Member Panel


Sponsors and Ads

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » IE and FF opening ad windows; programs shut down when ad windows are closed!

[Fixed] Hijackthis! Logs - IE and FF opening ad windows; programs shut down when ad windows are closed! posted in the Security & Safety forums; This is my first post; I thought I was good fighting malware, but I can't get this to end, and am gratefully seeking help! My browsers are functioning very slowly, ...

JOIN US NOW to remove these Ads

pc help forum number one in the search engines
Post New Thread  Reply
  #1  
Old 03-17-2008
awenner's Avatar
Bronze Member
 
Join Date: Mar 2008
Posts: 6
PC Experience: Experienced
awenner - See this Members User comments on their Profile page
Unhappy IE and FF opening ad windows; programs shut down when ad windows are closed!

This is my first post; I thought I was good fighting malware, but I can't get this to end, and am gratefully seeking help!

My browsers are functioning very slowly, and sprout magic ad windows frequently. Pop-ups are shut off, and I've followed all the prelim steps. I have Spybot, Windows Defender, McAfee Antivirus, Counter Spy, and SpyHunter going, and still can't get rid of this.

Hijackthis log is below and attached; any ideas? Thanks!!! AR Wenner

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:17:10 AM, on 3/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FolderShare\FolderShare.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\Install\N etFx30SP1_x86.exe
f:\185ae4ef7348229c8a\setup.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\msco rsvw.exe
C:\WINDOWS\System32\msiexec.exe
C:\WINDOWS\System32\MsiExec.exe
C:\WINDOWS\System32\MsiExec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://exchange.syr.edu/exchange/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R3 - URLSearchHook: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre1.dll (file missing)
O2 - BHO: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre1.dll (file missing)
O2 - BHO: (no name) - {17E7EDFE-3298-41E7-9FDB-494649B59091} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: {15dfc0b1-d674-b50a-6bf4-50a396cf73f5} - {5f37fc69-3a05-4fb6-a05b-476d1b0cfd51} - C:\WINDOWS\system32\aabdctds.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: (no name) - {758A7917-328C-4E1B-B13B-1D94316BE9FE} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {77A3F107-8918-40F2-A55C-5AA94C03487C} - C:\WINDOWS\system32\mljgf.dll (file missing)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
O2 - BHO: (no name) - {E9383002-FC55-4330-B9C9-67E03BC5C840} - C:\WINDOWS\system32\ssqpnli.dll (file missing)
O3 - Toolbar: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre1.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [BM174fffee] Rundll32.exe "C:\WINDOWS\system32\biwcwhmm.dll",s
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [FolderShare] "C:\Program Files\FolderShare\FolderShare.exe" /background
O4 - Startup: Anapod Manager.lnk = C:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1199485231692
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1199485372052
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
--
End of file - 9092 bytes
Attached Files
File Type: log hijackthis.log (8.9 KB, 0 views)


  #2  
Old 03-17-2008
Pancake's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 2,281
PC Experience: Elite PC Guru
Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page
Default Re: IE and FF opening ad windows; programs shut down when ad windows are closed!

Please download SDFix from here and save it to your desktop
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, the Advanced Options Menu should appear;
Select the first option, to run Windows in Safe Mode, then press Enter.
Choose your usual account.
Open the extracted SDFix folder and double click RunThis.bat to start the script.
Type Y to begin the cleanup process.
It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
Press any Key and it will restart the PC.
When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).
Post that log in your next reply.
=================================

Ok.We need to download ComboFix.exe. This will give a better view to the files running and also hidden on your computer.
Please visit this webpage for download links, and instructions for running the tool

When the tool is finished, it will produce a report for you. Please post the "C:\ComboFix.txt" along with a new HijackThis log so that we can continue to do any further cleaning that your system may require.
Caution: Never run and remove files with Combofix unless supervised by a security analyst.


__________________
  • An Australian Member of
  • and
My real name is Eddy
  #3  
Old 03-17-2008
awenner's Avatar
Bronze Member
 
Join Date: Mar 2008
Posts: 6
PC Experience: Experienced
awenner - See this Members User comments on their Profile page
Default Re: IE and FF opening ad windows; programs shut down when ad windows are closed!

Thank you so much!! I will try this soon, and upload the logs soon! AR Wenner


  #4  
Old 03-18-2008
awenner's Avatar
Bronze Member
 
Join Date: Mar 2008
Posts: 6
PC Experience: Experienced
awenner - See this Members User comments on their Profile page
Default Re: IE and FF opening ad windows; programs shut down when ad windows are closed!

Thank you for the guidance! I have run the recommended programs, and here are the results:
=========================
1) SDFIX:


SDFix: Version 1.158
Run by Administrator on Mon 03/17/2008 at 10:13 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :

Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting

Checking Files :
No Trojan Files Found



Removing Temp Files
ADS Check :


Final Check :
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-17 22:21:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
C:\WINDOWS\system32\wbem\Performance\WmiApRpl_new. h 357 bytes
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 1

Remaining Services :

Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\standard profile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"="C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe:*:Enabled:EasyShare"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\Common Files\\Nero\\Nero Web\\SetupX.exe"="C:\\Program Files\\Common Files\\Nero\\Nero Web\\SetupX.exe:*:Enabled:Nero ControlCenter"
"C:\\Documents and Settings\\Administrator\\Local Settings\\Temp\\OnlineUpdate8\\SetupXu.exe"="C:\\D ocuments and Settings\\Administrator\\Local Settings\\Temp\\OnlineUpdate8\\SetupXu.exe:*:Enabl ed:Nero ControlCenter"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\FolderShare\\FolderShare.exe"="C:\\Program Files\\FolderShare\\FolderShare.exe:*:Enabled:Fold erShare"
"J:\\utorrent.exe"="J:\\utorrent.exe:*:Enabled:æTo rrent"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Program Files\\Steam\\SteamApps\\bubbaw\\source sdk base\\hl2.exe"="C:\\Program Files\\Steam\\SteamApps\\bubbaw\\source sdk base\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\Steam\\SteamApps\\bubbaw\\condition zero\\hl.exe"="C:\\Program Files\\Steam\\SteamApps\\bubbaw\\condition zero\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\Program Files\\Steam\\SteamApps\\bubbaw\\half-life\\hl.exe"="C:\\Program Files\\Steam\\SteamApps\\bubbaw\\half-life\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS \\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"="C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe:*:Enabled:McAfee Framework Service"
"C:\\Program Files\\Red Chair Software\\Anapod Explorer\\anamgr.exe"="C:\\Program Files\\Red Chair Software\\Anapod Explorer\\anamgr.exe:*:Enabled:Anapod Xtreamer"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\domainpr ofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files :

File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Thu 24 Jan 2008 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 12 Jan 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Sun 9 Mar 2008 165,232 A..H. --- "C:\Documents and Settings\Administrator\Application Data\Microsoft\Virtual PC\VPCKeyboard.dll"
Fri 2 Feb 2007 31,744 A..H. --- "C:\Documents and Settings\Administrator\My Documents\My Pictures\boom\~WRL2394.tmp"
Fri 2 Feb 2007 31,232 A..H. --- "C:\Documents and Settings\Administrator\My Documents\My Pictures\boom\~WRL3485.tmp"
Finished!
=====================================
2) ComboFix

ComboFix 08-03-17.1 - Administrator 2008-03-17 22:37:10.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.465 [GMT -4:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM174fffee.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aabdctds.dll
C:\WINDOWS\system32\atnewxwt.ini
C:\WINDOWS\system32\biwcwhmm.dll
C:\WINDOWS\system32\brphcrgy.ini
C:\WINDOWS\system32\dfhkj.ini
C:\WINDOWS\system32\dfhkj.ini2
C:\WINDOWS\system32\ewfohfin.dll
C:\WINDOWS\system32\fgjlm.ini
C:\WINDOWS\system32\fgjlm.ini2
C:\WINDOWS\system32\kphbshua.dll
C:\WINDOWS\system32\kvcplduw.dll
C:\WINDOWS\system32\npqss.ini
C:\WINDOWS\system32\npqss.ini2
C:\WINDOWS\system32\qkyhvuuf.dll
C:\WINDOWS\system32\rpjtojvl.dll
C:\WINDOWS\system32\twxwenta.dll
C:\WINDOWS\system32\utstv.ini
C:\WINDOWS\system32\utstv.ini2
C:\WINDOWS\system32\xiemnrct.dll
C:\WINDOWS\system32\xkvwrtqm.dll
C:\WINDOWS\system32\ygrchprb.dll
C:\WINDOWS\system32\yqayhfyo.dll
C:\WINDOWS\system32\yyadd.ini
C:\WINDOWS\system32\yyadd.ini2
.
((((((((((((((((((((((((( Files Created from 2008-02-18 to 2008-03-18 )))))))))))))))))))))))))))))))
.
2008-03-17 22:09 . 2008-03-17 22:09 <DIR> d-------- C:\WINDOWS\ERUNT
2008-03-17 22:00 . 2008-03-17 22:26 <DIR> d-------- C:\SDFix
2008-03-17 20:29 . 2008-03-17 21:58 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-03-17 09:44 . 2008-03-17 09:44 <DIR> d-------- C:\Program Files\CCleaner
2008-03-16 20:06 . 2008-03-16 20:06 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-16 02:00 . 2008-03-16 02:00 0 --a------ C:\WINDOWS\system32\SBRC.dat
2008-03-16 02:00 . 2008-03-16 02:00 0 --a------ C:\WINDOWS\system32\SBFC.dat
2008-03-14 17:34 . 2008-03-15 05:42 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-03-14 12:31 . 2008-03-15 13:45 <DIR> d-------- C:\QUARANTINE
2008-03-14 12:26 . 2007-10-24 01:47 282,112 --a------ C:\WINDOWS\system32\TBD43.tmp
2008-03-14 12:25 . 2008-03-15 12:25 1,366,923 ---hs---- C:\WINDOWS\system32\oqonpasl.ini
2008-03-14 09:49 . 2008-03-14 09:49 <DIR> d-------- C:\Program Files\MSBuild
2008-03-14 09:25 . 2008-03-17 10:48 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-03-14 09:17 . 2008-03-14 09:17 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-03-14 09:12 . 2006-06-29 13:07 14,048 --a------ C:\WINDOWS\system32\spmsg2.dll
2008-03-14 09:03 . 2008-03-14 09:03 <DIR> d-------- C:\Program Files\Common Files\Cisco Systems
2008-03-14 09:03 . 2008-03-14 09:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-03-14 09:03 . 2006-12-19 15:06 1,495,552 --a------ C:\WINDOWS\system32\epoPGPsdk.dll
2008-03-14 09:03 . 2006-12-19 15:06 280 --a------ C:\WINDOWS\system32\epoPGPsdk.dll.sig
2008-03-14 09:02 . 2007-08-13 20:50 171,240 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-03-14 09:02 . 2007-08-13 20:50 72,712 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-03-14 09:02 . 2007-09-07 20:50 64,168 --a------ C:\WINDOWS\system32\drivers\mfeapfk.sys
2008-03-14 09:02 . 2007-08-13 20:50 52,200 --a------ C:\WINDOWS\system32\drivers\mfetdik.sys
2008-03-14 09:02 . 2007-08-13 20:50 34,184 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-03-14 09:00 . 2008-03-14 09:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-03-14 08:59 . 2008-03-14 09:03 <DIR> d-------- C:\Program Files\McAfee
2008-03-14 08:59 . 2008-03-14 08:59 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-03-14 08:53 . 2006-11-13 02:02 288,768 --a------ C:\WINDOWS\system32\rhttpaa.dll
2008-03-14 08:53 . 2006-11-13 02:02 116,736 --a------ C:\WINDOWS\system32\aaclient.dll
2008-03-14 08:53 . 2006-11-13 02:02 36,352 --a------ C:\WINDOWS\system32\tsgqec.dll
2008-03-13 09:39 . 2008-03-13 09:39 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-03-12 15:19 . 2008-03-12 15:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\logs
2008-03-12 09:53 . 2008-03-12 09:53 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-03-12 09:40 . 2008-03-12 09:40 15,544 --a------ C:\WINDOWS\system32\drivers\sbhr.sys
2008-03-12 09:37 . 2008-03-12 09:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Sunbelt Software
2008-03-12 09:37 . 2008-03-12 09:37 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sunbelt Software
2008-03-12 09:34 . 2008-03-12 09:34 <DIR> d-------- C:\Program Files\Sunbelt Software
2008-03-12 09:09 . 2008-03-12 09:41 <DIR> d-------- C:\Program Files\Exterminate It!
2008-03-10 10:08 . 2008-03-10 10:12 <DIR> d-------- C:\Program Files\CD Wave
2008-03-10 10:03 . 2008-03-10 10:03 <DIR> d-------- C:\Program Files\OpD2d
2008-03-10 09:58 . 2006-02-09 15:10 471,040 --a------ C:\WINDOWS\system32\SkinCrafter.dll
2008-03-10 09:58 . 2002-01-05 23:37 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2008-03-10 09:58 . 2000-12-07 02:02 209,608 --a------ C:\WINDOWS\system32\TABCTL32.OCX
2008-03-10 09:58 . 2001-03-14 03:49 140,288 --a------ C:\WINDOWS\system32\comdlg32.ocx
2008-03-10 09:58 . 2004-11-12 11:14 36,864 --a------ C:\WINDOWS\system32\SCLabel.ocx
2008-03-09 18:02 . 2008-03-10 09:49 <DIR> d-------- C:\Program Files\Audacity
2008-03-09 17:22 . 2008-03-09 18:01 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Audacity
2008-03-09 17:09 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2008-03-09 17:09 . 2004-08-03 23:07 59,264 --a--c--- C:\WINDOWS\system32\dllcache\usbaudio.sys
2008-03-09 17:09 . 2004-08-04 00:56 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-03-09 17:09 . 2004-08-04 00:56 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2008-03-09 17:09 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-03-09 17:09 . 2001-08-17 14:02 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
2008-03-08 13:02 . 2008-03-08 13:02 <DIR> d-------- C:\Program Files\Paint.NET
2008-03-07 11:05 . 2008-03-07 11:05 <DIR> d-------- C:\WINDOWS\Freecorder Toolbar
2008-03-07 11:05 . 2008-03-07 11:05 <DIR> d-------- C:\Program Files\Freecorder Toolbar
2008-03-07 11:05 . 2008-03-16 19:43 <DIR> d-------- C:\Program Files\Freecorder
2008-03-07 11:04 . 2008-03-07 11:04 <DIR> d-------- C:\Program Files\Real
2008-03-07 10:46 . 2008-03-07 10:46 <DIR> d-------- C:\Program Files\Torrent Harvester
2008-03-05 10:35 . 2004-08-04 00:10 48,128 --a------ C:\WINDOWS\system32\drivers\61883.sys
2008-03-05 10:35 . 2004-08-04 00:10 48,128 --a--c--- C:\WINDOWS\system32\dllcache\61883.sys
2008-03-05 10:35 . 2004-08-04 00:10 38,912 --a------ C:\WINDOWS\system32\drivers\avc.sys
2008-03-05 10:35 . 2004-08-04 00:10 38,912 --a--c--- C:\WINDOWS\system32\dllcache\avc.sys
2008-03-05 09:44 . 2008-03-05 10:23 <DIR> d-------- C:\Program Files\Mojave
2008-03-05 09:44 . 1999-03-30 18:58 220,482 --a------ C:\WINDOWS\system32\DrvAgent.dll
2008-03-05 09:44 . 1999-04-30 17:39 196,096 --a------ C:\WINDOWS\system32\AgentCD.sys
2008-03-05 09:44 . 1999-03-30 19:00 191,304 --a------ C:\WINDOWS\system32\AgentCD.vxd
2008-03-05 09:44 . 1999-03-30 18:58 179,007 --a------ C:\WINDOWS\system32\DaConfig.dll
2008-03-05 09:34 . 2008-03-05 09:34 <DIR> d-------- C:\WINDOWS\system32\Dell
2008-03-04 21:31 . 2008-03-04 21:31 <DIR> d-------- C:\Program Files\RADVideo
2008-03-02 11:18 . 2008-03-02 17:53 <DIR> d-------- C:\Program Files\Ubisoft
2008-03-01 20:13 . 2008-03-01 20:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\{B9DFDEF4-3471-4379-BDBB-DEDA8A9809DF}
2008-03-01 20:11 . 2008-03-01 20:11 <DIR> d-------- C:\Program Files\Sports Mogul
2008-03-01 09:08 . 2008-03-01 09:16 <DIR> d-------- C:\Program Files\Free Net TV and Radio Player
2008-02-29 08:35 . 2008-02-29 08:35 <DIR> d-------- C:\KodakFW
2008-02-28 22:26 . 2008-02-28 22:26 <DIR> d-------- C:\Program Files\Sony
2008-02-26 18:55 . 2008-02-26 18:55 <DIR> d-------- C:\Program Files\SanDisk
2008-02-26 18:55 . 2008-02-26 18:55 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-02-20 16:57 . 2008-02-23 20:58 <DIR> d-------- C:\HammerAutosave
2008-02-20 15:52 . 2008-02-20 15:52 <DIR> d-------- C:\Program Files\Citrix
2008-02-20 15:52 . 2008-02-20 15:56 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\ICAClient
2008-02-20 15:35 . 2008-03-02 13:17 <DIR> d-------- C:\Program Files\Steam
2008-02-18 10:17 . 2008-02-18 10:17 <DIR> d-------- C:\Program Files\DVDRipSys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-03-12 18:00 --------- d-----w C:\Program Files\Java
2008-03-12 12:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-11 19:22 --------- d-----w C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-03-10 13:58 --------- d-----w C:\Program Files\Common Files\Download Manager
2008-03-05 13:44 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-19 11:51 --------- d-----w C:\Program Files\Handbrake
2008-02-14 13:32 --------- d-----w C:\Documents and Settings\Administrator\Application Data\1ClickDVDCopy
2008-02-02 16:52 --------- d-----w C:\Program Files\FLAC
2008-02-02 16:45 --------- d-----w C:\Program Files\Common Files\Ahead
2008-02-02 16:45 --------- d-----w C:\Program Files\Ahead
2008-01-24 02:08 --------- d-----w C:\Program Files\Real Alternative
2008-01-21 19:32 --------- d-----w C:\Program Files\Allok Video to FLV Converter
2008-01-20 17:08 --------- d-----w C:\Program Files\EphPod
2008-01-20 15:14 --------- d-----w C:\Program Files\Abbie's Sleep Timer for iTunes
2008-01-20 01:49 --------- d-----w C:\Program Files\Gilligames
2008-01-20 00:04 --------- d-----w C:\Program Files\1Click DVD to Divx Avi
2008-01-19 23:33 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Nero8
2008-01-05 03:50 737,280 ----a-w C:\WINDOWS\iun6002.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 17:46 1460560]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-09-20 16:35 202024]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"FolderShare"="C:\Program Files\FolderShare\FolderShare.exe" [2005-10-30 23:12 851968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-10-06 15:16 5058560]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 10:51 1836328]
"Lexmark X74-X75"="C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe" [2002-10-14 16:09 57344]
"LVCOMS"="C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE" [2002-06-10 15:21 102400]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 16:57 153136]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"dvd43"="C:\Program Files\dvd43\dvd43_tray.exe" [2007-11-20 17:40 731136]
"SBCSTray"="C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe" [2007-12-21 15:30 698864]
"SpyHunter Security Suite"="C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2008-01-23 14:47 847872]
"ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.exe" [2007-08-13 20:50 111952]
"McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UdaterUI.exe" [2006-12-19 11:27 136768]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-09-19 05:33:46 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\147ccc72]
C:\WINDOWS\system32\lsapnoqo.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM174fffee]
C:\WINDOWS\system32\qkyhvuuf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 12:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Common Files\\Nero\\Nero Web\\SetupX.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\FolderShare\\FolderShare.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Steam\\SteamApps\\bubbaw\\source sdk base\\hl2.exe"=
"C:\\Program Files\\Steam\\SteamApps\\bubbaw\\condition zero\\hl.exe"=
"C:\\Program Files\\Steam\\SteamApps\\bubbaw\\half-life\\hl.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"C:\\Program Files\\Red Chair Software\\Anapod Explorer\\anamgr.exe"=

[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{9c98b2d3-bade-11dc-ba13-806d6172696f}]
\Shell\AutoRun\command - D:\autoRcd.exe
*Newly Created Service* - SBAPIFS
.
Contents of the 'Scheduled Tasks' folder
"2008-01-05 00:00:32 C:\WINDOWS\Tasks\EasyShare Registration Task.job"
- C:\WINDOWS\System32\rundll32.exelC:\DOCUME~1\ALLUS E~1\APPLIC~1\Kodak\EasyShareSetup\$REGIS~1\Registr ation_7.5.30.2.sxt _RegistrationOffer@16
"2008-03-18 06:15:01 C:\WINDOWS\Tasks\SpyHunter Scanner.job"
- C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
.
================================================

3) New HijackThis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 06:43, on 2008-03-18
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FolderShare\FolderShare.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://exchange.syr.edu/exchange/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R3 - URLSearchHook: (no name) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - (no file)
O2 - BHO: (no name) - {17E7EDFE-3298-41E7-9FDB-494649B59091} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5f37fc69-3a05-4fb6-a05b-476d1b0cfd51} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: (no name) - {758A7917-328C-4E1B-B13B-1D94316BE9FE} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {77A3F107-8918-40F2-A55C-5AA94C03487C} - (no file)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
O2 - BHO: (no name) - {E9383002-FC55-4330-B9C9-67E03BC5C840} - (no file)
O3 - Toolbar: (no name) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [FolderShare] "C:\Program Files\FolderShare\FolderShare.exe" /background
O4 - Startup: Anapod Manager.lnk = C:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1199485231692
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1199485372052
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
--
End of file - 8615 bytes


Thank you very much for your feedback; I am deeply grateful for the help!!

AR Wenner


  #5  
Old 03-18-2008
Pancake's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 2,281
PC Experience: Elite PC Guru
Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page
Default Re: IE and FF opening ad windows; programs shut down when ad windows are closed!

We need to install your Recovery Console first.
Go to Microsoft's website => How to obtain Windows XP Setup boot disks
Select the download that's appropriate for your Operating System



Download the file & save it as its originally named, next to ComboFix.exe.



Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it. Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console. When complete, a log named CF_RC.txt will open. Please post the contents of that log.


__________________
  • An Australian Member of
  • and
My real name is Eddy
  #6  
Old 03-18-2008
awenner's Avatar
Bronze Member
 
Join Date: Mar 2008
Posts: 6
PC Experience: Experienced
awenner - See this Members User comments on their Profile page
Default Re: IE and FF opening ad windows; programs shut down when ad windows are closed!

Thank you! Here is the text of that requested file:
=====================================

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOW S
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Micro soft Windows XP Professional" /fastdetect /NoExecute=OptIn
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

Thank you; is there a next step?

AR Wenner



Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 06:31 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7