Help!

Help - Google and Yahoo Hijack - Log Posted

 
  

Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> HijackThis Logs RSS
Next:  Hijacking My Google searches  
Author Message
Artymuse



Joined: Jun 29, 2009
Posts: 5



PostPosted: Tue Jun 30, 2009 7:06 am    Post subject: Help - Google and Yahoo Hijack - Log Posted

Noticed a couple days ago that when i got my search results back from google any attempt to click on the links would invariably redirect me to some ad site or another. I tried Yahoo and got the same problem. I've been right-clicking on the links and selecting "copy link location" then pasting the link location in the address bar to get around this problem, but it is very troublesome.

Anyway, i followed the steps on the 'KRC Anti-Spyware Tutorial' first before posting my HijackThis log below.

I don't know if it is related, but my Norton Internet Security keeps finding and failing to fix a problem called "packed.generic.238." I even ran Norton in Safe Mode with System restore turned off; still doesn't do the job. I contacted Norton Symantec and they want me to pay an additional $99.00 for one of their 'professionals' to fix my computer. Can you help me?

------------------------------------------------------------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:00:04 AM, on 6/30/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\Elantech\ETDDect.exe
C:\Program Files\EeePC\ACPI\AsTray.exe
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
C:\Program Files\EeePC\ACPI\AsEPCMon.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Documents and Settings\Laura\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eeepc.asus.com/global
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
O1 - Hosts: 82.98.231.89 url.adtrgt.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O2 - BHO: (no name) - {65324ac4-1131-483d-b65d-6588acee6d79} - C:\WINDOWS\system32\mufojale.dll (file missing)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\IPSBHO.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O4 - HKLM\..\Run: [RTHDCPL] "RTHDCPL.EXE"
O4 - HKLM\..\Run: [Alcmtr] "ALCMTR.EXE"
O4 - HKLM\..\Run: [IgfxTray] "C:\WINDOWS\system32\igfxtray.exe"
O4 - HKLM\..\Run: [HotKeysCmds] "C:\WINDOWS\system32\hkcmd.exe"
O4 - HKLM\..\Run: [Persistence] "C:\WINDOWS\system32\igfxpers.exe"
O4 - HKLM\..\Run: [ETDWare] "C:\Program Files\Elantech\ETDCtrl.exe"
O4 - HKLM\..\Run: [ETDWareDetect] "C:\Program Files\Elantech\ETDDect.exe"
O4 - HKLM\..\Run: [AsusTray] "C:\Program Files\EeePC\ACPI\AsTray.exe"
O4 - HKLM\..\Run: [AsusACPIServer] "C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe"
O4 - HKLM\..\Run: [AsusEPCMonitor] "C:\Program Files\EeePC\ACPI\AsEPCMon.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ErrorFix] C:\Program Files\ErrorFix\ErrorFix.exe -boot
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [tidapasete] Rundll32.exe "C:\WINDOWS\system32\jahamure.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [tidapasete] Rundll32.exe "C:\WINDOWS\system32\jahamure.dll",s (User 'NETWORK SERVICE')
O4 - Global Startup: SuperHybridEngine.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O20 - AppInit_DLLs: c:\windows\system32\vevozere.dll,c:\windows\system32\nifarake.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe

--
End of file - 7230 bytes
Back to top
Artymuse



Joined: Jun 29, 2009
Posts: 5



PostPosted: Tue Jun 30, 2009 11:29 pm    Post subject: ComboFix Fixed It!

Well, i needed my computer up running so i took a gamble and went through with installing and running the ComboFix program from bleepingcomputer. Read in a few other posts that that was what fixed the problem in the end.... and it worked for me too! No more hijacked search engine results. Plus! It also got rid of the 'packed.generic.238' that my Norton Internet Security 2009 couldn't fix.

Before trying this solution, be aware that bleepingcomputer advises not to use ComboFix unless directed to by a forum specialist who is familiar with the program. ComboFix has a disclaimer you must agree to in order to run the program that states it does not take any responsibility for human errors in running the program.

Anyway, i'm just pleased it all worked out for me! ^_^
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Thu Jul 02, 2009 2:00 pm    Post subject:

Welcome to Lockergnome.

Glad you resolved the problem. Can I take a quick look at the ComboFix log (located in the C: drive) to verify that nothing else is hiding there?

Also run a new HijackThis scan and post that log here.
Back to top
AIM Address Yahoo Messenger
Artymuse



Joined: Jun 29, 2009
Posts: 5



PostPosted: Thu Jul 02, 2009 7:37 pm    Post subject:

Thanks!

Here is my combofix log:



ComboFix 09-06-29.07 - Laura 06/30/2009 21:24.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2039.1694 [GMT -4:00]
Running from: c:\documents and settings\Laura\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\abehipik.ini
c:\windows\system32\abidafay.ini
c:\windows\system32\arohokub.ini
c:\windows\system32\avisihok.ini
c:\windows\system32\drivers\SKYNETkmpmqwuy.sys
c:\windows\system32\edikeles.ini
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\ohomotoh.ini
c:\windows\system32\omodeviz.ini
c:\windows\system32\onofavan.ini
c:\windows\system32\osekohel.ini
c:\windows\system32\SKYNETabrnttkw.dll
c:\windows\system32\SKYNETduyqoeqa.dll
c:\windows\system32\SKYNETpbwoptob.dat
c:\windows\system32\SKYNETprhhlnkr.dat
c:\windows\system32\uyidimev.ini
c:\windows\system32\uzazivik.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_SKYNETtkioylvh


((((((((((((((((((((((((( Files Created from 2009-06-01 to 2009-07-01 )))))))))))))))))))))))))))))))
.

2009-07-01 01:29 . 2009-06-28 22:40 165240 ----a-r- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
2009-06-30 10:40 . 2009-06-30 10:42 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-30 10:40 . 2009-06-30 10:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-30 10:13 . 2008-06-19 21:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-06-30 10:12 . 2009-06-30 10:12 -------- d-----w- c:\program files\Panda Security
2009-06-30 09:41 . 2009-07-01 01:30 117760 ----a-w- c:\documents and settings\Laura\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-30 09:41 . 2009-06-30 09:41 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-06-30 09:40 . 2009-06-30 09:41 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-06-30 09:40 . 2009-06-30 09:40 -------- d-----w- c:\documents and settings\Laura\Application Data\SUPERAntiSpyware.com
2009-06-30 09:40 . 2009-06-30 09:40 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-06-30 03:07 . 2009-06-30 03:07 -------- d-----w- c:\documents and settings\Laura\Local Settings\Application Data\Help
2009-06-30 02:35 . 2009-06-30 02:35 -------- d-----w- c:\documents and settings\Laura\Application Data\Malwarebytes
2009-06-30 02:35 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-30 02:35 . 2009-06-30 02:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-30 02:35 . 2009-06-30 02:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-30 02:35 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-29 01:29 . 2009-06-29 01:29 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Symantec
2009-06-28 22:55 . 2009-06-28 22:55 -------- d-----r- c:\program files\Norton Support
2009-06-28 22:51 . 2009-06-28 22:51 -------- d-----w- c:\documents and settings\Laura\Local Settings\Application Data\Symantec
2009-06-28 22:41 . 2009-06-28 22:40 554352 ----a-r- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
2009-06-28 22:41 . 2009-06-28 22:40 36400 ----a-r- c:\windows\system32\drivers\SymIM.sys
2009-06-28 22:41 . 2009-06-29 01:51 -------- d-----w- c:\program files\Symantec
2009-06-28 22:41 . 2009-06-29 01:51 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-06-28 22:41 . 2009-06-28 22:41 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2009-06-28 22:41 . 2009-06-28 22:41 124464 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-06-28 22:40 . 2009-06-28 22:40 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSxpx86.sys
2009-06-28 22:40 . 2009-06-28 22:40 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSvia64.sys
2009-06-28 22:40 . 2009-06-28 22:40 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSvix86.sys
2009-06-28 22:40 . 2009-06-28 22:40 1290592 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
2009-06-28 22:40 . 2009-06-28 22:40 136840 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
2009-06-28 22:40 . 2009-06-28 22:40 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\idsxpx86.dll
2009-06-28 22:40 . 2009-06-28 22:40 796016 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
2009-06-28 22:40 . 2009-06-28 22:40 -------- d-----w- c:\windows\system32\drivers\NIS
2009-06-28 22:39 . 2009-06-29 01:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-28 22:39 . 2009-06-28 22:40 -------- d-----w- c:\program files\Norton Internet Security
2009-06-28 22:39 . 2009-06-28 22:39 -------- d-----w- c:\program files\Windows Sidebar
2009-06-28 22:30 . 2009-06-28 22:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2009-06-28 22:30 . 2009-06-28 22:38 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-06-28 22:30 . 2009-06-28 22:30 -------- d-----w- c:\program files\NortonInstaller
2009-06-28 22:25 . 2009-06-28 22:25 -------- d-----w- c:\documents and settings\All Users\Symantec Temporary Files
2009-06-28 04:14 . 2009-06-28 04:14 -------- d-----w- c:\program files\MSXML 4.0
2009-06-04 15:08 . 2009-06-04 15:08 -------- d-----w- c:\documents and settings\Laura\Local Settings\Application Data\Identities

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-29 01:25 . 2009-06-29 01:25 136 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2009-06-28 22:41 . 2009-06-28 22:41 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-06-28 22:41 . 2009-06-28 22:41 7386 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-06-28 22:40 . 2009-06-30 23:15 89104 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090630.032\NAVENG.SYS
2009-06-28 22:40 . 2009-06-30 23:15 876144 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090630.032\NAVEX15.SYS
2009-06-28 22:40 . 2009-06-30 23:15 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys
2009-06-28 22:40 . 2009-06-30 23:15 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090630.032\EECTRL.SYS
2009-06-28 22:40 . 2009-06-30 23:15 101936 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090630.032\ERASER.SYS
2009-06-28 22:40 . 2009-06-30 23:15 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSviA64.sys
2009-06-28 22:40 . 2009-06-30 23:15 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSvix86.sys
2009-06-28 22:40 . 2009-06-30 23:15 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090630.032\NAVENG32.DLL
2009-06-28 22:40 . 2009-06-30 23:15 1181040 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090630.032\NAVEX32A.DLL
2009-06-28 22:40 . 2009-06-30 23:15 259368 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090630.032\ECMSVR32.DLL
2009-06-28 22:40 . 2009-06-30 23:15 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSxpx86.dll
2009-06-28 22:40 . 2009-06-30 23:15 2414128 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090630.032\CCERASER.DLL
2009-06-28 22:37 . 2009-05-21 02:46 -------- d-----w- c:\documents and settings\Laura\Application Data\Webroot
2009-06-28 22:33 . 2009-01-17 19:40 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-28 04:18 . 2008-09-11 11:50 -------- d-----w- c:\program files\Microsoft Works
2009-06-21 17:13 . 2009-04-17 21:21 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-06-14 01:27 . 2009-01-17 20:09 1 ----a-w- c:\documents and settings\Laura\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-05-31 16:57 . 2009-05-31 16:57 74 ----a-w- c:\documents and settings\Laura\Application Data\wklnhst.dat
2009-05-31 16:57 . 2009-05-31 16:57 -------- d-----w- c:\documents and settings\Laura\Application Data\Template
2009-05-24 18:26 . 2009-02-14 19:42 -------- d-----w- c:\program files\PageBreeze
2009-05-21 03:57 . 2009-05-18 23:24 -------- d-----w- c:\documents and settings\All Users\Application Data\13663754
2009-05-21 02:47 . 2009-05-21 02:47 -------- d-----w- c:\program files\MSSOAP
2009-05-21 02:43 . 2009-05-21 02:43 164 ----a-w- c:\windows\install.dat
2009-05-19 02:06 . 2009-05-19 01:08 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-05-19 01:09 . 2009-05-19 00:56 -------- d-----w- c:\program files\SpyZooka
2009-05-12 06:17 . 2009-05-12 06:17 -------- d-----w- c:\documents and settings\Laura\Application Data\aAvgApi
2009-05-07 15:32 . 2008-08-09 14:32 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-07 10:48 . 2009-05-07 10:48 2098 -csh--w- c:\windows\system32\vonatahi.dll
2009-05-07 10:48 . 2009-05-07 10:48 2098 -csh--w- c:\windows\system32\teyunufa.dll
2009-05-06 04:52 . 2009-05-06 04:49 -------- d-----w- c:\documents and settings\Laura\Application Data\ErrorFix
2009-04-29 04:46 . 2008-08-09 14:32 666624 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:46 . 2008-08-09 14:32 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-04-19 04:01 . 2009-01-17 11:24 44944 -c--a-w- c:\documents and settings\Laura\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-17 12:26 . 2008-08-09 14:32 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2008-08-09 14:32 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2008-05-07 23:34 . 2008-09-11 13:03 15523560 ----a-w- c:\program files\Install AiGuruU1 Skype Phone.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-06-23 1830128]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-20 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-20 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-20 131072]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2008-09-03 335872]
"ETDWareDetect"="c:\program files\Elantech\ETDDect.exe" [2008-08-23 204800]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2008-09-03 106496]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2008-09-03 593920]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2008-05-21 94208]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-07-31 16806912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
SuperHybridEngine.lnk - c:\program files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2008-9-11 311296]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [6/30/2009 6:13 AM 28544]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1005000.087\SymEFA.sys [6/28/2009 6:40 PM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1005000.087\BHDrvx86.sys [6/28/2009 6:40 PM 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1005000.087\cchpx86.sys [6/28/2009 6:40 PM 482352]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys [6/30/2009 7:15 PM 276344]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 72944]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe [6/28/2009 6:40 PM 115560]
R3 AsusACPI;ASUS ACPI Driver;c:\windows\system32\drivers\ASUSACPI.SYS [9/11/2008 7:17 AM 10752]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/28/2009 7:13 PM 101936]
R3 Ktp;Elantech Smart-Pad;c:\windows\system32\drivers\ETD.sys [9/11/2008 6:18 PM 26112]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408]
S3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [1/2/2002 3:51 PM 36864]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [6/29/2009 10:35 PM 38160]
S3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [9/11/2008 10:42 PM 625024]
.
Contents of the 'Scheduled Tasks' folder

2009-07-01 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 18:20]
.
- - - - ORPHANS REMOVED - - - -

BHO-{65324ac4-1131-483d-b65d-6588acee6d79} - c:\windows\system32\mufojale.dll
HKCU-Run-ErrorFix - c:\program files\ErrorFix\ErrorFix.exe


.
------- Supplementary Scan -------
.
uStart Page = hxxp://eeepc.asus.com/global
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
FF - ProfilePath - c:\documents and settings\Laura\Application Data\Mozilla\Firefox\Profiles\xskmiyyt.default\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-30 21:30
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.5.0.135\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(584)
c:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(192)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\Microsoft.NET\Framework\v1.1.4322\fusion.dll
c:\program files\eee storage\xpclient.dll
c:\program files\eee storage\logicnp.eznamespaceextensions.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-01 21:33 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-01 01:33

Pre-Run: 74,780,753,920 bytes free
Post-Run: 74,735,120,384 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

236 --- E O F --- 2009-06-28 04:18


---------------------------------------------------------------------------------------------
---------------------------------------------------------------------------------------------
---------------------------------------------------------------------------------------------


And here is the new hijack this log that i ran just now:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:40:34 PM, on 7/2/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\EeePC\ACPI\AsTray.exe
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
C:\Program Files\EeePC\ACPI\AsEPCMon.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Laura\Desktop\Anti Virus Programs\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eeepc.asus.com/global
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O2 - BHO: (no name) - {65324ac4-1131-483d-b65d-6588acee6d79} - (no file)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\IPSBHO.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O4 - HKLM\..\Run: [RTHDCPL] "RTHDCPL.EXE"
O4 - HKLM\..\Run: [IgfxTray] "C:\WINDOWS\system32\igfxtray.exe"
O4 - HKLM\..\Run: [HotKeysCmds] "C:\WINDOWS\system32\hkcmd.exe"
O4 - HKLM\..\Run: [Persistence] "C:\WINDOWS\system32\igfxpers.exe"
O4 - HKLM\..\Run: [ETDWare] "C:\Program Files\Elantech\ETDCtrl.exe"
O4 - HKLM\..\Run: [ETDWareDetect] "C:\Program Files\Elantech\ETDDect.exe"
O4 - HKLM\..\Run: [AsusTray] "C:\Program Files\EeePC\ACPI\AsTray.exe"
O4 - HKLM\..\Run: [AsusACPIServer] "C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe"
O4 - HKLM\..\Run: [AsusEPCMonitor] "C:\Program Files\EeePC\ACPI\AsEPCMon.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: SuperHybridEngine.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe

--
End of file - 6747 bytes


Everything look alright?
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Fri Jul 03, 2009 10:46 am    Post subject:

Just a little more cleaning up...

Open up your Notepad editor (Start->Run, type in notepad and click OK). Copy the text from the quotebox below into Notepad:
Quote:
File::
c:\windows\system32\vonatahi.dll
c:\windows\system32\teyunufa.dll
Folder::
c:\documents and settings\Laura\Application Data\ErrorFix
c:\program files\ErrorFix\
Reglock::
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]

Save this as CFScript.txt in the same location as the ComboFix.exe tool.
Drag the CFScript.txt into ComboFix.exe
Follow the prompts. When finished, it shall produce a log for you. Post that log in your next reply.

Note: Do not click on combofix's window while it's running. That may cause it to stall.
Back to top
AIM Address Yahoo Messenger
Artymuse



Joined: Jun 29, 2009
Posts: 5



PostPosted: Fri Jul 03, 2009 9:57 pm    Post subject:

Ok, i followed your previous instruction and below is the new ComboFix log.


ComboFix 09-06-29.07 - Laura 07/03/2009 21:56.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2039.776 [GMT -4:00]
Running from: c:\documents and settings\Laura\Desktop\Anti Virus Programs\ComboFix.exe
Command switches used :: c:\documents and settings\Laura\Desktop\Anti Virus Programs\CFScript.txt
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

FILE ::
"c:\windows\system32\teyunufa.dll"
"c:\windows\system32\vonatahi.dll"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Laura\Application Data\ErrorFix
c:\documents and settings\Laura\Application Data\ErrorFix\Logs\2009-05-06 00-49-480.log
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\filelist.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-0.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-1.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-10.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-11.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-12.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-13.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-14.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-15.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-16.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-17.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-18.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-19.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-2.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-20.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-21.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-22.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-23.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-24.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-25.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-26.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-27.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-28.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-29.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-3.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-30.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-31.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-32.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-33.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-34.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-35.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-36.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-37.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-38.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-39.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-4.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-40.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-41.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-42.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-43.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-44.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-45.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-46.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-47.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-48.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-49.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-5.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-50.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-51.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-52.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-53.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-54.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-55.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-56.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-57.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-58.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-59.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-6.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-60.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-61.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-62.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-63.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-64.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-65.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-66.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-67.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-68.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-69.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-7.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-70.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-71.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-72.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-73.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-74.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-75.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-76.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-77.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-78.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-79.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-8.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-80.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-81.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-82.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-83.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-84.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-85.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-86.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-87.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-88.db
c:\documents and settings\Laura\Application Data\ErrorFix\QuarantineW\2009-05-06 00-52-090\regb-9.db
c:\documents and settings\Laura\Application Data\ErrorFix\Results\Evidence.db
c:\documents and settings\Laura\Application Data\ErrorFix\Results\Junk.db
c:\documents and settings\Laura\Application Data\ErrorFix\Results\Registry.db
c:\documents and settings\Laura\Application Data\ErrorFix\Results\Update.db
c:\documents and settings\Laura\Application Data\ErrorFix\spy_ignore.db
c:\windows\system32\teyunufa.dll
c:\windows\system32\vonatahi.dll

.
((((((((((((((((((((((((( Files Created from 2009-06-04 to 2009-07-04 )))))))))))))))))))))))))))))))
.

2009-07-03 11:17 . 2009-06-28 22:40 89104 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090702.039\NAVENG.SYS
2009-07-03 11:17 . 2009-06-28 22:40 876144 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090702.039\NAVEX15.SYS
2009-07-03 11:17 . 2009-06-28 22:40 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090702.039\NAVENG32.DLL
2009-07-03 11:17 . 2009-06-28 22:40 1181040 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090702.039\NAVEX32A.DLL
2009-07-03 11:17 . 2009-06-28 22:40 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090702.039\EECTRL.SYS
2009-07-03 11:17 . 2009-06-28 22:40 101936 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090702.039\ERASER.SYS
2009-07-03 11:17 . 2009-06-28 22:40 259368 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090702.039\ECMSVR32.DLL
2009-07-03 11:17 . 2009-06-28 22:40 2414128 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090702.039\CCERASER.DLL
2009-07-01 01:29 . 2009-06-28 22:40 165240 ----a-r- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
2009-06-30 23:15 . 2009-06-28 22:40 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys
2009-06-30 23:15 . 2009-06-28 22:40 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSviA64.sys
2009-06-30 23:15 . 2009-06-28 22:40 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSvix86.sys
2009-06-30 23:15 . 2009-06-28 22:40 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSxpx86.dll
2009-06-30 23:15 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\Scxpx86.dll
2009-06-30 10:40 . 2009-06-30 10:42 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-30 10:40 . 2009-06-30 10:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-30 10:13 . 2008-06-19 21:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-06-30 10:12 . 2009-06-30 10:12 -------- d-----w- c:\program files\Panda Security
2009-06-30 09:41 . 2009-07-01 01:30 117760 ----a-w- c:\documents and settings\Laura\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-30 09:41 . 2009-06-30 09:41 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-06-30 09:40 . 2009-06-30 09:41 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-06-30 09:40 . 2009-06-30 09:40 -------- d-----w- c:\documents and settings\Laura\Application Data\SUPERAntiSpyware.com
2009-06-30 09:40 . 2009-06-30 09:40 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-06-30 03:07 . 2009-06-30 03:07 -------- d-----w- c:\documents and settings\Laura\Local Settings\Application Data\Help
2009-06-30 02:35 . 2009-06-30 02:35 -------- d-----w- c:\documents and settings\Laura\Application Data\Malwarebytes
2009-06-30 02:35 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-30 02:35 . 2009-06-30 02:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-30 02:35 . 2009-06-30 02:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-30 02:35 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-29 01:29 . 2009-06-29 01:29 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Symantec
2009-06-28 22:55 . 2009-06-28 22:55 -------- d-----r- c:\program files\Norton Support
2009-06-28 22:51 . 2009-06-28 22:51 -------- d-----w- c:\documents and settings\Laura\Local Settings\Application Data\Symantec
2009-06-28 22:41 . 2009-06-28 22:40 554352 ----a-r- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
2009-06-28 22:41 . 2009-06-28 22:40 36400 ----a-r- c:\windows\system32\drivers\SymIM.sys
2009-06-28 22:41 . 2009-06-29 01:51 -------- d-----w- c:\program files\Symantec
2009-06-28 22:41 . 2009-06-29 01:51 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-06-28 22:41 . 2009-06-28 22:41 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2009-06-28 22:41 . 2009-06-28 22:41 124464 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-06-28 22:40 . 2009-06-28 22:40 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSxpx86.sys
2009-06-28 22:40 . 2009-06-28 22:40 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSvia64.sys
2009-06-28 22:40 . 2009-06-28 22:40 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSvix86.sys
2009-06-28 22:40 . 2009-06-28 22:40 1290592 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
2009-06-28 22:40 . 2009-06-28 22:40 136840 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
2009-06-28 22:40 . 2009-06-28 22:40 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\idsxpx86.dll
2009-06-28 22:40 . 2009-06-28 22:40 796016 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
2009-06-28 22:40 . 2009-06-28 22:40 -------- d-----w- c:\windows\system32\drivers\NIS
2009-06-28 22:39 . 2009-06-29 01:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-28 22:39 . 2009-06-28 22:40 -------- d-----w- c:\program files\Norton Internet Security
2009-06-28 22:39 . 2009-06-28 22:39 -------- d-----w- c:\program files\Windows Sidebar
2009-06-28 22:30 . 2009-06-28 22:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2009-06-28 22:30 . 2009-06-28 22:38 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-06-28 22:30 . 2009-06-28 22:30 -------- d-----w- c:\program files\NortonInstaller
2009-06-28 22:25 . 2009-06-28 22:25 -------- d-----w- c:\documents and settings\All Users\Symantec Temporary Files
2009-06-28 04:14 . 2009-06-28 04:14 -------- d-----w- c:\program files\MSXML 4.0
2009-06-04 15:08 . 2009-06-04 15:08 -------- d-----w- c:\documents and settings\Laura\Local Settings\Application Data\Identities

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-29 01:25 . 2009-06-29 01:25 136 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2009-06-28 22:41 . 2009-06-28 22:41 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-06-28 22:41 . 2009-06-28 22:41 7386 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-06-28 22:37 . 2009-05-21 02:46 -------- d-----w- c:\documents and settings\Laura\Application Data\Webroot
2009-06-28 22:33 . 2009-01-17 19:40 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-28 04:18 . 2008-09-11 11:50 -------- d-----w- c:\program files\Microsoft Works
2009-06-21 17:13 . 2009-04-17 21:21 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-06-14 01:27 . 2009-01-17 20:09 1 ----a-w- c:\documents and settings\Laura\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-05-31 16:57 . 2009-05-31 16:57 74 ----a-w- c:\documents and settings\Laura\Application Data\wklnhst.dat
2009-05-31 16:57 . 2009-05-31 16:57 -------- d-----w- c:\documents and settings\Laura\Application Data\Template
2009-05-24 18:26 . 2009-02-14 19:42 -------- d-----w- c:\program files\PageBreeze
2009-05-21 03:57 . 2009-05-18 23:24 -------- d-----w- c:\documents and settings\All Users\Application Data\13663754
2009-05-21 02:47 . 2009-05-21 02:47 -------- d-----w- c:\program files\MSSOAP
2009-05-21 02:43 . 2009-05-21 02:43 164 ----a-w- c:\windows\install.dat
2009-05-19 02:06 . 2009-05-19 01:08 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-05-19 01:09 . 2009-05-19 00:56 -------- d-----w- c:\program files\SpyZooka
2009-05-12 06:17 . 2009-05-12 06:17 -------- d-----w- c:\documents and settings\Laura\Application Data\aAvgApi
2009-05-07 15:32 . 2008-08-09 14:32 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:46 . 2008-08-09 14:32 666624 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:46 . 2008-08-09 14:32 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-04-19 04:01 . 2009-01-17 11:24 44944 -c--a-w- c:\documents and settings\Laura\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-17 12:26 . 2008-08-09 14:32 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2008-08-09 14:32 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2008-05-07 23:34 . 2008-09-11 13:03 15523560 ----a-w- c:\program files\Install AiGuruU1 Skype Phone.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-06-23 1830128]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-20 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-20 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-20 131072]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2008-09-03 335872]
"ETDWareDetect"="c:\program files\Elantech\ETDDect.exe" [2008-08-23 204800]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2008-09-03 106496]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2008-09-03 593920]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2008-05-21 94208]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-07-31 16806912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
SuperHybridEngine.lnk - c:\program files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2008-9-11 311296]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [6/30/2009 6:13 AM 28544]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1005000.087\SymEFA.sys [6/28/2009 6:40 PM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1005000.087\BHDrvx86.sys [6/28/2009 6:40 PM 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1005000.087\cchpx86.sys [6/28/2009 6:40 PM 482352]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys [6/30/2009 7:15 PM 276344]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 72944]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe [6/28/2009 6:40 PM 115560]
R3 AsusACPI;ASUS ACPI Driver;c:\windows\system32\drivers\ASUSACPI.SYS [9/11/2008 7:17 AM 10752]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/28/2009 7:13 PM 101936]
R3 Ktp;Elantech Smart-Pad;c:\windows\system32\drivers\ETD.sys [9/11/2008 6:18 PM 26112]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408]
S3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [1/2/2002 3:51 PM 36864]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [6/29/2009 10:35 PM 38160]
S3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [9/11/2008 10:42 PM 625024]
.
Contents of the 'Scheduled Tasks' folder

2009-07-03 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 18:20]
.
- - - - ORPHANS REMOVED - - - -

BHO-{65324ac4-1131-483d-b65d-6588acee6d79} - (no file)


.
------- Supplementary Scan -------
.
uStart Page = hxxp://eeepc.asus.com/global
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
FF - ProfilePath - c:\documents and settings\Laura\Application Data\Mozilla\Firefox\Profiles\xskmiyyt.default\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-03 22:00
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.5.0.135\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(584)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\igfxdev.dll
.
Completion time: 2009-07-04 22:02
ComboFix-quarantined-files.txt 2009-07-04 02:02
ComboFix2.txt 2009-07-01 01:33

Pre-Run: 74,614,923,264 bytes free
Post-Run: 74,605,043,712 bytes free

292 --- E O F --- 2009-06-28 04:18
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Sat Jul 04, 2009 11:50 am    Post subject:

Good job. Your log is clean.

To help prevent future spyware infections, read the Anti-Spyware Tutorial and use the tools provided.

Are there any problems now? If none, go to Start->Run, copy/paste in combofix /u and hit OK to remove it. You should be set to go.
Back to top
AIM Address Yahoo Messenger
Artymuse



Joined: Jun 29, 2009
Posts: 5



PostPosted: Sat Jul 04, 2009 7:32 pm    Post subject:

Thank you very much! You are a life-saver!!!
Back to top
Display posts from previous:   
Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> HijackThis Logs All times are: Eastern Time (US & Canada) (change)
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum