Help - Search - Members - Calendar
Full Version: Fake Security Warnings and IE Popus
Lavasoft Support Forums > Archived Topics > Archives: Resolved/Inactive Topics > Resolved/Inactive HijackThis Logs
Warmbrak
Hi everyone, this is my first post here, and would really appreciate some help. I had a look through many of the posts around, and it seems like there are many different solutions to the problems here, probably indicating that different approaches are required for individual problems?

I did scan with the latest Ad-Aware, and generated a Hijack This log. During operation of my Windows XP SP2, fake security warnings pop up in my system tray, and windows in IE pops up at random, although Firefox is my primary browser. I have already tried a VundoFix process as described in another thread - not sure what it was supposed to do, but it did remove two files, but could not remove a DLL. During a previous run of Hijack This I fixed an item showing some OIN thing with some yazoo.installer thing (can't remember exactly now), but I still get the popups and fake warnings.

Your help will be greatly appreciated! Attached please find my Hijack This log:

Logfile of HijackThis v1.99.1
Scan saved at 22:48:22, on 2006/07/03
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dcomcfg.exe
C:\WINDOWS\system32\atmclk.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\nthClock\nthClock.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wpabaln.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Images\PC Utils\HijackThis\hijackthis\HijackThis.exe

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: nthClock.lnk = C:\Program Files\nthClock\nthClock.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{BC6F4B2E-5DBE-4FD1-879F-89669BBB9CCC}: NameServer = 137.215.101.16,137.215.101.101
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

I removed all Java software from my Control Panel, and am downloading the latest JRE. Here is the log from my VundoFix session:

VundoFix V4.2.84

Running as SYSTEM
from c:\windows\system32\VundoFix.exe

Checking Java version...

Sun Java not detected
Scan started at 21:52:08 2006/07/03

Listing files found while scanning....


C:\WINDOWS\system32\bccdd.bak1
C:\WINDOWS\system32\bccdd.ini
C:\WINDOWS\system32\ddccb.dll
Attempting to delete C:\WINDOWS\system32\bccdd.bak1
C:\WINDOWS\system32\bccdd.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\bccdd.ini
C:\WINDOWS\system32\bccdd.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\ddccb.dll
C:\WINDOWS\system32\ddccb.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Thanks in advance!
Warmbrak
During my virus scan, I always pick up a Trojan Downloader, as again this morning before work. The virus is removed, but only comes back again. Why can't the anti-virus utilities remove this thing once and for all, as I'm assuming that the culprit does not appear to be a malicious piece of software?
Warmbrak
Hi there,

I almost have this one resolved. It appears to have been the Zlob.Downloader. Spybot S&D finally detected it, and although the fix removes is, it always comes back, but the pop-ups have ceased and I have tightened security on all ends for my PC. The only file that still comes back is the stdole3.tld file, and I will try and get rid of it with one SmitFraudFix tonight. Although there have been no replies to this post, many threads around here has given me great insight on how to approach the problem, and tighten security.

Thanks for a great forum!
LS CalamityJane
Hi Warmbrak,

Sorry for the late reply, we've been swamped in here. I need to get a couple of other logs from you.

1. Download this file - combofix.exe
http://download.bleepingcomputer.com/sUBs/combofix.exe

2. Double click on combofix.exe & follow the prompts.

Note: If you receive a popup with a Disclaimer, read that and answer Y for yes (or N for no)
Y is recommended (if you put N, the tool will exit without fixing and will remove the combofix file and folders)


Do NOT click on the window while the fix is running, because that will cause your system to hang and the fix to stall.

3. When finished, it shall produce a log for you. Post that log in your next reply

..................
Next, please open HijackThis and instead of scan, please choose *Open Misc Tools Section*
Then choose *Open Uninstall Manager*

Wait while it prepares a list. When finished, press the *Save List* button and post that list back here with the ComboFix log
Warmbrak
Hi CalamityJane,

Thanks a lot for the reply. Here are the results of the Combofix log:

Start Time= 2006/07/06 20:12:29.28

QuickScan did not find any signs of infected files

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-07-04 23:28:56 ( .D... ) "C:\Program Files\ewido anti-spyware 4.0"
2006-07-04 21:35:24 ( .D... ) "C:\Program Files\Spybot - Search & Destroy"
2006-07-04 20:10:18 2508 ( A.... ) "C:\Documents and Settings\Hotdag\Application Data\$_hpcst$.hpc"
2006-07-04 20:06:40 ( .D... ) "C:\Program Files\Malicious Software Removal Tool"
2006-07-04 20:02:08 ( .D... ) "C:\Program Files\Microsoft ActiveSync"
2006-07-04 19:57:36 ( .D... ) "C:\Program Files\MSN Messenger"
2006-07-04 19:53:50 ( .D... ) "C:\Program Files\Windows Journal Viewer"
2006-07-04 19:51:42 ( .D... ) "C:\Program Files\HighMAT CD Writing Wizard"
2006-07-04 19:41:54 ( .D... ) "C:\Program Files\AutoPatcher"
2006-07-03 20:47:56 569396 ( ..... ) "C:\WINDOWS\system32\ddccb.dll"
2006-07-03 07:02:52 ( .D... ) "C:\Documents and Settings\Hotdag\Application Data\Lavasoft"
2006-07-03 07:02:38 ( .D... ) "C:\Program Files\Lavasoft"
2006-07-03 00:53:40 69120 ( A.... ) "C:\WINDOWS\system32\dcomcfg.exe"
2006-07-03 00:51:20 18432 ( A.... ) "C:\WINDOWS\system32\winzoa32.dll"
2006-06-27 20:01:58 ( .D... ) "C:\Documents and Settings\Hotdag\Application Data\Sun"
2006-06-27 19:58:56 ( .D... ) "C:\Program Files\Ubisoft"
2006-06-27 19:58:10 ( .D... ) "C:\Program Files\QuickTime"
2006-06-26 23:28:44 ( .D... ) "C:\Program Files\nthClock"
2006-06-26 19:53:14 ( .D... ) "C:\Program Files\DAEMON Tools"
2006-06-26 07:16:36 ( .D... ) "C:\Documents and Settings\Hotdag\Application Data\AVG7"
2006-06-26 07:16:20 ( .D... ) "C:\Program Files\Grisoft"
2006-06-26 00:30:58 ( .D... ) "C:\Documents and Settings\Hotdag\Application Data\Macromedia"
2006-06-25 22:06:56 ( .D... ) "C:\Program Files\WinAce"
2006-06-25 22:04:40 ( .D... ) "C:\Program Files\DivX"
2006-06-25 21:48:58 ( .D... ) "C:\Program Files\eMule"
2006-06-25 19:12:12 ( .D... ) "C:\Program Files\NaturalPoint"
2006-06-25 19:05:14 ( .D... ) "C:\Documents and Settings\Hotdag\Application Data\Help"
2006-06-25 18:58:20 ( .D... ) "C:\Program Files\HOTAS"
2006-06-25 18:56:16 ( .D... ) "C:\Program Files\Foxy"
2006-06-25 00:50:18 ( .D... ) "C:\Documents and Settings\Hotdag\Application Data\AdobeUM"
2006-06-24 18:33:50 ( .D... ) "C:\Program Files\Common Files\Adobe Systems Shared"
2006-06-24 18:33:50 ( .D... ) "C:\Documents and Settings\Hotdag\Application Data\Adobe"
2006-06-24 18:33:18 ( .D... ) "C:\Program Files\Common Files\Adobe"
2006-06-24 18:32:24 ( .D... ) "C:\Program Files\Adobe"
2006-06-24 17:08:08 ( .D.H. ) "C:\Program Files\InstallShield Installation Information"
2006-06-24 17:07:24 ( .D... ) "C:\Program Files\Creative"
2006-06-24 16:58:22 ( .D... ) "C:\Program Files\Mozilla Firefox"
2006-06-24 16:58:22 ( .D... ) "C:\Documents and Settings\Hotdag\Application Data\Mozilla"
2006-06-24 16:40:54 ( .D... ) "C:\Program Files\Winamp"
2006-06-23 19:57:02 ( .D... ) "C:\Program Files\Common Files\Nero"
2006-06-23 19:56:06 ( .D... ) "C:\Program Files\Common Files\Ahead"
2006-06-23 19:56:04 ( .D... ) "C:\Program Files\Ahead"
2006-06-23 05:40:22 ( .D... ) "C:\Program Files\Common Files\ODBC"
2006-06-23 05:40:18 ( .D... ) "C:\Program Files\Common Files\SpeechEngines"
2006-06-23 05:40:18 ( .D... ) "C:\Program Files\Common Files\Microsoft Shared"
2006-06-23 05:40:18 ( .D... ) "C:\Program Files\Common Files"
2006-06-23 05:40:00 62 ( A.SH. ) "C:\Documents and Settings\Hotdag\Application Data\desktop.ini"
2006-06-23 04:09:54 ( .D... ) "C:\Program Files\Gigabyte"
2006-06-23 04:08:50 ( .D... ) "C:\Program Files\Common Files\InstallShield"
2006-06-23 04:00:28 ( .D... ) "C:\Documents and Settings\Hotdag\Application Data\Identities"
2006-06-23 04:00:26 ( .D.H. ) "C:\Program Files\Uninstall Information"
2006-06-23 04:00:20 ( .DS.. ) "C:\Documents and Settings\Hotdag\Application Data\Microsoft"
2006-06-23 03:54:14 ( .D... ) "C:\Program Files\xerox"
2006-06-23 03:54:14 ( .D... ) "C:\Program Files\microsoft frontpage"
2006-06-23 03:53:58 0 ( A.... ) "C:\AUTOEXEC.BAT"
2006-06-23 03:52:46 ( .D.H. ) "C:\Program Files\WindowsUpdate"
2006-06-23 03:52:02 ( .D... ) "C:\Program Files\Common Files\Services"
2006-06-23 03:52:00 ( .D... ) "C:\Program Files\Common Files\MSSoap"
2006-06-23 03:51:46 ( .D... ) "C:\Program Files\Movie Maker"
2006-06-23 03:51:34 ( .D... ) "C:\Program Files\NetMeeting"
2006-06-23 03:51:32 ( .D... ) "C:\Program Files\Outlook Express"
2006-06-23 03:51:26 ( .D... ) "C:\Program Files\Common Files\System"
2006-06-23 03:51:24 ( .D... ) "C:\Program Files\Internet Explorer"
2006-06-23 03:51:02 ( .D... ) "C:\Program Files\ComPlus Applications"
2006-06-23 03:50:58 ( .D... ) "C:\Program Files\Windows Media Player"
2006-06-23 03:50:58 ( .D... ) "C:\Program Files\Online Services"
2006-06-23 03:50:54 ( .D... ) "C:\Program Files\Messenger"
2006-06-23 03:50:50 ( .D... ) "C:\Program Files\MSN Gaming Zone"
2006-06-23 03:50:14 ( .D... ) "C:\Program Files\MSN"
2006-06-23 03:50:12 ( .D... ) "C:\Program Files\Windows NT"
2006-06-22 12:47:18 181248 ( A.... ) "C:\WINDOWS\system32\rasmans.dll"
2006-06-18 15:54:08 36864 ( A.... ) "C:\WINDOWS\system32\frapsvid.dll"
2006-06-08 18:19:52 5967776 ( A.... ) "C:\WINDOWS\system32\MRT.exe"
2006-06-01 20:47:08 163840 ( A.... ) "C:\WINDOWS\system32\jgdw400.dll"
2006-06-01 20:47:08 27648 ( A.... ) "C:\WINDOWS\system32\jgpl400.dll"
2006-05-29 17:32:10 1496576 ( A.... ) "C:\WINDOWS\system32\shdocvw.dll"
2006-05-19 17:06:04 3055104 ( A.... ) "C:\WINDOWS\system32\mshtml.dll"
2006-05-11 10:37:26 90112 ( A.... ) "C:\WINDOWS\system32\xpsp3res.dll"
2006-05-10 14:51:40 1287680 ( A.... ) "C:\WINDOWS\system32\quartz.dll"
2006-05-10 07:25:22 663552 ( A.... ) "C:\WINDOWS\system32\wininet.dll"
2006-05-10 07:25:22 615424 ( A.... ) "C:\WINDOWS\system32\urlmon.dll"
2006-05-10 07:25:22 532480 ( A.... ) "C:\WINDOWS\system32\mstime.dll"
2006-05-10 07:25:22 474112 ( A.... ) "C:\WINDOWS\system32\shlwapi.dll"
2006-05-10 07:25:22 448512 ( A.... ) "C:\WINDOWS\system32\mshtmled.dll"
2006-05-10 07:25:22 357888 ( A.... ) "C:\WINDOWS\system32\dxtmsft.dll"
2006-05-10 07:25:22 251904 ( A.... ) "C:\WINDOWS\system32\iepeers.dll"
2006-05-10 07:25:22 205312 ( A.... ) "C:\WINDOWS\system32\dxtrans.dll"
2006-05-10 07:25:22 146432 ( A.... ) "C:\WINDOWS\system32\msrating.dll"
2006-05-10 07:25:22 96256 ( A.... ) "C:\WINDOWS\system32\inseng.dll"
2006-05-10 07:25:22 55808 ( A.... ) "C:\WINDOWS\system32\extmgr.dll"
2006-05-10 07:25:22 39424 ( A.... ) "C:\WINDOWS\system32\pngfilt.dll"
2006-05-10 07:25:22 15872 ( A.... ) "C:\WINDOWS\system32\jsproxy.dll"
2006-05-10 07:25:20 1022976 ( A.... ) "C:\WINDOWS\system32\browseui.dll"
2006-05-10 07:25:20 151040 ( A.... ) "C:\WINDOWS\system32\cdfview.dll"
2006-04-29 06:07:48 5533696 ( A.... ) "C:\WINDOWS\system32\wmp.dll"
2006-04-07 08:02:18 414024 ( A.... ) "C:\WINDOWS\system32\WMSPDMOD.DLL"
2006-04-07 06:04:18 940544 ( A.... ) "C:\WINDOWS\system32\WMSPDMOE.DLL"


((((((((((((((((((((((((((((((((((((((((( Files Created - Last 30days ))))))))))))))))))))))))))))))))))))))))))))))


2006-07-03 20:45 569,396 C:\WINDOWS\system32\ddccb.dll
2006-07-03 00:53 69,120 C:\WINDOWS\system32\dcomcfg.exe
2006-07-03 00:51 18,432 C:\WINDOWS\system32\winzoa32.dll
2006-06-28 07:56 5,967,776 C:\WINDOWS\system32\MRT.exe
2006-06-27 19:58 89,360 C:\WINDOWS\system32\VB5DB.DLL
2006-06-27 19:58 86,016 C:\WINDOWS\unvise32qt.exe
2006-06-27 19:58 69,632 C:\WINDOWS\system32\xmltok.dll
2006-06-27 19:58 36,864 C:\WINDOWS\system32\xmlparse.dll
2006-06-27 19:58 26,088 C:\WINDOWS\system32\xmlinst.exe
2006-06-27 19:58 24,576 C:\WINDOWS\system32\msxml3a.dll
2006-06-26 23:28 299,520 C:\WINDOWS\uninst.exe
2006-06-26 20:43 61,136 C:\WINDOWS\system32\xinput9_1_0.dll
2006-06-26 20:43 2,337,488 C:\WINDOWS\system32\d3dx9_25.dll
2006-06-26 20:43 2,323,664 C:\WINDOWS\system32\d3dx9_28.dll
2006-06-26 20:43 2,319,568 C:\WINDOWS\system32\d3dx9_27.dll
2006-06-26 20:43 2,297,552 C:\WINDOWS\system32\d3dx9_26.dll
2006-06-26 20:43 2,222,800 C:\WINDOWS\system32\d3dx9_24.dll
2006-06-25 18:58 45,056 C:\WINDOWS\system32\HOTASCPL.dll
2006-06-25 18:58 147,456 C:\WINDOWS\system32\STTubeDevice203.dll
2006-06-24 17:08 94,208 C:\WINDOWS\DEVREG.DLL
2006-06-24 17:08 90,112 C:\WINDOWS\Updreg.EXE
2006-06-24 17:08 84,992 C:\WINDOWS\system32\SFCVRT32.DLL
2006-06-24 17:08 82,432 C:\WINDOWS\system32\CTWFLT32.DLL
2006-06-24 17:08 77,824 C:\WINDOWS\system32\EAXAC3.DLL
2006-06-24 17:08 65,536 C:\WINDOWS\system32\a3d.dll
2006-06-24 17:08 643,072 C:\WINDOWS\system32\CTSBLFX.DLL
2006-06-24 17:08 61,440 C:\WINDOWS\system32\CTAGENT.DLL
2006-06-24 17:08 61,440 C:\WINDOWS\MIDIDEF.EXE
2006-06-24 17:08 54,784 C:\WINDOWS\system32\INETWH32.DLL
2006-06-24 17:08 53,552 C:\WINDOWS\CTCCW.DLL
2006-06-24 17:08 53,248 C:\WINDOWS\system32\AC3API.DLL
2006-06-24 17:08 49,152 C:\WINDOWS\system32\KILLAPPS.EXE
2006-06-24 17:08 49,152 C:\WINDOWS\CTDCRES.DLL
2006-06-24 17:08 36,864 C:\WINDOWS\system32\REGPLIB.EXE
2006-06-24 17:08 36,864 C:\WINDOWS\system32\CTEMUPIA.DLL
2006-06-24 17:08 319,488 C:\WINDOWS\system32\CTDEVCON.DLL
2006-06-24 17:08 28,672 C:\WINDOWS\system32\CTSPKHLP.DLL
2006-06-24 17:08 270,336 C:\WINDOWS\system32\SFMS32.DLL
2006-06-24 17:08 26,768 C:\WINDOWS\system32\CTL3D.DLL
2006-06-24 17:08 24,976 C:\WINDOWS\CTRES.DLL
2006-06-24 17:08 24,576 C:\WINDOWS\system32\CTHELPER.EXE
2006-06-24 17:08 20,480 C:\WINDOWS\INRES.DLL
2006-06-24 17:08 184,320 C:\WINDOWS\PSCONV.EXE
2006-06-24 17:08 176,128 C:\WINDOWS\READREG.EXE
2006-06-24 17:08 155,648 C:\WINDOWS\system32\CTOSUSER.DLL
2006-06-24 17:08 149,504 C:\WINDOWS\system32\MFCANS32.DLL
2006-06-24 17:08 135,168 C:\WINDOWS\system32\OPENAL32.DLL
2006-06-24 17:08 12,288 C:\WINDOWS\system32\AHQCpURes.dll
2006-06-24 17:08 110,592 C:\WINDOWS\system32\PIAPROXY.DLL
2006-06-24 17:08 110,592 C:\WINDOWS\system32\COMMONFX.DLL
2006-06-24 17:08 108,032 C:\WINDOWS\system32\MFCUIA32.DLL
2006-06-24 17:08 106,496 C:\WINDOWS\system32\CTDPROXY.DLL
2006-06-24 17:08 106,496 C:\WINDOWS\system32\CTASIO.DLL
2006-06-24 17:07 6,752 C:\WINDOWS\system32\PFMODNT.SYS
2006-06-24 16:40 61,440 C:\WINDOWS\system32\pxhpinst.exe
2006-06-24 16:40 56,832 C:\WINDOWS\system32\pxcpya64.exe
2006-06-24 16:40 56,320 C:\WINDOWS\system32\pxinsa64.exe
2006-06-24 16:40 405,504 C:\WINDOWS\system32\pxdrv.dll
2006-06-24 16:40 339,968 C:\WINDOWS\system32\pxwave.dll
2006-06-24 16:40 339,968 C:\WINDOWS\system32\px.dll
2006-06-24 16:40 28,672 C:\WINDOWS\system32\vxblock.dll
2006-06-24 16:40 172,032 C:\WINDOWS\system32\pxmas.dll
2006-06-24 16:40 151,552 C:\WINDOWS\system32\pxwma.dll
2006-06-24 16:40 109,568 C:\WINDOWS\system32\pxinsi64.exe
2006-06-24 16:40 108,544 C:\WINDOWS\system32\pxcpyi64.exe
