<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Trojan] HJT log : A little help please. in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r20327322</link>
<description></description>
<language>en</language>
<pubDate>Wed, 20 Aug 2008 21:27:04 EDT</pubDate>
<lastBuildDate>Wed, 20 Aug 2008 21:27:04 EDT</lastBuildDate>

<item>
<title>Re: [Trojan] HJT log : A little help please.</title>
<link>http://www.dslreports.com/forum/remark,20333701</link>
<description><![CDATA[<A HREF="/useremail/u/844536"><b>Action_Man</b></A> : I thought i might keep it as evidence :).<br><br>Anyway i will inform you of anymore unusualities .<br><br>And thank you <b>very</b> much for your assistance, hopefully i`m back to normal now ...<br><br>Gordon<br><small>--<br>&raquo;<A HREF="http://www.supermacro.net/" >www.supermacro.net/</A><br>&raquo;<A HREF="http://www.flickr.com/photos/action_man/" >www.flickr.com/photos/action_man/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20333701</guid>
<pubDate>Mon, 14 Apr 2008 18:28:48 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] HJT log : A little help please.</title>
<link>http://www.dslreports.com/forum/remark,20333386</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Why not delete the PDF and the Folder?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20333386</guid>
<pubDate>Mon, 14 Apr 2008 17:29:37 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] HJT log : A little help please.</title>
<link>http://www.dslreports.com/forum/remark,20332574</link>
<description><![CDATA[<A HREF="/useremail/u/844536"><b>Action_Man</b></A> : I have done everything you have asked, and all seemed ok for a little while, until a short while ago, when i noticed this folder on my desktop, i know i dident put it there, i dont even gamble :).<br><br>Here is an image of it ...<br>[att=1]<br><br>And also my net connection icon is still missing, but maybe thats another issue ...<br><small>--<br>&raquo;<A HREF="http://www.supermacro.net/" >www.supermacro.net/</A><br>&raquo;<A HREF="http://www.flickr.com/photos/action_man/" >www.flickr.com/photos/action_man/</A></small><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20332574?c=1297470&ret=L2ZvcnVtL3IyMDMyNzMyMi54bWw%3D"><IMG TITLE="26910 bytes" BORDER=0 WIDTH=481 HEIGHT=254 SRC="/r0/download/1297470~0d1e7889689bc0a385e799779ac38d9e/texas.jpg"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20332574</guid>
<pubDate>Mon, 14 Apr 2008 14:59:07 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] HJT log : A little help please.</title>
<link>http://www.dslreports.com/forum/remark,20331148</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : Open <b>Acrobat</b> if you have the Full Version installed  Click <b>Help</b> and run the <b>Upgrade</b> applet found there.  If no update is offered:  Use the Preferences, Internet submenu of Acrobat and uncheck to integrate with your Browser.  Close Acrobat.<br>Whether you had the Full Version of Acrobat or not, download and install <b>Adobe Reader 8.1.1</b> and use this as the integrated PDF Reader insider your browser:  &raquo;<A HREF="http://www.adobe.com/products/acrobat/readstep2.html" >www.adobe.com/products/acrobat/r&middot;&middot;&middot;ep2.html</A><br><br><b><u>Clean-up & Prevention:</u></b><br><br>&#8226;  Right click "My Computer", Properties, and then click the System Restore tab.  <b>Checkmark</b> the box at the top to stop System Restore on all drives.  Click the "<b>Apply</b>" button.  Agree to the deletion of old Restore Points.  Then <b><u>uncheck</u></b> the box at the top and again click the "<b>Apply</b>" button.  Finally, click the "<b>OK</b>" button.  This will create a new Restore Point reflecting your clean system state.<br><br>&#8226; Click <b>Start</b>, then click <b>Run</b>.<br>Enter into the command box that opens:  <b>combofix /u</b> and then click <b>OK</b>.<br>(If we have renamed this file, please use the current name for the program in this instruction.)<br> <IMG SRC="http://i78.photobucket.com/albums/j116/amateur_photos/CFuninstall.png"> <br><br>&#8226; Run <b>ATF Cleaner</b>  <IMG SRC="http://www.geekstogo.com/misc/guide_icons/ATF.gif"> , and checkmark "Empty Recycle Bin", click "Empty Selected" and exit the program.  You can delete or keep this utility as you wish.<br><br>&#8226; Use Control Panel, Add or Remove Programs, and Uninstall any entry related to an On-Line scanner we may have used.  <br>If you find any files or folders created during this cleanup operation remaining, please feel free to delete them.<br><br>&#8226; Configure your Antivirus software to check for updates daily, at a time in which you are sure the computer will be on.<br><br>&#8226; If I asked you to <b>Disable</b> something like TeaTimer or another malware blocker, please go ahead an re-enable them if you wish.<br><br>&#8226;  <b>Download and Install Windows Defender by Microsoft (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.microsoft.com/downloads/details.aspx?FamilyId=435BFCE7-DA2B-4A6A-AFA4-F7F14E605A0D&#012;</textarea><!--end code block--><br>&#8226;  <b>Download and install Comodo BOClean (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.comodo.com/boclean/CBO_download.html&#012;</textarea><!--end code block--><br>&#8226;  <b>Download, install, and keep updated Spyware Blaster (free):</b><br><textarea name="code" class="text" cols=50 rows=10>http://www.javacoolsoftware.com/spywareblaster.html&#012;</textarea><!--end code block--><br>&#8226; <b>Download, install, and keep updated SpyBot S&D (free) if you have not yet done so:</b><br><b><i>Tutorial:</i></b>  <br><textarea name="code" class="text" cols=50 rows=10>http://www.bleepingcomputer.com/tutorials/tutorial43.html&#012;</textarea><!--end code block--><br>&#8226; <b>Download, install, and keep updated AdAware 2007 by Lavasoft (free), if you have not done so:</b><br><b><i>Tutorial:</b></i>  <br><textarea name="code" class="text" cols=50 rows=10>http://www.bleepingcomputer.com/tutorials/tutorial48.html&#012;</textarea><!--end code block--><br>&#8226; Refer to my first set of instructions above, and reconfigure <b>Hidden Files and Folders</b> to your choosing.<br><br>Best wishes.<br>Bill Castner<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20331148</guid>
<pubDate>Mon, 14 Apr 2008 10:37:36 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] HJT log : A little help please.</title>
<link>http://www.dslreports.com/forum/remark,20330465</link>
<description><![CDATA[<A HREF="/useremail/u/844536"><b>Action_Man</b></A> : F:\WINDOWS\system32\svchost.exe<br>F:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe<br>F:\Program Files\Microsoft IntelliPoint\point32.exe<br>F:\WINDOWS\system32\RunDll32.exe<br>F:\WINDOWS\system32\rundll32.exe<br>F:\WINDOWS\system32\RUNDLL32.EXE<br>F:\WINDOWS\system32\ctfmon.exe<br>F:\WINDOWS\system32\wscntfy.exe<br>F:\Program Files\GIGABYTE\VGA Utility Manager\Utility.exe<br>F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>F:\WINDOWS\explorer.exe<br>F:\Program Files\Grisoft\AVG7\avgcc.exe<br>F:\Program Files\Mozilla Firefox\firefox.exe<br>F:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.google.co.uk/" >www.google.co.uk/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &raquo;<A HREF="http://www.btopenworld.com/" >www.btopenworld.com/</A><br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br>O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "F:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\windows\System32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd<br>O4 - HKLM\..\Run: [IntelliPoint] "F:\Program Files\Microsoft IntelliPoint\point32.exe"<br>O4 - HKLM\..\Run: [C6501Sound] RunDll32 c6501.cpl,CMICtrlWnd<br>O4 - HKLM\..\Run: [AVG7_CC] F:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP<br>O4 - HKLM\..\Run: [IMJPMIG8.1] "F:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32<br>O4 - HKLM\..\Run: [MSPY2002] F:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC<br>O4 - HKLM\..\Run: [PHIME2002ASync] F:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC<br>O4 - HKLM\..\Run: [PHIME2002A] F:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\windows\System32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br>O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] F:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')<br>O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] F:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')<br>O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] F:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')<br>O4 - Startup: Adobe Gamma.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br>O4 - Startup: GIGABYTE VGA Utility.lnk = ?<br>O8 - Extra context menu item: eBay Search - res://F:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html<br>O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - F:\WINDOWS\bdoscandel.exe<br>O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - F:\WINDOWS\bdoscandel.exe<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab" >messenger.zone.msn.com/binary/Me&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - &raquo;<A HREF="http://download.bitdefender.com/resources/scan8/oscan8.cab" >download.bitdefender.com/resourc&middot;&middot;&middot;can8.cab</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1207769248809" >www.update.microsoft.com/microso&middot;&middot;&middot;69248809</A><br>O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - &raquo;<A HREF="http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab" >www.nvidia.com/content/DriverDow&middot;&middot;&middot;lab2.cab</A><br>O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &raquo;<A HREF="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1207769228778" >www.update.microsoft.com/microso&middot;&middot;&middot;69228778</A><br>O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab" >messenger.zone.msn.com/binary/Me&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab" >messenger.zone.msn.com/binary/ZI&middot;&middot;&middot;2846.cab</A><br>O16 - DPF: {BF6BBE9A-0656-4598-A0CD-32DAC03959B5} (Image Uploader 3.0 Control) - &raquo;<A HREF="http://www.tescophoto.com/wpp/tesco//app/opcuploader.cab" >www.tescophoto.com/wpp/tesco//ap&middot;&middot;&middot;ader.cab</A><br>O17 - HKLM\System\CCS\Services\Tcpip\..\{35D0F5A8-55A1-4A1F-8B09-483A09054769}: NameServer = 194.74.65.69 62.6.40.178<br>O23 - Service: Adobe LM Service - Adobe Systems - F:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br>O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - F:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe<br>O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - F:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe<br>O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - F:\PROGRA~1\Grisoft\AVG7\avgemc.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - F:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: KService - Kontiki Inc. - F:\Program Files\Kontiki\KService.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\System32\nvsvc32.exe<br>O23 - Service: PnkBstrA - Unknown owner - F:\windows\System32\PnkBstrA.exe<br>O23 - Service: Start BT in service - Unknown owner - F:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe<br><br>BitDefender Online Scanner<br>  <br><br>Scan report generated at: Mon, Apr 14, 2008 - 11:28:57<br> <br><br>Scan path: C:\;E:\;F:\;<br>  <br><br>Statistics<br> <br>Time<br> 00:52:55<br> <br>Files<br> 198765<br> <br>Folders<br> 12428<br> <br>Boot Sectors<br> 4<br> <br>Archives<br> 1713<br> <br>Packed Files<br> 199<br> <br>  <br>  <br> <br>Results<br> <br>Identified Viruses <br> 6<br> <br>Infected Files <br> 6<br> <br>Suspect Files <br> 0<br> <br>Warnings<br> 0<br> <br>Disinfected<br> 0<br> <br>Deleted Files<br> 6<br> <br>Engines Info<br> <br>Virus Definitions<br> 35250<br> <br>Engine build<br> AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)<br> <br>Scan plugins<br> 3<br> <br>Archive plugins<br> 10<br> <br>Unpack plugins<br> 3<br> <br>E-mail plugins<br> 1<br> <br>System plugins<br> 1<br> <br>Scan Settings<br> <br>First Action<br> Disinfect<br> <br>Second Action<br> Delete<br> <br>Heuristics<br> Yes<br> <br>Enable Warnings<br> Yes<br> <br>Scanned Extensions<br> *;<br> <br>Exclude Extensions<br>  <br> <br>Scan Emails<br> Yes<br> <br>Scan Archives<br> Yes<br> <br>Scan Packed<br> Yes<br> <br>Scan Files<br> Yes<br> <br>Scan Boot<br> Yes<br><br>  Scanned File<br>  Status<br> <br>C:\WINDOWS\system32\.pif<br> Infected with: Generic.Botget.81CA81B0<br> <br>C:\WINDOWS\system32\.pif<br> Deleted<br> <br>C:\WINDOWS\system32\1.bat<br> Infected with: Generic.Botget.E657EBC4<br> <br>C:\WINDOWS\system32\1.bat<br> Deleted<br> <br>C:\WINDOWS\system32\c.bat<br> Infected with: Generic.Botget.B61E09E3<br> <br>C:\WINDOWS\system32\c.bat<br> Deleted<br> <br>C:\WINDOWS\system32\o<br> Infected with: Generic.Botget.A12F6AD5<br> <br>C:\WINDOWS\system32\o<br> Deleted<br> <br>F:\$VAULT$.AVG\20273875.FIL<br> Infected with: Win32.Msblast.A.damaged<br> <br>F:\$VAULT$.AVG\20273875.FIL<br> Deleted<br> <br>F:\WINDOWS\system32\servupdate.exe<br> Infected with: Packer.PrivateExeProtector.A<br> <br>F:\WINDOWS\system32\servupdate.exe<br> Disinfection failed<br> <br>F:\WINDOWS\system32\servupdate.exe<br> Deleted<br><small>--<br>&raquo;<A HREF="http://www.supermacro.net/" >www.supermacro.net/</A><br>&raquo;<A HREF="http://www.flickr.com/photos/action_man/" >www.flickr.com/photos/action_man/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20330465</guid>
<pubDate>Mon, 14 Apr 2008 06:38:28 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] HJT log : A little help please.</title>
<link>http://www.dslreports.com/forum/remark,20329016</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : TeaTimer is an excellent tool for the prevention of spyware but it can sometimes prevent HijackThis from fixing certain things. Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your HijackThis log is clean.<br>&#8226; Open Spybot Search & Destroy.<br>&#8226; In the Mode menu click "Advanced mode" if not already selected.<br>&#8226; Choose Yes at the Warning prompt.<br>&#8226; Expand the Tools menu.<br>&#8226; Click Resident.<br>&#8226; <b>Uncheck</b> the Resident "TeaTimer" (Protection of overall system settings) active. box.<br>&#8226; In the File menu click Exit to exit Spybot Search & Destroy.<br>&#8226; Download and Unzip to your Desktop:  &raquo;<A HREF="http://www.techsupportforum.com/sectools/ResetTeaTimer.zip" >www.techsupportforum.com/sectool&middot;&middot;&middot;imer.zip</A><br>&#8226; Double click <b>ResetTeaTimer.bat</b> to remove all entries set by TeaTimer.<br><br>1. Open <b>HijackThis</b> again, System scan only.  <b>Checkmark</b> these items:<br><br><b>O2 - BHO: (no name) - {22D8E815-4A5E-4dfb-845E-AAB64207F5BD} - (no file)<br>O4 - HKLM\..\RunServices: [tk] F:\windows\System32\tk.exe</b><br><br>Click "<b>Fix checked</b>" and when the log panel clears exit HijackThis.<br><br>2. Download -- but <i>do not</i> yet run  -- <b>ComboFix&copy; </b> <br><br>Download this file <b><u>-- to your Desktop --</u></b> [/b]from any of these sources:  <br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br>Right-click on the header of the Code box below, where on the right side it says:  "<b>Copy to clipboard</b>":<br><textarea name="code" class="text" cols=50 rows=10>File::&#012;F:\WINDOWS\system32\servupdate.exe&#012;F:\WINDOWS\system32\whlprd32a.dll&#012;F:\WINDOWS\system32\rxuybwm.exe&#012;F:\WINDOWS\system32\nwahgi.exe&#012;F:\WINDOWS\unins000.exe&#012;F:\WINDOWS\unins000.dat&#012;F:\windows\System32\tk.exe&#012; &#012;</textarea><!--end code block--><br>Open a new Notepad session - (Do <b><i>not</i></b> use a Word Processor or WordPad).  Click "<b>Format</b>" and be certain that Word Wrap is not enabled.  Right-click | <b>Paste</b> the Code box contents from above into Notepad.  Click File, <b><i>Save as...</i></b>, and set the location to your Desktop, and enter (including quotation marks) as the filename: <b>"CFscript.txt"</b> .  <br><br>&#8226; Disconnect from the Internet.<br>&#8226; Disable your Antivirus.  If the Antivirus software you use has any Script Blocking features, be certain to disable these as well.<br><b> Important:</b>  Have no other programs running.  Your Task Bar should be clear of any program entries including your Browser.<br>&#8226; A window will open with a warning.  Accept any Disclaimers to start the fix.<br>Using your mouse, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown in this little picture:<br> <IMG SRC="http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif"> <br><br>When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.<br>&#8226;<b>!</b>&#8226; A caution - Do <b>not</b> run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.<br><br>3. Run the <b>BitDefender Online Scanner</b> using Internet Explorer (Only):<br>&raquo;<A HREF="http://www.bitdefender.com/scan8/ie.htm" >www.bitdefender.com/scan8/ie.htm</A><br><br>&#8226; Read the 'END USER SOFTWARE LICENSE AGREEMENT' then click 'I agree'.<br>&#8226; You'll be prompted to install the activex control,please do so.<br>&#8226; Once installed, <b>Disable</b> your current Antivirus program, then click the '<b>Click here to scan</b>' button.<br>&#8226; The virus signatures will then load.<br>&#8226; The scan will take quite some time so please be patient.<br>&#8226; Once the scan has finished select the 'Detected Problems' tab.<br>&#8226; Click on 'Click here to export scan'.<br>&#8226; Save the file as an HTML file to your desktop.  <br>&#8226; Re-enable your Antivirus program.<br>&#8226; Click on the saved file and allow it to open with IE.<br>&#8226; Go to '<b>Edit', 'Select All</b>' then Copy and Paste that log result into a new Notepad session, with a filename you can easily locate later.<br><br>Post back to the Forum a brand new HijackThis log, and the results of your BitDefender scan.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20329016</guid>
<pubDate>Sun, 13 Apr 2008 21:01:43 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] HJT log : A little help please.</title>
<link>http://www.dslreports.com/forum/remark,20328611</link>
<description><![CDATA[<A HREF="/useremail/u/844536"><b>Action_Man</b></A> : I think these are the text files you have asked for, i wont get an answer from you this evening i know, its 12:30am here, so i will check back tomorrow, thank you for all the help ...<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 00:04:02, on 14/04/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br>Boot mode: Normal<br><br>Running processes:<br>F:\WINDOWS\System32\smss.exe<br>F:\WINDOWS\system32\winlogon.exe<br>F:\WINDOWS\system32\services.exe<br>F:\WINDOWS\system32\lsass.exe<br>F:\WINDOWS\system32\svchost.exe<br>F:\WINDOWS\System32\svchost.exe<br>F:\WINDOWS\system32\spoolsv.exe<br>F:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe<br>F:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe<br>F:\PROGRA~1\Grisoft\AVG7\avgemc.exe<br>F:\Program Files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe<br>F:\WINDOWS\System32\nvsvc32.exe<br>F:\windows\System32\PnkBstrA.exe<br>F:\WINDOWS\system32\svchost.exe<br>F:\WINDOWS\system32\wscntfy.exe<br>F:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe<br>F:\WINDOWS\system32\rundll32.exe<br>F:\Program Files\Microsoft IntelliPoint\point32.exe<br>F:\WINDOWS\system32\RunDll32.exe<br>F:\WINDOWS\system32\RUNDLL32.EXE<br>F:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe<br>F:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe<br>F:\WINDOWS\system32\ctfmon.exe<br>F:\Program Files\GIGABYTE\VGA Utility Manager\Utility.exe<br>F:\Program Files\Common Files\Teleca Shared\Generic.exe<br>F:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe<br>F:\WINDOWS\explorer.exe<br>F:\WINDOWS\system32\NOTEPAD.EXE<br>F:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.google.co.uk/" >www.google.co.uk/</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=69157" >go.microsoft.com/fwlink/?LinkId=69157</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://go.microsoft.com/fwlink/?LinkId=54896" >go.microsoft.com/fwlink/?LinkId=54896</A><br>R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &raquo;<A HREF="http://www.btopenworld.com/" >www.btopenworld.com/</A><br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br>O2 - BHO: (no name) - {22D8E815-4A5E-4dfb-845E-AAB64207F5BD} - (no file)<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br>O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br>O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "F:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\windows\System32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd<br>O4 - HKLM\..\Run: [IntelliPoint] "F:\Program Files\Microsoft IntelliPoint\point32.exe"<br>O4 - HKLM\..\Run: [C6501Sound] RunDll32 c6501.cpl,CMICtrlWnd<br>O4 - HKLM\..\Run: [AVG7_CC] F:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP<br>O4 - HKLM\..\Run: [IMJPMIG8.1] "F:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32<br>O4 - HKLM\..\Run: [MSPY2002] F:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC<br>O4 - HKLM\..\Run: [PHIME2002ASync] F:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC<br>O4 - HKLM\..\Run: [PHIME2002A] F:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\windows\System32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "F:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions<br>O4 - HKLM\..\Run: [Adobe Photo Downloader] "F:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br>O4 - HKLM\..\RunServices: [tk] F:\windows\System32\tk.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] F:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')<br>O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] F:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')<br>O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] F:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')<br>O4 - Startup: Adobe Gamma.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br>O4 - Startup: GIGABYTE VGA Utility.lnk = ?<br>O8 - Extra context menu item: eBay Search - res://F:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab" >messenger.zone.msn.com/binary/Me&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1207769248809" >www.update.microsoft.com/microso&middot;&middot;&middot;69248809</A><br>O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - &raquo;<A HREF="http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab" >www.nvidia.com/content/DriverDow&middot;&middot;&middot;lab2.cab</A><br>O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &raquo;<A HREF="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1207769228778" >www.update.microsoft.com/microso&middot;&middot;&middot;69228778</A><br>O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab" >messenger.zone.msn.com/binary/Me&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab" >messenger.zone.msn.com/binary/ZI&middot;&middot;&middot;2846.cab</A><br>O16 - DPF: {BF6BBE9A-0656-4598-A0CD-32DAC03959B5} (Image Uploader 3.0 Control) - &raquo;<A HREF="http://www.tescophoto.com/wpp/tesco//app/opcuploader.cab" >www.tescophoto.com/wpp/tesco//ap&middot;&middot;&middot;ader.cab</A><br>O23 - Service: Adobe LM Service - Adobe Systems - F:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br>O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - F:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe<br>O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - F:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe<br>O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - F:\PROGRA~1\Grisoft\AVG7\avgemc.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - F:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: KService - Kontiki Inc. - F:\Program Files\Kontiki\KService.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\System32\nvsvc32.exe<br>O23 - Service: PnkBstrA - Unknown owner - F:\windows\System32\PnkBstrA.exe<br>O23 - Service: Start BT in service - Unknown owner - F:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe<br><br>ComboFix 08-04-13.1 - gordon 2008-04-13 23:58:19.1 - NTFSx86<br>Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.624 [GMT 1:00]<br>Running from: F:\Documents and Settings\gordon\Desktop\ComboFix.exe<br> * Created a new restore point<br><br>[color=red]<b>WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!</b>[/color]<br>.<br><br>(((((((((((((((((((((((((   Files Created from 2008-03-13 to 2008-04-13  )))))))))))))))))))))))))))))))<br>.<br><br>2008-04-13 23:43 . 2008-04-13 23:43&#9;&#9;d--------&#9;F:\Program Files\Malwarebytes' Anti-Malware<br>2008-04-13 23:43 . 2008-04-13 23:43&#9;&#9;d--------&#9;F:\Program Files\Common Files\Download Manager<br>2008-04-13 23:43 . 2008-04-13 23:43&#9;&#9;d--------&#9;F:\Documents and Settings\gordon\Application Data\Malwarebytes<br>2008-04-13 23:43 . 2008-04-13 23:43&#9;&#9;d--------&#9;F:\Documents and Settings\All Users\Application Data\Malwarebytes<br>2008-04-13 23:22 . 2008-04-13 23:22&#9;&#9;d--------&#9;F:\WINDOWS\ERUNT<br>2008-04-13 23:15 . 2008-04-13 23:36&#9;&#9;d--------&#9;F:\SDFix<br>2008-04-13 19:10 . 2008-04-13 19:10&#9;&#9;d--------&#9;F:\Program Files\Trend Micro<br>2008-04-12 17:31 . 2008-04-12 17:31&#9;279&#9;--a------&#9;F:\WINDOWS\wininit.ini<br>2008-04-12 15:12 . 2008-04-12 15:12&#9;&#9;d--------&#9;F:\Program Files\Disc2Phone<br>2008-04-12 14:18 . 2008-04-12 14:18&#9;&#9;d--------&#9;F:\Documents and Settings\gordon\Application Data\Teleca<br>2008-04-12 14:18 . 2008-04-12 14:18&#9;&#9;d--------&#9;F:\Documents and Settings\gordon\Application Data\Sony Ericsson<br>2008-04-12 14:15 . 2008-04-12 14:15&#9;&#9;d--------&#9;F:\Documents and Settings\All Users\Application Data\Sony Ericsson<br>2008-04-12 14:14 . 2008-04-12 14:15&#9;&#9;d--------&#9;F:\Program Files\Common Files\Teleca Shared<br>2008-04-12 14:14 . 2008-04-12 14:15&#9;&#9;d--------&#9;F:\Program Files\Common Files\Sony Ericsson Shared<br>2008-04-12 14:14 . 2008-04-12 14:15&#9;&#9;d--------&#9;F:\Documents and Settings\All Users\Application Data\Teleca<br>2008-04-12 13:57 . 2008-04-12 13:57&#9;&#9;d--------&#9;F:\WINDOWS\Provisioning<br>2008-04-12 13:57 . 2008-04-12 14:02&#9;&#9;d--------&#9;F:\WINDOWS\PeerNet<br>2008-04-12 13:57 . 2008-04-12 14:01&#9;&#9;d--------&#9;F:\WINDOWS\ehome<br>2008-04-12 13:24 . 2004-08-04 13:00&#9;562,176&#9;--a--c---&#9;F:\WINDOWS\system32\dllcache\fxsst.dll<br>2008-04-12 13:23 . 2004-08-04 13:00&#9;2,134,528&#9;--a--c---&#9;F:\WINDOWS\system32\dllcache\smtpsnap.dll<br>2008-04-12 13:22 . 2004-08-04 13:00&#9;221,184&#9;--a------&#9;F:\WINDOWS\system32\wmpns.dll<br>2008-04-12 13:20 . 2004-08-04 13:00&#9;124,800&#9;--a------&#9;F:\WINDOWS\system32\drivers\fltMgr.sys<br>2008-04-12 13:20 . 2004-08-04 13:00&#9;124,800&#9;--a--c---&#9;F:\WINDOWS\system32\dllcache\fltmgr.sys<br>2008-04-12 13:20 . 2004-08-04 13:00&#9;81,920&#9;--a--c---&#9;F:\WINDOWS\system32\dllcache\msado27.tlb<br>2008-04-12 13:20 . 2004-08-04 13:00&#9;22,528&#9;--a------&#9;F:\WINDOWS\system32\fltMc.exe<br>2008-04-12 13:20 . 2004-08-04 13:00&#9;22,528&#9;--a--c---&#9;F:\WINDOWS\system32\dllcache\fltmc.exe<br>2008-04-12 13:20 . 2004-08-04 13:00&#9;18,944&#9;--a--c---&#9;F:\WINDOWS\system32\dllcache\hscupd.exe<br>2008-04-12 13:20 . 2004-08-04 13:00&#9;18,432&#9;--a--c---&#9;F:\WINDOWS\system32\dllcache\iedw.exe<br>2008-04-12 13:20 . 2004-08-04 13:00&#9;16,896&#9;--a------&#9;F:\WINDOWS\system32\fltlib.dll<br>2008-04-12 13:20 . 2004-08-04 13:00&#9;16,896&#9;--a--c---&#9;F:\WINDOWS\system32\dllcache\fltlib.dll<br>2008-04-12 13:06 . 2004-08-04 13:00&#9;10,096,640&#9;--a--c---&#9;F:\WINDOWS\system32\dllcache\hwxcht.dll<br>2008-04-12 12:22 . 2008-04-12 12:22&#9;&#9;d--------&#9;F:\Program Files\LSoft Technologies<br>2008-04-12 10:36 . 2006-05-15 14:35&#9;90,800&#9;-ra------&#9;F:\WINDOWS\system32\drivers\se27unic.sys<br>2008-04-12 10:36 . 2006-05-15 14:35&#9;88,688&#9;-ra------&#9;F:\WINDOWS\system32\drivers\SE27mgmt.sys<br>2008-04-12 10:36 . 2006-05-15 14:35&#9;18,704&#9;-ra------&#9;F:\WINDOWS\system32\drivers\se27nd5.sys<br>2008-04-12 10:36 . 2006-05-15 14:35&#9;6,240&#9;-ra------&#9;F:\WINDOWS\system32\drivers\SE27cmnt.sys<br>2008-04-12 10:36 . 2006-05-15 14:35&#9;6,240&#9;-ra------&#9;F:\WINDOWS\system32\drivers\SE27cm.sys<br>2008-04-12 10:36 . 2006-05-15 14:36&#9;5,872&#9;-ra------&#9;F:\WINDOWS\system32\drivers\se27wh.sys<br>2008-04-12 10:36 . 2006-05-15 14:35&#9;4,128&#9;-ra------&#9;F:\WINDOWS\system32\drivers\se27cr.sys<br>2008-04-12 10:35 . 2006-05-15 14:35&#9;97,184&#9;-ra------&#9;F:\WINDOWS\system32\drivers\SE27mdm.sys<br>2008-04-12 10:35 . 2006-05-15 14:35&#9;86,560&#9;-ra------&#9;F:\WINDOWS\system32\drivers\SE27obex.sys<br>2008-04-12 10:35 . 2006-05-15 14:35&#9;9,360&#9;-ra------&#9;F:\WINDOWS\system32\drivers\SE27mdfl.sys<br>2008-04-12 10:34 . 2006-05-15 14:35&#9;61,600&#9;-ra------&#9;F:\WINDOWS\system32\drivers\SE27bus.sys<br>2008-04-12 10:34 . 2006-05-15 14:36&#9;5,872&#9;-ra------&#9;F:\WINDOWS\system32\drivers\SE27whnt.sys<br>2008-04-12 10:30 . 2008-04-12 13:27&#9;4,512&#9;--a------&#9;F:\WINDOWS\imsins.BAK<br>2008-04-11 11:11 . 2008-04-11 12:03&#9;&#9;d--------&#9;F:\Documents and Settings\gordon\.housecall6.6<br>2008-04-10 22:36 . 2008-04-10 22:36&#9;&#9;d--------&#9;F:\Program Files\Enigma Software Group<br>2008-04-10 19:31 . 2008-04-10 19:31&#9;&#9;d--------&#9;F:\Documents and Settings\All Users\Application Data\PC Tools<br>2008-04-10 19:23 . 2008-04-10 19:23&#9;&#9;d--------&#9;F:\Program Files\CCleaner<br>2008-04-10 16:59 . 2008-04-10 16:59&#9;&#9;d--------&#9;F:\Documents and Settings\gordon\Application Data\True Sword<br>2008-04-10 16:58 . 2008-04-10 18:10&#9;&#9;d--------&#9;F:\Program Files\True Sword 4<br>2008-04-09 20:28 . 2004-08-04 13:00&#9;162,304&#9;--a------&#9;F:\WINDOWS\system32\wuaucpl.cpl<br>2008-04-09 20:28 . 2004-08-04 13:00&#9;162,304&#9;--a--c---&#9;F:\WINDOWS\system32\dllcache\wuaucpl.cpl<br>2008-04-09 20:28 . 2007-07-30 19:18&#9;34,136&#9;--a------&#9;F:\WINDOWS\system32\wucltui.dll.mui<br>2008-04-09 20:28 . 2007-07-30 19:19&#9;25,944&#9;--a------&#9;F:\WINDOWS\system32\wuaucpl.cpl.mui<br>2008-04-09 20:28 . 2007-07-30 19:19&#9;25,944&#9;--a------&#9;F:\WINDOWS\system32\wuapi.dll.mui<br>2008-04-09 20:28 . 2007-07-30 19:18&#9;20,312&#9;--a------&#9;F:\WINDOWS\system32\wuaueng.dll.mui<br>2008-04-07 23:10 . 2008-04-07 23:10&#9;&#9;d--------&#9;F:\WINDOWS\system32\SuperAdBlocker.com<br>2008-04-07 22:32 . 2008-04-07 22:32&#9;&#9;d--------&#9;F:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com<br>2008-04-07 22:31 . 2008-04-12 16:57&#9;&#9;d--------&#9;F:\Program Files\SUPERAntiSpyware<br>2008-04-07 22:31 . 2008-04-12 16:57&#9;&#9;d--------&#9;F:\Documents and Settings\gordon\Application Data\SUPERAntiSpyware.com<br>2008-04-07 21:28 . 2008-04-07 21:29&#9;&#9;d--------&#9;F:\Program Files\XoftSpySE<br>2008-04-07 13:52 . 2008-04-07 13:52&#9;80,384&#9;--a------&#9;F:\WINDOWS\system32\rxuybwm.exe<br>2008-04-07 10:27 . 2008-04-07 10:27&#9;80,384&#9;--a------&#9;F:\WINDOWS\system32\nwahgi.exe<br>2008-04-06 21:17 . 2008-04-06 21:13&#9;691,545&#9;--a------&#9;F:\WINDOWS\unins000.exe<br>2008-04-06 21:17 . 2008-04-06 21:17&#9;2,546&#9;--a------&#9;F:\WINDOWS\unins000.dat<br>2008-04-04 17:28 . 2008-04-04 17:28&#9;152,954&#9;-rahs----&#9;F:\WINDOWS\system32\servupdate.exe<br>2008-04-04 16:15 . 2008-04-04 16:15&#9;&#9;d--------&#9;F:\Documents and Settings\gordon\Application Data\Flickr<br>2008-03-16 22:43 . 2008-03-16 22:43&#9;&#9;d--------&#9;F:\Program Files\iTunes<br>2008-03-16 22:43 . 2008-03-16 22:43&#9;&#9;d--------&#9;F:\Program Files\iPod<br>2008-03-16 22:43 . 2008-03-16 22:43&#9;&#9;d--------&#9;F:\Program Files\Apple Software Update<br>2008-03-16 22:43 . 2008-03-16 22:43&#9;&#9;d--------&#9;F:\Documents and Settings\All Users\Application Data\Apple<br><br>.<br>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>2008-04-13 19:59&#9;---------&#9;d-s---w&#9;F:\Program Files\HLSW<br>2008-04-13 18:26&#9;22,328&#9;----a-w&#9;F:\WINDOWS\system32\drivers\PnkBstrK.sys<br>2008-04-13 18:25&#9;103,736&#9;----a-w&#9;F:\WINDOWS\system32\PnkBstrB.exe<br>2008-04-12 18:25&#9;12,464&#9;----a-w&#9;F:\WINDOWS\system32\drivers\secdrv.sys<br>2008-04-12 15:57&#9;---------&#9;d-----w&#9;F:\Program Files\Common Files\Wise Installation Wizard<br>2008-04-12 15:54&#9;---------&#9;d---a-w&#9;F:\Documents and Settings\All Users\Application Data\TEMP<br>2008-04-12 15:48&#9;---------&#9;d-----w&#9;F:\Program Files\Common Files\Adobe<br>2008-04-12 15:31&#9;---------&#9;d-----w&#9;F:\Documents and Settings\gordon\Application Data\AVG7<br>2008-04-12 13:14&#9;---------&#9;d-----w&#9;F:\Program Files\Sony Ericsson<br>2008-04-12 13:09&#9;---------&#9;d-----w&#9;F:\Documents and Settings\All Users\Application Data\Avg7<br>2008-04-12 10:14&#9;---------&#9;d-----w&#9;F:\Program Files\Microsoft IntelliPoint<br>2008-04-12 09:28&#9;---------&#9;d-----w&#9;F:\Program Files\LGGSM<br>2008-04-10 19:48&#9;---------&#9;d-----w&#9;F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy<br>2008-04-09 10:46&#9;---------&#9;d-----w&#9;F:\Documents and Settings\gordon\Application Data\Uniblue<br>2008-04-06 20:21&#9;---------&#9;d-----w&#9;F:\Program Files\Spybot - Search & Destroy<br>2008-04-06 15:16&#9;---------&#9;d-----w&#9;F:\Program Files\TweakNow RegCleaner Std<br>2008-04-06 15:10&#9;---------&#9;d-----w&#9;F:\Program Files\HP<br>2008-04-04 17:19&#9;---------&#9;d-----w&#9;F:\Documents and Settings\All Users\Application Data\Kontiki<br>2008-03-13 13:39&#9;---------&#9;d-----w&#9;F:\Documents and Settings\gordon\Application Data\LimeWire<br>2008-03-08 22:01&#9;---------&#9;d-----w&#9;F:\Program Files\VstPlugins<br>2008-03-08 19:33&#9;---------&#9;d-----w&#9;F:\Program Files\Image-Line<br>2008-03-03 17:18&#9;---------&#9;d-----w&#9;F:\Program Files\FinalBurner<br>2008-02-27 19:07&#9;---------&#9;d-----w&#9;F:\Documents and Settings\gordon\Application Data\gtk-2.0<br>2008-02-23 13:46&#9;---------&#9;d--h--w&#9;F:\Program Files\InstallShield Installation Information<br>2008-02-22 21:57&#9;---------&#9;d-----w&#9;F:\Program Files\Trillian<br>2008-02-22 14:46&#9;---------&#9;d-----w&#9;F:\Documents and Settings\gordon\Application Data\.RawTherapee<br>2008-02-22 14:45&#9;---------&#9;d-----w&#9;F:\Program Files\Raw Therapee<br>2008-02-22 12:26&#9;---------&#9;d-----w&#9;F:\Program Files\LG Electronics<br>2008-02-22 00:03&#9;---------&#9;d-----w&#9;F:\Documents and Settings\All Users\Application Data\River Past G5<br>2008-02-10 22:07&#9;737,280&#9;----a-w&#9;F:\WINDOWS\iun6002.exe<br>2008-01-17 20:06&#9;35,363&#9;----a-w&#9;F:\WINDOWS\system32\windrvNT.sys<br>2007-12-06 16:28&#9;20&#9;---h--w&#9;F:\Documents and Settings\All Users\Application Data\PKP_DLea.DAT<br>2007-11-01 21:43&#9;0&#9;----a-w&#9;F:\Documents and Settings\All Users\Application Data\PKP_DLbz.DAT<br>2007-03-14 00:29&#9;32,768&#9;--sha-w&#9;F:\Program Files\Thumbs.db<br>.<br><br>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))<br>.<br>.<br>*Note* empty entries & legit default entries are not shown <br>REGEDIT4<br><br>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"ctfmon.exe"="F:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]<br>"SpybotSD TeaTimer"="F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br>"SpeedTouch USB Diagnostics"="F:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 20:38 866816]<br>"NvCplDaemon"="F:\windows\System32\NvCpl.dll" [2007-05-10 23:03 8429568]<br>"nwiz"="nwiz.exe" [2007-05-10 23:03 1626112 F:\WINDOWS\system32\nwiz.exe]<br>"Cmaudio"="cmicnfg.cpl" []<br>"IntelliPoint"="F:\Program Files\Microsoft IntelliPoint\point32.exe" [2004-06-03 02:50 204800]<br>"C6501Sound"="c6501.cpl" []<br>"AVG7_CC"="F:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-07 12:55 579072]<br>"IMJPMIG8.1"="F:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 13:00 208952]<br>"MSPY2002"="F:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 13:00 59392]<br>"PHIME2002ASync"="F:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 13:00 455168]<br>"PHIME2002A"="F:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 13:00 455168]<br>"NvMediaCenter"="F:\windows\System32\NvMcTray.dll" [2007-05-10 23:03 81920]<br>"Sony Ericsson PC Suite"="F:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2006-11-24 01:06 487424]<br>"Adobe Photo Downloader"="F:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344]<br>"Adobe Reader Speed Launcher"="F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]<br><br>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]<br>"tk"="F:\windows\System32\tk.exe" [ ]<br><br>[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]<br>"AVG7_Run"="F:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-07 12:55 219136]<br><br>F:\Documents and Settings\gordon\Start Menu\Programs\Startup\<br>Adobe Gamma.lnk - F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]<br>GIGABYTE VGA Utility.lnk - F:\Documents and Settings\gordon\Application Data\Microsoft\Installer\{D27BDB5D-3B4C-44F0-A648-BD00B0E79B39}\Utility.exe2_D27BDB5D3B4C44F0A648BD00B0E79B39.exe [2007-11-14 18:34:56 40960]<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]<br>""= 0<br>"NoFileAssociate"= 0 (0x0)<br><br>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]<br>"F:\\windows\\System32\\servupdate.exe"=<br>"F:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=<br>"F:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=<br>"F:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=<br>"F:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=<br>"F:\\WINDOWS\\system32\\sessmgr.exe"=<br>"F:\\Program Files\\HLSW\\hlsw_1_0_0_19-beta.exe"=<br><br>R0 uliagpkx;ULi AGP Bus Filter Driver;F:\WINDOWS\system32\DRIVERS\agpkx.sys [2005-05-03 17:31]<br>R3 CHSBXX33;CHSBXX33;F:\WINDOWS\system32\Drivers\CHSBXX33.sys [2002-05-27 15:34]<br>R3 cm102u32;C-Media CM6501 Like Sound Interface;F:\WINDOWS\system32\drivers\c6501.sys [2006-07-11 07:05]<br>R3 Ma730Pt;MA730 Bluetooth VCOM Driver;F:\WINDOWS\system32\DRIVERS\Ma730Pt.sys [2006-09-21 13:23]<br>R3 Ma730Vad;MA730 Bluetooth Audio;F:\WINDOWS\system32\DRIVERS\Ma730Vad.sys [2005-11-22 15:32]<br>S3 mam4410m;mam4410m;F:\WINDOWS\system32\Drivers\mam4410m.sys [2005-06-16 19:13]<br>S3 mam4410u;mam4410u;F:\WINDOWS\system32\Drivers\mam4410u.sys [2007-03-19 15:39]<br>S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;F:\WINDOWS\system32\DRIVERS\wg111v2.sys [2005-10-24 15:18]<br>S3 Start BT in service;Start BT in service;F:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [2007-04-21 14:54]<br><br>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]<br>\Shell\AutoRun\command - E:\AUTORUN.EXE<br><br>.<br>Contents of the 'Scheduled Tasks' folder<br>"2007-10-15 18:41:00 F:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"<br>- F:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe<br>"2008-04-13 22:31:48 F:\WINDOWS\Tasks\XoftSpySE 2.job"<br>- F:\Program Files\XoftSpySE\XoftSpy.exe<br>"2008-04-07 20:28:48 F:\WINDOWS\Tasks\XoftSpySE.job"<br>- F:\Program Files\XoftSpySE\XoftSpy.exe<br>.<br>**************************************************************************<br><br>catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-04-14 00:00:05<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ... <br><br>scanning hidden autostart entries ...<br><br>scanning hidden files ... <br><br>scan completed successfully <br>hidden files: 0 <br><br>**************************************************************************<br>.<br>--------------------- DLLs Loaded Under Running Processes ---------------------<br><br>PROCESS: F:\WINDOWS\explorer.exe<br>-> F:\WINDOWS\system32\nview.dll<br>.<br>Completion time: 2008-04-14  0:00:46<br>ComboFix-quarantined-files.txt  2008-04-13 23:00:34<br>Pre-Run: 56,534,892,544 bytes free<br>Post-Run: 56,521,650,176 bytes free<br><br><b>SDFix: Version 1.170 </b><br>Run by gordon on 13/04/2008 at 23:24<br><br>Microsoft Windows XP [Version 5.1.2600]<br>Running From: F:\SDFix<br><br><b>Checking Services </b>:<br><br>Restoring Windows Registry Values<br>Restoring Windows Default Hosts File<br><br>Rebooting<br><br><b>Checking Files </b>: <br><br>Trojan Files Found:<br><br>F:\WINDOWS\system32\i  - Deleted<br><br>Removing Temp Files<br><br><b>ADS Check </b>:<br> <br><br>                                 <b>Final Check </b>:<br><br>catchme 0.3.1351.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &raquo;<A HREF="http://www.gmer.net" >www.gmer.net</A><br>Rootkit scan 2008-04-13 23:32:24<br>Windows 5.1.2600 Service Pack 2 NTFS<br><br>scanning hidden processes ...<br><br>scanning hidden services & system hive ...<br><br>scanning hidden registry entries ...<br><br>scanning hidden files ...<br><br>scan completed successfully<br>hidden processes: 0<br>hidden services: 0<br>hidden files: 8<br><br><b>Remaining Services </b>:<br><br>Authorized Application Key Export:<br><br>[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]<br>"F:\\windows\\System32\\servupdate.exe"="F:\\windows\\System32\\servupdate.exe:*:Enabled:Windows USB Monitor"<br>"F:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="F:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"<br>"F:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="F:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"<br>"F:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="F:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"<br>"F:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="F:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc.exe"<br>"F:\\WINDOWS\\system32\\sessmgr.exe"="F:\\WINDOWS\\system32\\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"<br>"F:\\Program Files\\HLSW\\hlsw_1_0_0_19-beta.exe"="F:\\Program Files\\HLSW\\hlsw_1_0_0_19-beta.exe:*:Enabled:MFC-Anwendung HLSW"<br><br>[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]<br>"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"<br><br><b>Remaining Files </b>:<br><br>File Backups: - F:\SDFix\backups\backups.zip<br><br><b>Files with Hidden Attributes </b>:<br><br>Sat 12 Apr 2008           332 ..SH. --- "F:\BOOT.BAK"<br>Mon 28 Jan 2008     1,404,240 A.SHR --- "F:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"<br>Mon 28 Jan 2008     5,146,448 A.SHR --- "F:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"<br>Mon 28 Jan 2008     2,097,488 A.SHR --- "F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"<br>Fri  4 Apr 2008       152,954 A.SHR --- "F:\WINDOWS\system32\servupdate.exe"<br>Wed  5 Jan 2005         2,045 A..H. --- "F:\WINDOWS\system32\whlprd32a.dll"<br>Wed 15 Aug 2007         4,348 A.SH. --- "F:\Documents and Settings\All Users\DRM\DRMv1.bak"<br>Sun  5 Feb 2006         4,348 A.SH. --- "F:\Documents and Settings\All Users\DRM\DRMv1.key.bak"<br>Thu  9 Aug 2007           400 A.SH. --- "F:\Documents and Settings\All Users\DRM\v2ks.bla.bak"<br>Thu  9 Aug 2007            48 A.SH. --- "F:\Documents and Settings\All Users\DRM\v2ks.sec.bak"<br><br><b>Finished!</b><br><small>--<br>&raquo;<A HREF="http://www.supermacro.net/" >www.supermacro.net/</A><br>&raquo;<A HREF="http://www.flickr.com/photos/action_man/" >www.flickr.com/photos/action_man/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20328611</guid>
<pubDate>Sun, 13 Apr 2008 19:30:35 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] HJT log : A little help please.</title>
<link>http://www.dslreports.com/forum/remark,20328282</link>
<description><![CDATA[<A HREF="/useremail/u/693977"><b>bcastner</b></A> : I can deal with every issue in your screenshot but <b><u>Virut</u></b>, as it is a file injector.  If it has not gotten very far, it is possible, (no great hopes, now), possible, this computer can be recovered.  Most malware removal folks when they see Virut recomment a clean reinstall.  I happen to agree with them.<br><br>Lets see how it goes; I am not optomistic.  In a later session we will have to deal with Virut by itself.<br><br><b><u>First Steps</u></b><br><b>:!: The following instructions are <u>only</u> for this Forum member. Please do not use these instructions on another computer system. You can seriously damage your system by following the instructions below without guided assistance. You assuredly will make a cleanup of your system more difficult.</b><br><br>TeaTimer is an excellent tool for the prevention of spyware but it can sometimes prevent HijackThis from fixing certain things. Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your HijackThis log is clean.<br>&#8226; Open Spybot Search & Destroy.<br>&#8226; In the Mode menu click "Advanced mode" if not already selected.<br>&#8226; Choose Yes at the Warning prompt.<br>&#8226; Expand the Tools menu.<br>&#8226; Click Resident.<br>&#8226; <b>Uncheck</b> the Resident "TeaTimer" (Protection of overall system settings) active. box.<br>&#8226; In the File menu click Exit to exit Spybot Search & Destroy.<br>&#8226; Download and Unzip to your Desktop:  &raquo;<A HREF="http://www.techsupportforum.com/sectools/ResetTeaTimer.zip" >www.techsupportforum.com/sectool&middot;&middot;&middot;imer.zip</A><br>&#8226; Double click <b>ResetTeaTimer.bat</b> to remove all entries set by TeaTimer.<br><br>Please download<b>  <i>ATF Cleaner</i></b> <br><textarea name="code" class="text" cols=50 rows=10>http://www.atribune.org/ccount/click.php?id=1&#012;</textarea><!--end code block-->It does not require any installation.. It is set up to clean Windows TEMP folders, as well as IE, FireFox and Opera, Temporary Internet Files and Cookies.<br>&#8226;      Double-click <b>ATF-Cleaner.exe</b> to run the program. <br><br><b>First Step:</b><br>&#8226;      Under <b>Main</b> choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <br><b><u>Next, if you use Firefox (and <i>some</i> Mozilla-based browsers)</u></b> <br>&#8226;      Click Firefox at the top and choose: <b>Select All</b><br>&#8226;      Click the <b>Empty Selected</b> button. <b><u><br>Next, if you use the Opera browser</u></b> <br>&#8226;      Click <b>Opera</b> at the top and choose: <b>Select All</b> <br>&#8226;      Click the <b>Empty Selected</b> button. <b>:!: Click Exit on the Main menu to close the program.