It is currently Tue Sep 01, 2026 1:52 pm


Please check.

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

Please check.

Postby wintacs » Thu Dec 31, 2009 7:25 am

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 12:23:55 AM, on 12/31/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\htpatch.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\sistray.exe
C:\Documents and Settings\ryan\My Documents\RCA Detective\RCADetective.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\ryan\Desktop\hjt\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://catatwork.cat.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.0\masqform.exe -UpdateCurrentUser
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - Startup: RCA Detective.lnk = C:\Documents and Settings\ryan\My Documents\RCA Detective\RCADetective.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net ... plugin.cab
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} (VaioInfo.CMClass) - http://esupport.sony.com/VaioInfo.CAB
O16 - DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} (VatCtrl Class) - http://www.hoppy.com/sacramento/cams/vatdec.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/house ... hcImpl.cab
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n042p/EN/install/gtdownlr.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 2412367421
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSCDL/ ... 586-jc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://l.yimg.com/jh/games/web_games/po ... der_v6.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol ... _en_dl.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Sony SCSI Helper Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe

--
End of file - 8760 bytes
A+, Network+, MCP
wintacs
Geek
Geek
 
Posts: 34
Joined: Thu Apr 05, 2007 12:43 am

Thanks given:0
Thanks received:0
Top

Re: Please check.

Postby Gecko » Fri Jan 01, 2010 1:14 pm

wintacs,

Please download to your desktop.

Double click combofix.exe and follow the prompts.

Do not exit Combofix while it is running you my loose all your personal settings!
Important Note - Do not mouseclick combofix's window while it's running, that may cause it to stall.

When it's done running it will produce a log for you. Please post that log in your next reply.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: Please check.

Postby wintacs » Sat Jan 02, 2010 4:40 am

ComboFix 09-12-31.A1 - ryan 01/01/2010 21:26:11.5.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1504.957 [GMT -6:00]
Running from: c:\documents and settings\ryan\My Documents\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100101-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
c:\documents and settings\All Users\Start Menu\Programs\Hotbar
c:\documents and settings\All Users\Start Menu\Programs\Hotbar\About Hotbar.lnk
c:\documents and settings\All Users\Start Menu\Programs\Hotbar\Hotbar Customer Support Center.lnk
c:\documents and settings\All Users\Start Menu\Programs\Hotbar\Hotbar Games!.lnk
c:\documents and settings\All Users\Start Menu\Programs\Hotbar\Hotbar Uninstall Instructions.lnk
c:\documents and settings\All Users\Start Menu\Programs\Hotbar\Hotbar Videos!.lnk
c:\documents and settings\All Users\Start Menu\Programs\Hotbar\Reset Cursor.lnk
c:\documents and settings\All Users\Start Menu\Programs\Hotbar\Weather.lnk
c:\documents and settings\ryan\Application Data\Hotbar
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\dynamic\1.sdf
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\dynamic\domains.txt
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\1000030162
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\21060
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\552212
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\585345
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\79246
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\dynamic\TooltipXML\87439
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\dynamic\ustat\390e.dat
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\ads.cdf
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\btntrans.idx
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\btntrans1.dat
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\business_promo.htm
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\buttondir.txt
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\components.cdf
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\cursors.res
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\d_icons_buttons_1000.res
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\d_icons_buttons_2000.res
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\d_icons_buttons_3000.res
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\d_icons_buttons_bar.res
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\d_icons_buttons_bbar1.res
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\d_icons_buttons_logos.res
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\d_icons_buttons_other.res
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\d_icons_weather.res
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\default.cdf
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_511745-514279.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz1.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz10.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz11.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz12.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz13.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz14.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz15.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz16.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz17.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz18.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz19.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz2.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz20.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz3.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz4.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz5.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz6.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz7.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz8.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_bidz9.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_categorize.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_comparison.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_em_PROFL_CA_flow_b_IEB.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_explorer-Mails.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_explorer-people.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_favorites.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_Games.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_Hide.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_hotbarcom.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_Hotmail.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_hsskin.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_jemster.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_jemsterie.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_jemsteruk.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_jobsearch.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_Mails.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_new.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_premium.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_reun.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_ringtones.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_SearchBoxTrapper.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_searchfor.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_searchgo.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_weather.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Default_yellowpages.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\editblbuttons.res
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\email-def-511724-548964.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\email-def-511724-9595.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\email-t1-bg.res
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\gamesmenu.cdf
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\gamesMenu.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\hb_ie_menu.res
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\hotbar-premium-hotbar-premium.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\hotbar-premium.cdf
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\hotbar_promo.htm
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\icons2.res
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\ie_games_icon.res
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\ie_video.res
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\keywords.idx
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\keywords1.dat
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\layout.cdf
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\linkpathlegal.txt
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\more.res
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\new_games.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\progress.res
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\s_icons_buttons.res
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\sales_buttons.res
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\sdfmodifier.xml
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\t2_bg.res
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\theweb.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\top7.cdf
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\Top7_theweb.mnu
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\tsd_bg.res
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\1\weathericon.res
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\ads.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\BtnTrans.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\BtnTrans1.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\business_promo.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\buttondir.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\cursors.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_buttons_1000.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_buttons_2000.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_buttons_3000.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_buttons_bar.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_buttons_bbar1.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_buttons_logos.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_buttons_other.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\d_icons_weather.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\default.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\editblbuttons.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\email-t1-bg.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\gamesmenu.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\hb_ie_menu.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\hotbar-premium.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\hotbar_promo.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\icons2.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\ie_games_icon.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\ie_video.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\keywords.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\keywords1.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\layout.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\linkpathlegal.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\more.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\progress.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\s_icons_buttons.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\sales_buttons.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\samplegroups2.txt
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\samplegroups2.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\sdfmodifier.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\t2_bg.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\top7.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\tsd_bg.xip
c:\documents and settings\ryan\Application Data\Hotbar\v3.5\Hotbar\static\DownLoad\weathericon.xip
c:\documents and settings\ryan\Application Data\Hotbar\Weather\history
c:\documents and settings\ryan\Application Data\Hotbar\Weather\Weather_XML\Default
c:\documents and settings\ryan\Application Data\Hotbar\Weather\Weather_XML\Genera1
c:\documents and settings\ryan\Application Data\Hotbar\Weather\Weather_XML\General
c:\documents and settings\ryan\Application Data\Hotbar\Weather\WeatherDPA\Links
c:\documents and settings\ryan\Application Data\Hotbar\Weather\WeatherDPA\radar-big.jpg
c:\documents and settings\ryan\Application Data\Hotbar\Weather\WeatherDPA\radar-small
c:\documents and settings\ryan\Application Data\Hotbar\Weather\WeatherDPA\satellite-big.jpg
c:\documents and settings\ryan\Application Data\Hotbar\Weather\WeatherDPA\satellite-small
c:\documents and settings\ryan\Application Data\Hotbar\Weather\WeatherDPA\Weather_XML\Display
c:\documents and settings\ryan\Application Data\Hotbar\Weather\WeatherDPA\Weather_XML\Loading
c:\documents and settings\ryan\Application Data\Hotbar\Weather\WeatherDPA\Weather_XML\screen2
c:\documents and settings\ryan\Application Data\Hotbar\Weather\WeatherDPA\WeatherPreferences
c:\documents and settings\ryan\Application Data\Hotbar\Weather\WeatherStartup.xml
c:\documents and settings\ryan\Application Data\WeatherDPA
c:\program files\Hotbar
c:\program files\Hotbar\bin\11.0.78.0\arrow.ico
c:\program files\Hotbar\bin\11.0.78.0\CntntCntr.dll
c:\program files\Hotbar\bin\11.0.78.0\copyright.txt
c:\program files\Hotbar\bin\11.0.78.0\CoreSrv.dll
c:\program files\Hotbar\bin\11.0.78.0\firefox\extensions\chrome.manifest
c:\program files\Hotbar\bin\11.0.78.0\firefox\extensions\components\npclntax.xpt
c:\program files\Hotbar\bin\11.0.78.0\firefox\extensions\install.rdf
c:\program files\Hotbar\bin\11.0.78.0\firefox\extensions\plugins\npclntax_HotbarSA.dll
c:\program files\Hotbar\bin\11.0.78.0\HostIE.dll
c:\program files\Hotbar\bin\11.0.78.0\HostOL.dll
c:\program files\Hotbar\bin\11.0.78.0\HotbarSA.exe
c:\program files\Hotbar\bin\11.0.78.0\HotbarSAAX.dll
c:\program files\Hotbar\bin\11.0.78.0\HotbarSADF.exe
c:\program files\Hotbar\bin\11.0.78.0\HotbarSAHook.dll
c:\program files\Hotbar\bin\11.0.78.0\HotbarUninstaller.exe
c:\program files\Hotbar\bin\11.0.78.0\Srv.exe
c:\program files\Hotbar\bin\11.0.78.0\Toolbar.dll
c:\program files\Hotbar\bin\11.0.78.0\Weather.exe
c:\program files\Hotbar\bin\11.0.78.0\WeSkin.dll
c:\windows\Downloaded Program Files\poPCaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf

.
((((((((((((((((((((((((( Files Created from 2009-12-02 to 2010-01-02 )))))))))))))))))))))))))))))))
.

2009-12-28 07:50 . 2009-12-28 07:51 -------- d-----w- c:\program files\TuneUpMedia
2009-12-28 07:50 . 2010-01-01 22:13 -------- d-----w- c:\documents and settings\ryan\Application Data\TuneUpMedia
2009-12-28 07:50 . 2009-12-28 07:51 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUpMedia
2009-12-28 07:49 . 2009-12-28 07:49 -------- d-----w- c:\documents and settings\ryan\Application Data\Hotbar_Icons
2009-12-28 07:49 . 2009-12-28 07:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Azureus
2009-12-28 07:49 . 2009-12-28 08:18 -------- d-----w- c:\documents and settings\ryan\Application Data\Azureus
2009-12-28 07:48 . 2009-12-28 07:52 -------- d-----w- c:\program files\Vuze
2009-12-28 07:47 . 2009-12-28 07:49 -------- d-----w- c:\documents and settings\All Users\Application Data\HotbarSA

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-28 07:51 . 2009-03-29 16:40 -------- d-----w- c:\program files\iTunes
2009-12-24 15:54 . 2008-04-05 04:04 -------- d-----w- c:\documents and settings\ryan\Application Data\Apple Computer
2009-12-02 07:15 . 2009-12-02 07:15 -------- d-----w- c:\program files\Common Files\NSV
2009-12-02 07:14 . 2009-12-02 07:14 -------- d-----w- c:\program files\Common Files\Nullsoft
2009-11-24 23:54 . 2009-01-14 05:59 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2009-01-14 05:59 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:50 . 2009-01-14 05:59 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-24 23:50 . 2009-01-14 05:59 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2009-01-14 05:59 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2009-01-14 05:59 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-01-14 05:59 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-01-14 05:59 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2009-01-14 05:59 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-14 10:50 . 2008-01-28 05:54 -------- d-----w- c:\documents and settings\ryan\Application Data\eBookPro6
2009-11-12 06:37 . 2007-07-09 06:02 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-05 00:23 . 2009-03-29 16:08 -------- d-----w- c:\program files\Bonjour
2009-11-03 10:11 . 2009-11-03 10:11 152576 ----a-w- c:\documents and settings\ryan\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-11-03 09:51 . 2007-05-29 00:44 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-17 03:34 . 2008-03-08 07:58 147616 -c--a-w- c:\windows\hpoins21.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-10-30 02:55 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-10-30 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-10-30 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HTpatch"="c:\windows\htpatch.exe" [2002-10-30 28672]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-05 53248]
"masqform.exe"="c:\program files\PureEdge\Viewer 6.0\masqform.exe" [2003-12-03 1052672]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2008-10-09 333120]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-10-03 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"SiSPower"="SiSPower.dll" [2006-03-09 49152]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]

c:\documents and settings\ryan\Start Menu\Programs\Startup\
RCA Detective.lnk - c:\documents and settings\ryan\My Documents\RCA Detective\RCADetective.exe [2009-4-6 1069056]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Utility Tray.lnk - c:\windows\system32\sistray.exe [2007-5-28 262144]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [1/13/2009 11:59 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [1/13/2009 11:59 PM 20560]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2009-12-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://catatwork.cat.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} - hxxp://www.hoppy.com/sacramento/cams/vatdec.cab
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Easy Dock - (no file)
MSConfigStartUp-CTFMON - (no file)
AddRemove-{242B78B1-956B-4304-9104-F1619BE694C8} - c:\program files\InstallShield Installation Information\{242B78B1-956B-4304-9104-F1619BE694C8}\setup.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-01 21:33
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IE40.BrowseUI\RegBackup]
@DACL=(02 0000)

[HKEY_LOCAL_MACHINE\software\swearware\backup\winsock2]
@DACL=(02 0000)
@SACL=
.
Completion time: 2010-01-01 21:37:49
ComboFix-quarantined-files.txt 2010-01-02 03:37
ComboFix2.txt 2009-01-07 07:05
ComboFix3.txt 2008-12-31 22:19
ComboFix4.txt 2008-02-08 06:48
ComboFix5.txt 2010-01-02 03:24

Pre-Run: 58,051,928,064 bytes free
Post-Run: 58,058,645,504 bytes free

- - End Of File - - 26A417910F8F72CB3F453ADCF203356F
A+, Network+, MCP
wintacs
Geek
Geek
 
Posts: 34
Joined: Thu Apr 05, 2007 12:43 am

Thanks given:0
Thanks received:0
Top

Re: Please check.

Postby Gecko » Sat Jan 02, 2010 12:40 pm

wintacs,

Wow it was infected!
It looks like combofix got everything.

So how is it running now?
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: Please check.

Postby wintacs » Sat Jan 02, 2010 7:20 pm

Much better now. I downloaded Vuze, and then tried to get a new movie. I knew better but still tried it. Thanks again, you guys are the best.
A+, Network+, MCP
wintacs
Geek
Geek
 
Posts: 34
Joined: Thu Apr 05, 2007 12:43 am

Thanks given:0
Thanks received:0
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 1 guest

cron