Cid Highwind
New member
I partially removed that "Antivirus XP 2008" Malware using Spybot S&D and Malwarebytes' Anti-Malware. Spybot didn't seem that successful in trying to remove it, it kept saying it got rid of the problems while it didn't.
Here is my HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:28:54 PM, on 8/30/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\All Users\Application Data\zevkxwds\fulcxmts.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\bexstefw.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.6.26.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [cfghlpstr] C:\WINDOWS\system32\bexstefw.exe
O4 - HKCU\..\Run: [uicomapl] C:\WINDOWS\system32\fkbqzwzk.exe
O4 - HKCU\..\Run: [apichkmon] C:\WINDOWS\system32\vwzgtuhy.exe
O4 - HKCU\..\Run: [admmsg] C:\WINDOWS\system32\knwrynav.exe
O4 - HKLM\..\Policies\Explorer\Run: [dc7vryB54f] C:\Documents and Settings\All Users\Application Data\zevkxwds\fulcxmts.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.6.26.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 4812 bytes
And here is my Combofix Log:
ComboFix 08-08-29.02 - Hierophant Driud 2008-08-30 15:21:14.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3210 [GMT 2:00]
Running from: C:\Documents and Settings\Hierophant Driud\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-07-28 to 2008-08-30 )))))))))))))))))))))))))))))))
.
2008-08-30 15:17 . 2008-08-30 15:17 86,016 --a------ C:\WINDOWS\system32\knwrynav.exe
2008-08-30 14:43 . 2008-08-30 14:43 86,016 --a------ C:\WINDOWS\system32\vwzgtuhy.exe
2008-08-30 14:39 . 2008-08-30 14:39 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-30 14:39 . 2008-08-30 14:39 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\Malwarebytes
2008-08-30 14:39 . 2008-08-30 14:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-30 14:39 . 2008-08-17 15:04 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-30 14:39 . 2008-08-17 15:04 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-30 14:22 . 2008-08-30 14:22 86,016 --a------ C:\WINDOWS\system32\fkbqzwzk.exe
2008-08-30 13:59 . 2008-08-30 13:59 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-30 13:59 . 2008-08-30 14:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-30 13:52 . 2008-08-30 13:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\zevkxwds
2008-08-30 13:52 . 2008-08-30 13:52 86,016 --a------ C:\WINDOWS\system32\bexstefw.exe
2008-08-30 13:50 . 2007-07-11 14:06 42,672 --------- C:\WINDOWS\system32\wbsys.dll
2008-08-30 13:48 . 2008-08-30 13:55 <DIR> d-------- C:\Program Files\BitComet
2008-08-30 13:46 . 2008-08-30 13:46 <DIR> d-------- C:\Program Files\VideoLAN
2008-08-30 13:46 . 2008-08-30 13:46 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\vlc
2008-08-29 23:33 . 2008-08-30 14:20 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Contacts
2008-08-29 23:21 . 2008-08-29 23:21 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-08-29 23:20 . 2008-08-29 23:21 <DIR> d-------- C:\Program Files\Windows Live
2008-08-29 23:20 . 2008-08-29 23:21 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-29 23:20 . 2008-08-29 23:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-29 22:12 . 2008-08-29 22:12 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\Media Player Classic
2008-08-29 22:05 . 2008-08-29 22:05 <DIR> d-------- C:\WINDOWS\system32\Lang
2008-08-29 22:05 . 2008-08-29 22:05 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav
2008-08-29 22:05 . 2008-08-29 22:05 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav
2008-08-29 20:39 . 2008-04-14 01:45 26,368 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-08-29 20:31 . 2008-08-29 20:31 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\InstallShield
2008-08-29 20:31 . 2006-11-07 12:28 356,352 --a------ C:\WINDOWS\system32\nvunrm.exe
