Topic:IE pop ups & virii Remainpoint:0
   
PostTime:12/16/2008 10:13:12 AM FloorTop
Lv is 1
Avatar
Level:
1
Professional point:
66
Experience:
1
Thread:
278
Post:
1007
Total online time:
1M
Joined date:
4/28/2007 11:31:00 PM
Last Visit:
12/16/2008 11:35:07 PM
Status:
Online
My initial problem was that I was getting IE pop ups while using Firefox.

I also notice that when I open IE (which I rarely use), I get a message that it can't connect to the internet.

I'm at work now and can't run the hijackthis scan until tonight so I figured I'd post the following scan that I did last night which found lots of bad stuff:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/24/2007 at 10:35 PM

Application Version : 3.9.1008

Core Rules Database Version : 3312
Trace Rules Database Version: 1315

Scan type : Complete Scan
Total Scan Time : 01:13:02

Memory items scanned : 379
Memory threats detected : 3
Registry items scanned : 5414
Registry threats detected : 36
File items scanned : 31417
File threats detected : 13

Adware.Vundo Variant/Resident
C:\WINDOWS\SYSTEM32\CBXVVTR.DLL
C:\WINDOWS\SYSTEM32\CBXVVTR.DLL

Trojan.WinFixer
C:\WINDOWS\SYSTEM32\YAYXX.DLL
C:\WINDOWS\SYSTEM32\YAYXX.DLL
HKLM\Software\Classes\CLSID\{6043D040-9BE1-4323-ACB5-B726C0BF45EC}
HKCR\CLSID\{6043D040-9BE1-4323-ACB5-B726C0BF45EC}
HKCR\CLSID\{6043D040-9BE1-4323-ACB5-B726C0BF45EC}\InprocServer32
HKCR\CLSID\{6043D040-9BE1-4323-ACB5-B726C0BF45EC}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\DDCBA.DLL
HKLM\Software\Classes\CLSID\{AEAD70EF-9661-4F79-996F-048535ED1763}
HKCR\CLSID\{AEAD70EF-9661-4F79-996F-048535ED1763}
HKCR\CLSID\{AEAD70EF-9661-4F79-996F-048535ED1763}\InprocServer32
HKCR\CLSID\{AEAD70EF-9661-4F79-996F-048535ED1763}\InprocServer32#ThreadingModel
HKLM\Software\Classes\CLSID\{B92C6CDA-5893-444B-909B-FBD7A904D953}
HKCR\CLSID\{B92C6CDA-5893-444B-909B-FBD7A904D953}
HKCR\CLSID\{B92C6CDA-5893-444B-909B-FBD7A904D953}\InprocServer32
HKCR\CLSID\{B92C6CDA-5893-444B-909B-FBD7A904D953}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\JKKHE.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6043D040-9BE1-4323-ACB5-B726C0BF45EC}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AEAD70EF-9661-4F79-996F-048535ED1763}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B92C6CDA-5893-444B-909B-FBD7A904D953}

Adware.eZula
C:\WINDOWS\SYSTEM32\CBLIVKOB.EXE
C:\WINDOWS\SYSTEM32\CBLIVKOB.EXE
HKLM\System\ControlSet001\Services\DomainService
HKLM\System\ControlSet003\Services\DomainService
HKLM\System\CurrentControlSet\Services\DomainService
C:\DOCUMENTS AND SETTINGS\JOHN\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\GZ2ZCD45\VALERA[1]
C:\WINDOWS\SYSTEM32\GOLWHPKB.EXE
C:\WINDOWS\SYSTEM32\HHKHRYHC.EXE
C:\WINDOWS\SYSTEM32\JTRDIWTE.EXE
C:\WINDOWS\SYSTEM32\KJYAEFAS.EXE
C:\WINDOWS\SYSTEM32\RTTLDNIH.EXE

Adware.Vundo Variant
HKLM\Software\Classes\CLSID\{4AA49418-D47E-47EB-AAD9-3FA5155F3025}
HKCR\CLSID\{4AA49418-D47E-47EB-AAD9-3FA5155F3025}
HKCR\CLSID\{4AA49418-D47E-47EB-AAD9-3FA5155F3025}\InprocServer32
HKCR\CLSID\{4AA49418-D47E-47EB-AAD9-3FA5155F3025}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4AA49418-D47E-47EB-AAD9-3FA5155F3025}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{ 4AA49418-D47E-47EB-AAD9-3FA5155F3025}
HKCR\CLSID\{4AA49418-D47E-47EB-AAD9-3FA5155F3025}

Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{CF46BFB3-2ACC-441b-B82B-36B9562C7FF1}
HKCR\CLSID\{CF46BFB3-2ACC-441B-B82B-36B9562C7FF1}
HKCR\CLSID\{CF46BFB3-2ACC-441B-B82B-36B9562C7FF1}\InprocServer32
HKCR\CLSID\{CF46BFB3-2ACC-441B-B82B-36B9562C7FF1}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\FIWXEUOA.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CF46BFB3-2ACC-441b-B82B-36B9562C7FF1}
HKCR\CLSID\{CF46BFB3-2ACC-441B-B82B-36B9562C7FF1}

Unclassified.Unknown Origin/System
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ED8E7673-61E1-450B-8053-8D2351F29EF9}
HKCR\CLSID\{ED8E7673-61E1-450B-8053-8D2351F29EF9}
HKCR\CLSID\{ED8E7673-61E1-450B-8053-8D2351F29EF9}\InprocServer32
HKCR\CLSID\{ED8E7673-61E1-450B-8053-8D2351F29EF9}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\PMKJK.DLL

Trojan.Downloader-Gen/HitItQuitIt
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\cbxvvtr

________________________________

Please respond with any information or troubleshooting advice.

Respectfully

J
 
     
   
Gender PostTime:12/16/2008 11:18:17 AM Point:0 | Floor# 1
Lv is 1
portrait
Level:
1
Professional point:
52
Experience:
2
Thread:
291
Post:
928
Total online time:
2M
Joined date:
4/28/2007 10:52:00 PM
Last Visit:
12/17/2008 12:08:28 AM
Status:
Offline
ComboFix 07-09-21.2 - "John" 2007-09-25 22:53:18.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.652 [GMT -4:00]
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\check_LSA7.txt
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\trujdnhw.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\LEGACY_DOMAINSERVICE


((((((((((((((((((((((((( Files Created from 2007-08-26 to 2007-09-26 )))))))))))))))))))))))))))))))
.

2007-09-25 22:50 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-25 20:32 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-09-25 20:04 <DIR> d----c--- C:\DOCUME~1\John\APPLIC~1\RegistrySmart
2007-09-25 20:04 <DIR> d-------- C:\Program Files\RegistrySmart
2007-09-24 23:12 85,056 --a--c--- C:\WINDOWS\system32\spbexefb.dll
2007-09-24 22:46 2,011,375 ---hs---- C:\WINDOWS\system32\xwwvw.bak2
2007-09-24 21:18 <DIR> d----c--- C:\DOCUME~1\John\APPLIC~1\SUPERAntiSpyware.com
2007-09-24 21:18 <DIR> d----c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-09-24 21:18 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-09-24 21:15 2,005,654 ---hs---- C:\WINDOWS\system32\xxyay.bak1
2007-09-24 18:44 2,005,533 ---hs---- C:\WINDOWS\system32\kjkmp.bak1
2007-09-23 12:49 2,004,676 ---hs---- C:\WINDOWS\system32\xwwvw.bak1
2007-09-23 12:48 314,464 --a------ C:\WINDOWS\system32\wvwwx.dll
2007-09-22 19:12 2,138,144 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-09-22 19:06 75,248 --a------ C:\WINDOWS\zllsputility.exe
2007-09-22 19:06 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-09-22 19:06 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2007-09-22 19:06 <DIR> d----c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
2007-09-22 19:04 1,086,952 --a------ C:\WINDOWS\system32\zpeng24.dll
2007-09-22 19:04 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2007-09-22 19:01 <DIR> d-------- C:\WINDOWS\Internet Logs
2007-09-22 08:51 2,012,163 ---hs---- C:\WINDOWS\system32\ehkkj.bak2
2007-09-21 19:50 94,720 --a--c--- C:\WINDOWS\system32\dllcache\umaxud32.dll
2007-09-21 19:50 94,720 --a------ C:\WINDOWS\system32\umaxud32.dll
2007-09-21 19:50 69,632 --a--c--- C:\WINDOWS\system32\dllcache\umaxu12.dll
2007-09-21 19:50 69,632 --a------ C:\WINDOWS\system32\umaxu12.dll
2007-09-21 19:50 50,688 --a--c--- C:\WINDOWS\system32\dllcache\umaxscan.dll
2007-09-21 19:50 50,688 --a------ C:\WINDOWS\system32\umaxscan.dll
2007-09-21 19:49 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2007-09-21 19:49 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2007-09-21 19:27 <DIR> d----c--- C:\DOCUME~1\John\APPLIC~1\HP
2007-09-21 19:23 <DIR> d-------- C:\Program Files\Common Files\HP
2007-09-21 19:09 48,128 --a------ C:\WINDOWS\system32\hpzll463.dll
2007-09-21 18:39 13,767 --------- C:\WINDOWS\hphmdl11.dat
2007-09-21 18:39 122,709 --a------ C:\WINDOWS\HPHins11.dat
2007-09-21 18:26 <DIR> d----c--- C:\DOCUME~1\John\APPLIC~1\Image Zone Express
2007-09-21 18:18 <DIR> d-------- C:\Program Files\Paint.NET
2007-09-21 08:51 2,004,811 ---hs---- C:\WINDOWS\system32\ehkkj.bak1
2007-09-21 00:12 <DIR> d----c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
2007-09-20 23:37 94,208 --a------ C:\WINDOWS\system32\HPZipt12.dll
2007-09-20 23:37 69,632 --a------ C:\WINDOWS\system32\HPZipm12.exe
2007-09-20 23:37 65,536 --a------ C:\WINDOWS\system32\HPZinw12.exe
2007-09-20 23:37 57,344 --a------ C:\WINDOWS\system32\HPZisn12.dll
2007-09-20 23:37 278,584 --a------ C:\WINDOWS\system32\HPZidr12.dll
2007-09-20 23:37 204,800 --a------ C:\WINDOWS\system32\HPZipr12.dll
2007-09-20 23:36 306,688 --a------ C:\WINDOWS\IsUninst.exe
2007-09-20 23:33 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2007-09-20 23:33 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2007-09-20 23:33 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2007-09-20 23:33 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2007-09-20 23:25 <DIR> d-------- C:\Program Files\HP
2007-09-18 10:49 2,011,306 --ahs---- C:\WINDOWS\system32\abcdd.bak2
2007-09-17 22:49 6,448 --ahs---- C:\WINDOWS\system32\abcdd.bak1
2007-09-17 22:18 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-09-17 19:41 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-09-16 22:22 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-09-16 21:42 <DIR> d----c--- C:\DOCUME~1\John\APPLIC~1\Symantec
2007-09-15 22:23 <DIR> d-------- C:\Program Files\Norton 360
2007-09-15 22:19 <DIR> d----c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
2007-09-15 22:19 <DIR> d-------- C:\Program Files\Symantec
2007-09-15 22:18 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2007-09-15 14:23 <DIR> d-------- C:\Screen Printing
2007-09-10 22:31 <DIR> d-------- C:\Program Files\MagicDVDRipper
2007-09-10 21:50 <DIR> d-------- C:\tranSilvia video capture
2007-09-10 20:39 <DIR> d-------- C:\Program Files\directx
2007-09-10 20:19 299,520 --a------ C:\WINDOWS\uninst.exe
2007-09-10 20:19 <DIR> d-------- C:\DOCUME~1\John\WINDOWS
2007-09-04 17:41 <DIR> d-------- C:\Program Files\Microsoft.NET
2007-09-04 17:35 <DIR> d----c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
2007-09-04 17:34 <DIR> dr-h----- C:\MSOCache
2007-09-02 19:59 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-09-02 19:57 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-09-02 19:57 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-09-02 19:11 109,568 --a------ C:\WINDOWS\system32\pxinsi64.exe
2007-09-02 19:11 108,544 --a------ C:\WINDOWS\system32\pxcpyi64.exe
2007-09-02 19:11 <DIR> d----c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\YAHOO
2007-09-02 19:11 <DIR> d-------- C:\Program Files\illiminable
2007-09-02 19:09 <DIR> d-------- C:\Program Files\Yahoo!
2007-08-31 19:24 1,536 --a------ C:\WINDOWS\system32\TrueSoft.dat
2007-08-25 21:12 21,886 --a------ C:\WINDOWS\system32\nvModes.dat
2007-08-25 21:10 <DIR> d-------- C:\WINDOWS\nview

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-25 22:56 26108 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-09-24 21:16 --------- d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-09-20 19:12 9344 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
2007-09-20 19:12 8320 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-09-04 17:44 --------- d-------- C:\Program Files\Microsoft Works
2007-09-02 19:08 --------- d-------- C:\Program Files\Sirius
2007-08-25 21:09 --------- d-------- C:\Program Files\Common Files\InstallShield
2007-08-13 23:06 --------- d-------- C:\Program Files\Netflix
2007-08-07 23:57 --------- d-------- C:\Program Files\Picasa2
2007-08-07 23:57 --------- d-------- C:\Program Files\Google
2007-07-31 00:10 --------- d-------- C:\Program Files\TVUPlayer
2007-07-26 21:57 --------- d-------- C:\Program Files\iTunes
2007-07-26 21:57 --------- d-------- C:\Program Files\iPod
2007-07-26 21:55 --------- d-------- C:\Program Files\Common Files\Apple
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{44AA893D-E65D-403E-8AF0-E49D1F99FB51}]
C:\WINDOWS\system32\yayxx.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{992B062E-CAAB-4FA4-B297-174A78555A53}]
2007-09-23 12:48 314464 --a------ C:\WINDOWS\system32\wvwwx.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-02-10 09:27]
"nwiz"="nwiz.exe" [2003-02-10 09:27 C:\WINDOWS\system32\nwiz.exe]
"PCTVOICE"="pctspk.exe" [2003-02-24 15:35 C:\WINDOWS\system32\pctspk.exe]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-09-20 21:50]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14]
"SearchIndexer"="C:\WINDOWS\system32\spbexefb.dll" [2007-09-24 23:12]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-09-04 18:23:00]
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [1999-09-04 18:23:00]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell ExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

R3 wlluc48;Wireless LAN PC Card Driver;C:\WINDOWS\system32\DRIVERS\wlluc48.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-09-22 07:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.exe
"2007-09-06 23:45:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-09-26 00:05:03 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job"
- C:\Program Files\RegistrySmart\RegistrySmart.exe
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-25 23:17:43
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-25 23:20:38 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-25 23:20
.
--- E O F ---

#########################################################

Hijackthis scan 2

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 11:25:29 PM, on 9/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\John\Desktop\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {44AA893D-E65D-403E-8AF0-E49D1F99FB51} - C:\WINDOWS\system32\yayxx.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {992B062E-CAAB-4FA4-B297-174A78555A53} - C:\WINDOWS\system32\wvwwx.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\spbexefb.dll",sitypnow
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/micr...?1183668577013
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1183668557525
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - (no file)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 6888 bytes

My machine is running much better. I did get one random popup but it opened a new Firefox tab instead of an IE window. Definite progress. Hope the scans are clean.

Thanks again,

J
 
     
   
Gender PostTime:12/16/2008 12:32:55 PM Point:0 | Floor# 2
Lv is 1
portrait
Level:
1
Professional point:
62
Experience:
17
Thread:
308
Post:
944
Total online time:
17M
Joined date:
4/28/2007 11:22:00 PM
Last Visit:
12/16/2008 11:38:28 PM
Status:
Offline
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 9:02:10 PM, on 9/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\John\Desktop\HiJackThis_v2.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {44AA893D-E65D-403E-8AF0-E49D1F99FB51} - C:\WINDOWS\system32\yayxx.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {992B062E-CAAB-4FA4-B297-174A78555A53} - C:\WINDOWS\system32\wvwwx.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m

"C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\spbexefb.dll",sitypnow
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

http://www.update.microsoft.com/micr...?1183668577013
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -

http://www.update.microsoft.com/micr...?1183668557525
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - (no file)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 6999 bytes


Thank you in advance for your assistance Cheeseball.

J
 
     
   
Gender PostTime:12/16/2008 8:58:46 PM Point:0 | Floor# 3
Lv is 1
portrait
Level:
1
Professional point:
0
Experience:
0
Thread:
117
Post:
467
Total online time:
0M
Joined date:
4/19/2007 8:49:00 AM
Last Visit:
4/19/2007 8:49:19 AM
Status:
Offline
Definitely post the log when you are ready
 
     
   
Gender PostTime:12/16/2008 11:01:37 PM Point:0 | Floor# 4
Lv is 1
portrait
Level:
1
Professional point:
64
Experience:
3
Thread:
277
Post:
897
Total online time:
3M
Joined date:
4/28/2007 11:25:00 PM
Last Visit:
12/16/2008 11:33:11 PM
Status:
Offline
Download ComboFix to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it will produce a log for you. Post that log and a new HijackThis log in your next reply
Note: Do not mouseclick combofix's window while it's running as that may cause it to stall
 
     
1

Sorry, you are not login, click here to login

 

About us | Advertise | Contact us | Partner | Bug Report|Suggesting box|Donation
Home | Forum | Affiliate program| Remote help | Setting | Search | Document | Help | Download|Message

 

Start new topicAdvanced search