computer is messed beyond belief

Status
Not open for further replies.

bigdan

Daemon Poster
Messages
615
for the last few days my computer's been acting up. i recently downloaded a brower called wyzo, i dont know if that had anything to do w/ it or not. this browser was mentioned on lifehacker.

anyway so i did an AVG virus scan a few days ago which came up empty. i should mention that it wasnt updated, i couldnt for some reason which ive forgotten. since then ive followed the guide, and a number of problems have been found. oh btw the msconfig startup had some stuff which i didnt recognize and seemed to be the cause for some of the problems that had been happening. i just checked the startup, i dont see that problem anymore (i prolly deleted it) but im attaching a screenshot of my current startup and please tell me if anything needs to be added / erased.


<a href="http://s103.photobucket.com/albums/m140/bigdan1/?action=view&current=startup.jpg" target="_blank"><img src="http://i103.photobucket.com/albums/m140/bigdan1/startup.jpg" border="0" alt="Photobucket"></a>

http://i103.photobucket.com/albums/m140/bigdan1/startup.jpg

ive gone thru the guide. now windows wont even start properly! ive got to the point where the desktop background comes up. but no icons or anything else. i went to task manager, there the computer activity was 0-2%, ive never seen that before. when i tried to add new task -> explorer, that didnt work either. also my IE icon has disappeared and has been replaced w/ this Wyzo icon. Its still called IE but the icon is diff, and i cant get IE to start when I click on it.

attaching a HJT scan in case its relevant. pleeeease help!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:39:29 PM, on 5/7/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\HJT\HiJackThis.exe
C:\Program Files\Wyzo\wyzo.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = BBC NEWS | News Front Page
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {4b38aaa3-2356-4938-9562-a674728b35d6} - C:\WINDOWS\system32\kalahavi.dll (file missing)
O2 - BHO: MS extension - {BE83C3B6-0F77-436c-88B1-A56124A743CB} - fagw32.dll (file missing)
O2 - BHO: C:\WINDOWS\system32\afnoinkdsfe.dll - {C2BA40A1-74F3-42BD-F434-12345A2C8953} - C:\WINDOWS\system32\afnoinkdsfe.dll (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [nasotuwira] Rundll32.exe "C:\WINDOWS\system32\zahenese.dll",s
O4 - HKLM\..\Run: [combofix] C:\WINDOWS\system32\CF13362.exe /c C:\ComboFix\Combobatch.bat
O4 - HKCU\..\Run: [ptidle] "C:\Documents and Settings\Daanish Rashid\Application Data\ptidle\ptidle.exe" 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C8833201749139
O4 - HKCU\..\Run: [DigiFast] C:\Documents and Settings\Daanish Rashid\Application Data\digifast\digifast.exe
O4 - HKCU\..\Run: [flCB8ebG7QZBV] C:\Documents and Settings\Daanish Rashid\Application Data\Microsoft\Windows\wevly.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\RunOnce: [dcom] rundll32.exe fagw32.dll,ID
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [uidenhiufgsduiazghs] C:\WINDOWS\TEMP\b658uydh44.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Diagnostic Manager] C:\WINDOWS\TEMP\261193440.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [autochk] rundll32.exe C:\WINDOWS\system32\config\SYSTEM~1\protect.dll,_IWMPEvents@16 (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [A00F1C738FC.exe] C:\WINDOWS\TEMP\_A00F1C738FC.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/ca/en/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: __c0044809 - C:\WINDOWS\system32\__c0044809.dat (file missing)
O22 - SharedTaskScheduler: sdfsefsfdvdubgiungfuyd - {C2BA40A1-74F3-42BD-F434-12345A2C8953} - C:\WINDOWS\system32\afnoinkdsfe.dll (file missing)
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\vodawoja.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcSandraSrv.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe

--
End of file - 6683 bytes
 
Remove

O2 - BHO: (no name) - {4b38aaa3-2356-4938-9562-a674728b35d6} - C:\WINDOWS\system32\kalahavi.dll (file missing)

O2 - BHO: MS extension - {BE83C3B6-0F77-436c-88B1-A56124A743CB} - fagw32.dll (file missing)

O2 - BHO: C:\WINDOWS\system32\afnoinkdsfe.dll - {C2BA40A1-74F3-42BD-F434-12345A2C8953} - C:\WINDOWS\system32\afnoinkdsfe.dll (file missing)

O4 - HKLM\..\Run: [nasotuwira] Rundll32.exe "C:\WINDOWS\system32\zahenese.dll",s


O4 - HKCU\..\Run: [ptidle] "C:\Documents and Settings\Daanish Rashid\Application Data\ptidle\ptidle.exe" 61A847B5BBF728173599284503996897C881250221C8670836 AC4FA7C8833201749139

O4 - HKCU\..\Run: [DigiFast] C:\Documents and Settings\Daanish Rashid\Application Data\digifast\digifast.exe

O4 - HKCU\..\Run: [flCB8ebG7QZBV] C:\Documents and Settings\Daanish Rashid\Application Data\Microsoft\Windows\wevly.exe

O4 - HKCU\..\RunOnce: [dcom] rundll32.exe fagw32.dll,ID

O4 - HKUS\S-1-5-18\..\Run: [uidenhiufgsduiazghs] C:\WINDOWS\TEMP\b658uydh44.exe (User 'SYSTEM')


O4 - HKUS\S-1-5-18\..\Run: [Diagnostic Manager] C:\WINDOWS\TEMP\261193440.exe (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Run: [autochk] rundll32.exe C:\WINDOWS\system32\config\SYSTEM~1\protect.dll,_I WMPEvents@16 (User 'SYSTEM')


O4 - HKUS\S-1-5-18\..\Run: [A00F1C738FC.exe] C:\WINDOWS\TEMP\_A00F1C738FC.exe (User 'SYSTEM')


O20 - Winlogon Notify: __c0044809 - C:\WINDOWS\system32\__c0044809.dat (file missing)


O22 - SharedTaskScheduler: sdfsefsfdvdubgiungfuyd - {C2BA40A1-74F3-42BD-F434-12345A2C8953} - C:\WINDOWS\system32\afnoinkdsfe.dll (file missing)


O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\vodawoja.dll (file missing)


If you can, run combofix and then malwarebytes and post their logs along with a new hijackthis log
 
[post is too long. putting combofix log in next post]

**** youre fast man!

actually i already did the combofix and malwarebytes scans. combo was quite comprehensive. there was another scan which was taking too long so canceled it and will do it when im sleeping, i think that was malwarebytes. it did find 32 errors tho in an hour which i told to fix.

posting HJT and combofix logs.


here's my new HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:29:32 AM, on 5/8/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = BBC NEWS | News Front Page
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [combofix] C:\WINDOWS\system32\CF13362.exe /c C:\ComboFix\Combobatch.bat
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/ca/en/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcSandraSrv.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe

--
End of file - 4932 bytes
 
[this post is also too long! cutting ComboFix into separate parts]

ComboFix Log:

ComboFix 09-05-07.06 - Daanish Rashid 05/08/2009 0:39.5 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.640.276 [GMT -4:00]
Running from: c:\documents and settings\Daanish Rashid\Desktop\ComboFix.exe
AV: AVG 7.5.549 *On-access scanning enabled* (Outdated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Daanish Rashid\Local Settings\Temporary Internet Files\Cpvff.stt
.
---- Previous Run -------
.
c:\documents and settings\Daanish Rashid\Application Data\digifast
c:\documents and settings\Daanish Rashid\Application Data\digifast\config.cfg
c:\documents and settings\Daanish Rashid\Application Data\digifast\DFUninstall.exe
c:\documents and settings\Daanish Rashid\Application Data\digifast\digifast.exe
c:\documents and settings\Daanish Rashid\Application Data\twain\Twain.exe
c:\documents and settings\Daanish Rashid\Application Data\wiaserva.log
c:\documents and settings\Daanish Rashid\Local Settings\Temporary Internet Files\bestwiner.stt
c:\documents and settings\Daanish Rashid\Local Settings\Temporary Internet Files\Cpvff.stt
c:\documents and settings\Daanish Rashid\Local Settings\Temporary Internet Files\fbk.sts
c:\documents and settings\Daanish Rashid\protect.dll
c:\documents and settings\Daanish Rashid\Start Menu\Programs\Startup\ChkDisk.dll
c:\documents and settings\Daanish Rashid\Start Menu\Programs\Startup\ChkDisk.lnk
c:\documents and settings\NetworkService.NT AUTHORITY\protect.dll
C:\kmd.exe
c:\program files\Jcore
c:\program files\WWShow
c:\recycler\S-9-1-91-100028569-100012993-100019448-5755.com
c:\windows\ld08.exe
c:\windows\system32\__c0044809.dat
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\ak1.exe
c:\windows\system32\autochk.dll
c:\windows\system32\beuyybwu.ini
c:\windows\system32\config\systemprofile\protect.dll
c:\windows\system32\desoyahi.dll
c:\windows\system32\drivers\gaopdxoawadcni.sys
c:\windows\system32\drivers\npf.sys
c:\windows\system32\drivers\ovfsthgpcupxfqpabdqvylqayllmiybutltnpr.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\dz1.txt
c:\windows\system32\gaopdxcounter
c:\windows\system32\gaopdxlnnabewn.dll
c:\windows\system32\hayitapa.dll
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\inform.dat
c:\windows\system32\kjs
c:\windows\system32\nobupize.dll
c:\windows\system32\ntdll64.exe
c:\windows\system32\nuzomoyu.dll
c:\windows\system32\o4Patch.exe
c:\windows\system32\ovfsthghninqpnbksrrvxqulcawpkvqrosxtmk.dat
c:\windows\system32\ovfsthgibxbvcseroliklqwqcoqvhojayaqanw.dll
c:\windows\system32\ovfsthntiltqskwbvkfktlynguhribwdptaivv.dll
c:\windows\system32\ovfsthofetoiabbtqfcrbuppyuvuodsdfxcogf.dat
c:\windows\system32\ovfsthorwobwulnhnmefordsmrchceugrqxgir.dll
c:\windows\system32\p1.txt
c:\windows\system32\p2hhr.bat
c:\windows\system32\Packet.dll
c:\windows\system32\prnet.tmp
c:\windows\system32\Process.exe
c:\windows\system32\pthreadVC.dll
c:\windows\system32\qhhfhkau.ini
c:\windows\system32\r24.txt
c:\windows\system32\raduzuye.exe
c:\windows\system32\SCLabel.ocx
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\uniq.tll
c:\windows\system32\utedomuv.ini
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\vodawoja.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\watusero.dll
c:\windows\system32\wbem\grpconv.exe
c:\windows\system32\winglsetup.exe
c:\windows\system32\wpcap.dll
c:\windows\system32\WS2Fix.exe
c:\windows\system32\xqwjnrba.ini
c:\windows\system32\zahenese.dll
c:\windows\Sysvxd.exe
C:\xcrashdump.dat
E:\Autorun.inf
E:\install.exe
e:\recycler\S-9-1-91-100028569-100012993-100019448-5755.com

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_gaopdxserv.sys
-------\Service_ovfsthmkxymyktlwalmhsxrrovnqjwndugnomu
-------\Legacy_NPF
-------\Service_NPF


((((((((((((((((((((((((( Files Created from 2009-04-08 to 2009-05-08 )))))))))))))))))))))))))))))))
.

2009-05-08 02:58 . 2009-05-08 02:58 -------- d-sh--w C:\found.000
2009-05-08 02:02 . 2005-08-26 05:50 77312 ----a-w c:\windows\system32\ztvunace26.dll
2009-05-08 02:02 . 2006-05-25 19:52 162304 ----a-w c:\windows\system32\ztvunrar36.dll
2009-05-08 02:02 . 2006-06-19 17:01 69632 ----a-w c:\windows\system32\ztvcabinet.dll
2009-05-08 02:02 . 2002-03-06 05:00 75264 ----a-w c:\windows\system32\unacev2.dll
2009-05-08 02:02 . 2003-02-03 00:06 153088 ----a-w c:\windows\system32\UNRAR3.dll
2009-05-08 02:02 . 2009-05-08 02:02 -------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Simply Super Software
2009-05-08 02:02 . 2009-05-08 02:03 -------- d-----w c:\program files\Trojan Remover
2009-05-08 02:02 . 2009-05-08 02:02 -------- d-----w c:\documents and settings\Daanish Rashid\Application Data\Simply Super Software
2009-05-07 04:49 . 2009-05-08 02:42 -------- d-----w c:\documents and settings\Daanish Rashid\Application Data\Twain
2009-05-07 04:38 . 2009-05-07 04:38 33792 ----a-w c:\windows\system32\fagw32.dll
2009-05-07 03:08 . 2009-05-07 03:08 -------- d-----w c:\program files\MSConfig CleanUp
2009-05-07 02:49 . 2009-05-08 03:39 664 ----a-w c:\windows\system32\d3d9caps.dat
2009-05-06 14:47 . 2009-05-08 01:20 27648 ----a-w c:\windows\system32\lmn_setup.exe
2009-05-06 13:15 . 2009-05-06 13:15 -------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\STOPzilla!
2009-05-06 01:49 . 2009-05-06 01:49 23040 ----a-w c:\windows\system32\loader49.exe
2009-05-06 01:44 . 2009-05-06 01:44 -------- d-----w c:\windows\system32\config\systemprofile\Local Settings\Application Data\Google
2009-05-06 01:19 . 2009-05-06 01:19 -------- d-----w c:\documents and settings\Daanish Rashid\Application Data\ptidle
2009-05-05 03:18 . 2009-05-05 03:18 -------- d-----w c:\documents and settings\Daanish Rashid\Local Settings\Application Data\Cooliris
2009-05-05 03:18 . 2009-05-05 03:18 -------- d-----w c:\documents and settings\Daanish Rashid\Local Settings\Application Data\Radical Software Ltd
2009-05-05 03:18 . 2009-05-05 03:18 -------- d-----w c:\documents and settings\Daanish Rashid\Application Data\Radical Software Ltd
2009-05-05 03:16 . 2009-05-08 03:39 -------- d-----w c:\program files\Wyzo
2009-05-02 07:03 . 2009-05-02 07:03 -------- d-----w c:\program files\Antivirus Agent Pro
2009-05-02 06:57 . 2009-05-02 06:57 2320000 ----a-w c:\windows\system32\TUKernel.exe
2009-05-02 04:50 . 2009-05-02 07:03 24576 ----a-w c:\windows\system32\winarps32.exe
2009-05-02 04:43 . 2009-05-02 04:43 167 ----a-w C:\43454354.bat
2009-04-21 01:50 . 2009-04-21 01:50 603904 ----a-w c:\windows\system32\TUProgSt.exe
2009-04-21 01:50 . 2008-12-11 18:31 27904 ----a-w c:\windows\system32\uxtuneup.dll
2009-04-21 01:50 . 2009-04-21 01:50 360192 ----a-w c:\windows\system32\TuneUpDefragService.exe
2009-04-21 01:50 . 2009-04-21 01:50 -------- d-----w c:\documents and settings\Daanish Rashid\Application Data\TuneUp Software
2009-04-21 01:49 . 2009-04-21 01:49 -------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\TuneUp Software
2009-04-21 01:48 . 2009-04-21 01:49 -------- d-----w c:\program files\TuneUp Utilities 2009
2009-04-21 01:48 . 2009-04-21 01:48 -------- d-sh--w c:\documents and settings\All Users.WINDOWS\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-04-20 07:12 . 2008-02-24 20:17 11264 ----a-w c:\windows\system32\drivers\supermounter.sys
2009-04-20 07:12 . 2007-03-12 01:39 44000 ----a-w c:\windows\system32\drivers\AFPUni.sys
2009-04-20 07:12 . 2007-03-12 01:39 43936 ----a-w c:\windows\system32\drivers\AFPAnsi.sys
2009-04-20 07:12 . 2008-12-18 02:09 261120 ----a-w c:\windows\system32\baksm.dll
2009-04-20 07:12 . 2008-12-18 02:09 261120 ----a-w c:\windows\system32\baksm.dat
2009-04-20 07:12 . 2008-12-18 02:09 261120 ----a-w c:\windows\system32\SuperMenuHook.dll
2009-04-20 07:12 . 2009-04-09 11:05 1459712 ----a-w c:\windows\system32\vbsbak.dat
2009-04-20 07:12 . 2003-10-17 02:56 6144 ----a-w c:\windows\system32\SuperRes.dll
2009-04-20 07:12 . 2003-09-07 02:32 73728 ----a-w c:\windows\system32\smh.dat
2009-04-20 07:12 . 2003-10-11 14:24 89088 ----a-w c:\windows\system32\Shreder.dll
2009-04-20 07:12 . 2008-02-28 13:43 56 ----a-w c:\windows\system32\vb6sock.dll
2009-04-20 07:12 . 2008-08-08 03:13 1473536 ----a-w c:\windows\system32\context.dll
2009-04-20 07:11 . 2009-04-20 07:11 -------- d-----w c:\program files\SuperLogix
2009-04-20 07:11 . 2009-05-07 13:28 -------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\SecTaskMan
2009-04-20 07:11 . 2009-04-20 07:18 -------- d-----w c:\program files\Security Task Manager
2009-04-19 19:55 . 2009-04-19 19:55 -------- d-----w c:\documents and settings\Daanish Rashid\Application Data\PCF-VLC
2009-04-19 19:52 . 2009-04-19 19:55 -------- d-----w c:\documents and settings\Daanish Rashid\Application Data\gtk-2.0
2009-04-19 06:02 . 2009-04-19 06:02 -------- d-----w c:\documents and settings\Daanish Rashid\Application Data\IObit
2009-04-19 06:01 . 2009-04-19 06:01 -------- d-----w c:\program files\IObit
2009-04-19 05:45 . 2009-04-19 18:49 -------- d-----w c:\program files\Defraggler
2009-04-18 20:26 . 2009-04-18 20:26 -------- d-----w c:\documents and settings\Daanish Rashid\Application Data\Participatory Culture Foundation
2009-04-18 20:22 . 2009-04-18 20:22 -------- d-----w c:\program files\Participatory Culture Foundation
2009-04-18 20:20 . 2009-04-18 20:20 -------- d-----w c:\program files\Paglo
2009-04-18 20:11 . 2009-04-18 20:11 -------- d-----w c:\documents and settings\Daanish Rashid\Local Settings\Application Data\K-Meleon
2009-04-18 20:11 . 2009-04-18 20:12 -------- d-----w c:\documents and settings\Daanish Rashid\Application Data\K-Meleon
2009-04-18 20:09 . 2009-04-18 20:10 -------- d-----w c:\program files\K-Meleon
2009-04-15 13:32 . 2009-04-15 13:32 -------- d-----w c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Application Data\IsolatedStorage
2009-04-15 13:31 . 2009-04-15 13:31 -------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\SoftwareSecure
2009-04-15 13:28 . 2009-04-16 05:25 -------- d-----w c:\windows\system32\SSI

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-07 03:12 . 2001-04-21 02:17 -------- d-----w c:\program files\Opera
2009-05-06 13:24 . 2009-02-06 13:24 80896 --sha-w c:\windows\system32\nokihino.dll
2009-05-06 01:24 . 2009-02-06 01:24 81920 ----a-w c:\windows\system32\wumikigo.dll.vir
2009-05-03 05:24 . 2006-05-21 05:56 -------- d-----w c:\program files\Google
2009-05-03 05:17 . 2000-05-19 03:25 -------- d-----w c:\program files\Logitech
2009-05-03 05:08 . 2009-04-05 07:56 -------- d-----w c:\program files\The KMPlayer
2009-05-03 05:07 . 2009-01-30 05:22 -------- d-----w c:\program files\Kantaris
2009-05-02 07:09 . 2009-03-07 05:29 -------- d-----w c:\program files\Privacy Mantra 2.05
2009-05-02 07:05 . 2007-07-20 21:53 -------- d-----w c:\program files\Mozilla Thunderbird
2009-04-19 11:06 . 2008-01-30 19:36 -------- d-----w c:\program files\eMule
2009-04-18 23:16 . 2008-09-13 09:50 -------- d-----w c:\program files\Power Audio Recorder
2009-04-05 07:31 . 2009-04-05 07:31 -------- d-----w c:\program files\Webteh
2009-04-05 07:12 . 2009-04-05 05:04 -------- d-----w c:\program files\Easy DVD Player
2009-02-17 13:37 . 2009-02-17 13:37 22 ----a-w c:\windows\INTUSB.DAT
2009-02-17 13:37 . 2009-02-17 13:37 22 ----a-w c:\windows\INTUPREM.DAT
2008-11-10 17:45 . 2008-11-10 17:45 14248 -c--a-w c:\program files\Common Files\qubycig.db
2008-11-09 09:16 . 2008-11-09 09:16 14118 -c--a-w c:\program files\Common Files\esomywif.reg
2008-11-04 23:48 . 2008-11-04 23:48 18191 -c--a-w c:\program files\Common Files\kajiwiqovu.reg
2001-09-15 03:49 . 2001-09-15 03:49 286720 -c--a-w c:\program files\WakeMeUP.exe
2001-05-24 18:18 . 2001-05-24 18:18 389158 -c--a-w c:\program files\TalkAny.exe
2001-05-08 05:05 . 2001-05-08 05:05 76800 -c--a-w c:\program files\ipscan.exe
2000-09-16 00:49 . 2000-09-16 00:49 881 -c--a-w c:\program files\uninstal.log
2000-07-01 16:27 . 2000-05-16 20:15 266 -csha-w c:\program files\desktop.ini
2000-07-01 16:27 . 2000-05-16 20:15 11079 -c-ha-w c:\program files\folder.htt
2001-02-27 00:16 . 2001-04-21 02:17 53295 -c--a-w c:\program files\opera\program\plugins\PlugDef.dll
2009-05-07 04:55 . 2009-05-07 04:55 211968 ----a-w c:\program files\mozilla firefox\components\dfff.dll
2009-04-22 07:12 . 2009-04-22 07:12 90624 ----a-w c:\program files\mozilla firefox\components\WWShow.dll
2007-12-08 18:24 . 2007-12-08 18:24 8 --sha-r c:\windows\neoqaz2.dll
2008-01-09 10:18 . 2007-12-19 19:01 11270 -csha-w c:\windows\SYSTEM32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-21 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2004-08-04 158208]
"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2009-04-29 1053576]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2008-10-22 1261200]
 
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"AllowMultipleTSSessions"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"EnableProfileQuota"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"aux"= ctwdm32.dll

[HKLM\~\startupfolder\C:^Documents and Settings^Daanish Rashid^Start Menu^Programs^Startup^ChkDisk.dll]
path=c:\documents and settings\Daanish Rashid\Start Menu\Programs\Startup\ChkDisk.dll
backup=c:\windows\pss\ChkDisk.dllStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Daanish Rashid^Start Menu^Programs^Startup^ChkDisk.lnk]
path=c:\documents and settings\Daanish Rashid\Start Menu\Programs\Startup\ChkDisk.lnk
backup=c:\windows\pss\ChkDisk.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ewido anti-spyware 4.0 guard"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\rundisabled]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe"
"PC Pitstop Optimize Reminder"=c:\program files\PCPitstop\Optimize2\Reminder.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Shareaza Lite\\Shareaza.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\winsim\\ConnectionManager\\MySqlBinary\\5.0.38\\mysql\\mysqld-nt.exe"=
"c:\\Program Files\\winsim\\ConnectionManager\\SimplyConnectionManager.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Java\\jre1.5.0_06\\bin\\javaw.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\HelpCtr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2871:UDP"= 2871:UDP:Windows Media Format SDK (iexplore.exe)
"2870:UDP"= 2870:UDP:Windows Media Format SDK (iexplore.exe)

R0 AFPAnsi;Alfa File Protector Ansi;c:\windows\SYSTEM32\DRIVERS\AFPAnsi.sys [4/20/2009 3:12 AM 43936]
S1 SuperMounter;SuperMounter;c:\windows\SYSTEM32\DRIVERS\supermounter.sys [4/20/2009 3:12 AM 11264]
S2 mrtRate;mrtRate; [x]
S2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\SYSTEM32\TUProgSt.exe [4/20/2009 9:50 PM 603904]
S4 Simply Accounting Database Connection Manager;Simply Accounting Database Connection Manager;c:\program files\winsim\ConnectionManager\SimplyConnectionManager.exe [4/23/2008 12:40 PM 16168]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2f11ad50-89e9-11db-b880-806d6172696f}]
\Shell\Auto\command - zcgrbpcnr.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL zcgrbpcnr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{901A929E-1477-4b67-94FA-7A8EE43ED159}]
rundll32 fagw32.dll,InitO
.
Contents of the 'Scheduled Tasks' folder

2009-05-08 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-12 02:36]

2009-05-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:57]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://news.bbc.co.uk/
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
Handler: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - c:\windows\wc98pp.dll
FF - ProfilePath - c:\documents and settings\Daanish Rashid\Application Data\Mozilla\Firefox\Profiles\1gjwvkcl.default\
FF - component: c:\program files\Mozilla Firefox\components\dfff.dll
FF - component: c:\program files\Mozilla Firefox\components\WWShow.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-08 00:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1409082233-1708537768-1441702643-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0F5D5A1B-692B-B881-D684-C2F24DA2281C}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaindmgknpkbfhohfo"=hex:6b,61,65,65,69,6f,63,68,68,69,65,62,70,67,68,6a,68,61,
6c,62,69,62,00,00
"hakmjcieagiepigm"=hex:6b,61,65,65,69,6f,63,68,68,69,65,62,70,67,68,6a,68,61,
6c,62,69,62,00,00

[HKEY_USERS\S-1-5-21-1409082233-1708537768-1441702643-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C7243119-F9AE-D90F-029E-57D786BC68B7}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"oaffogmienlkegfeakanmoageehikd"=hex:64,61,63,68,64,62,61,69,00,60
"oabfpkknplchjegkndjmekphledipe"=hex:6a,61,63,68,61,62,69,6b,6f,70,6c,68,70,64,
67,66,67,6b,63,6b,00,fd
"nahfigkgdmhmlcbaecpofhigcdld"=hex:6a,61,63,68,61,62,69,6b,6f,70,6c,68,70,64,
67,66,67,6b,63,6b,00,fd
.
Completion time: 2009-05-08 0:50
ComboFix-quarantined-files.txt 2009-05-08 04:49
ComboFix2.txt 2008-11-10 21:33

Pre-Run: 2,985,567,744 bytes free
Post-Run: 2,990,072,832 bytes free

320 --- E O F --- 2009-02-03 01:28
 
system seems much better now, thanks. the sound wasnt working for a while, until yesterday i think, but suddenly thats working as well.

unfortunately the computer is EXTREMEly slow these days. now its very old so it has reason to be sluggish, but despite its age ive been making do w/ it reasonably well. but i do so by having as few programs running as possible, including protective programs. for example i never put an antivirus on realtime protection, i just dont have the resources for that.

is there anything i can do to make it faster? for example i had to reinstall avg and now that has protection that is realtime i believe. ive pressed control-alt-del to shut it down but cant figure out how to not let it happen each time. ive gone to msconfig/startup but only google toolbar was checked there.
 
Probably wont see much of a difference if the hardware is slow, you can try to defrag the hdd, add some ram that you might have layin around, etc. :cool:
 
Status
Not open for further replies.
Back
Top Bottom