2006-06-23 20:07 22,752 C:\WINDOWS\system32\spupdsvc.exe
2006-06-23 20:07 13,536 C:\WINDOWS\system32\spmsg.dll
2006-06-23 19:56 476,320 C:\WINDOWS\system32\ImagXpr7.dll
2006-06-23 19:56 471,040 C:\WINDOWS\system32\ImagXRA7.dll
2006-06-23 19:56 364,544 C:\WINDOWS\system32\TwnLib4.dll
2006-06-23 19:56 262,144 C:\WINDOWS\system32\ImagXR7.dll
2006-06-23 19:56 155,648 C:\WINDOWS\system32\NeroCheck.exe
2006-06-23 19:56 106,496 C:\WINDOWS\system32\TwnLib20.dll
2006-06-23 19:56 1,568,768 C:\WINDOWS\system32\ImagX7.dll
2006-06-23 17:22 180,224 C:\WINDOWS\system32\nvudisp.exe
2006-06-23 05:43 495,616 C:\WINDOWS\system32\sblfx.dll
2006-06-23 05:43 4,096 C:\WINDOWS\system32\ksuser.dll
2006-06-23 05:43 4,096 C:\WINDOWS\system32\ctwdm32.dll
2006-06-23 05:43 36,864 C:\WINDOWS\system32\sfman32.dll
2006-06-23 05:43 256,512 C:\WINDOWS\system32\devcon32.dll
2006-06-23 05:43 24,064 C:\WINDOWS\system32\devldr32.exe
2006-06-23 05:41 74,240 C:\WINDOWS\system32\usbui.dll
2006-06-23 05:40 85,020 C:\WINDOWS\system32\dgsetup.dll
2006-06-23 05:40 8,704 C:\WINDOWS\system32\batt.dll
2006-06-23 05:40 8,192 C:\WINDOWS\system32\kbdhept.dll
2006-06-23 05:40 74,752 C:\WINDOWS\system32\storprop.dll
2006-06-23 05:40 7,168 C:\WINDOWS\system32\kbdcz.dll
2006-06-23 05:40 69,120 C:\WINDOWS\NOTEPAD.EXE
2006-06-23 05:40 6,656 C:\WINDOWS\system32\kbdycl.dll
2006-06-23 05:40 6,656 C:\WINDOWS\system32\kbdsl1.dll
2006-06-23 05:40 6,656 C:\WINDOWS\system32\kbdsl.dll
2006-06-23 05:40 6,656 C:\WINDOWS\system32\kbdpl.dll
2006-06-23 05:40 6,656 C:\WINDOWS\system32\kbdhu.dll
2006-06-23 05:40 6,656 C:\WINDOWS\system32\kbdhela3.dll
2006-06-23 05:40 6,656 C:\WINDOWS\system32\kbdcz2.dll
2006-06-23 05:40 6,656 C:\WINDOWS\system32\kbdcz1.dll
2006-06-23 05:40 6,656 C:\WINDOWS\system32\kbdcr.dll
2006-06-23 05:40 6,656 C:\WINDOWS\system32\KBDAL.DLL
2006-06-23 05:40 6,144 C:\WINDOWS\system32\kbdtuq.dll
2006-06-23 05:40 6,144 C:\WINDOWS\system32\kbdtuf.dll
2006-06-23 05:40 6,144 C:\WINDOWS\system32\kbdlv1.dll
2006-06-23 05:40 6,144 C:\WINDOWS\system32\kbdlv.dll
2006-06-23 05:40 6,144 C:\WINDOWS\system32\kbdhela2.dll
2006-06-23 05:40 6,144 C:\WINDOWS\system32\kbdgkl.dll
2006-06-23 05:40 6,144 C:\WINDOWS\system32\kbdest.dll
2006-06-23 05:40 5,632 C:\WINDOWS\system32\kbdycc.dll
2006-06-23 05:40 5,632 C:\WINDOWS\system32\kbduzb.dll
2006-06-23 05:40 5,632 C:\WINDOWS\system32\kbdur.dll
2006-06-23 05:40 5,632 C:\WINDOWS\system32\kbdtat.dll
2006-06-23 05:40 5,632 C:\WINDOWS\system32\kbdru1.dll
2006-06-23 05:40 5,632 C:\WINDOWS\system32\kbdru.dll
2006-06-23 05:40 5,632 C:\WINDOWS\system32\kbdro.dll
2006-06-23 05:40 5,632 C:\WINDOWS\system32\kbdpl1.dll
2006-06-23 05:40 5,632 C:\WINDOWS\system32\kbdmon.dll
2006-06-23 05:40 5,632 C:\WINDOWS\system32\kbdlt1.dll
2006-06-23 05:40 5,632 C:\WINDOWS\system32\kbdlt.dll
2006-06-23 05:40 5,632 C:\WINDOWS\system32\kbdkyr.dll
2006-06-23 05:40 5,632 C:\WINDOWS\system32\kbdkaz.dll
2006-06-23 05:40 5,632 C:\WINDOWS\system32\kbdhu1.dll
2006-06-23 05:40 5,632 C:\WINDOWS\system32\kbdhe319.dll
2006-06-23 05:40 5,632 C:\WINDOWS\system32\kbdhe220.dll
2006-06-23 05:40 5,632 C:\WINDOWS\system32\kbdhe.dll
2006-06-23 05:40 5,632 C:\WINDOWS\system32\kbdbu.dll
2006-06-23 05:40 5,632 C:\WINDOWS\system32\kbdblr.dll
2006-06-23 05:40 5,632 C:\WINDOWS\system32\kbdazel.dll
2006-06-23 05:40 5,632 C:\WINDOWS\system32\kbdaze.dll
2006-06-23 05:40 24,661 C:\WINDOWS\system32\spxcoins.dll
2006-06-23 05:40 176,157 C:\WINDOWS\system32\dgrpsetu.dll
2006-06-23 05:40 15,360 C:\WINDOWS\TASKMAN.EXE
2006-06-23 05:40 13,312 C:\WINDOWS\system32\irclass.dll
2006-06-23 05:40 103,424 C:\WINDOWS\system32\EqnClass.Dll
2006-06-23 05:31 1,609,801,728 C:\pagefile.sys
2006-06-23 04:09 32,768 C:\WINDOWS\system32\idecoi.dll
2006-06-23 04:09 306,688 C:\WINDOWS\IsUninst.exe
2006-06-23 04:09 180,224 C:\WINDOWS\system32\nvusmb.exe
2006-06-23 04:09 180,224 C:\WINDOWS\system32\NVUninst.exe
2006-06-23 04:09 180,224 C:\WINDOWS\system32\nvumctl.exe
2006-06-23 04:09 180,224 C:\WINDOWS\system32\nvuide.exe
2006-06-23 04:09 180,224 C:\WINDOWS\system32\nvugart.exe
2006-06-23 04:09 180,224 C:\WINDOWS\system32\nvuenet.exe
2006-06-23 03:53 112,128 C:\WINDOWS\system32\mapi32.dll
2006-06-23 03:53 0 C:\MSDOS.SYS
2006-06-23 03:53 0 C:\IO.SYS
2006-06-23 03:53 0 C:\CONFIG.SYS
2006-06-23 03:53 0 C:\AUTOEXEC.BAT
2006-06-23 03:52 64,512 C:\WINDOWS\system32\acctres.dll
2006-06-23 03:52 12,288 C:\WINDOWS\system32\nmevtmsg.dll
2006-06-23 03:52 11,264 C:\WINDOWS\system32\atrace.dll
2006-06-23 03:51 81,920 C:\WINDOWS\system32\isign32.dll
2006-06-23 03:51 81,920 C:\WINDOWS\system32\ils.dll
2006-06-23 03:51 8,192 C:\WINDOWS\system32\bitsprx2.dll
2006-06-23 03:51 73,728 C:\WINDOWS\system32\icwdial.dll
2006-06-23 03:51 7,168 C:\WINDOWS\system32\bitsprx3.dll
2006-06-23 03:51 69,632 C:\WINDOWS\system32\msconf.dll
2006-06-23 03:51 679,424 C:\WINDOWS\system32\inetcomm.dll
2006-06-23 03:51 67,584 C:\WINDOWS\system32\srclient.dll
2006-06-23 03:51 65,536 C:\WINDOWS\system32\icwphbk.dll
2006-06-23 03:51 6,656 C:\WINDOWS\system32\wuauserv.dll
2006-06-23 03:51 48,128 C:\WINDOWS\system32\inetres.dll
2006-06-23 03:51 465,176 C:\WINDOWS\system32\wuapi.dll
2006-06-23 03:51 45,568 C:\WINDOWS\system32\safrslv.dll
2006-06-23 03:51 43,520 C:\WINDOWS\system32\safrcdlg.dll
2006-06-23 03:51 43,520 C:\WINDOWS\system32\racpldlg.dll
2006-06-23 03:51 41,240 C:\WINDOWS\system32\wups.dll
2006-06-23 03:51 382,464 C:\WINDOWS\system32\qmgr.dll
2006-06-23 03:51 34,560 C:\WINDOWS\system32\mnmdd.dll
2006-06-23 03:51 32,768 C:\WINDOWS\system32\mnmsrvc.exe
2006-06-23 03:51 32,768 C:\WINDOWS\system32\isrdbg32.dll
2006-06-23 03:51 29,696 C:\WINDOWS\system32\safrdm.dll
2006-06-23 03:51 28,672 C:\WINDOWS\system32\nmmkcert.dll
2006-06-23 03:51 274,944 C:\WINDOWS\system32\mstask.dll
2006-06-23 03:51 274,432 C:\WINDOWS\system32\inetcfg.dll
2006-06-23 03:51 252,928 C:\WINDOWS\system32\msoeacct.dll
2006-06-23 03:51 239,104 C:\WINDOWS\system32\srrstr.dll
2006-06-23 03:51 22,528 C:\WINDOWS\system32\fltMc.exe
2006-06-23 03:51 194,328 C:\WINDOWS\system32\wuaueng1.dll
2006-06-23 03:51 190,976 C:\WINDOWS\system32\schedsvc.dll
2006-06-23 03:51 18,944 C:\WINDOWS\system32\qmgrprxy.dll
2006-06-23 03:51 173,536 C:\WINDOWS\system32\wuweb.dll
2006-06-23 03:51 172,312 C:\WINDOWS\system32\wuauclt1.exe
2006-06-23 03:51 170,496 C:\WINDOWS\system32\srsvc.dll
2006-06-23 03:51 16,896 C:\WINDOWS\system32\fltlib.dll
2006-06-23 03:51 16,384 C:\WINDOWS\system32\icfgnt5.dll
2006-06-23 03:51 127,256 C:\WINDOWS\system32\wucltui.dll
2006-06-23 03:51 124,184 C:\WINDOWS\system32\wuauclt.exe
2006-06-23 03:51 12,288 C:\WINDOWS\system32\mstinit.exe
2006-06-23 03:51 105,984 C:\WINDOWS\system32\msoert2.dll
2006-06-23 03:51 1,343,768 C:\WINDOWS\system32\wuaueng.dll
2006-06-23 03:50 97,792 C:\WINDOWS\system32\comrepl.dll
2006-06-23 03:50 956,416 C:\WINDOWS\system32\msdtctm.dll
2006-06-23 03:50 93,696 C:\WINDOWS\system32\tscfgwmi.dll
2006-06-23 03:50 91,136 C:\WINDOWS\system32\mtxoci.dll
2006-06-23 03:50 9,728 C:\WINDOWS\system32\reset.exe
2006-06-23 03:50 87,176 C:\WINDOWS\system32\rdpwsx.dll
2006-06-23 03:50 85,504 C:\WINDOWS\system32\catsrvps.dll
2006-06-23 03:50 80,384 C:\WINDOWS\system32\charmap.exe
2006-06-23 03:50 73,216 C:\WINDOWS\system32\avwav.dll
2006-06-23 03:50 67,072 C:\WINDOWS\system32\rdshost.exe
2006-06-23 03:50 655,360 C:\WINDOWS\system32\mstscax.dll
2006-06-23 03:50 625,152 C:\WINDOWS\system32\catsrvut.dll
2006-06-23 03:50 62,464 C:\WINDOWS\system32\rdpclip.exe
2006-06-23 03:50 605,696 C:\WINDOWS\system32\getuname.dll
2006-06-23 03:50 60,416 C:\WINDOWS\system32\remotepg.dll
2006-06-23 03:50 60,416 C:\WINDOWS\system32\colbact.dll
2006-06-23 03:50 6,144 C:\WINDOWS\system32\msdtc.exe
2006-06-23 03:50 58,880 C:\WINDOWS\system32\msdtclog.dll
2006-06-23 03:50 56,832 C:\WINDOWS\system32\sol.exe
2006-06-23 03:50 55,296 C:\WINDOWS\system32\freecell.exe
2006-06-23 03:50 540,160 C:\WINDOWS\system32\comuid.dll
2006-06-23 03:50 54,272 C:\WINDOWS\system32\stclient.dll
2006-06-23 03:50 538,624 C:\WINDOWS\system32\spider.exe
2006-06-23 03:50 5,632 C:\WINDOWS\system32\write.exe
2006-06-23 03:50 5,120 C:\WINDOWS\system32\dcomcnfg.exe
2006-06-23 03:50 498,688 C:\WINDOWS\system32\clbcatq.dll
2006-06-23 03:50 44,544 C:\WINDOWS\system32\tscupgrd.exe
2006-06-23 03:50 44,544 C:\WINDOWS\system32\hticons.dll
2006-06-23 03:50 426,496 C:\WINDOWS\system32\msdtcprx.dll
2006-06-23 03:50 407,552 C:\WINDOWS\system32\mstsc.exe
2006-06-23 03:50 4,096 C:\WINDOWS\system32\rdpcfgex.dll
2006-06-23 03:50 4,096 C:\WINDOWS\system32\mtxex.dll
2006-06-23 03:50 38,912 C:\WINDOWS\system32\cfgbkend.dll
2006-06-23 03:50 35,328 C:\WINDOWS\system32\winchat.exe
2006-06-23 03:50 347,136 C:\WINDOWS\system32\hypertrm.dll
2006-06-23 03:50 343,040 C:\WINDOWS\system32\mspaint.exe
2006-06-23 03:50 33,792 C:\WINDOWS\system32\regini.exe
2006-06-23 03:50 295,424 C:\WINDOWS\system32\termsrv.dll
2006-06-23 03:50 25,600 C:\WINDOWS\system32\comaddin.dll
2006-06-23 03:50 25,088 C:\WINDOWS\system32\mtxlegih.dll
2006-06-23 03:50 227,840 C:\WINDOWS\system32\avtapi.dll
2006-06-23 03:50 225,792 C:\WINDOWS\system32\catsrv.dll
2006-06-23 03:50 22,016 C:\WINDOWS\system32\qwinsta.exe
2006-06-23 03:50 20,992 C:\WINDOWS\system32\msg.exe
2006-06-23 03:50 20,480 C:\WINDOWS\system32\qprocess.exe
2006-06-23 03:50 20,480 C:\WINDOWS\system32\mtxdm.dll
2006-06-23 03:50 19,968 C:\WINDOWS\system32\rdpsnd.dll
2006-06-23 03:50 183,808 C:\WINDOWS\system32\accwiz.exe
2006-06-23 03:50 161,280 C:\WINDOWS\system32\msdtcuiu.dll
2006-06-23 03:50 16,896 C:\WINDOWS\system32\tsshutdn.exe
2006-06-23 03:50 16,896 C:\WINDOWS\system32\qappsrv.exe
2006-06-23 03:50 16,384 C:\WINDOWS\system32\tskill.exe
2006-06-23 03:50 16,384 C:\WINDOWS\system32\avmeter.dll
2006-06-23 03:50 15,872 C:\WINDOWS\system32\rwinsta.exe
2006-06-23 03:50 15,872 C:\WINDOWS\system32\cdmodem.dll
2006-06-23 03:50 15,360 C:\WINDOWS\system32\logoff.exe
2006-06-23 03:50 147,968 C:\WINDOWS\system32\rdchost.dll
2006-06-23 03:50 147,456 C:\WINDOWS\system32\comsnap.dll
2006-06-23 03:50 140,800 C:\WINDOWS\system32\sessmgr.exe
2006-06-23 03:50 14,848 C:\WINDOWS\system32\tsdiscon.exe
2006-06-23 03:50 14,848 C:\WINDOWS\system32\tscon.exe
2006-06-23 03:50 14,848 C:\WINDOWS\system32\shadow.exe
2006-06-23 03:50 138,752 C:\WINDOWS\system32\sndvol32.exe
2006-06-23 03:50 131,584 C:\WINDOWS\system32\sndrec32.exe
2006-06-23 03:50 13,824 C:\WINDOWS\system32\rdsaddin.exe
2006-06-23 03:50 126,976 C:\WINDOWS\system32\mshearts.exe
2006-06-23 03:50 123,392 C:\WINDOWS\system32\mplay32.exe
2006-06-23 03:50 119,808 C:\WINDOWS\system32\winmine.exe
2006-06-23 03:50 114,688 C:\WINDOWS\system32\calc.exe
2006-06-23 03:50 110,080 C:\WINDOWS\system32\clbcatex.dll
2006-06-23 03:50 11,776 C:\WINDOWS\system32\xolehlp.dll
2006-06-23 03:50 11,264 C:\WINDOWS\system32\icaapi.dll
2006-06-23 03:50 102,912 C:\WINDOWS\system32\clipbrd.exe
2006-06-23 03:50 1,267,200 C:\WINDOWS\system32\comsvcs.dll
2006-06-23 03:50 1,161 C:\WINDOWS\system32\usrlogon.cmd
2006-06-23 03:49 58,880 C:\WINDOWS\system32\licwmi.dll
2006-06-23 03:49 56,320 C:\WINDOWS\system32\servdeps.dll
2006-06-23 03:49 185,344 C:\WINDOWS\system32\cmprops.dll
2006-06-23 03:49 17,408 C:\WINDOWS\system32\mmfutil.dll
2006-06-18 15:54 36,864 C:\WINDOWS\system32\frapsvid.dll


((((((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"WINDVDPatch"="CTHELPER.EXE"
"Jet Detection"="\"C:\\Program Files\\Creative\\SBLive\\PROGRAM\\ADGJDet.exe\""
"Acrobat Assistant 7.0"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Distillr\\Acrotray.exe\""
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"wininet.dll"=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"H/PC Connection Agent"="\"C:\\PROGRA~1\\MICROS~2\\wcescomm.exe\""
"SpybotSD TeaTimer"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,00,04,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3a,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3a,02,\
00,00,01,00,00,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{7916f057-223f-4612-ac84-e882cbe043d4}"="bals"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKLM"
"command"=""
"inimapping"="0"



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\fredlist.job

Completion time: 2006/07/06 20:12:39.07
ComboFix ver 06.07.04 - This logfile is located at C:\ComboFix.txt


I followed the steps to save the Uninstall Manager list through HighjackThis, but for some reason when I click on Save List, it does not prompt me for a location to save the log, and I can't seem to find such a log if it is saving it. As soon as I finished the Combofix process, Ewido came up with a malware warning, notifying me of a Downloader.Zlob.wy malware that was situated at C:\Windows\system32\hp100.tmp. Shortly after, I got a string of popups, so something is still messy here. Any ideas on that Uninstall Manager List?
LS CalamityJane
Ok, let's run this free fix tool

1. Download SmitfraudFix (by S!Ri) to your Desktop (Win2k/WinXP only!).
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

How to extract (decompress) zipped or compressed files
http://www.lvsonline.com/compresstut/index.shtml

Note : process.exe is part of the SmitFraudFix tool and is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky, Panda) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.


2. Reboot into Safe Mode
You can usually do this by restarting your computer and continually tapping F8 until a menu appears. Highlight Safe Mode and hit enter.

How to start the computer in Safe mode
http://service1.symantec.com/SUPPORT/tsgen...src=sec_doc_nam

3. Once in Safe mode, open the SmitfraudFix folder and double-click smitfraudfix.cmd

Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually.

4. Once back into normal mode, please scan with HijackThis to produce a log. Post that log into your topic along with the other requested logs named below.


......................
Next - Delete the VundoFix folder and files. It's been updated to ver. 5 just today and may help us here. You can get the fresh copy of Ver. 5 VundoFix here:

Please download VundoFix.exe to your desktop.

double-click *VundoFix.exe* to run it.
- Put a check next to *Run VundoFix as a task*.
- You will receive a message saying vundofix will close and re-open in a minute or less. Click *OK*
- When VundoFix re-opens, click the *Scan for Vundo* button.
- Once it's done scanning, click the *Remove Vundo* button.
- You will receive a prompt asking if you want to remove the files, click *YES*
- Once you click yes, your desktop will go blank as it starts removing Vundo.
- When completed, it will prompt that it will shutdown your computer, click *OK*.
- Turn your computer back on.
- Please post the contents of C:\vundofix.txt into your next reply

Please scan once more with HijackThis and post a fresh log.

Logs needed in your next post are:

rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed

C:\vundofix.txt

Fresh HijackThis log
Warmbrak
Hi CalamityJane,

I followed the procedures, and here are the logs:

Logfile of HijackThis v1.99.1
Scan saved at 19:41:54, on 2006/07/07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\MICROS~2\wcescomm.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\nthClock\nthClock.exe
C:\PROGRA~1\MICROS~2\rapimgr.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wuauclt.exe
D:\Images\PC Utils\HijackThis\hijackthis\HijackThis.exe
C:\WINDOWS\system32\wpabaln.exe
C:\WINDOWS\system32\wuauclt1.exe

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MICROS~2\wcescomm.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: nthClock.lnk = C:\Program Files\nthClock\nthClock.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O17 - HKLM\System\CCS\Services\Tcpip\..\{BC6F4B2E-5DBE-4FD1-879F-89669BBB9CCC}: NameServer = 137.215.101.16,137.215.101.101
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

Here is the Vundofix Log:


VundoFix V4.2.84

Running as SYSTEM
from c:\windows\system32\VundoFix.exe

Checking Java version...

Sun Java not detected
Scan started at 20:00:03 2006/07/07

Listing files found while scanning....


C:\WINDOWS\system32\bccdd.bak1
C:\WINDOWS\system32\bccdd.ini
C:\WINDOWS\system32\ddccb.dll
Attempting to delete C:\WINDOWS\system32\bccdd.bak1
C:\WINDOWS\system32\bccdd.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\bccdd.ini
C:\WINDOWS\system32\bccdd.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\ddccb.dll
C:\WINDOWS\system32\ddccb.dll Could not be deleted.

Performing Repairs to the registry.
Done!

When I ran Vundofix, Spybot S&D picked up all kinds of registry entries, and I asked it to log it. Not sure if this is helpful, but I'm posting it here anyway. Looks like the critter is still active, and had a popup to winantivirus.com again just now in IE. Here is the Spybot S&D log:

2006/07/07 19:45:54 Denied value "ddccb" (new data: "") deleted in Winlogon Notifiers!
2006/07/07 19:46:10 Denied value "ddccb" (new data: "") deleted in Winlogon Notifiers!
2006/07/07 19:46:25 Denied value "ddccb" (new data: "") deleted in Winlogon Notifiers!
2006/07/07 19:57:15 Denied value "{F8F88D76-977D-4395-99BA-BCA2DB52BCA0}" (new data: "") added in Browser Helper Object!
2006/07/07 19:57:19 Denied value "{0A20C3AD-DDF3-4472-8202-E9950BDE0829}" (new data: "") deleted in Browser Helper Object!
2006/07/07 19:57:20 Denied value "ddccb" (new data: "") added in Winlogon Notifiers!
2006/07/07 19:57:23 Denied value "{F8F88D76-977D-4395-99BA-BCA2DB52BCA0}" (new data: "") added in Browser Helper Object!
2006/07/07 19:57:24 Denied value "{0A20C3AD-DDF3-4472-8202-E9950BDE0829}" (new data: "") deleted in Browser Helper Object!
2006/07/07 19:57:30 Denied value "ddccb" (new data: "") added in Winlogon Notifiers!
2006/07/07 19:57:32 Denied value "{F8F88D76-977D-4395-99BA-BCA2DB52BCA0}" (new data: "") added in Browser Helper Object!
2006/07/07 19:57:33 Denied value "{0A20C3AD-DDF3-4472-8202-E9950BDE0829}" (new data: "") deleted in Browser Helper Object!
2006/07/07 19:57:34 Denied value "ddccb" (new data: "") added in Winlogon Notifiers!
2006/07/07 19:57:36 Denied value "{F8F88D76-977D-4395-99BA-BCA2DB52BCA0}" (new data: "") added in Browser Helper Object!
2006/07/07 19:57:36 Denied value "{0A20C3AD-DDF3-4472-8202-E9950BDE0829}" (new data: "") deleted in Browser Helper Object!
2006/07/07 19:57:38 Denied value "ddccb" (new data: "") added in Winlogon Notifiers!
2006/07/07 19:57:40 Denied value "{F8F88D76-977D-4395-99BA-BCA2DB52BCA0}" (new data: "") added in Browser Helper Object!
2006/07/07 19:57:41 Denied value "{0A20C3AD-DDF3-4472-8202-E9950BDE0829}" (new data: "") deleted in Browser Helper Object!
2006/07/07 19:57:41 Denied value "ddccb" (new data: "") added in Winlogon Notifiers!
2006/07/07 19:57:43 Denied value "{F8F88D76-977D-4395-99BA-BCA2DB52BCA0}" (new data: "") added in Browser Helper Object!
2006/07/07 19:57:44 Denied value "{0A20C3AD-DDF3-4472-8202-E9950BDE0829}" (new data: "") deleted in Browser Helper Object!
2006/07/07 19:57:54 Allowed value "ddccb" (new data: "") added in Winlogon Notifiers!
2006/07/07 19:58:01 Allowed value "{F8F88D76-977D-4395-99BA-BCA2DB52BCA0}" (new data: "") added in Browser Helper Object!
2006/07/07 19:58:11 Allowed value "{0A20C3AD-DDF3-4472-8202-E9950BDE0829}" (new data: "") deleted in Browser Helper Object!
2006/07/07 20:00:26 Allowed value "ddccb" (new data: "") deleted in Winlogon Notifiers!
2006/07/07 20:03:38 Allowed value "{C7F14187-6B6F-4CF2-903B-429B1FB9EE45}" (new data: "") added in Browser Helper Object!
2006/07/07 20:04:11 Allowed value "{F8F88D76-977D-4395-99BA-BCA2DB52BCA0}" (new data: "") deleted in Browser Helper Object!
2006/07/07 20:04:11 Allowed value "ddccb" (new data: "") added in Winlogon Notifiers!
Warmbrak
Fresh HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 20:25:59, on 2006/07/07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\PROGRA~1\MICROS~2\wcescomm.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\nthClock\nthClock.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\MICROS~2\rapimgr.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wpabaln.exe
D:\Images\PC Utils\HijackThis\hijackthis\HijackThis.exe

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MICROS~2\wcescomm.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: nthClock.lnk = C:\Program Files\nthClock\nthClock.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O17 - HKLM\System\CCS\Services\Tcpip\..\{BC6F4B2E-5DBE-4FD1-879F-89669BBB9CCC}: NameServer = 137.215.101.16,137.215.101.101
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
LS CalamityJane
Hi Warmbrak,

You're still using the old VundoFix V4.2.84

Could you please delete that one.

And download the new version 5.0

When you run the new version again, don't block anything with Spybot's teatimer. The changes we are trying to make are being blocked. So please allow if it alerts you after running VundoFix. (Or just turn it off until we are done).
Warmbrak
Hi CalamityJane,

For some unkown reason I cannot find the latest Vundofix 5. The link you have given and the one on Atribune's forums all point to V4.2.84. Do you perhaps have another link for me?

Enjoy the weekend!
LS CalamityJane
Delete the old VundoFix first.

Then download my copy attached here in a zip file. Unzip/extract Vundofix.exe to your desktop

It should now say version 5.1.0 (He must have updated it again)
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.