</b><br><br><b>Reconfigure Windows XP to show hidden files:</b><br><i>To enable the viewing of Hidden files follow these steps: </i><br>&#8226; Close all programs so that you are at your desktop. <br>&#8226; Double-click on the My Computer icon. <br>&#8226; Select the Tools menu and click Folder Options. <br>&#8226; After the new window appears select the View tab. <br>&#8226; Put a checkmark in the checkbox labeled Display the contents of system folders. <br>&#8226; Under the Hidden files and folders section select the radio button labeled Show hidden files and folders. <br>&#8226; Remove the checkmark from the checkbox labeled Hide file extensions for known file types. <br>&#8226; Remove the checkmark from the checkbox labeled Hide protected operating system files. <br>&#8226; Press the Apply button and then the OK button and exit My Computer. <br>&#8226; Now your computer is configured to show all hidden files. <br><br><b><u>Malware Removal Steps</u></b><br>1. Open <b>HijackThis</b> again, System scan only.  <b>Checkmark</b> these items:<br><br><b>O2 - BHO: (no name) - {22D8E815-4A5E-4dfb-845E-AAB64207F5BD} - (no file)<br>O3 - Toolbar: (no name) - {92085AD4-F48A-450d-BD93-B28CC7DF67CE} - (no file)<br>O4 - HKLM\..\RunServices: [tk] F:\windows\System32\tk.exe<br>O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present<br>O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present</b><br><br>Click "<b>Fix checked</b>" and when the log panel clears exit HijackThis.<br><br>2. Download <b>SDFix</b> and save it to your Desktop.<br><textarea name="code" class="text" cols=50 rows=10>http://downloads.andymanchesta.com/RemovalTools/SDFix.exe&#012;</textarea><!--end code block--><br>Double click<b>SDFix.exe</b> and it will extract the files to  the Windows Directory,  <b>C:\SDFix</b>. <br><br>Please then reboot your computer in <b><i>Safe Mode</i></b> by doing the following :<br>&#8226; Restart your computer <br>&#8226; After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually; <br>&#8226; Instead of Windows loading as normal, the Advanced Options Menu should appear; <br>&#8226; Select the first option, to run Windows in Safe Mode, then press [Enter]. <br>&#8226; Choose your usual account. <br>&#8226;  Open the extracted SDFix folder and double click <b>RunThis.ba</b> to start the script. <br>&#8226;  Type <b>Y[</b> to begin the cleanup process. <br>&#8226;  It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot. <br>&#8226;  Press any Key and it will restart the PC. <br>&#8226;  When the PC restarts the Fixtool will run again and complete the removal process then display <b>]Finished</b>, press any key to end the script and load your desktop icons. <br>&#8226;  Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as <b>Report.txt</b> <br>(Report.txt will also be copied to Clipboard ready for posting back on the forum). <br>&#8226;  For now, simply close Notepad.<br><br>3. Please download MalwareBytes Anti-malware (MBAM) from one of the following links:<br><textarea name="code" class="text" cols=50 rows=10>http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html&#012;http://www.besttechie.net/tools/mbam-setup.exe&#012;</textarea><!--end code block--><br>Once downloaded, close all programs and Windows on your computer (including this one.)<br><br>Double-click on the icon on your desktop named Download_mbam-setup.exe. This will start the installation of MBAM onto your computer.<br><br>When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware checked. Then click on the Finish button.<br><br>MBAM will now automatically start and you will see a message stating that you should update the program before performing a scan. As MBAM will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main program.<br><br>On the <b>Scanner tab</b>, make sure the the <b>Perform quick scan</b> option is selected and then click on the <b>Scan</b> button to start scanning your computer.<br><br>MBAM will now start scanning your computer for malware. This process can take quite a while, so we suggest you go and do something else and periodically check on the status of the scan. <br><br>When the scan is finished a message box will appear that it has completed scanning successfully.  Click <b>OK</b>.  Now click <b>Show Results</b>.  Make sure all entries have a checkmark at their far left.  You should now click on the <b>Remove Selected</b> button to remove all the listed malware. MBAM will now delete all of the files and registry keys and add them to the programs quarantine.<br><br>When MBAM has finished removing the malware, it will open the scan log and display it in Notepad. Review the log as desired, and then close the Notepad window.  Remember where you saved the log file, as we will want to see it later.<br><br>4. Download and Run  -- <b>ComboFix&copy; </b> <br>Download this file <b><u>-- to your Desktop --</u></b> from any of these sources:  <br><textarea name="code" class="text" cols=50 rows=10>http://download.bleepingcomputer.com/sUBs/ComboFix.exe&#012;http://www.forospyware.com/sUBs/ComboFix.exe&#012;http://subs.geekstogo.com/ComboFix.exe&#012;</textarea><!--end code block--><br>&#8226; Disconnect from the Internet.<br>&#8226; Disable  your Antivirus  software -- this includes any Script Blocking Feature it may have.<br><br><b>Important:  Have no other programs running.  Your Task Bar should be clear of any program entries including your Browser.</b><br>&#8226; A window will open with a warning.  Accept any disclaimers to start the fix. When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.<br>A caution - Do <b>not</b> run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.<br><br>5. Run <b>HijackThis</b> again, and save the log file.<br><br><b><i>Submit to the Forum:</i></b><br>&#8226; The contents of C:\SDFix\Report.txt;<br>&#8226; The contents of your <b>MBAM</b> log;<br>&#8226; The contents of C:\Combofix.txt;<br>&#8226; The new HijackThis log.<br><br><small>--<br><b>============</b><br><b>MS-MVP 2004 - -2008, ASAP Member</b><br><b><i>Users Helping Users</i></b><br><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20328282</guid>
<pubDate>Sun, 13 Apr 2008 17:59:36 EDT</pubDate>
</item>

<item>
<title>Re: [Trojan] HJT log : A little help please.</title>
<link>http://www.dslreports.com/forum/remark,20327338</link>
<description><![CDATA[<A HREF="/useremail/u/844536"><b>Action_Man</b></A> : One more thing, my network icon has been removed from the notification area, i know how to get it back but it wont let me, i suspect it doesent want me to see the activity ...<br><small>--<br>&raquo;<A HREF="http://www.supermacro.net/" >www.supermacro.net/</A><br>&raquo;<A HREF="http://www.flickr.com/photos/action_man/" >www.flickr.com/photos/action_man/</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20327338</guid>
<pubDate>Sun, 13 Apr 2008 13:46:04 EDT</pubDate>
</item>

<item>
<title>[Trojan] HJT log : A little help please.</title>
<link>http://www.dslreports.com/forum/remark,20327322</link>
<description><![CDATA[<A HREF="/useremail/u/844536"><b>Action_Man</b></A> : I think i have met most of the criteria for posting (i hope).<br><br>I have the latest updates from Windows(XP).<br><br>I have Windows Firewall running.<br><br>I have done online scans.<br><br>I have AVG running, and have so for several years.<br><br>I have Spybot SD resident running.<br><br>If i run Spybot and do a full scan, my computer usually goes to a blue screen of death for some unknown reason.<br><br>The problem i`m having at the moment is that AVG keeps picking up on virus`s, mainly trojan horses. They arent causing a great problem, but obviously i would like this to stop.<br><br>One other slight problem is that my adsl modem keeps initialising itself, and cutting me off from the internet, but this maybe my isp, i dont know.<br><br>Anyway here is the Hijackthis log : -<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 19:11:24, on 13/04/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br>Boot mode: Normal<br><br>Running processes:<br>F:\WINDOWS\System32\smss.exe<br>F:\WINDOWS\system32\winlogon.exe<br>F:\WINDOWS\system32\services.exe<br>F:\WINDOWS\system32\lsass.exe<br>F:\WINDOWS\system32\svchost.exe<br>F:\WINDOWS\System32\svchost.exe<br>F:\WINDOWS\Explorer.EXE<br>F:\WINDOWS\system32\spoolsv.exe<br>F:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe<br>F:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe<br>F:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe<br>F:\PROGRA~1\Grisoft\AVG7\avgemc.exe<br>F:\Program Files\Microsoft IntelliPoint\point32.exe<br>F:\WINDOWS\system32\RunDll32.exe<br>F:\PROGRA~1\Grisoft\AVG7\avgcc.exe<br>F:\WINDOWS\system32\rundll32.exe<br>F:\WINDOWS\system32\RUNDLL32.EXE<br>F:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe<br>F:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe<br>F:\WINDOWS\System32\nvsvc32.exe<br>F:\windows\System32\PnkBstrA.exe<br>F:\WINDOWS\system32\ctfmon.exe<br>F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>F:\WINDOWS\system32\svchost.exe<br>F:\Program Files\GIGABYTE\VGA Utility Manager\Utility.exe<br>F:\WINDOWS\system32\wscntfy.exe<br>F:\Program Files\Common Files\Teleca Shared\Generic.exe<br>F:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe<br>F:\Program Files\Mozilla Firefox\firefox.exe<br>F:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.google.co.uk/" >www.google.co.uk/</A><br>R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &raquo;<A HREF="http://www.btopenworld.com/" >www.btopenworld.com/</A><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BTopenworld<br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll<br>O2 - BHO: (no name) - {22D8E815-4A5E-4dfb-845E-AAB64207F5BD} - (no file)<br>O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br>O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)<br>O3 - Toolbar: (no name) - {92085AD4-F48A-450d-BD93-B28CC7DF67CE} - (no file)<br>O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "F:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon<br>O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\windows\System32\NvCpl.dll,NvStartup<br>O4 - HKLM\..\Run: [nwiz] nwiz.exe /install<br>O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd<br>O4 - HKLM\..\Run: [IntelliPoint] "F:\Program Files\Microsoft IntelliPoint\point32.exe"<br>O4 - HKLM\..\Run: [C6501Sound] RunDll32 c6501.cpl,CMICtrlWnd<br>O4 - HKLM\..\Run: [AVG7_CC] F:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP<br>O4 - HKLM\..\Run: [IMJPMIG8.1] "F:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32<br>O4 - HKLM\..\Run: [MSPY2002] F:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC<br>O4 - HKLM\..\Run: [PHIME2002ASync] F:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC<br>O4 - HKLM\..\Run: [PHIME2002A] F:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName<br>O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\windows\System32\NvMcTray.dll,NvTaskbarInit<br>O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "F:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions<br>O4 - HKLM\..\Run: [Adobe Photo Downloader] "F:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"<br>O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"<br>O4 - HKLM\..\RunServices: [tk] F:\windows\System32\tk.exe<br>O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe<br>O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe<br>O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] F:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')<br>O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')<br>O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] F:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')<br>O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] F:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')<br>O4 - Startup: Adobe Gamma.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br>O4 - Startup: GIGABYTE VGA Utility.lnk = ?<br>O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present<br>O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present<br>O8 - Extra context menu item: eBay Search - res://F:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html<br>O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab" >messenger.zone.msn.com/binary/Me&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1207769248809" >www.update.microsoft.com/microso&middot;&middot;&middot;69248809</A><br>O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - &raquo;<A HREF="http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab" >www.nvidia.com/content/DriverDow&middot;&middot;&middot;lab2.cab</A><br>O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &raquo;<A HREF="http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1207769228778" >www.update.microsoft.com/microso&middot;&middot;&middot;69228778</A><br>O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab" >messenger.zone.msn.com/binary/Me&middot;&middot;&middot;1267.cab</A><br>O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - &raquo;<A HREF="http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab" >messenger.zone.msn.com/binary/ZI&middot;&middot;&middot;2846.cab</A><br>O16 - DPF: {BF6BBE9A-0656-4598-A0CD-32DAC03959B5} (Image Uploader 3.0 Control) - &raquo;<A HREF="http://www.tescophoto.com/wpp/tesco//app/opcuploader.cab" >www.tescophoto.com/wpp/tesco//ap&middot;&middot;&middot;ader.cab</A><br>O17 - HKLM\System\CCS\Services\Tcpip\..\{35D0F5A8-55A1-4A1F-8B09-483A09054769}: NameServer = 194.74.65.69 62.6.40.178<br>O23 - Service: Adobe LM Service - Adobe Systems - F:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe<br>O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - F:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe<br>O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - F:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe<br>O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - F:\PROGRA~1\Grisoft\AVG7\avgemc.exe<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe<br>O23 - Service: iPod Service - Apple Inc. - F:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: KService - Kontiki Inc. - F:\Program Files\Kontiki\KService.exe<br>O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\System32\nvsvc32.exe<br>O23 - Service: PnkBstrA - Unknown owner - F:\windows\System32\PnkBstrA.exe<br>O23 - Service: Start BT in service - Unknown owner - F:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe<br><br>And here is selection of the types of trojans i`m getting :-<br><br>[att=1]<br><small>--<br>&raquo;<A HREF="http://www.supermacro.net/" >www.supermacro.net/</A><br>&raquo;<A HREF="http://www.flickr.com/photos/action_man/" >www.flickr.com/photos/action_man/</A></small><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20327322?c=1296976&ret=L2ZvcnVtL3IyMDMyNzMyMi54bWw%3D"><IMG class="apic" BORDER=0 TITLE="271004 bytes" WIDTH=600 HEIGHT=469 SRC="/r0/download/1296976.thumb600~e06d061a77a7bde916b8a91163029d41/Untitled-1.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20327322</guid>
<pubDate>Sun, 13 Apr 2008 13:41:12 EDT</pubDate>
</item>

</channel>
</rss>
