Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Spyware is killing me
   
BullGuard Antivirus Forum > General Security > Spyware > Spyware is killing me  
Forum Quick Jump
 
New Topic Post reply to : Spyware is killing me Printable version of : Spyware is killing me
[ << Previous Thread | Next Thread >> ]

yondaime
New Member


Date Joined Dec 2007
Total Posts : 10
 
   Posted 12-9-2007 1:34 (GMT +1)    Quote: Spyware is killing meAlert an admin about: Spyware is killing me
Hi guys i'm having some problem with a spyware which makes it impssible to access control panel, i've tried every reboot run all  adware and spyware prevention, still same problem the spyware keeps copying files, and after some advertisement asked me to use their anti spyware, can u guys help.
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:13:34 AM, on 12/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
 
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\lxczcoms.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\proper.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\sm56hlpr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Avant Browser\avant.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\FlashGet\flashget.exe
C:\Downloads\HiJackThis.exe
 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\proper.exe
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll (file missing)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {D27987B8-7244-4DE0-AE10-39B826B492F1} - C:\WINDOWS\system32\bronto.dll
O2 - BHO: (no name) - {DABCE839-3831-3818-AF3A-3837BCD324D2} - C:\WINDOWS\system32\mspoolg.dll (file missing)
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [lxczbmgr.exe] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Undefined] C:\WINDOWS\system32\winter.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Undefined] C:\WINDOWS\system32\winter.exe
O4 - HKUS\S-1-5-18\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit (User 'Default user')
O4 - Startup: infos.exe
O4 - Global Startup: autos.exe
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {18D63578-EA2F-4A59-A49A-7F62E6B3DF3E} (ImP3 Control) - http://activexdown.paran.com/paranactivex/data/ImP3.cab
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} (NeffyLauncherCtl Class) - http://dist.globalgamecdn.com/dist/neffy/NeffyLauncher.cab
O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - http://cdn1.acclaimdownloads.com/solidstateion.cab
O16 - DPF: {C26027F5-C7EF-4CC1-9637-B514BCF8BF4E} (SAIOnlineAForm Control) - http://www.arcadetown.com/swf/scorchanisland/saionline.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - http://update.nprotect.net/keycrypt/TwelveSky/KeyCrypt/npkcx.cab
O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} (Logout Class) - http://www.gamengame.com/KALogoutComponent.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\sol1040.txt
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: lxcz_device -   - C:\WINDOWS\system32\lxczcoms.exe
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\system32\npkcsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 
--
End of file - 8605 bytes
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13599
 
   Posted 12-9-2007 1:48 (GMT +1)    Quote: Spyware is killing meAlert an admin about: Spyware is killing me
Hi yondaime smile
 
 
 
You have several infections, I´ll therefore suggest You -
 
 
Click here - ->>  Before posting a log 
 
 
 After You have run the scan tools -
 
Reboot normally
 
Post Hijackthis log along with AVG Anti-Spyware log, C: Rootlog TXT, C: combofix txt in this topic
 
 
 
 


Do NOT post your problem in someone elses thread.

Back to Top
 

yondaime
New Member


Date Joined Dec 2007
Total Posts : 10
 
   Posted 12-9-2007 2:17 (GMT +1)    Quote: Spyware is killing meAlert an admin about: Spyware is killing me
what am i suppose to do
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13599
 
   Posted 12-9-2007 2:21 (GMT +1)    Quote: Spyware is killing meAlert an admin about: Spyware is killing me
Click here - ->>  Before posting a log 
 
 
 
And follow the instructions


Do NOT post your problem in someone elses thread.

Back to Top
 

yondaime
New Member


Date Joined Dec 2007
Total Posts : 10
 
   Posted 12-9-2007 2:42 (GMT +1)    Quote: Spyware is killing meAlert an admin about: Spyware is killing me
here

********************************* ROOTCHK-(5-12-07)-LOG, by ejvindh
Sun 12/09/2007 8:35:34.82

The rootkits that are detected by this tool were not found.

********************************* ROOTCHK-LOG-end


catchme 0.3.1319 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-09 08:35:40
Windows 5.1.2600 Service Pack 2
scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

hidden processes: 0
hidden services: 0
hidden files: 0
Back to Top
 

yondaime
New Member


Date Joined Dec 2007
Total Posts : 10
 
   Posted 12-9-2007 2:53 (GMT +1)    Quote: Spyware is killing meAlert an admin about: Spyware is killing me
oh ok i'll make a full report after i'm done downloading avg but i can't download combo tool is it necesary
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13599
 
   Posted 12-9-2007 3:51 (GMT +1)    Quote: Spyware is killing meAlert an admin about: Spyware is killing me
This link to combofix should work:


Do NOT post your problem in someone elses thread.

Back to Top
 

yondaime
New Member


Date Joined Dec 2007
Total Posts : 10
 
   Posted 12-9-2007 5:22 (GMT +1)    Quote: Spyware is killing meAlert an admin about: Spyware is killing me
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:21:09 AM, on 12/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\lxczcoms.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\proper.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\sm56hlpr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Avant Browser\avant.exe
C:\Program Files\FlashGet\flashget.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\NOTEPAD.EXE
C:\Downloads\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\proper.exe
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll (file missing)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {D27987B8-7244-4DE0-AE10-39B826B492F1} - C:\WINDOWS\system32\bronto.dll
O2 - BHO: (no name) - {DABCE839-3831-3818-AF3A-3837BCD324D2} - C:\WINDOWS\system32\mspoolg.dll (file missing)
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [lxczbmgr.exe] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Undefined] C:\WINDOWS\system32\winter.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Undefined] C:\WINDOWS\system32\winter.exe
O4 - HKUS\S-1-5-18\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit (User 'Default user')
O4 - Startup: infos.exe
O4 - Global Startup: autos.exe
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {18D63578-EA2F-4A59-A49A-7F62E6B3DF3E} (ImP3 Control) - http://activexdown.paran.com/paranactivex/data/ImP3.cab
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} (NeffyLauncherCtl Class) - http://dist.globalgamecdn.com/dist/neffy/NeffyLauncher.cab
O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - http://cdn1.acclaimdownloads.com/solidstateion.cab
O16 - DPF: {C26027F5-C7EF-4CC1-9637-B514BCF8BF4E} (SAIOnlineAForm Control) - http://www.arcadetown.com/swf/scorchanisland/saionline.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - http://update.nprotect.net/keycrypt/TwelveSky/KeyCrypt/npkcx.cab
O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} (Logout Class) - http://www.gamengame.com/KALogoutComponent.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\sol1040.txt
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: lxcz_device - - C:\WINDOWS\system32\lxczcoms.exe
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\system32\npkcsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 8909 bytes
Back to Top
 

yondaime
New Member


Date Joined Dec 2007
Total Posts : 10
 
   Posted 12-9-2007 5:23 (GMT +1)    Quote: Spyware is killing meAlert an admin about: Spyware is killing me
********************************* ROOTCHK-(5-12-07)-LOG, by ejvindh
Sun 12/09/2007 10:52:41.37

The rootkits that are detected by this tool were not found.

********************************* ROOTCHK-LOG-end


catchme 0.3.1319 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-09 10:52:45
Windows 5.1.2600 Service Pack 2
scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

hidden processes: 0
hidden services: 0
hidden files: 0
Back to Top
 

yondaime
New Member


Date Joined Dec 2007
Total Posts : 10
 
   Posted 12-9-2007 5:23 (GMT +1)    Quote: Spyware is killing meAlert an admin about: Spyware is killing me
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 11:21:35 AM 12/9/2007

+ Scan result:



C:\System Volume Information\_restore{1FDB9C89-C7F8-4D9D-845B-7B2FB413BDCF}\RP306\A0203542.exe -> Downloader.Wixud.j : No action taken.
C:\System Volume Information\_restore{1FDB9C89-C7F8-4D9D-845B-7B2FB413BDCF}\RP307\A0207627.exe -> Downloader.Wixud.j : No action taken.
C:\System Volume Information\_restore{1FDB9C89-C7F8-4D9D-845B-7B2FB413BDCF}\RP308\A0207702.exe -> Downloader.Wixud.j : No action taken.
C:\System Volume Information\_restore{1FDB9C89-C7F8-4D9D-845B-7B2FB413BDCF}\RP309\A0208771.exe -> Downloader.Wixud.j : No action taken.
C:\System Volume Information\_restore{1FDB9C89-C7F8-4D9D-845B-7B2FB413BDCF}\RP313\A0211862.exe -> Downloader.Wixud.j : No action taken.
C:\System Volume Information\_restore{1FDB9C89-C7F8-4D9D-845B-7B2FB413BDCF}\RP314\A0211930.exe -> Downloader.Wixud.j : No action taken.
C:\System Volume Information\_restore{1FDB9C89-C7F8-4D9D-845B-7B2FB413BDCF}\RP315\A0211998.exe -> Downloader.Wixud.j : No action taken.
C:\WINDOWS\ddexxz.exe -> Downloader.Wixud.j : No action taken.
C:\WINDOWS\ksacre.exe -> Proxy.!!!la.ao : No action taken.
:mozilla.10:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.11:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.200:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.219:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.88:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.8:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.9:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Owner\Cookies\owner@2o7.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.16:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.17:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.18:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.299:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.300:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Owner\Cookies\owner@adbrite.txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Owner\Cookies\owner@ads.adbrite.txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Owner\Cookies\owner@ads.addynamix.txt -> TrackingCookie.Addynamix : No action taken.
:mozilla.378:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Adengage : No action taken.
:mozilla.379:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Adengage : No action taken.
:mozilla.427:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.48:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.406:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Cqcounter : No action taken.
:mozilla.23:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Euroclick : No action taken.
:mozilla.24:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Euroclick : No action taken.
:mozilla.25:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Euroclick : No action taken.
:mozilla.438:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.141:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Imrworldwide : No action taken.
:mozilla.142:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Imrworldwide : No action taken.
:mozilla.417:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Information : No action taken.
C:\Documents and Settings\Owner\Cookies\owner@ssl-hints.netflame.txt -> TrackingCookie.Netflame : No action taken.
:mozilla.29:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.30:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.31:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.32:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.33:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.34:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.35:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.36:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.37:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.259:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Pro-market : No action taken.
:mozilla.260:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Pro-market : No action taken.
:mozilla.263:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.264:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.270:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.271:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.272:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.273:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.274:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.97:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.98:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.282:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.283:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.284:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.285:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.286:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.287:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.57:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.301:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.302:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.303:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.382:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.308:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.309:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.310:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.311:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.312:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.316:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.399:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Webtrends : No action taken.
:mozilla.354:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Yadro : No action taken.
:mozilla.373:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.374:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.375:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.376:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.377:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\4ozuhwwn.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.


::Report end
Back to Top
 

yondaime
New Member


Date Joined Dec 2007
Total Posts : 10
 
   Posted 12-9-2007 5:24 (GMT +1)    Quote: Spyware is killing meAlert an admin about: Spyware is killing me
does that help please
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13599
 
   Posted 12-9-2007 5:46 (GMT +1)    Quote: Spyware is killing meAlert an admin about: Spyware is killing me
It´s a start smile
 
 
Please download Combofix:

Close all other browser windows. 

 
go to start --> run and copy/paste in the following:

"%userprofile%\desktop\combofix.exe" /killall

 
 When finished, it will produce a logfile located at C:\ComboFix.txt.

Post the contents of that log in your next reply with a new hijackthis log.

Note:
Do not mouseclick combofix's window while it is running. That may cause your system to stall/hang.
 


Do NOT post your problem in someone elses thread.

Back to Top
 

yondaime
New Member


Date Joined Dec 2007
Total Posts : 10
 
   Posted 12-9-2007 6:01 (GMT +1)    Quote: Spyware is killing meAlert an admin about: Spyware is killing me
Thx alot for the link and the help combo automatically fix the spyware problem thx again.ComboFix 07-12-09.3 - Owner 2007-12-09 11:39:16.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.75 [GMT -5:00]
Running from: C:\Downloads\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\infos.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\autos.exe
C:\Documents and Settings\Owner\Application Data\PCTurbo Pro Free
C:\Documents and Settings\Owner\Application Data\PCTurbo Pro Free\Logs\update.log
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\infos.exe
C:\WINDOWS\ksacre.exe
C:\WINDOWS\system32\bronto.dll
C:\WINDOWS\system32\cfx32.ocx
C:\WINDOWS\system32\launcher.exe
C:\WINDOWS\system32\proper.exe
C:\WINDOWS\system32\winter.exe

.
((((((((((((((((((((((((( Files Created from 2007-11-09 to 2007-12-09 )))))))))))))))))))))))))))))))
.

2007-12-09 09:30 . 2007-12-09 09:30 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Grisoft
2007-12-09 09:30 . 2007-12-09 09:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-09 09:30 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-08 21:41 . 2007-12-08 21:41 59,392 --a------ C:\WINDOWS\derc32xz.exe
2007-12-08 20:48 . 2007-12-08 20:48 16,384 --a------ C:\WINDOWS\ddexxz.exe
2007-12-08 20:14 . 2007-12-08 20:14 159,408 --a------ C:\WINDOWS\bagvdg.exe
2007-12-08 01:45 . 2007-12-08 01:45 159,408 --a------ C:\WINDOWS\bagzdg.exe
2007-12-08 01:39 . 2007-12-08 01:39 383,488 --a------ C:\WINDOWS\ddubbv.exe
2007-12-08 01:39 . 2007-12-08 01:39 291,328 --a------ C:\WINDOWS\system32\libcurl.dll
2007-12-08 01:39 . 2007-12-08 01:39 138,240 --a------ C:\WINDOWS\xnnnav.exe
2007-12-08 01:39 . 2007-12-08 01:39 87,552 --a------ C:\WINDOWS\system32\spoolc.exe
2007-12-06 15:52 . 2007-12-09 05:15 <DIR> d-------- C:\Program Files\Elf Online
2007-12-01 22:44 . 2007-12-01 22:44 <DIR> d-------- C:\UserJoy
2007-12-01 22:43 . 2007-12-01 22:43 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\InstallShield
2007-12-01 18:40 . 2006-04-20 06:51 359,808 --a------ C:\WINDOWS\system32\drivers\tcpip.sys.flg
2007-12-01 18:39 . 2007-12-09 11:49 <DIR> d-------- C:\Program Files\FlashGet
2007-11-29 20:02 . 2007-11-29 21:21 <DIR> d-------- C:\Program Files\Yahoo!
2007-11-17 13:48 . 2007-11-22 09:11 <DIR> d-------- C:\TSBot
2007-11-16 23:12 . 1998-06-24 00:00 244,024 --a------ C:\WINDOWS\system32\MSFLXGRD.OCX
2007-11-16 23:12 . 2000-12-06 00:00 209,608 --a------ C:\WINDOWS\system32\tabctl32.ocx
2007-11-16 23:12 . 1998-06-24 01:00 203,576 --a------ C:\WINDOWS\system32\RICHTX32.OCX
2007-11-16 23:12 . 2005-09-23 09:20 118,784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-09 10:15 --------- d-----w C:\Program Files\Avant Browser
2007-12-02 03:44 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-01 23:10 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-26 23:28 65,536 ----a-w C:\WINDOWS\IFinst27.exe
2007-11-04 01:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2007-11-04 01:44 --------- d-----w C:\Program Files\Chinesegamer
2007-10-30 10:52 --------- d-----w C:\Program Files\ONWIND
2007-10-21 13:35 --------- d-----w C:\Program Files\Java
2007-10-13 00:10 --------- d-----w C:\Program Files\SystemRequirementsLab
2007-09-19 03:41 258,352 ----a-w C:\WINDOWS\system32\unicows.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" []
"NVIEW"="nview.dll" [2003-07-28 13:19 C:\WINDOWS\system32\nview.dll]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-04 07:00 C:\WINDOWS\system32\rundll32.exe]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2007-11-13 15:48]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"lxczbmgr.exe"="C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe" [2007-02-08 17:52]
"FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2007-02-08 17:56]
"NvMediaCenter"="RunDLL32.exe" [2004-08-04 07:00 C:\WINDOWS\system32\rundll32.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-07-27 17:03]
"SMSERIAL"="sm56hlpr.exe" [2004-12-29 07:01 C:\WINDOWS\sm56hlpr.exe]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 07:00 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2003-07-28 13:19 C:\WINDOWS\system32\nwiz.exe]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-04 07:00 C:\WINDOWS\system32\rundll32.exe]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
sm56hlpr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe -quiet

R2 lxcz_device;lxcz_device;C:\WINDOWS\system32\lxczcoms.exe -service
S3 npkycryp;npkycryp;\??\C:\Program Files\Gravity\RO\npkycryp.sys
S3 XDva005;XDva005;\??\C:\WINDOWS\system32\XDva005.sys
S3 XDva011;XDva011;\??\C:\WINDOWS\system32\XDva011.sys

*Newly Created Service* - AVGASCLN
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\DOCUME~1\Owner\LOCALS~1\Temp\coirgnmoC99987F.dll
.
**************************************************************************

catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-09 11:52:18
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-09 11:57:30 - machine was rebooted
.
--- E O F ---
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13599
 
   Posted 12-10-2007 5:49 (GMT +1)    Quote: Spyware is killing meAlert an admin about: Spyware is killing me
sounds good smile
 
 
However, You still have some infections We need to get rid of -
 
 
Open notepad and copy/paste the text in the quote box below into it:
Quote:
-----------------------------------------------------
KILLALL::
 
File::
C:\WINDOWS\derc32xz.exe
C:\WINDOWS\ddexxz.exe
C:\WINDOWS\bagvdg.exe
C:\WINDOWS\bagzdg.exe
C:\WINDOWS\ddubbv.exe
C:\WINDOWS\xnnnav.exe
C:\WINDOWS\system32\spoolc.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\coirgnmoC99987F.dll
 
----------------------------------------------
 
Save this as CFScript.txt
 
 
Referring to the picture above, drag CFScript.txt into ComboFix.exe.
ComboFix will now run a scan on your system.
It may reboot your system when it finishes. This is normal.
 
 
Post new hijackthis log along with fresh combofix log
 


Do NOT post your problem in someone elses thread.

Back to Top
 
New Topic Post reply to : Spyware is killing me Printable version of : Spyware is killing me
 
Forum Information
Currently it is Friday, November 21, 2008 1:30 AM (GMT +1)
There are a total of 63.951 posts in 15.824 threads.
In the last 3 days there were 33 new threads and 167 reply posts. View Active Threads
Who's Online
This forum has 27181 registered members. Please welcome our newest member, DilbertCube.
36 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Win 32-trojan-gen (15)21-11-2008 00:08:56 (RAYJAY)
Help please!!! (7)20-11-2008 23:03:58 (paytons place)
Generic Host processor for Win32 services (0)20-11-2008 21:28:28 (gio)
Trojan horse SHeur2.FO help :( (3)20-11-2008 21:23:39 (bizzaro)
Bullguard quits scanning after 6200 files (0)20-11-2008 19:59:07 (Ruud Smit)