2008-08-29 20:31 . 2006-06-07 16:19 208,896 --a------ C:\WINDOWS\system32\nvusmb.exe
2008-08-29 20:31 . 2006-10-19 07:06 3,903 --a------ C:\WINDOWS\system32\nvnrm.nvu
2008-08-29 20:31 . 2006-06-01 12:02 1,864 --a------ C:\WINDOWS\system32\nvsmb.nvu
2008-08-29 20:31 . 2006-10-05 10:37 1,428 --a------ C:\WINDOWS\system32\drivers\nvphy.bin
2008-08-29 20:22 . 2008-08-29 20:22 <DIR> d-------- C:\WINDOWS\nview
2008-08-29 20:22 . 2008-08-29 20:22 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-08-29 20:22 . 2008-05-16 09:18 446,464 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-08-29 20:22 . 2008-05-16 11:31 446,464 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-08-29 20:22 . 2008-08-30 15:16 186,097 --a------ C:\WINDOWS\system32\nvapps.xml
2008-08-29 20:22 . 2008-05-16 11:31 18,070 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-08-29 20:20 . 2008-08-29 20:20 0 --a------ C:\WINDOWS\nsreg.dat
2008-08-29 20:12 . 2008-08-30 14:41 <DIR> d-------- C:\Documents and Settings\Hierophant Driud
2008-08-29 20:08 . 2008-08-29 20:08 <DIR> d---s---- C:\WINDOWS\system32\Microsoft
2008-08-29 20:08 . 2008-08-29 20:08 <DIR> d--hs---- C:\Documents and Settings\LocalService
2008-08-29 20:05 . 2008-08-30 15:19 <DIR> d--hs---- C:\Documents and Settings\NetworkService
2008-08-29 20:05 . 2008-08-29 20:05 8,192 --a------ C:\WINDOWS\REGLOCS.OLD
2008-08-29 20:02 . 2008-08-29 20:02 <DIR> d-------- C:\WINDOWS\system32\xircom
2008-08-29 20:02 . 2008-08-29 20:02 <DIR> d-------- C:\Program Files\microsoft frontpage
2008-08-29 20:01 . 2008-08-29 20:01 316,640 --a------ C:\WINDOWS\WMSysPr9.prx
2008-08-29 20:01 . 2008-08-29 20:01 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2008-08-29 20:01 . 2008-08-29 20:01 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2008-08-29 20:01 . 2008-08-29 20:01 2,577 --a------ C:\WINDOWS\system32\CONFIG.NT
2008-08-29 20:01 . 2008-08-29 20:01 0 --a------ C:\WINDOWS\control.ini
2008-08-29 20:00 . 2008-08-30 13:45 <DIR> d--hs---- C:\Documents and Settings\All Users\DRM
2008-08-18 10:57 . 2008-08-18 10:57 34,312 --a------ C:\WINDOWS\system32\drivers\epfwtdir.sys
2008-08-18 10:49 . 2008-08-18 10:49 53,256 --a------ C:\WINDOWS\system32\drivers\easdrv.sys
2008-08-18 10:48 . 2008-08-18 10:48 39,944 --a------ C:\WINDOWS\system32\drivers\eamon.sys
2008-07-12 21:24 . 2008-07-12 21:24 2,603,008 --a------ C:\WINDOWS\system32\wpdshext.dll
2008-07-12 21:20 . 2008-07-12 21:20 1,614,848 --a------ C:\WINDOWS\system32\sfcfiles.dll
2008-07-12 21:09 . 2008-07-12 21:09 1,288,192 --a------ C:\WINDOWS\system32\quartz.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-29 19:56 319,488 ----a-w C:\WINDOWS\HideWin.exe
2008-08-29 19:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-29 19:56 --------- d-----w C:\Program Files\Realtek
2008-08-29 19:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Last.fm
2008-08-29 19:44 --------- d-----w C:\Program Files\Last.fm
2008-08-29 19:43 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-08-29 19:34 --------- d-----w C:\Documents and Settings\Hierophant Driud\Application Data\Winamp
2008-08-29 19:33 --------- d-----w C:\Program Files\Winamp
2008-08-29 19:30 --------- d-----w C:\Program Files\CCleaner
2008-08-29 19:28 --------- d-----w C:\Program Files\IZArc
2008-08-29 19:17 --------- d-----w C:\Program Files\ESET
2008-08-29 19:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-08-29 17:58 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-08-12 14:10 4,751,360 ----a-w C:\WINDOWS\system32\drivers\RtkHDAud.sys
2008-08-06 13:51 1,200,128 ----a-w C:\WINDOWS\RtlUpd.exe
2008-07-31 13:05 16,806,912 ----a-w C:\WINDOWS\RTHDCPL.EXE
2008-07-29 13:42 528,384 ----a-w C:\WINDOWS\RtlExUpd.dll
2008-07-12 19:24 991,744 ----a-w C:\WINDOWS\system32\drmv2clt.dll
2008-07-12 19:19 80,128 ----a-w C:\WINDOWS\system32\drivers\parport.sys
2008-07-12 19:18 86,073 ----a-w C:\WINDOWS\system32\usrfaxa.dll
2008-07-12 19:10 990,208 ----a-w C:\WINDOWS\system32\syssetup.dll
2008-07-12 19:10 78,336 ----a-w C:\WINDOWS\system32\ieencode.dll
2008-07-12 19:10 55,296 ----a-w C:\WINDOWS\system32\iesetup.dll
2008-07-12 19:10 48,128 ----a-w C:\WINDOWS\system32\mshtmler.dll
2008-07-12 19:10 45,568 ----a-w C:\WINDOWS\system32\mshta.exe
2008-07-12 19:10 40,960 ----a-w C:\WINDOWS\system32\licmgr10.dll
2008-07-12 19:10 36,352 ----a-w C:\WINDOWS\system32\imgutil.dll
2008-07-12 19:10 26,112 ----a-w C:\WINDOWS\system32\idndl.dll
2008-07-12 19:10 24,576 ----a-w C:\WINDOWS\system32\nlsdl.dll
2008-07-12 19:10 23,552 ----a-w C:\WINDOWS\system32\normaliz.dll
2008-07-12 19:10 156,160 ----a-w C:\WINDOWS\system32\msls31.dll
2008-06-19 14:42 2,808,832 ----a-w C:\WINDOWS\ALCWZRD.EXE
2008-06-19 14:27 9,715,200 ----a-w C:\WINDOWS\RTLCPL.EXE
2008-06-19 14:20 57,344 ----a-w C:\WINDOWS\ALCMTR.EXE
2008-06-18 16:01 77,824 ----a-w C:\WINDOWS\SOUNDMAN.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 10:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"cfghlpstr"="C:\WINDOWS\system32\bexstefw.exe" [2008-08-30 13:52 86016]
"uicomapl"="C:\WINDOWS\system32\fkbqzwzk.exe" [2008-08-30 14:22 86016]
"apichkmon"="C:\WINDOWS\system32\vwzgtuhy.exe" [2008-08-30 14:43 86016]
"admmsg"="C:\WINDOWS\system32\knwrynav.exe" [2008-08-30 15:17 86016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 10:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 10:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 10:00 455168]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-16 11:31 13529088]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-16 11:31 86016]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-08-18 10:53 1447168]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-08-04 01:02 36352]
"nwiz"="nwiz.exe" [2008-05-16 11:31 1630208 C:\WINDOWS\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-31 15:05 16806912 C:\WINDOWS\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"dc7vryB54f"="C:\Documents and Settings\All Users\Application Data\zevkxwds\fulcxmts.exe" [2008-08-30 13:52 69632]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Antivirus"=C:\Program Files\SAV\sav.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Antivirus"=C:\Program Files\SAV\sav.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"14376:TCP"= 14376:TCP:BitComet 14376 TCP
"14376:UDP"= 14376:UDP:BitComet 14376 UDP
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-08-18 10:57]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Hierophant Driud\Application Data\Mozilla\Firefox\Profiles\qfim5rjr.default\
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-30 15:21:55
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-30 15:22:17
ComboFix-quarantined-files.txt 2008-08-30 13:22:15
ComboFix2.txt 2008-08-30 13:19:35
Pre-Run: 49,871,171,584 bytes free
Post-Run: 49,860,231,168 bytes free
171
Sorry for the double post, but I didn't see an edit button, which made it hard not to double post for an edit.
I just would like to add that from the Antivirus 2008 almost every annoying thing is gone, except that Firewall warning that pops up every 5-10 minutes saying I am being attacked by something, and then an option to Enable it.
Apart from that Spybot S&D still keeps finding the popular Smitfraud-C.
Sorry for not properly introducing myself as well, and saying hi, this malware is just really annoying, I saw a lot of people that share my problem but according to the Introduction FAQs that I read it said that the solution the Mods post are almost always the solution for that specific person with his specific pc stats. So that's why I decided to post this topic.
New information: All files keep returning, and when Windows keeps starting up my Nod32 keeps saying it blocked and deleted a certain Trojan, but it keeps doing it whenever I restart so i'm quite confused with all this.
Thanks
-------------------------------------
Do NOT run 'FIXES' before helpers have analyzed HJT log
Here is my HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:28:54 PM, on 8/30/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\All Users\Application Data\zevkxwds\fulcxmts.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\bexstefw.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.6.26.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [cfghlpstr] C:\WINDOWS\system32\bexstefw.exe
O4 - HKCU\..\Run: [uicomapl] C:\WINDOWS\system32\fkbqzwzk.exe
O4 - HKCU\..\Run: [apichkmon] C:\WINDOWS\system32\vwzgtuhy.exe
O4 - HKCU\..\Run: [admmsg] C:\WINDOWS\system32\knwrynav.exe
O4 - HKLM\..\Policies\Explorer\Run: [dc7vryB54f] C:\Documents and Settings\All Users\Application Data\zevkxwds\fulcxmts.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.6.26.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 4812 bytes
And here is my Combofix Log:
ComboFix 08-08-29.02 - Hierophant Driud 2008-08-30 15:21:14.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3210 [GMT 2:00]
Running from: C:\Documents and Settings\Hierophant Driud\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-07-28 to 2008-08-30 )))))))))))))))))))))))))))))))
.
2008-08-30 15:17 . 2008-08-30 15:17 86,016 --a------ C:\WINDOWS\system32\knwrynav.exe
2008-08-30 14:43 . 2008-08-30 14:43 86,016 --a------ C:\WINDOWS\system32\vwzgtuhy.exe
2008-08-30 14:39 . 2008-08-30 14:39 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-30 14:39 . 2008-08-30 14:39 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\Malwarebytes
2008-08-30 14:39 . 2008-08-30 14:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-30 14:39 . 2008-08-17 15:04 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-30 14:39 . 2008-08-17 15:04 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-30 14:22 . 2008-08-30 14:22 86,016 --a------ C:\WINDOWS\system32\fkbqzwzk.exe
2008-08-30 13:59 . 2008-08-30 13:59 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-30 13:59 . 2008-08-30 14:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-30 13:52 . 2008-08-30 13:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\zevkxwds
2008-08-30 13:52 . 2008-08-30 13:52 86,016 --a------ C:\WINDOWS\system32\bexstefw.exe
2008-08-30 13:50 . 2007-07-11 14:06 42,672 --------- C:\WINDOWS\system32\wbsys.dll
2008-08-30 13:48 . 2008-08-30 13:55 <DIR> d-------- C:\Program Files\BitComet
2008-08-30 13:46 . 2008-08-30 13:46 <DIR> d-------- C:\Program Files\VideoLAN
2008-08-30 13:46 . 2008-08-30 13:46 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\vlc
2008-08-29 23:33 . 2008-08-30 14:20 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Contacts
2008-08-29 23:21 . 2008-08-29 23:21 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-08-29 23:20 . 2008-08-29 23:21 <DIR> d-------- C:\Program Files\Windows Live
2008-08-29 23:20 . 2008-08-29 23:21 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-29 23:20 . 2008-08-29 23:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-29 22:12 . 2008-08-29 22:12 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\Media Player Classic
2008-08-29 22:05 . 2008-08-29 22:05 <DIR> d-------- C:\WINDOWS\system32\Lang
2008-08-29 22:05 . 2008-08-29 22:05 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav
2008-08-29 22:05 . 2008-08-29 22:05 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav
2008-08-29 20:39 . 2008-04-14 01:45 26,368 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-08-29 20:31 . 2008-08-29 20:31 <DIR> d-------- C:\Documents and Settings\Hierophant Driud\Application Data\InstallShield
2008-08-29 20:31 . 2006-11-07 12:28 356,352 --a------ C:\WINDOWS\system32\nvunrm.exe
2008-08-29 20:31 . 2006-06-07 16:19 208,896 --a------ C:\WINDOWS\system32\nvusmb.exe
2008-08-29 20:31 . 2006-10-19 07:06 3,903 --a------ C:\WINDOWS\system32\nvnrm.nvu
2008-08-29 20:31 . 2006-06-01 12:02 1,864 --a------ C:\WINDOWS\system32\nvsmb.nvu
2008-08-29 20:31 . 2006-10-05 10:37 1,428 --a------ C:\WINDOWS\system32\drivers\nvphy.bin
2008-08-29 20:22 . 2008-08-29 20:22 <DIR> d-------- C:\WINDOWS\nview
2008-08-29 20:22 . 2008-08-29 20:22 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-08-29 20:22 . 2008-05-16 09:18 446,464 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-08-29 20:22 . 2008-05-16 11:31 446,464 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-08-29 20:22 . 2008-08-30 15:16 186,097 --a------ C:\WINDOWS\system32\nvapps.xml
2008-08-29 20:22 . 2008-05-16 11:31 18,070 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-08-29 20:20 . 2008-08-29 20:20 0 --a------ C:\WINDOWS\nsreg.dat
2008-08-29 20:12 . 2008-08-30 14:41 <DIR> d-------- C:\Documents and Settings\Hierophant Driud
2008-08-29 20:08 . 2008-08-29 20:08 <DIR> d---s---- C:\WINDOWS\system32\Microsoft
2008-08-29 20:08 . 2008-08-29 20:08 <DIR> d--hs---- C:\Documents and Settings\LocalService
2008-08-29 20:05 . 2008-08-30 15:19 <DIR> d--hs---- C:\Documents and Settings\NetworkService
2008-08-29 20:05 . 2008-08-29 20:05 8,192 --a------ C:\WINDOWS\REGLOCS.OLD
2008-08-29 20:02 . 2008-08-29 20:02 <DIR> d-------- C:\WINDOWS\system32\xircom
2008-08-29 20:02 . 2008-08-29 20:02 <DIR> d-------- C:\Program Files\microsoft frontpage
2008-08-29 20:01 . 2008-08-29 20:01 316,640 --a------ C:\WINDOWS\WMSysPr9.prx
2008-08-29 20:01 . 2008-08-29 20:01 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2008-08-29 20:01 . 2008-08-29 20:01 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2008-08-29 20:01 . 2008-08-29 20:01 2,577 --a------ C:\WINDOWS\system32\CONFIG.NT
2008-08-29 20:01 . 2008-08-29 20:01 0 --a------ C:\WINDOWS\control.ini
2008-08-29 20:00 . 2008-08-30 13:45 <DIR> d--hs---- C:\Documents and Settings\All Users\DRM
2008-08-18 10:57 . 2008-08-18 10:57 34,312 --a------ C:\WINDOWS\system32\drivers\epfwtdir.sys
2008-08-18 10:49 . 2008-08-18 10:49 53,256 --a------ C:\WINDOWS\system32\drivers\easdrv.sys
2008-08-18 10:48 . 2008-08-18 10:48 39,944 --a------ C:\WINDOWS\system32\drivers\eamon.sys
2008-07-12 21:24 . 2008-07-12 21:24 2,603,008 --a------ C:\WINDOWS\system32\wpdshext.dll
2008-07-12 21:20 . 2008-07-12 21:20 1,614,848 --a------ C:\WINDOWS\system32\sfcfiles.dll
2008-07-12 21:09 . 2008-07-12 21:09 1,288,192 --a------ C:\WINDOWS\system32\quartz.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-29 19:56 319,488 ----a-w C:\WINDOWS\HideWin.exe
2008-08-29 19:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-29 19:56 --------- d-----w C:\Program Files\Realtek
2008-08-29 19:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Last.fm
2008-08-29 19:44 --------- d-----w C:\Program Files\Last.fm
2008-08-29 19:43 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-08-29 19:34 --------- d-----w C:\Documents and Settings\Hierophant Driud\Application Data\Winamp
2008-08-29 19:33 --------- d-----w C:\Program Files\Winamp
2008-08-29 19:30 --------- d-----w C:\Program Files\CCleaner
2008-08-29 19:28 --------- d-----w C:\Program Files\IZArc
2008-08-29 19:17 --------- d-----w C:\Program Files\ESET
2008-08-29 19:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-08-29 17:58 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-08-12 14:10 4,751,360 ----a-w C:\WINDOWS\system32\drivers\RtkHDAud.sys
2008-08-06 13:51 1,200,128 ----a-w C:\WINDOWS\RtlUpd.exe
2008-07-31 13:05 16,806,912 ----a-w C:\WINDOWS\RTHDCPL.EXE
2008-07-29 13:42 528,384 ----a-w C:\WINDOWS\RtlExUpd.dll
2008-07-12 19:24 991,744 ----a-w C:\WINDOWS\system32\drmv2clt.dll
2008-07-12 19:19 80,128 ----a-w C:\WINDOWS\system32\drivers\parport.sys
2008-07-12 19:18 86,073 ----a-w C:\WINDOWS\system32\usrfaxa.dll
2008-07-12 19:10 990,208 ----a-w C:\WINDOWS\system32\syssetup.dll
2008-07-12 19:10 78,336 ----a-w C:\WINDOWS\system32\ieencode.dll
2008-07-12 19:10 55,296 ----a-w C:\WINDOWS\system32\iesetup.dll
2008-07-12 19:10 48,128 ----a-w C:\WINDOWS\system32\mshtmler.dll
2008-07-12 19:10 45,568 ----a-w C:\WINDOWS\system32\mshta.exe
2008-07-12 19:10 40,960 ----a-w C:\WINDOWS\system32\licmgr10.dll
2008-07-12 19:10 36,352 ----a-w C:\WINDOWS\system32\imgutil.dll
2008-07-12 19:10 26,112 ----a-w C:\WINDOWS\system32\idndl.dll
2008-07-12 19:10 24,576 ----a-w C:\WINDOWS\system32\nlsdl.dll
2008-07-12 19:10 23,552 ----a-w C:\WINDOWS\system32\normaliz.dll
2008-07-12 19:10 156,160 ----a-w C:\WINDOWS\system32\msls31.dll
2008-06-19 14:42 2,808,832 ----a-w C:\WINDOWS\ALCWZRD.EXE
2008-06-19 14:27 9,715,200 ----a-w C:\WINDOWS\RTLCPL.EXE
2008-06-19 14:20 57,344 ----a-w C:\WINDOWS\ALCMTR.EXE
2008-06-18 16:01 77,824 ----a-w C:\WINDOWS\SOUNDMAN.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 10:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"cfghlpstr"="C:\WINDOWS\system32\bexstefw.exe" [2008-08-30 13:52 86016]
"uicomapl"="C:\WINDOWS\system32\fkbqzwzk.exe" [2008-08-30 14:22 86016]
"apichkmon"="C:\WINDOWS\system32\vwzgtuhy.exe" [2008-08-30 14:43 86016]
"admmsg"="C:\WINDOWS\system32\knwrynav.exe" [2008-08-30 15:17 86016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 10:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 10:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 10:00 455168]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-16 11:31 13529088]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-16 11:31 86016]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-08-18 10:53 1447168]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-08-04 01:02 36352]
"nwiz"="nwiz.exe" [2008-05-16 11:31 1630208 C:\WINDOWS\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-31 15:05 16806912 C:\WINDOWS\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"dc7vryB54f"="C:\Documents and Settings\All Users\Application Data\zevkxwds\fulcxmts.exe" [2008-08-30 13:52 69632]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Antivirus"=C:\Program Files\SAV\sav.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Antivirus"=C:\Program Files\SAV\sav.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"14376:TCP"= 14376:TCP:BitComet 14376 TCP
"14376:UDP"= 14376:UDP:BitComet 14376 UDP
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-08-18 10:57]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Hierophant Driud\Application Data\Mozilla\Firefox\Profiles\qfim5rjr.default\
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-30 15:21:55
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-30 15:22:17
ComboFix-quarantined-files.txt 2008-08-30 13:22:15
ComboFix2.txt 2008-08-30 13:19:35
Pre-Run: 49,871,171,584 bytes free
Post-Run: 49,860,231,168 bytes free
171
Sorry for the double post, but I didn't see an edit button, which made it hard not to double post for an edit.
I just would like to add that from the Antivirus 2008 almost every annoying thing is gone, except that Firewall warning that pops up every 5-10 minutes saying I am being attacked by something, and then an option to Enable it.
Apart from that Spybot S&D still keeps finding the popular Smitfraud-C.
Sorry for not properly introducing myself as well, and saying hi, this malware is just really annoying, I saw a lot of people that share my problem but according to the Introduction FAQs that I read it said that the solution the Mods post are almost always the solution for that specific person with his specific pc stats. So that's why I decided to post this topic.
New information: All files keep returning, and when Windows keeps starting up my Nod32 keeps saying it blocked and deleted a certain Trojan, but it keeps doing it whenever I restart so i'm quite confused with all this.
Thanks
-------------------------------------
Do NOT run 'FIXES' before helpers have analyzed HJT log
Last edited by a moderator: