contains the Windows Directory, typically C:\SDFix)

    Please then reboot your computer in Safe Mode by doing the following :
    • Restart your computer
    • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
    • Instead of Windows loading as normal, the Advanced Options Menu should appear;
    • Select the first option, to run Windows in Safe Mode, then press Enter.
    • Choose your usual account.
    • Open the extracted SDFix folder and double click RunThis.bat to start the script.
    • Type Y to begin the cleanup process.
    • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
    • Press any Key and it will restart the PC.
    • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
      (Report.txt will also be copied to Clipboard ready for posting back on the forum).
    • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log


    Also tell me if this is your preferred home page:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  6. #6
    Junior Member
    Join Date
    Mar 2008
    Posts
    16

    Default

    SDFix report


    SDFix: Version 1.152

    Run by Tanja on 04-03-2008 at 16:22

    Microsoft Windows XP [version 5.1.2600]
    Running From: C:\SDFix

    Checking Services :


    Restoring Windows Registry Values
    Restoring Windows Default Hosts File

    Rebooting


    Checking Files :

    Trojan Files Found:

    C:\WINDOWS\admintxt.txt - Deleted
    C:\WINDOWS\system32\drivers\etc\BackupHosts.bak - Deleted





    Removing Temp Files

    ADS Check :



    Final Check :

    catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-03-04 16:36:42
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden services & system hive ...

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\ESENT]
    "EventMessageFile"=str(2):"c:\windows\system32\ESENT.dll"
    "CategoryMessageFile"=str(2):"c:\windows\system32\ESENT.dll"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
    "s1"=dword:2df9c43f
    "s2"=dword:110480d0
    "h0"=dword:00000001

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
    "p0"="C:\Programmer\DAEMON Tools\"
    "h0"=dword:00000000
    "khjeh"=hex:48,7f,67,72,30,af,00,98,b0,72,72,21,ef,4c,e9,77,67,bc,e4,f0,0e,..

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
    "a0"=hex:20,01,00,00,96,32,20,86,7f,6d,47,8f,82,0c,aa,bc,86,fb,3a,6d,58,..
    "khjeh"=hex:b4,d3,48,e5,35,06,86,a9,97,cd,99,52,65,08,58,f1,05,af,cb,6b,c3,..

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
    "khjeh"=hex:8f,28,af,95,60,7e,41,44,45,17,69,5d,5e,2e,a9,b8,9a,41,4d,cd,55,..
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
    "p0"="C:\Programmer\DAEMON Tools\"
    "h0"=dword:00000000
    "khjeh"=hex:48,7f,67,72,30,af,00,98,b0,72,72,21,ef,4c,e9,77,67,bc,e4,f0,0e,..

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
    "a0"=hex:20,01,00,00,96,32,20,86,7f,6d,47,8f,82,0c,aa,bc,86,fb,3a,6d,58,..
    "khjeh"=hex:b4,d3,48,e5,35,06,86,a9,97,cd,99,52,65,08,58,f1,05,af,cb,6b,c3,..

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
    "khjeh"=hex:8f,28,af,95,60,7e,41,44,45,17,69,5d,5e,2e,a9,b8,9a,41,4d,cd,55,..

    scanning hidden registry entries ...

    scanning hidden files ...

    scan completed successfully
    hidden processes: 0
    hidden services: 0
    hidden files: 0


    Remaining Services :



    Authorized Application Key Export:

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\\Games\\World of Warcraft\\WoW-1.12.0-enGB-downloader.exe"="C:\\Games\\World of Warcraft\\WoW-1.12.0-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
    "C:\\Programmer\\Grisoft\\AVG Free\\avginet.exe"="C:\\Programmer\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
    "C:\\Programmer\\Grisoft\\AVG Free\\avgemc.exe"="C:\\Programmer\\Grisoft\\AVG Free\\avgemc.exe:*:Enabled:avgemc.exe"
    "C:\\Programmer\\VentSrv\\ventrilo_srv.exe"="C:\\Programmer\\VentSrv\\ventrilo_srv.exe:*:Enabled:ventrilo_srv"
    "C:\\Programmer\\Shareaza\\Shareaza.exe"="C:\\Programmer\\Shareaza\\Shareaza.exe:*:Enabled:Shareaza Ultimate File Sharing"
    "C:\\Games\\World of Warcraft\\WoW-1.12.0.5595-to-1.12.1.5875-enGB-downloader.exe"="C:\\Games\\World of Warcraft\\WoW-1.12.0.5595-to-1.12.1.5875-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
    "C:\\Games\\World of Warcraft\\BackgroundDownloader.exe"="C:\\Games\\World of Warcraft\\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader"
    "C:\\Programmer\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"="C:\\Programmer\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe:*:Enabled:DarkCrusade"
    "F:\\Dawn of War\\W40k.exe"="F:\\Dawn of War\\W40k.exe:*:Enabled:W40k"
    "C:\\Games\\World of Warcraft\\WoW-2.0.3-enGB-downloader.exe"="C:\\Games\\World of Warcraft\\WoW-2.0.3-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
    "C:\\Games\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.5.6320-enGB-downloader.exe"="C:\\Games\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.5.6320-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
    "C:\\Games\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enGB-downloader.exe"="C:\\Games\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
    "F:\\Dawn of War\\W40kWA.exe"="F:\\Dawn of War\\W40kWA.exe:*:Enabled:W40kWA"
    "C:\\Games\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enGB-downloader.exe"="C:\\Games\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
    "C:\\Programmer\\Grisoft\\AVG7\\avginet.exe"="C:\\Programmer\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
    "C:\\Programmer\\Grisoft\\AVG7\\avgcc.exe"="C:\\Programmer\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
    "C:\\Programmer\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Programmer\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
    "C:\\Programmer\\eMule\\emule.exe"="C:\\Programmer\\eMule\\emule.exe:*:Enabled:eMule"
    "C:\\Games\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enGB-downloader.exe"="C:\\Games\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enGB-downloader.exe:*:Enabled:Blizzard Downloader"
    "C:\\Programmer\\F‘lles filer\\AOL\\Loader\\aolload.exe"="C:\\Programmer\\F‘lles filer\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
    "C:\\Programmer\\F‘lles filer\\AOL\\1183328871\\ee\\aolsoftware.exe"="C:\\Programmer\\F‘lles filer\\AOL\\1183328871\\ee\\aolsoftware.exe:*:Enabled:AOL Services"
    "C:\\Programmer\\F‘lles filer\\AOL\\1183328871\\ee\\aim6.exe"="C:\\Programmer\\F‘lles filer\\AOL\\1183328871\\ee\\aim6.exe:*:Enabled:AIM"
    "C:\\Programmer\\Xfire\\xfire.exe"="C:\\Programmer\\Xfire\\xfire.exe:*:Enabled:Xfire"
    "C:\\Programmer\\uTorrent\\uTorrent.exe"="C:\\Programmer\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
    "C:\\Games\\Titan Quest\\Titan Quest.exe"="C:\\Games\\Titan Quest\\Titan Quest.exe:*:Disabled:Titan Quest"
    "C:\\Programmer\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Programmer\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
    "C:\\Programmer\\BitTorrent_DNA\\dna.exe"="C:\\Programmer\\BitTorrent_DNA\\dna.exe:*:Enabled:BitTorrent DNA"
    "C:\\Programmer\\BitTorrent\\bittorrent.exe"="C:\\Programmer\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
    "C:\\Programmer\\FlashGet\\flashget.exe"="C:\\Programmer\\FlashGet\\flashget.exe:*:Enabled:Flashget"
    "C:\\Games\\Sacred Underworld\\sacred.exe"="C:\\Games\\Sacred Underworld\\sacred.exe:*:Enabled:Sacred"
    "C:\\Games\\Sacred Underworld\\gameserver.exe"="C:\\Games\\Sacred Underworld\\gameserver.exe:*:Enabled:Sacred Gameserver"
    "C:\\Programmer\\DNA\\btdna.exe"="C:\\Programmer\\DNA\\btdna.exe:*:Enabled:DNA"
    "C:\\Programmer\\Veoh Networks\\Veoh\\VeohClient.exe"="C:\\Programmer\\Veoh Networks\\Veoh\\VeohClient.exe:*:Enabled:Veoh Client"
    "C:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\\Programmer\\Windows Live\\Messenger\\livecall.exe"="C:\\Programmer\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
    "C:\\Programmer\\Skype\\Phone\\Skype.exe"="C:\\Programmer\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
    "C:\\Programmer\\AVG\\AVG8\\avgupd.exe"="C:\\Programmer\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
    "C:\\Programmer\\AVG\\AVG8\\avgemc.exe"="C:\\Programmer\\AVG\\AVG8\\avgemc.exe:*:Enabled:avgemc.exe"
    "C:\\Programmer\\AVG\\AVG8\\avgnsx.exe"="C:\\Programmer\\AVG\\AVG8\\avgnsx.exe:*:Enabled:avgnsx.exe"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\\Programmer\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Programmer\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
    "C:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Programmer\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\\Programmer\\Windows Live\\Messenger\\livecall.exe"="C:\\Programmer\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

    Remaining Files :


    File Backups: - C:\SDFix\backups\backups.zip

    Files with Hidden Attributes :

    Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Programmer\Spybot - Search & Destroy\SDUpdate.exe"
    Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Programmer\Spybot - Search & Destroy\SpybotSD.exe"
    Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe"
    Sun 11 Jan 2004 22,016 A..H. --- "C:\Fra gammel harddisk (Home C)\Misc\Private Eyes Only\~WRL0001.tmp"
    Wed 4 Feb 2004 23,040 A..H. --- "C:\Fra gammel harddisk (Home C)\Misc\Private Eyes Only\~WRL1067.tmp"
    Wed 30 Mar 2005 28,672 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Dansk, SVW\~WRL0003.tmp"
    Fri 25 Mar 2005 24,576 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Dansk, SVW\~WRL0130.tmp"
    Fri 15 Apr 2005 19,968 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Engelsk, JCL\~WRL0003.tmp"
    Fri 15 Apr 2005 24,576 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Engelsk, JCL\~WRL0483.tmp"
    Fri 15 Apr 2005 25,088 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Engelsk, JCL\~WRL0579.tmp"
    Fri 15 Apr 2005 24,576 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Engelsk, JCL\~WRL1247.tmp"
    Fri 15 Apr 2005 24,064 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Engelsk, JCL\~WRL2505.tmp"
    Fri 15 Apr 2005 25,088 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Engelsk, JCL\~WRL2814.tmp"
    Fri 15 Apr 2005 24,064 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Engelsk, JCL\~WRL3000.tmp"
    Fri 15 Apr 2005 25,088 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Engelsk, JCL\~WRL3682.tmp"
    Fri 15 Apr 2005 25,600 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Engelsk, JCL\~WRL3818.tmp"
    Sun 19 Sep 2004 25,088 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\S&S, FK\~WRL0001.tmp"
    Fri 15 Oct 2004 24,064 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\S&S, FK\~WRL2421.tmp"
    Sat 13 Nov 2004 37,376 A..H. --- "C:\Programmer\F‘lles filer\Adobe\ESD\DLMCleanup.exe"
    Wed 23 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\f7db876e78b88fd8276fd7d29cb7e4eb\BIT1.tmp"
    Sun 27 Feb 2005 25,088 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Engelsk\~WRL0002.tmp"
    Fri 15 Apr 2005 19,968 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Engelsk\~WRL0003.tmp"
    Tue 1 Mar 2005 27,648 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Engelsk\~WRL0004.tmp"
    Fri 15 Apr 2005 24,576 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Engelsk\~WRL0483.tmp"
    Fri 15 Apr 2005 25,088 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Engelsk\~WRL0579.tmp"
    Fri 15 Apr 2005 24,576 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Engelsk\~WRL1247.tmp"
    Fri 15 Apr 2005 24,064 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Engelsk\~WRL2505.tmp"
    Fri 15 Apr 2005 25,088 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Engelsk\~WRL2814.tmp"
    Fri 15 Apr 2005 24,064 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Engelsk\~WRL3000.tmp"
    Fri 15 Apr 2005 25,088 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Engelsk\~WRL3682.tmp"
    Fri 15 Apr 2005 25,600 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Engelsk\~WRL3818.tmp"
    Sun 19 Sep 2004 25,088 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\~WRL0001.tmp"
    Fri 15 Oct 2004 24,064 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\~WRL2421.tmp"
    Fri 18 Mar 2005 74,752 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Tysk\~WRL0156.tmp"
    Fri 18 Mar 2005 131,072 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Tysk\~WRL0721.tmp"
    Fri 18 Mar 2005 29,696 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Tysk\~WRL1510.tmp"
    Fri 18 Mar 2005 131,072 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Tysk\~WRL2060.tmp"
    Fri 18 Mar 2005 86,528 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Tysk\~WRL2554.tmp"
    Fri 18 Mar 2005 37,376 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Tysk\~WRL3325.tmp"
    Fri 18 Mar 2005 131,072 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Tysk\~WRL3536.tmp"
    Fri 18 Mar 2005 38,912 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Tysk\~WRL3547.tmp"
    Fri 18 Mar 2005 177,152 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Tysk\~WRL3691.tmp"
    Fri 18 Mar 2005 38,912 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Tysk\~WRL3933.tmp"
    Fri 18 Mar 2005 74,752 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\Tysk\~WRL4013.tmp"
    Sun 22 May 2005 30,208 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\VOF\~WRL0001.tmp"
    Mon 30 May 2005 39,424 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\IT\Til fremlaegningen\~WRL0001.tmp"
    Tue 31 May 2005 40,448 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\IT\Til fremlaegningen\~WRL0004.tmp"
    Tue 31 May 2005 40,960 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\IT\Til fremlaegningen\~WRL0327.tmp"
    Tue 31 May 2005 42,496 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\IT\Til fremlaegningen\~WRL0916.tmp"
    Tue 31 May 2005 41,472 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\IT\Til fremlaegningen\~WRL1122.tmp"
    Tue 31 May 2005 41,984 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\IT\Til fremlaegningen\~WRL1515.tmp"
    Tue 31 May 2005 40,448 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\IT\Til fremlaegningen\~WRL1732.tmp"
    Tue 31 May 2005 40,448 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\IT\Til fremlaegningen\~WRL1976.tmp"
    Tue 31 May 2005 41,472 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\IT\Til fremlaegningen\~WRL3387.tmp"
    Sat 23 Apr 2005 57,344 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0020.tmp"
    Sat 23 Apr 2005 60,416 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0037.tmp"
    Sat 23 Apr 2005 57,344 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0101.tmp"
    Sat 23 Apr 2005 57,856 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0145.tmp"
    Sat 23 Apr 2005 56,832 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0309.tmp"
    Sat 23 Apr 2005 57,344 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0505.tmp"

  7. #7
    Junior Member
    Join Date
    Mar 2008
    Posts
    16

    Default

    Sat 23 Apr 2005 59,904 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0536.tmp"
    Sat 23 Apr 2005 58,368 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0615.tmp"
    Sat 23 Apr 2005 55,296 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0670.tmp"
    Sat 23 Apr 2005 60,928 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0699.tmp"
    Fri 22 Apr 2005 54,272 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0785.tmp"
    Sat 23 Apr 2005 60,416 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0853.tmp"
    Sat 23 Apr 2005 56,832 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0876.tmp"
    Sat 23 Apr 2005 57,856 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL0995.tmp"
    Sat 23 Apr 2005 57,856 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL1008.tmp"
    Sat 23 Apr 2005 59,392 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL1069.tmp"
    Sat 23 Apr 2005 60,928 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL1426.tmp"
    Sat 23 Apr 2005 58,880 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL1697.tmp"
    Sat 23 Apr 2005 60,928 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL1872.tmp"
    Sat 23 Apr 2005 56,832 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL1988.tmp"
    Sat 23 Apr 2005 56,832 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2052.tmp"
    Sat 23 Apr 2005 58,880 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2053.tmp"
    Sat 23 Apr 2005 56,832 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2063.tmp"
    Sat 23 Apr 2005 60,928 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2169.tmp"
    Sat 23 Apr 2005 57,856 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2177.tmp"
    Sat 23 Apr 2005 57,856 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2221.tmp"
    Sat 23 Apr 2005 58,880 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2351.tmp"
    Sat 23 Apr 2005 55,808 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2456.tmp"
    Sat 23 Apr 2005 55,808 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2474.tmp"
    Sat 23 Apr 2005 26,624 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2567.tmp"
    Sat 23 Apr 2005 56,320 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2713.tmp"
    Sat 23 Apr 2005 57,856 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2749.tmp"
    Sat 23 Apr 2005 59,904 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2756.tmp"
    Sat 23 Apr 2005 55,808 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2769.tmp"
    Sat 23 Apr 2005 57,344 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2881.tmp"
    Sat 23 Apr 2005 60,928 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL2916.tmp"
    Sat 23 Apr 2005 26,624 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3015.tmp"
    Sat 23 Apr 2005 60,928 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3150.tmp"
    Sat 23 Apr 2005 56,832 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3207.tmp"
    Sat 23 Apr 2005 55,808 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3290.tmp"
    Sat 23 Apr 2005 60,928 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3326.tmp"
    Sat 23 Apr 2005 60,416 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3369.tmp"
    Sat 23 Apr 2005 60,928 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3518.tmp"
    Sat 23 Apr 2005 57,856 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3870.tmp"
    Sat 23 Apr 2005 57,856 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3871.tmp"
    Sat 23 Apr 2005 59,392 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3872.tmp"
    Sat 23 Apr 2005 55,296 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3906.tmp"
    Sat 23 Apr 2005 60,416 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3978.tmp"
    Sat 23 Apr 2005 60,416 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL3979.tmp"
    Sat 23 Apr 2005 60,928 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL4061.tmp"
    Sat 23 Apr 2005 55,808 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL4074.tmp"
    Sat 23 Apr 2005 55,808 A..H. --- "C:\Fra gammel harddisk (Home C)\Niels Brock, HGV 1\Niels Brock 2004 - 2005\Fra Mighty Drive\S&S\Salg og Service - Horizon Hill\~WRL4094.tmp"

    Finished!

  8. #8
    Junior Member
    Join Date
    Mar 2008
    Posts
    16

    Default

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 16:44:46, on 04-03-2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Programmer\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\Programmer\Fælles filer\Logitech\Bluetooth\LBTSERV.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Programmer\Logitech\Easy Synchronization\servicestub.exe
    C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Programmer\Canon\CAL\CALMAIN.exe
    C:\PROGRA~1\AVG\AVG8\avgam.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe
    C:\Programmer\Fælles filer\Logitech\G-series Software\LGDCore.exe
    C:\Programmer\Logitech\SetPoint\LBTWiz.exe
    C:\Programmer\ClamWin\bin\ClamTray.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programmer\DAEMON Tools\daemon.exe
    C:\Programmer\DNA\btdna.exe
    C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Programmer\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Programmer\Logitech\SetPoint\SetPoint.exe
    C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
    C:\Programmer\OpenOffice.org 2.2\program\soffice.exe
    C:\Programmer\OpenOffice.org 2.2\program\soffice.BIN
    C:\Programmer\Fælles filer\Logishrd\KHAL2\KHALMNPR.EXE
    C:\Programmer\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://netbank.danskebank.dk/html/index.html?site=DBNB
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.zitech.dk
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programmer\AVG\AVG8\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: CVirtualDNSObj Object - {86C510E9-97EF-4749-914F-0280247BE3A6} - C:\WINDOWS\VirtualDNS.dll (file missing)
    O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programmer\AVG\AVG8\avgtoolbar.dll
    O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Programmer\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
    O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Programmer\AVG\AVG8\avgtoolbar.dll
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Easy Synchronization] C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe
    O4 - HKLM\..\Run: [Launch LGDCore] "C:\Programmer\Fælles filer\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
    O4 - HKLM\..\Run: [Bluetooth Connection Assistant] LBTWIZ.EXE -silent
    O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
    O4 - HKLM\..\Run: [ClamWin] "C:\Programmer\ClamWin\bin\ClamTray.exe" --logon
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\RunOnce: [Easy Synchronization] C:\Programmer\Logitech\Easy Synchronization\LogitechEasySync.exe --ports
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Programmer\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Programmer\DNA\btdna.exe"
    O4 - HKCU\..\Run: [LDM] C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: OpenOffice.org 2.2.lnk = C:\Programmer\OpenOffice.org 2.2\program\quickstart.exe
    O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Bluetooth.lnk = ?
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programmer\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Logitech SetPoint.lnk = ?
    O8 - Extra context menu item: &Search - ?p=ZJfox000
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmer\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.zitech.dk
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/.../GAME_UNO1.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
    O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/a.../e-Safekey.cab
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programmer\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programmer\AVG\AVG8\avgpp.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FLLESF~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: avgrsstx.dll
    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmer\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Programmer\Canon\CAL\CALMAIN.exe
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Programmer\Fælles filer\Logitech\Bluetooth\LBTSERV.EXE
    O23 - Service: Logitech Easy Synchronization - Unknown owner - C:\Programmer\Logitech\Easy Synchronization\servicestub.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Programmer\PC Connectivity Solution\ServiceLayer.exe

    --
    End of file - 9304 bytes

  9. #9
    Junior Member
    Join Date
    Mar 2008
    Posts
    16

    Default

    To answer your question about my preferred home page I have to say I'm a bit baffled. I use Mozilla Firefox as my regular browser, where I have a personalized Google.com as my home page. I do have IE installed and use it for net banking. And the home page of my bank is my start up page in IE. That link/site it mentions... I don't know anything about it.

    My PC has for a reeeheeeally long time randomly crashed to a blue screen with a lot of nonsense info on it... Could that have something to do with that link/site you're asking about?

  10. #10
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    "To answer your question about my preferred home page I have to say I'm a bit baffled. I use Mozilla Firefox as my regular browser, where I have a personalized Google.com as my home page. I do have IE installed and use it for net banking. And the home page of my bank is my start up page in IE. That link/site it mentions... I don't know anything about it.
    "

    Thanks for the info.

    "My PC has for a reeeheeeally long time randomly crashed to a blue screen with a lot of nonsense info on it... Could that have something to do with that link/site you're asking about?"

    Likely a hardware issue. What is the temperature of your CPU?

    Open HijackThis, click do a system scan only and checkmark these:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    O2 - BHO: CVirtualDNSObj Object - {86C510E9-97EF-4749-914F-0280247BE3A6} - C:\WINDOWS\VirtualDNS.dll (file missing)
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE


    Close all windows includiung browser and press fix checked.

    Reboot.

    Post back a fresh HijackThis log.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •