My Anti Spyware
News, Free Programs, Online Scanners, Tutorials
Post your problems with Spyware, Hijackers, Trojans...
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister     ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Infected with Trojan.Vundo PLEASE HELP

 
Post new topic   Reply to topic    My Anti Spyware Forum Index -> Spyware Removal
View previous topic :: View next topic  
Author Message
rednate06



Joined: 03 Jun 2008
Posts: 3

PostPosted: Tue Jun 03, 2008 4:42 pm    Post subject: Infected with Trojan.Vundo PLEASE HELP Reply with quote

I have scanned with Norton 360, Ad-Aware Free 8 and Spybot S&D.

All claim to have removed the virus but it keeps coming back.

Symptoms include random advertising pages popping up when using internet explorer and generally slow system taking especially long to start up.

Any help is much appreciated.

I have run a hijackthis scan and the log file is as follows:

Logfile of HijackThis v1.99.1

Scan saved at 17:29:51, on 03/06/2008

Platform: Unknown Windows (WinNT 6.00.1905 SP1)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)



Running processes:

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files\Windows Defender\MSASCui.exe

C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe

C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe

C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Windows\RtHDVCpl.exe

C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Kontiki\KHost.exe

C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\System32\igfxpers.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Windows\system32\igfxsrvc.exe

C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\Synaptics\SynTP\SynToshiba.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\HijackThis\HijackThis.exe

C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe

C:\Windows\system32\SearchFilterHost.exe



R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.live.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=127.0.0.1:8080;http=127.0.0.1:8080;https=127.0.0.1:8080;socks=127.0.0.1:1080

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {0EDE6A10-A615-4440-9FD2-6CA412EEE6F2} - C:\Windows\system32\yayyaBrq.dll (file missing)

O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: (no name) - {514A5C49-0C7D-42c3-A71B-38864A269B7A} - C:\Windows\system32\ioshaipa.dll (file missing)

O2 - BHO: (no name) - {688B55B3-46BB-4ECC-B4E6-9FA7AE3A3E30} - C:\Windows\system32\yayxwtqo.dll (file missing)

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: (no name) - {90d91a59-3c7f-4e2c-a84a-048744f49bb3} - (no file)

O2 - BHO: (no name) - {F0E738CA-4E59-446F-B34A-6BC26FB2C735} - C:\Windows\system32\yayyVpNd.dll (file missing)

O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll

O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE

O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe

O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe

O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe

O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe

O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE

O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?EN (file missing)

O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll

O11 - Options group: [INTERNATIONAL] International*

O13 - Gopher Prefix:

O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9563.cab

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: igfxcui - C:\Windows\SYSTEM32\igfxdev.dll

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: ccEvtMgr - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: ccSetMgr - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe

O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)

O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe

O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe

O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe

O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)

Thank you.
Back to top
View user's profile Send private message
patrik
Site Admin


Joined: 08 Jan 2006
Posts: 1229

PostPosted: Wed Jun 04, 2008 2:10 am    Post subject: Reply with quote

Hello Rednate06, welcome to the forum!

Run HijackThis. Click “Do a system scan only.” and put a checkmark next to the following items:
Quote:
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=127.0.0.1:8080;http=127.0.0.1:8080;https=127.0.0.1:8080;socks=127.0.0.1:1080
O2 - BHO: (no name) - {0EDE6A10-A615-4440-9FD2-6CA412EEE6F2} - C:\Windows\system32\yayyaBrq.dll (file missing)
O2 - BHO: (no name) - {514A5C49-0C7D-42c3-A71B-38864A269B7A} - C:\Windows\system32\ioshaipa.dll (file missing)
O2 - BHO: (no name) - {688B55B3-46BB-4ECC-B4E6-9FA7AE3A3E30} - C:\Windows\system32\yayxwtqo.dll (file missing)
O2 - BHO: (no name) - {90d91a59-3c7f-4e2c-a84a-048744f49bb3} - (no file)
O2 - BHO: (no name) - {F0E738CA-4E59-446F-B34A-6BC26FB2C735} - C:\Windows\system32\yayyVpNd.dll (file missing)


Now close all browser and other windows except for HijackThis, and click “Fix Checked” to have HijackThis fix the entries you checked.

Download combofix. Close any open browsers. Double click on combofix.exe and follow the prompts.

Make a fresh HijackThis log.

Post HijackThis log and Combofix log with your reply.

_________________
Antispyware: HijackThis, SmitfraudFix, ComboFix, CounterSpy Antispyware, Super Antispyware
Instructions: Show hidden files, Reboot in Safe Mode
Back to top
View user's profile Send private message Send e-mail
rednate06



Joined: 03 Jun 2008
Posts: 3

PostPosted: Wed Jun 04, 2008 9:07 am    Post subject: Reply with quote

Thank you for your reply.

I did not fix the following line using combofix since those are actually my required internet proxy settings.

Quote:
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=127.0.0.1:8080;http=127.0.0.1:8080;https=127.0.0.1:8080;socks=127.0.0.1:1080


After fixing the other entries in hijackthis and combofix, the logs are as follows:

Code:
ComboFix 08-06-03.1 - Nate Dogg 2008-06-04  9:50:38.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1252.1.1033.18.185 [GMT 1:00]
Running from: C:\Users\Nate Dogg\Desktop\ComboFix.exe
 * Created a new restore point
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Windows\system32\ftqyylou.dll
C:\Windows\system32\guvxktbj.ini
C:\Windows\system32\hwelbffy.ini
C:\Windows\system32\mcrh.tmp
C:\Windows\system32\oqtwxyay.ini
C:\Windows\System32\oqtwxyay.ini2
C:\Windows\System32\qrBayyay.ini
C:\Windows\System32\qrBayyay.ini2
C:\Windows\system32\sYyIPXyb.ini
C:\Windows\System32\sYyIPXyb.ini2
C:\Windows\System32\uuFiknpo.ini
C:\Windows\System32\uuFiknpo.ini2
C:\Windows\system32\x64
C:\Windows\system32\xdfxqdoj.ini

.
(((((((((((((((((((((((((   Files Created from 2008-05-04 to 2008-06-04  )))))))))))))))))))))))))))))))
.

2008-06-03 15:13 . 2008-06-03 15:13   0   --ah-----   C:\ntuser.dat.LOG2
2008-06-03 15:13 . 2008-06-03 15:13   0   --ah-----   C:\ntuser.dat.LOG1
2008-06-03 15:13 . 2008-06-03 15:13   0   --a------   C:\ntuser.dat
2008-06-02 15:33 . 2008-06-02 15:33   <DIR>   d--------   C:\Users\All Users\Avg8
2008-06-02 15:33 . 2008-06-02 15:33   <DIR>   d--------   C:\ProgramData\Avg8
2008-06-01 17:07 . 2008-06-01 17:07   <DIR>   d--------   C:\Program Files\FreeUndelete
2008-06-01 16:19 . 2008-06-01 16:26   <DIR>   d--------   C:\Program Files\Windows Live Safety Center
2008-06-01 12:31 . 2008-06-01 12:31   <DIR>   d--------   C:\VundoFix Backups
2008-05-30 13:22 . 2008-05-30 13:22   <DIR>   d--------   C:\Users\All Users\WindowsSearch
2008-05-30 13:22 . 2008-05-30 13:22   <DIR>   d--------   C:\ProgramData\WindowsSearch
2008-05-30 02:01 . 2008-05-30 10:47   268   --a------   C:\Windows\wininit.ini
2008-05-30 01:39 . 2008-05-30 01:43   <DIR>   d--------   C:\Users\All Users\Lavasoft
2008-05-30 01:39 . 2008-05-30 01:43   <DIR>   d--------   C:\ProgramData\Lavasoft
2008-05-30 01:39 . 2008-05-30 01:39   <DIR>   d--------   C:\Program Files\Lavasoft
2008-05-30 01:36 . 2008-05-30 01:36   <DIR>   d--------   C:\Program Files\Common Files\Wise Installation Wizard
2008-05-30 01:31 . 2008-05-30 02:02   <DIR>   d--------   C:\Users\All Users\Spybot - Search & Destroy
2008-05-30 01:31 . 2008-05-30 02:02   <DIR>   d--------   C:\ProgramData\Spybot - Search & Destroy
2008-05-30 01:31 . 2008-05-30 01:31   <DIR>   d--------   C:\Program Files\Spybot - Search & Destroy
2008-05-29 11:32 . 2008-05-29 11:32   <DIR>   d--------   C:\Users\Nate Dogg\AppData\Roaming\Ubisoft
2008-05-29 11:32 . 2008-05-29 11:32   <DIR>   d--------   C:\Users\All Users\Ubisoft
2008-05-29 11:32 . 2008-05-29 11:32   <DIR>   d--------   C:\ProgramData\Ubisoft
2008-05-29 11:04 . 2006-09-28 16:05   2,414,360   --a------   C:\Windows\System32\d3dx9_31.dll
2008-05-29 11:04 . 2006-09-28 16:05   237,848   --a------   C:\Windows\System32\xactengine2_4.dll
2008-05-29 11:04 . 2006-07-28 09:30   236,824   --a------   C:\Windows\System32\xactengine2_3.dll
2008-05-29 11:04 . 2006-07-28 09:30   62,744   --a------   C:\Windows\System32\xinput1_2.dll
2008-05-29 11:04 . 2007-03-05 12:42   15,128   --a------   C:\Windows\System32\x3daudio1_1.dll
2008-05-29 10:19 . 2008-06-03 17:35   <DIR>   d--------   C:\Program Files\Ubisoft
2008-05-29 10:05 . 2008-05-29 10:05   <DIR>   d--------   C:\Users\Nate Dogg\AppData\Roaming\DAEMON Tools Pro
2008-05-29 10:05 . 2008-05-29 10:05   <DIR>   d--------   C:\Users\All Users\DAEMON Tools Pro
2008-05-29 10:05 . 2008-05-29 10:05   <DIR>   d--------   C:\ProgramData\DAEMON Tools Pro
2008-05-29 10:03 . 2008-05-29 10:07   <DIR>   d--------   C:\Program Files\DAEMON Tools Pro
2008-05-28 10:51 . 2008-03-08 05:21   1,695,744   --a------   C:\Windows\System32\gameux.dll
2008-05-28 10:50 . 2008-03-08 03:08   4,240,384   --a------   C:\Windows\System32\GameUXLegacyGDFs.dll
2008-05-26 09:36 . 2008-05-26 09:36   0   --ah-----   C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-05-24 03:03 . 2008-05-24 03:03   <DIR>   d--------   C:\PerfLogs
2008-05-24 02:03 . 2008-01-19 08:35   4,875,776   --a------   C:\Windows\System32\NlsData0009.dll
2008-05-24 02:02 . 2008-01-19 08:35   9,847,296   --a------   C:\Windows\System32\NlsData000a.dll
2008-05-24 02:01 . 2008-01-19 08:35   3,072,000   --a------   C:\Windows\System32\networkmap.dll
2008-05-24 02:00 . 2008-01-19 08:34   6,103,040   --a------   C:\Windows\System32\chtbrkr.dll
2008-05-24 01:59 . 2008-01-19 07:06   8,147,456   --a------   C:\Windows\System32\wmploc.DLL
2008-05-24 01:57 . 2008-01-19 08:36   704,512   --a------   C:\Windows\System32\SmiEngine.dll
2008-05-24 01:57 . 2008-01-19 08:36   357,888   --a------   C:\Windows\System32\wbemcomn.dll
2008-05-24 01:57 . 2008-01-19 08:34   305,152   --a------   C:\Windows\System32\msdelta.dll
2008-05-24 01:57 . 2008-01-19 08:34   258,560   --a------   C:\Windows\System32\dpx.dll
2008-05-24 01:57 . 2008-01-19 08:34   246,784   --a------   C:\Windows\System32\drvstore.dll
2008-05-24 01:57 . 2008-01-19 08:36   218,624   --a------   C:\Windows\System32\wdscore.dll
2008-05-24 01:57 . 2008-01-19 08:36   139,264   --a------   C:\Windows\System32\SmiInstaller.dll
2008-05-24 01:57 . 2008-01-19 08:33   130,560   --a------   C:\Windows\System32\PkgMgr.exe
2008-05-24 01:57 . 2008-01-19 08:35   35,328   --a------   C:\Windows\System32\mspatcha.dll
2008-05-16 11:58 . 2008-05-16 11:58   12,632   --a------   C:\Windows\System32\lsdelete.exe
2008-05-12 23:25 . 2008-05-12 23:26   <DIR>   d--------   C:\Program Files\AC3Filter
2008-05-11 10:08 . 2008-05-11 10:08   <DIR>   dr-------   C:\Windows\System32\config\systemprofile\Music
2008-05-06 23:39 . 2008-05-06 23:39   <DIR>   d--------   C:\Users\Nate Dogg\AppData\Roaming\vlc
2008-05-06 21:14 . 2008-05-06 21:14   <DIR>   d--------   C:\Program Files\VideoLAN

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-04 08:43   ---------   d-----w   C:\ProgramData\Symantec
2008-06-03 16:33   ---------   d--h--w   C:\Program Files\InstallShield Installation Information
2008-06-01 19:01   ---------   d-----w   C:\Users\Nate Dogg\AppData\Roaming\Azureus
2008-06-01 15:36   ---------   d-----w   C:\Program Files\Symantec
2008-06-01 15:35   805   ----a-w   C:\Windows\system32\drivers\SYMEVENT.INF
2008-06-01 15:35   123,952   ----a-w   C:\Windows\system32\drivers\SYMEVENT.SYS
2008-06-01 15:35   10,671   ----a-w   C:\Windows\system32\drivers\SYMEVENT.CAT
2008-05-30 00:09   ---------   d-----w   C:\Program Files\Norton 360
2008-05-28 12:58   ---------   d-----w   C:\ProgramData\Kontiki
2008-05-24 10:34   174   --sha-w   C:\Program Files\desktop.ini
2008-05-24 02:08   ---------   d-----w   C:\Program Files\Windows Sidebar
2008-05-24 02:08   ---------   d-----w   C:\Program Files\Windows Photo Gallery
2008-05-24 02:08   ---------   d-----w   C:\Program Files\Windows Mail
2008-05-24 02:08   ---------   d-----w   C:\Program Files\Windows Journal
2008-05-24 02:08   ---------   d-----w   C:\Program Files\Windows Defender
2008-05-24 02:08   ---------   d-----w   C:\Program Files\Windows Collaboration
2008-05-24 02:08   ---------   d-----w   C:\Program Files\Windows Calendar
2008-05-24 01:27   82,432   ----a-w   C:\Windows\System32\axaltocm.dll
2008-05-24 01:27   101,888   ----a-w   C:\Windows\System32\ifxcardm.dll
2008-05-24 00:31   ---------   d-----w   C:\ProgramData\Microsoft Help
2008-05-24 00:29   ---------   d-----w   C:\Program Files\Microsoft Silverlight
2008-05-23 23:24   ---------   d-----w   C:\Program Files\Azureus
2008-05-23 23:11   ---------   d-----w   C:\Users\Nate Dogg\AppData\Roaming\LimeWire
2008-05-06 11:25   ---------   d-----w   C:\Program Files\Valve
2008-04-30 18:34   ---------   d-----w   C:\Users\Nate Dogg\AppData\Roaming\Apple Computer
2008-04-29 21:03   ---------   d-----w   C:\ProgramData\Office Genuine Advantage
2008-04-29 10:20   15,648   ----a-w   C:\Windows\system32\drivers\NSDriver.sys
2008-04-29 10:19   15,648   ----a-w   C:\Windows\system32\drivers\Awrtrd.sys
2008-04-29 10:19   12,960   ----a-w   C:\Windows\system32\drivers\Awrtpd.sys
2008-04-19 18:37   ---------   d-----w   C:\Program Files\Alcohol Soft
2008-04-15 20:18   ---------   d-----w   C:\Program Files\iDump
2008-04-15 12:43   ---------   d-----w   C:\ProgramData\Driving Test Success
2008-04-15 12:43   ---------   d-----w   C:\Program Files\Driving Test Success 2006-2007
2008-04-15 11:00   ---------   d-----w   C:\Program Files\Your Freedom
2008-04-15 10:21   ---------   d-----w   C:\Program Files\Activision
2008-04-12 23:17   ---------   d-----w   C:\Users\Nate Dogg\AppData\Roaming\Talkback
2008-04-08 11:23   ---------   d-----w   C:\Users\Nate Dogg\AppData\Roaming\Symantec
2008-04-08 11:21   ---------   d-----w   C:\Program Files\LimeWire
2008-03-08 04:19   540,672   ----a-w   C:\Windows\AppPatch\AcLayers.dll
2008-03-08 04:19   458,752   ----a-w   C:\Windows\AppPatch\AcSpecfc.dll
2008-03-08 04:19   2,153,984   ----a-w   C:\Windows\AppPatch\AcGenral.dll
2008-03-08 04:19   173,056   ----a-w   C:\Windows\AppPatch\AcXtrnal.dll
2008-03-08 01:58   2,560   ----a-w   C:\Windows\AppPatch\AcRes.dll
2007-11-25 20:59   9,679,815   ----a-w   C:\Users\Public\vlc-0.8.6c-win32.exe
.

------- Sigcheck -------

.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 08:33 1233920]
"TOSCDSPD"="TOSCDSPD.EXE" []
"kdx"="C:\Program Files\Kontiki\KHost.exe" [2007-04-23 12:23 1032640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPwrMain"="C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE" [2006-12-14 20:07 411768]
"HSON"="C:\Program Files\TOSHIBA\TBS\HSON.exe" [2006-12-07 17:49 55416]
"SmoothView"="C:\Program Files\Toshiba\SmoothView\SmoothView.exe" [2006-12-14 20:09 493688]
"00TCrdMain"="C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe" [2006-12-11 18:27 530552]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2006-12-07 20:25 90191]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2006-12-07 20:25 7766016]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2006-12-07 20:25 81920]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 09:12 1029416]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-07 14:50 3772416 C:\Windows\RtHDVCpl.exe]
"NDSTray.exe"="NDSTray.exe" []
"topi"="C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2006-12-15 17:11 577536]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 06:59 115816]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 18:38 583048]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"4oD"="C:\Program Files\Kontiki\KHost.exe" [2007-04-23 12:23 1032640]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-02-11 20:13 141848]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-02-11 20:13 166424]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2008-02-11 20:13 133656]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\vio\dvacm.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3958010173-3800541347-37436649-1000]
"EnableNotificationsRef"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{524094B7-DE4C-4D93-8202-F8E7F50B7F78}"= UDP:C:\Program Files\AOL\RC\regClient.exe:AOL
"{55A2FB0F-C696-456A-A13F-AF5946317DE6}"= TCP:C:\Program Files\AOL\RC\regClient.exe:AOL
"TCP Query User{A60993EA-989D-4C55-A814-556AE43109E4}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus
"UDP Query User{84267534-5EA6-486A-A9F8-C8ABDD058DDA}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus
"{8CC7C127-0FC7-4492-B070-5D183556B357}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{8C67F6DA-BC42-4288-A912-B377D094D6A4}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{640397D3-F0F6-46B7-85E2-7389E6E26FAF}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{FF60D330-EE83-4E01-9821-E1843A413636}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{1DBA8D3E-7B1C-487F-8203-556069D63775}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{E27EDE94-229D-4D05-ABA3-0ECEC96E8F58}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{E14AC465-2362-43DB-84E2-9F1849633C08}"= UDP:C:\Program Files\Kontiki\KService.exe:Delivery Manager Service
"{1D393B7D-8EB0-46EF-8DEF-1A073FB5E2EF}"= TCP:C:\Program Files\Kontiki\KService.exe:Delivery Manager Service
"{CE250353-9CAD-4D26-B254-216D20DD722C}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{A53BE13B-2BA7-4193-AC8D-E4DF5FB51AD3}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{2B080112-978B-425A-B255-06160EDEF38D}"= UDP:C:\Program Files\Kontiki\KService.exe:Delivery Manager Service
"{0A1B51B9-CF1B-4185-873B-C21FAF3CBAE5}"= TCP:C:\Program Files\Kontiki\KService.exe:Delivery Manager Service
"{EA66ECEC-77B8-455B-9E09-6B54B296390A}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{8C37FB3A-FB20-4E9C-92B8-7711D348A72F}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{70594DFF-BD11-45EF-AEEE-40FEBD122A44}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{E481B2A7-554B-4905-B939-8FA5B638B329}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{ACBE1497-5BF3-4C7D-AFAA-8D92A16B578B}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{683E1986-EDC0-4F7C-8C2C-6B86259A2931}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{982A6F12-211B-49EE-8CF8-EAA0438AF27E}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080530.001\IDSvix86.sys [2008-03-11 23:36]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R3 FwLnk;FwLnk Driver;C:\Windows\system32\DRIVERS\FwLnk.sys [2006-11-19 23:11]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 19:36]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2007-01-09 23:32]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver;C:\Windows\system32\DRIVERS\tdcmdpst.sys [2006-10-18 12:50]
S3 tosrfec;Bluetooth ACPI;C:\Windows\system32\DRIVERS\tosrfec.sys [2006-10-23 17:32]
S4 KR10I;KR10I;C:\Windows\system32\drivers\kr10i.sys [2006-02-14 18:50]
S4 KR10N;KR10N;C:\Windows\system32\drivers\kr10n.sys [2006-02-14 18:41]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{56cf952e-0d4f-11dd-a3fe-00a0d176eb1d}]
\shell\AutoRun\command - F:\LaunchU3.exe

*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-06-04 00:10:25 C:\Windows\Tasks\User_Feed_Synchronization-{D9B30BB4-63C0-47D4-A444-A174F9308500}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-04 09:56:34
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-04  9:57:46
ComboFix-quarantined-files.txt  2008-06-04 08:57:39

Pre-Run: 56,933,568,512 bytes free
Post-Run: 56,702,472,192 bytes free

234   --- E O F ---   2008-05-28 10:29:31


Code:
Logfile of HijackThis v1.99.1
Scan saved at 10:01:26, on 04/06/2008
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Kontiki\KHost.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Windows\explorer.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Nate Dogg\Desktop\HijackThis.exe
C:\PROGRA~1\Java\JRE16~1.0\bin\javaw.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.live.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=127.0.0.1:8080;http=127.0.0.1:8080;https=127.0.0.1:8080;socks=127.0.0.1:1080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?EN (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9563.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: igfxcui - C:\Windows\SYSTEM32\igfxdev.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ccEvtMgr - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: ccSetMgr - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)

Back to top
View user's profile Send private message
patrik
Site Admin


Joined: 08 Jan 2006
Posts: 1229

PostPosted: Thu Jun 05, 2008 1:50 am    Post subject: Reply with quote

Both logs look are ok.

Are you have any problems ?

_________________
Antispyware: HijackThis, SmitfraudFix, ComboFix, CounterSpy Antispyware, Super Antispyware
Instructions: Show hidden files, Reboot in Safe Mode
Back to top
View user's profile Send private message Send e-mail
rednate06



Joined: 03 Jun 2008
Posts: 3

PostPosted: Thu Jun 05, 2008 10:48 am    Post subject: Reply with quote

No.

Everthing seems fine for now.

Thank you very much for all your help.

Nate.
Back to top
View user's profile Send private message
patrik
Site Admin


Joined: 08 Jan 2006
Posts: 1229

PostPosted: Thu Jun 05, 2008 11:59 pm    Post subject: Reply with quote

last steps:

1. Uninstall combofix.

2. Make a new restore point.
Quote:
Disable system restore to flush out infected restore points. Reboot your computer again. Turn on Windows System Restore. After that click START > ALL PROGRAMS > ACCESSORIES > SYSTEM TOOLS > SYSTEM RESTORE. click on “create new restore point” > click on NEXT and follow the prompts.


3. Check your antivirus/antispyware auto protection, enable if need (some spyware/trojans can disable autoprotection)

Safe surfing Smile

_________________
Antispyware: HijackThis, SmitfraudFix, ComboFix, CounterSpy Antispyware, Super Antispyware
Instructions: Show hidden files, Reboot in Safe Mode
Back to top
View user's profile Send private message Send e-mail
Display posts from previous:   
Post new topic   Reply to topic    My Anti Spyware Forum Index -> Spyware Removal All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group
phpBB SEO