Spyware.Ispynow Hijackthis log and uninstall log included. Please help

View previous topic View next topic Go down

Solved Spyware.Ispynow Hijackthis log and uninstall log included. Please help

Post by Elcskater on Mon Dec 01, 2008 3:52 pm

I'm having some trouble with Spyware.Ispynow on my computer, It started last night when I was just using AIM, I was typing and then suddenly my computer began to close out apps and continued to restart itself. When it came back to desktop my internet explorer would not work. It would play an error sound and pop up a message from Windows Internet Explorer saying "Cannot find "http://go.mircosoft.com/fwlink/?LinkId=74005'. Make sure the path or internet address is correct." I was able to get firefox to work in safe mode allowing me to search around for awhile and now here i am. I also found a site suggesting to use Malwarebytes' Anti-Malware program, first time i tried downloading it my pc restarted again like it did last night, second time i was able to finish the download and install the program but it seems like it will not run. Any help would be appreciated.

Here is my Hijackthis log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:42:19 PM, on 12/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\WINDOWS\system32\fppsys.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Documents and Settings\Eric\Desktop\inane.exe
C:\DOCUME~1\Eric\LOCALS~1\Temp\is-TM7CQ.tmp\inane.tmp
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Eric\Desktop\Hijack(GP)This.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Warning: do not remove it! (system)] fppsys.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [appdscapl] C:\WINDOWS\system32\lmzstafm.exe
O4 - HKCU\..\Run: [LaunchList] C:\Program Files\Pinnacle\Studio 11\LaunchList2.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - [You must be registered and logged in to see this link.]
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - [You must be registered and logged in to see this link.]
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - [You must be registered and logged in to see this link.]
O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - [You must be registered and logged in to see this link.]
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - [You must be registered and logged in to see this link.]
O20 - AppInit_DLLs: karna.dat
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: geBsqRlm - geBsqRlm.dll (file missing)
O20 - Winlogon Notify: pmnoPiHA - pmnoPiHA.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 9300 bytes

Elcskater
Novice
Novice

Posts Posts : 11
Joined Joined : 2008-12-01
OS OS : windows xp
Points Points : 29320
# Likes # Likes : 0

View user profile

Back to top Go down

Solved Re: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

Post by Elcskater on Mon Dec 01, 2008 3:52 pm

Here is the uninstall Log

7-Zip 4.58 beta
Ad-Aware
Adobe Common File Installer
Adobe Flash Player ActiveX
Adobe Help Center 1.0
Adobe Photoshop 7.0
Adobe Photoshop CS2
Adobe Reader 8.1.2
Adobe Shockwave Player
Adobe Stock Photos 1.0
AIM 6
AOL Instant Messenger
Apple Software Update
ArcSoft MediaImpression
ArcSoft PhotoImpression
AxCrypt (Remove Only)
Azureus Vuze
Command & Conquer 3
Command & Conquer The First Decade
ConvertXtoDVD 2.2.2.256
Creative System Information
DAEMON Tools
Diablo II
DivX
DivX Content Uploader
DivX Converter
DivX Converter
DivX Player
DivX Web Player
Download Updater (AOL LLC)
EPSON Copy Utility
EPSON Photo Print
EPSON Scanner Reference Guide
EPSON Smart Panel
EPSON TWAIN 5
ESET Online Scanner
Final Fantasy VII - Ultima Edition
FINAL FANTASY XI
FINAL FANTASY XI: Chains of Promathia
FINAL FANTASY XI: Rise of the Zilart
FINAL FANTASY XI: Treasures of Aht Urhgan
FINAL FANTASY XI: Wings of the Goddess
Folder Password Protect 2.7
Fraps (remove only)
Google Earth
Hamachi 0.9.9.9
HijackThis 2.0.2
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
HP Imaging Device Functions 7.0
HP Photosmart and Deskjet 7.0 Software
ijji - Gunz
ijji Auto Installer
iWheelWorks 7.72
J2SE Runtime Environment 5.0 Update 11
LG USB Drivers
LimeWire 4.18.8
Lock Folder XP 3.6
Logitech QuickCam
Logitech QuickCam Driver Package
Magic ISO Maker v5.5 (build 0272)
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Silverlight
Microsoft Text-to-Speech Engine 4.0 (English)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (2.0.0.12)
MSN Music Assistant
MSXML 4.0 SP2 Parser and SDK
MSXML4 Parser
NASA World Wind 1.4
Nero 7 Essentials
NVIDIA Drivers
Oblivion
OpenMG Limited Patch 4.1-05-13-31-01
OpenMG Secure Module 4.1.00
Paint Shop Pro 7 ESD
Pinnacle Hollywood FX for Studio
Pinnacle Instant DVD Recorder
Pinnacle Studio LINX
Pinnacle USB device drivers
PlayOnline Viewer & Tetra Master
PowerDVD
QuickTime
RTPatch Update
ScanToWeb
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Skype 2.0
Solid State ION Internet Explorer Plugin
SonicStage 3.0
Sound Blaster Live!
SoundMAX
Spyware Doctor 6.0
Studio 11
Studio 9
SUPERAntiSpyware Free Edition
TeamSpeak 2 RC2
The Rosetta Stone
TomTom HOME
Tweakui Powertoy for Windows XP
Universal SCSI Controller
upapp
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB936357)
VC_MergeModuleToMSI
Ventrilo Client
VideoLAN VLC media player 0.8.1
Viewpoint Manager (Remove Only)
Viewpoint Media Player
Virtual Desktop Manager Powertoy for Windows XP
WD Diagnostics
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Messenger
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
WinPcap 3.1
WinRAR archiver
Yahoo! Desktop Login
ZoneAlarm
ZoneAlarm Spy Blocker

Elcskater
Novice
Novice

Posts Posts : 11
Joined Joined : 2008-12-01
OS OS : windows xp
Points Points : 29320
# Likes # Likes : 0

View user profile

Back to top Go down

Solved Re: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

Post by Belahzur on Mon Dec 01, 2008 3:56 pm

Hello.


  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
    O4 - HKLM\..\Run: [Warning: do not remove it! (system)] fppsys.exe
    O4 - HKCU\..\Run: [appdscapl] C:\WINDOWS\system32\lmzstafm.exe
    O20 - AppInit_DLLs: karna.dat
    O20 - Winlogon Notify: geBsqRlm - geBsqRlm.dll (file missing)
    O20 - Winlogon Notify: pmnoPiHA - pmnoPiHA.dll (file missing)


  • Press "Fix Checked"
  • Close Hijack This.


Delete these files in bold:
C:\windows\system32\fppsys.exe
C:\windows\system32\lmzstafm.exe
C:\windows\system32\karna.dat



  • Download combofix from here, use the top links - [You must be registered and logged in to see this link.]
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.



  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will this next prompt that asks if you want to continue the malware scan, select yes



  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245121
# Likes # Likes : 1

View user profile

Back to top Go down

Solved Re: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

Post by Elcskater on Mon Dec 01, 2008 4:32 pm

Combofix logfile.

ComboFix 08-12-01.01 - Eric 2008-12-01 16:14:40.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.721 [GMT -6:00]
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Eric\Application Data\DOBE~1
c:\documents and settings\Eric\Application Data\google\runhh6110411.exe
c:\documents and settings\Eric\Application Data\inst.exe
c:\documents and settings\Eric\Application Data\SKS~1
c:\documents and settings\Eric\nah_yyja.exe
c:\program files\Common Files\{7B5DF~1
c:\temp\vtmp2
c:\windows\a.bat
c:\windows\base64.tmp
c:\windows\bdn.com
c:\windows\Downloaded Program Files\setup.inf
c:\windows\FVProtect.exe
c:\windows\IE4 Error Log.txt
c:\windows\iTunesMusic.exe
c:\windows\mbols~1
c:\windows\mcroso~1.net
c:\windows\mcroso~1.net\M?crosoft.NET\
c:\windows\mslagent
c:\windows\mssecu.exe
c:\windows\system32\akttzn.exe
c:\windows\system32\anticipator.dll
c:\windows\system32\awtoolb.dll
c:\windows\system32\bdn.com
c:\windows\system32\dpcproxy.exe
c:\windows\system32\drivers\npf.sys
c:\windows\system32\drivers\TDSSrfdc.sys
c:\windows\system32\fnts~1
c:\windows\system32\h@tkeysh@@k.dll
c:\windows\system32\hoproxy.dll
c:\windows\system32\hxiwlgpm.dat
c:\windows\system32\hxiwlgpm.exe
c:\windows\system32\IiSYJRqr.ini
c:\windows\system32\IiSYJRqr.ini2
c:\windows\system32\msgp.exe
c:\windows\system32\mssecu.exe
c:\windows\system32\mtr2.exe
c:\windows\system32\mwin32.exe
c:\windows\system32\netode.exe
c:\windows\system32\newsd32.exe
c:\windows\system32\packet.dll
c:\windows\system32\ppqss.ini2
c:\windows\system32\ps1.exe
c:\windows\system32\psoft1.exe
c:\windows\system32\pthreadVC.dll
c:\windows\system32\pYFOnnmp.ini
c:\windows\system32\pYFOnnmp.ini2
c:\windows\system32\regm64.dll
c:\windows\system32\Rundl1.exe
c:\windows\system32\smp
c:\windows\system32\smp\msrc.exe
c:\windows\system32\ssvchost.exe
c:\windows\system32\sysreq.exe
c:\windows\system32\taack.dat
c:\windows\system32\taack.exe
c:\windows\system32\TDSSblat.dat
c:\windows\system32\TDSSdlpb.dll
c:\windows\system32\TDSSkfkl.dll
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSottp.dll
c:\windows\system32\TDSSqogd.log
c:\windows\system32\TDSSqshc.dll
c:\windows\system32\TDSSshbe.log
c:\windows\system32\TDSSurev.dll
c:\windows\system32\TDSSxnyq.dll
c:\windows\system32\temp#01.exe
c:\windows\system32\UuFgfMoq.ini
c:\windows\system32\UuFgfMoq.ini2
c:\windows\system32\VBIEWER.OCX
c:\windows\system32\wanpacket.dll
c:\windows\system32\winlogonpc.exe
c:\windows\system32\winsystem.exe
c:\windows\system32\WINWGPX.EXE
c:\windows\system32\wpcap.dll
c:\windows\userconfig9x.dll
c:\windows\zip1.tmp
c:\windows\zip2.tmp
c:\windows\zip3.tmp
c:\windows\zipped.tmp

Infected copy of c:\windows\system32\winlogon.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\winlogon.exe


.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_TDSSSERV.SYS
-------\Legacy_TDSSSERV.SYS
-------\Service_NPF


((((((((((((((((((((((((( Files Created from 2008-11-01 to 2008-12-01 )))))))))))))))))))))))))))))))
.

2008-12-01 15:07 . 2008-12-01 16:23 d-------- C:\-Combo-Fix-
2008-12-01 14:03 . 2008-12-01 14:32 d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-01 14:03 . 2008-12-01 14:03 d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-01 14:03 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-01 14:03 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-01 01:07 . 2008-12-01 16:21 54,156 --ah----- c:\windows\QTFont.qfn
2008-12-01 01:07 . 2008-12-01 16:12 1,409 --a------ c:\windows\QTFont.for
2008-11-23 20:36 . 2008-11-23 20:36 d-------- c:\program files\Common Files\Software Update Utility
2008-11-23 20:36 . 2008-11-23 20:36 d-------- c:\documents and settings\All Users\Application Data\acccore
2008-11-23 05:46 . 2008-11-23 05:47 d-------- c:\documents and settings\Eric\Application Data\Move Networks
2008-11-15 03:59 . 2008-11-15 03:59 d-------- c:\program files\Microsoft Silverlight

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-01 22:21 0 ----a-w c:\windows\system32\drivers\logiflt.iad
2008-12-01 22:19 502,272 ----a-w c:\windows\system32\winlogon.exe
2008-12-01 21:06 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-01 07:49 0 ----a-w c:\windows\system32\drivers\lvuvc.hs
2008-12-01 07:00 --------- d-----w c:\program files\Spyware Doctor
2008-12-01 05:17 44,312 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-01 05:17 3,600,416 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\ArcSoft
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\Ahead
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\AdobeUM
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\Acreon
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\acccore
2008-12-01 05:12 295,424 ----a-w c:\windows\system32\termsrv.dll
2008-11-27 11:33 --------- d-----w c:\documents and settings\Eric\Application Data\LimeWire
2008-11-24 04:06 --------- d-----w c:\documents and settings\Eric\Application Data\Azureus
2008-11-24 02:36 --------- d-----w c:\program files\Viewpoint
2008-11-24 02:36 --------- d-----w c:\program files\AIM6
2008-11-24 02:36 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2008-11-24 02:35 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2008-11-24 02:34 --------- d-----w c:\documents and settings\All Users\Application Data\AOL Downloads
2008-11-21 16:43 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-27 12:46 2,918,912 ----a-w c:\windows\Internet Logs\xDB2.tmp
2008-10-27 12:46 1,392,640 ----a-w c:\windows\Internet Logs\xDB3.tmp
2008-10-25 04:45 --------- d-----w c:\documents and settings\Eric\Application Data\Vso
2008-10-25 02:23 --------- d-----w c:\program files\LimeWire
2008-10-24 09:42 --------- d-----w c:\program files\Everstrike Software
2008-10-24 09:42 --------- d-----w c:\program files\Common Files\Everstrike Software
2008-10-24 09:38 --------- d-----w c:\program files\Folder Password Protect
2008-10-23 00:15 --------- d-----w c:\program files\Axon Data
2008-10-22 00:49 --------- d-----w c:\documents and settings\All Users\Application Data\Pinnacle Studio
2008-10-22 00:49 --------- d-----w c:\documents and settings\All Users\Application Data\Pinnacle
2008-10-22 00:44 --------- d-----w c:\program files\Pinnacle
2008-10-22 00:24 --------- d-----w c:\documents and settings\Eric\Application Data\InstallShield
2008-10-21 22:25 --------- d-----w c:\program files\MagicISO
2008-10-19 21:57 --------- d-----w c:\program files\Ventrilo
2008-10-19 21:57 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-10-17 21:27 2,946,048 ----a-w c:\windows\Internet Logs\xDB1.tmp
2008-10-14 03:58 --------- d-----w c:\program files\SUPERAntiSpyware
2008-10-14 03:55 --------- d-----w c:\program files\ZoneAlarmSB
2008-10-14 03:51 --------- d-----w c:\documents and settings\All Users\Application Data\MailFrontier
2008-10-14 03:50 --------- d-----w c:\program files\Zone Labs
2008-10-13 08:36 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2008-10-13 08:34 --------- d-----w c:\program files\Lavasoft
2008-10-13 08:19 --------- d-----w c:\documents and settings\Eric\Application Data\Lavasoft
2008-10-13 05:56 --------- d-----w c:\program files\AML Products
2008-10-13 04:53 --------- d-----w c:\program files\StreamCast
2008-10-13 03:44 --------- d-----w c:\documents and settings\Eric\Application Data\PC Tools
2008-10-13 03:11 --------- d-----w c:\program files\Microsoft AntiSpyware
2008-10-13 02:39 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-12 23:01 --------- d-----w c:\documents and settings\All Users\Application Data\AntiVir PersonalEdition classic
2008-10-12 22:07 --------- d-----w c:\program files\fhuuifg
2008-10-12 22:07 --------- d-----w c:\documents and settings\All Users\Application Data\pkbwfgrq
2008-10-09 00:20 --------- d-----w c:\program files\Morpheus
2008-10-04 02:44 --------- d-----w c:\documents and settings\Eric\Application Data\dvdcss
2007-06-20 07:45 47,360 -c--a-w c:\documents and settings\Eric\Application Data\pcouffin.sys
2004-06-03 00:01 121,344 --sha-w c:\windows\system32\fppsys.exe
.

Continued...

Elcskater
Novice
Novice

Posts Posts : 11
Joined Joined : 2008-12-01
OS OS : windows xp
Points Points : 29320
# Likes # Likes : 0

View user profile

Back to top Go down

Solved Re: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

Post by Elcskater on Mon Dec 01, 2008 4:32 pm

------- Sigcheck -------

2008-11-30 23:12 295424 40ffc19a8d4875e9e19cecdc76ef9201 c:\windows\system32\termsrv.dll
2004-08-04 06:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\system32\dllcache\termsrv.dll
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 442,368 2008-10-02 04:06:05 c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_10_1.db

----a-w 471,040 2008-10-11 03:25:46 c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_10_10.db

----a-w 471,040 2008-10-11 03:25:46 c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_10_12.db

----a-w 471,040 2008-10-25 04:22:46 c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_10_24.db

----a-w 471,040 2008-10-27 04:00:19 c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_10_26.db

----a-w 471,040 2008-11-23 19:13:20 c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_11_23.db

----a-w 413,696 2008-09-28 19:19:19 c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_9_28.db

----a-w 147,456 2006-04-13 03:44:48 c:\program files\A4Tech\Mouse\bak\Amoumain.exe

----a-w 585,728 2003-05-30 16:42:22 c:\program files\Analog Devices\SoundMAX\bak\Smax4.exe

----a-w 790,528 2003-05-29 23:28:32 c:\program files\Analog Devices\SoundMAX\bak\SMax4PNP.exe

-c--a-w 262,184 2007-01-13 22:46:02 c:\program files\AntiVir PersonalEdition Classic\bak\avgnt.exe

----a-w 81,920 2004-06-15 00:18:22 c:\program files\Common Files\InstallShield\UpdateService\bak\issch.exe

----a-w 28,672 2001-11-29 08:00:00 c:\program files\Creative\SBLive\Program\bak\ADGJDet.exe
----a-w 28,672 2001-11-29 07:00:00 c:\program files\Creative\SBLive\Program\ADGJDet.exe

----a-w 30,208 2005-12-08 06:57:00 c:\program files\CyberLink\PowerDVD\bak\PDVDServ.exe

----a-w 49,152 2006-05-18 19:29:00 c:\program files\CyberLink\PowerDVD\Language\bak\Language.exe

-c--a-w 473,928 2005-11-15 20:12:14 c:\program files\Microsoft AntiSpyware\bak\gcasServ.exe

----a-w 397,312 2005-07-22 01:03:24 c:\program files\SMCWUSBT-G EZ Connect TM g 108 Mbps 802.11g Wireless USB 2.0 Adapter\bak\ACU.exe

-c--a-w 111,816 2004-11-11 04:15:31 c:\program files\Viewpoint\Viewpoint Manager\bak\ViewMgr.exe

-c--a-w 1,580,032 2005-01-29 01:34:58 c:\program files\WebSTAR\WLAN Card Utilities\bak\Center.exe

----a-w 90,112 2000-05-11 08:00:00 c:\windows\bak\UpdReg.EXE

----a-w 155,648 2001-07-09 18:50:42 c:\windows\system32\bak\NeroCheck.exe

-c--a-w 406,016 2004-03-10 23:26:10 c:\windows\system32\bak\PSDrvCheck.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-10-13 1576176]
"LaunchList"="c:\program files\Pinnacle\Studio 11\LaunchList2.exe" [2007-03-21 145496]
"Aim6"="" [N/A]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-04-01 5562368]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-04-01 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-08-18 77824]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 75520]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 564496]
"Jet Detection"="c:\program files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 28672]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-11-20 178688]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"Tweak UI"="TWEAKUI.CPL" [2000-06-18 c:\windows\system32\TWEAKUI.CPL]
"pdfSaver3"="" [N/A]
"CTHelper"="CTHELPER.EXE" [2003-08-28 c:\windows\system32\CTHELPER.EXE]
"nwiz"="nwiz.exe" [2005-04-01 c:\windows\system32\nwiz.exe]
"NWEReboot"="" [N/A]
"LFAgent"="" [N/A]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-27 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-10-13 21:58 352256 c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= vdrcodec.dll
"VIDC.MJPG"= Pvmjpg30.dll
"VIDC.PIM1"= pclepim1.dll
"VIDC.PIXL"= pclepixl.dll
"VIDC.NTN1"= Nuvision.ax
"msacm.ctmp3"= c:\windows\system32\ctmp3.acm
"VIDC.MJPX"= PICVideo MJPEG Codec

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AresChatServer"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Morpheus\\Morpheus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\PlayOnline\\SquareEnix\\PlayOnlineViewer\\pol.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\umi.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"27693:TCP"= 27693:TCP:SolidNetworkManager
"27693:UDP"= 27693:UDP:SolidNetworkManager
"32397:TCP"= 32397:TCP:*:Disabled:SolidNetworkManager
"32397:UDP"= 32397:UDP:*:Disabled:SolidNetworkManager

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)

R1 SSHDRV65;SSHDRV65;\??\c:\windows\system32\drivers\SSHDRV65.sys [2005-06-15 120320]
R1 SSHDRV85;SSHDRV85;\??\c:\windows\system32\drivers\SSHDRV85.sys [2002-01-02 78848]
R2 ACDaemon;ArcSoft Connect Daemon;c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2008-09-23 109056]
R2 LF30FS;LF30FS;\??\c:\program files\Everstrike Software\Lock Folder XP 3.6\LF30XP.sys [2004-11-19 101488]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2008-11-23 24652]
R3 LVRS;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs.sys [2008-07-12 628760]
R3 uscbs109;uscbs109;c:\windows\system32\DRIVERS\uscbs109.sys [2005-12-05 8672]
R3 uscsc109;uscsc109;c:\windows\system32\DRIVERS\uscsc109.sys [2005-12-05 102336]
S2 VRDVC20;Sony VRD-VC20 [Video Capture];c:\windows\system32\Drivers\VRDVC20X.SYS [2006-02-14 02:25:02 31104]
S3 AR5523;Atheros USB Wireless Network Adapter Service;c:\windows\system32\DRIVERS\ar5523.sys []
S3 asbp2poa;asbp2poa; []
S3 ASNDIS5;ASNDIS5 Protocol Driver;\??\c:\windows\system32\ASNDIS5.SYS [2007-01-13 16269]
S3 ATHFMWDL;Atheros USB Wireless Adapter Bootloader driver;c:\windows\system32\Drivers\ATHFMWDL.sys []
S3 NUVision;Pinnacle LINX;c:\windows\system32\DRIVERS\NUVision.sys [2006-09-19 136352]
S3 SjyPkt;SjyPkt;\??\c:\windows\System32\Drivers\SjyPkt.sys [2007-05-10 13532]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{17906ce3-fe56-11d5-99a5-806d6172696f}]
\Shell\AutoRun\command - rundll32.exe url.dll,FileProtocolHandler START.HTM
.
Contents of the 'Scheduled Tasks' folder

2008-09-30 c:\windows\Tasks\Best.job
- c:\documents and settings\Eric\Desktop\Shrek_1_and_2_dvd_rip_s_eng_XviD.torrent []

2008-11-30 c:\windows\Tasks\friday.job
- c:\documents and settings\Eric\My Documents\My Music\My Playlists\Country.wpl [2008-10-01 17:24]

2008-12-01 c:\windows\Tasks\one.job
- c:\documents and settings\Eric\My Documents\My Music\My Playlists\Now.wpl [2008-09-13 19:27]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Eric\Application Data\Mozilla\Firefox\Profiles\5t724z67.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - [You must be registered and logged in to see this link.]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2008-12-01 16:21:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(892)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ZoneLabs\vsmon.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\MsPMSPSv.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\msiexec.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2008-12-01 16:28:01 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-01 22:27:51

Pre-Run: 51,267,923,968 bytes free
Post-Run: 51,440,910,336 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

358 --- E O F --- 2007-08-26 06:47:50

Elcskater
Novice
Novice

Posts Posts : 11
Joined Joined : 2008-12-01
OS OS : windows xp
Points Points : 29320
# Likes # Likes : 0

View user profile

Back to top Go down

Solved Re: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

Post by Belahzur on Mon Dec 01, 2008 4:43 pm

Hello.
A few leftovers to get.

Now open a new notepad file.
Input this into the notepad file:

File::
c:\windows\Internet Logs\xDB3.tmp
c:\windows\Internet Logs\xDB2.tmp
c:\windows\Internet Logs\xDB1.tmp
c:\windows\system32\fppsys.exe

Folder::
c:\program files\Viewpoint
c:\documents and settings\All Users\Application Data\Viewpoint

DirLook::
c:\program files\fhuuifg

AWF::
c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_10_1.db
c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_10_10.db
c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_10_12.db
c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_10_24.db
c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_10_26.db
c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_11_23.db
c:\documents and settings\Eric\Application Data\ArcSoft\Rocket Data\bak\bak_2008_9_28.db
c:\program files\A4Tech\Mouse\bak\Amoumain.exe
c:\program files\Analog Devices\SoundMAX\bak\Smax4.exe
c:\program files\Analog Devices\SoundMAX\bak\SMax4PNP.exe
C:\program files\AntiVir PersonalEdition Classic\bak\avgnt.exe
c:\program files\Common Files\InstallShield\UpdateService\bak\issch.exe
c:\program files\Creative\SBLive\Program\bak\ADGJDet.exe
c:\program files\CyberLink\PowerDVD\bak\PDVDServ.exe
c:\program files\CyberLink\PowerDVD\Language\bak\Language.exe
c:\program files\Microsoft AntiSpyware\bak\gcasServ.exe
c:\program files\SMCWUSBT-G EZ Connect TM g 108 Mbps 802.11g Wireless USB 2.0 Adapter\bak\ACU.exe
c:\program files\Viewpoint\Viewpoint Manager\bak\ViewMgr.exe
c:\program files\WebSTAR\WLAN Card Utilities\bak\Center.exe
c:\windows\bak\UpdReg.EXE
c:\windows\system32\bak\NeroCheck.exe
c:\windows\system32\bak\PSDrvCheck.exe

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{17906ce3-fe56-11d5-99a5-806d6172696f}]

Save this as CFScript.txt, save it to your desktop also.
Then drag and drop CFScript.txt into combofix as seen below:


This will open combofix.exe again, agree to it's terms and allow it to run, it may want to reboot after it's done. Post the resulting log back here.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245121
# Likes # Likes : 1

View user profile

Back to top Go down

Solved Re: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

Post by Elcskater on Mon Dec 01, 2008 4:57 pm

Alright, I did that. Here is the log report.

ComboFix 08-12-01.01 - Eric 2008-12-01 16:50:40.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.637 [GMT -6:00]
Running from: c:\documents and settings\Eric\Desktop\-Combo-Fix-.exe
Command switches used :: c:\documents and settings\Eric\Desktop\CFscript.txt
* Created a new restore point

FILE ::
c:\windows\Internet Logs\xDB1.tmp
c:\windows\Internet Logs\xDB2.tmp
c:\windows\Internet Logs\xDB3.tmp
c:\windows\system32\fppsys.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Viewpoint
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\config.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\1370BA437EF5D05D058A24D054D8F5229852A4F4.dat
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\25E530C0266043F06DDBF19083992C55D506A67D.dat
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\38CBCADAB1DF0A74CD37BD40BFF0C3F43CC0E15A.dat
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\5A5581E621F635409ED9BD1E1DB0228DD928E72D.dat
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\5D77D966848120E827ECF25D743E9AEA6B68CC1D.dat
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\85344854BEDF85C7E9F0C8F7AB68C9DF167143AA.dat
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\ABBD43425986400A6FE8F86615469618A73E28D6.dat
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\cache.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\Cache\D1A57250C5C318DC64EB161B38082AB72920FFF4.dat
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\history.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\locate-akamai.mtx
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\locate.mtz
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\policy-akamai.mtx
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\ServicesRegistry.xml
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\updates-akamai.mtx
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Manager\vdt.dat
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\ComponentRegistry.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\DownLoadHist.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\HostRegistry.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\MetaStreamConfig.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\MetaStreamID.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\MTSDownloadSites.txt
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_00\-205313940.mtj&p2=1&p3=05924506146770111252716023524557&p4=50335505
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_00\-469794846.mtz
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_00\1808705174.swf
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_00\URLCache.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_01\-1930728742.swf
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_01\URLCache.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02\-417622574.mts
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02\1143604292.swf
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02\1478937782.mtj&p2=0&p3=05924506146770111252716023524557&p4=0
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02\243401297.swf
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02\407034558.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_02\URLCache.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_03\-1670706830.mtj&p2=0&p3=05924506146770111252716023524557&p4=0
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_03\1888168788.swf
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\ResourceFolder_03\URLCache.ini
c:\documents and settings\All Users\Application Data\Viewpoint\Viewpoint Media Player\Resources\UpdateVersionList_v2.mtx
c:\program files\Viewpoint
c:\program files\Viewpoint\Common\ViewpointService.exe
c:\program files\Viewpoint\Common\VistaBoot.sdll
c:\program files\Viewpoint\Viewpoint Experience Technology\AxMetaStream.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\ClassIDs.ini
c:\program files\Viewpoint\Viewpoint Experience Technology\ComponentMgr.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\ComponentMgr_0305001C.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\ComponentRegistry.ini
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\AOLArt.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\AOLShell.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\AOLUserShell.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\Cursors.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\DataTracking.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\GifReader.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\LensFlares.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\MTS3Reader.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\ObjectMovie.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\SceneComponent.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\ServiceComponent.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\SreeDMMX.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\SWFView.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VectorView.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPAudio.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPExtras.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPSpeech.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPVideo.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPVideo2.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\WaveletReader.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\ZoomView.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\DownloadedComponents\SWFView_Win.mtj
c:\program files\Viewpoint\Viewpoint Experience Technology\DownLoadHist.ini
c:\program files\Viewpoint\Viewpoint Experience Technology\HostRegistry.ini
c:\program files\Viewpoint\Viewpoint Experience Technology\MetaStreamID.ini
c:\program files\Viewpoint\Viewpoint Experience Technology\MtsAxInstaller.exe
c:\program files\Viewpoint\Viewpoint Experience Technology\MTSDownloadSites.txt
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\AOLUserShell.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\Cursors.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\JpegReader.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\Mts3Reader.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\SceneComponent.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\SreeDMMX.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\SWFView.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\VETscriptInterpreter.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\VMPSpeech.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\VMPVideo2.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.xpt
c:\program files\Viewpoint\Viewpoint Manager\VETscriptInterpreter.dll
c:\program files\Viewpoint\Viewpoint Manager\ViewCP.cpl
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\s.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_av.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_cp.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_up.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_inner_bg.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_inner_bottom.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab_bg.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab1_off.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab1_on.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab2_off.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab2_on.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vwpt_logo.gif
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\options.ini
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\viewpoint.ico
c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\vmctrl.html
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgrCore.dll
c:\program files\Viewpoint\Viewpoint Manager\ViewMgrInstaller.exe
c:\program files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll
c:\program files\Viewpoint\Viewpoint Media Player\AxMetaStream_.dll
c:\program files\Viewpoint\Viewpoint Media Player\AxMetaStream_0302021C.dll
c:\program files\Viewpoint\Viewpoint Media Player\AxMetaStream_0302021C_.dll
c:\program files\Viewpoint\Viewpoint Media Player\AxMetaStream_0305000D.dll
c:\program files\Viewpoint\Viewpoint Media Player\ClassIDs.ini
c:\program files\Viewpoint\Viewpoint Media Player\ComponentMgr_0305000D.dll
c:\program files\Viewpoint\Viewpoint Media Player\ComponentRegistry.ini
c:\program files\Viewpoint\Viewpoint Media Player\Components\AOLUserShell.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\Cursors.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\JpegReader.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\Mts3Reader.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\SceneComponent.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\SreeDMMX.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\SWFView.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VMgr.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VMPSpeech.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VMPVideo.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VMPVideo2.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\WaveletReader.dll
c:\program files\Viewpoint\Viewpoint Media Player\DownLoadHist.ini
c:\program files\Viewpoint\Viewpoint Media Player\HostRegistry.ini
c:\program files\Viewpoint\Viewpoint Media Player\MetaStreamConfig.ini
c:\program files\Viewpoint\Viewpoint Media Player\MetaStreamID.ini
c:\program files\Viewpoint\Viewpoint Media Player\MtsAxInstaller.exe
c:\program files\Viewpoint\Viewpoint Media Player\MTSDownloadSites.txt
c:\windows\Internet Logs\xDB1.tmp
c:\windows\Internet Logs\xDB2.tmp
c:\windows\Internet Logs\xDB3.tmp
c:\windows\system32\fppsys.exe

.
((((((((((((((((((((((((( Files Created from 2008-11-01 to 2008-12-01 )))))))))))))))))))))))))))))))
.

2008-12-01 16:49 . 2008-12-01 16:53 d-------- C:\-Combo-Fix-
2008-12-01 14:03 . 2008-12-01 14:32 d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-01 14:03 . 2008-12-01 14:03 d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-01 14:03 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-01 14:03 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-01 01:07 . 2008-12-01 16:21 54,156 --ah----- c:\windows\QTFont.qfn
2008-12-01 01:07 . 2008-12-01 16:12 1,409 --a------ c:\windows\QTFont.for
2008-11-23 20:36 . 2008-11-23 20:36 d-------- c:\program files\Common Files\Software Update Utility
2008-11-23 20:36 . 2008-11-23 20:36 d-------- c:\documents and settings\All Users\Application Data\acccore
2008-11-23 05:46 . 2008-11-23 05:47 d-------- c:\documents and settings\Eric\Application Data\Move Networks
2008-11-15 03:59 . 2008-11-15 03:59 d-------- c:\program files\Microsoft Silverlight

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

Continued...

Elcskater
Novice
Novice

Posts Posts : 11
Joined Joined : 2008-12-01
OS OS : windows xp
Points Points : 29320
# Likes # Likes : 0

View user profile

Back to top Go down

Solved Re: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

Post by Elcskater on Mon Dec 01, 2008 4:59 pm

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-01 22:50 --------- d-----w c:\program files\SMCWUSBT-G EZ Connect TM g 108 Mbps 802.11g Wireless USB 2.0 Adapter
2008-12-01 22:50 --------- d-----w c:\program files\Microsoft AntiSpyware
2008-12-01 22:21 0 ----a-w c:\windows\system32\drivers\logiflt.iad
2008-12-01 22:19 502,272 ----a-w c:\windows\system32\winlogon.exe
2008-12-01 21:06 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-01 07:49 0 ----a-w c:\windows\system32\drivers\lvuvc.hs
2008-12-01 07:00 --------- d-----w c:\program files\Spyware Doctor
2008-12-01 05:17 44,312 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-01 05:17 3,600,416 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\ArcSoft
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\Ahead
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\AdobeUM
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\Acreon
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\acccore
2008-12-01 05:12 295,424 ----a-w c:\windows\system32\termsrv.dll
2008-11-27 11:33 --------- d-----w c:\documents and settings\Eric\Application Data\LimeWire
2008-11-24 04:06 --------- d-----w c:\documents and settings\Eric\Application Data\Azureus
2008-11-24 02:36 --------- d-----w c:\program files\AIM6
2008-11-24 02:35 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2008-11-24 02:34 --------- d-----w c:\documents and settings\All Users\Application Data\AOL Downloads
2008-11-21 16:43 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-25 04:45 --------- d-----w c:\documents and settings\Eric\Application Data\Vso
2008-10-25 02:23 --------- d-----w c:\program files\LimeWire
2008-10-24 09:42 --------- d-----w c:\program files\Everstrike Software
2008-10-24 09:42 --------- d-----w c:\program files\Common Files\Everstrike Software
2008-10-24 09:38 --------- d-----w c:\program files\Folder Password Protect
2008-10-23 00:15 --------- d-----w c:\program files\Axon Data
2008-10-22 00:49 --------- d-----w c:\documents and settings\All Users\Application Data\Pinnacle Studio
2008-10-22 00:49 --------- d-----w c:\documents and settings\All Users\Application Data\Pinnacle
2008-10-22 00:44 --------- d-----w c:\program files\Pinnacle
2008-10-22 00:24 --------- d-----w c:\documents and settings\Eric\Application Data\InstallShield
2008-10-21 22:25 --------- d-----w c:\program files\MagicISO
2008-10-19 21:57 --------- d-----w c:\program files\Ventrilo
2008-10-19 21:57 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-10-14 03:58 --------- d-----w c:\program files\SUPERAntiSpyware
2008-10-14 03:55 --------- d-----w c:\program files\ZoneAlarmSB
2008-10-14 03:51 --------- d-----w c:\documents and settings\All Users\Application Data\MailFrontier
2008-10-14 03:50 --------- d-----w c:\program files\Zone Labs
2008-10-13 08:36 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2008-10-13 08:34 --------- d-----w c:\program files\Lavasoft
2008-10-13 08:19 --------- d-----w c:\documents and settings\Eric\Application Data\Lavasoft
2008-10-13 05:56 --------- d-----w c:\program files\AML Products
2008-10-13 04:53 --------- d-----w c:\program files\StreamCast
2008-10-13 03:44 --------- d-----w c:\documents and settings\Eric\Application Data\PC Tools
2008-10-13 02:39 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-12 23:01 --------- d-----w c:\documents and settings\All Users\Application Data\AntiVir PersonalEdition classic
2008-10-12 22:07 --------- d-----w c:\program files\fhuuifg
2008-10-12 22:07 --------- d-----w c:\documents and settings\All Users\Application Data\pkbwfgrq
2008-10-09 00:20 --------- d-----w c:\program files\Morpheus
2008-10-04 02:44 --------- d-----w c:\documents and settings\Eric\Application Data\dvdcss
2007-06-20 07:45 47,360 -c--a-w c:\documents and settings\Eric\Application Data\pcouffin.sys
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

---- Directory of c:\program files\fhuuifg ----

2008-10-12 16:07 106496 --a------ c:\program files\fhuuifg\procsys.dll


------- Sigcheck -------

2008-11-30 23:12 295424 40ffc19a8d4875e9e19cecdc76ef9201 c:\windows\system32\termsrv.dll
2004-08-04 06:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\system32\dllcache\termsrv.dll
.
((((((((((((((((((((((((((((( [You must be registered and logged in to see this link.] )))))))))))))))))))))))))))))))))))))))))
.
+ 2001-07-09 18:50:42 155,648 ----a-w c:\windows\system32\NeroCheck.exe
- 2008-12-01 22:18:00 62,344 ----a-w c:\windows\system32\perfc009.dat
+ 2008-12-01 22:26:00 62,344 ----a-w c:\windows\system32\perfc009.dat
- 2008-12-01 22:18:00 401,064 ----a-w c:\windows\system32\perfh009.dat
+ 2008-12-01 22:26:00 401,064 ----a-w c:\windows\system32\perfh009.dat
+ 2004-03-10 23:26:10 406,016 -c--a-w c:\windows\system32\PSDrvCheck.exe
+ 2000-05-11 08:00:00 90,112 ----a-w c:\windows\UpdReg.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-10-13 1576176]
"LaunchList"="c:\program files\Pinnacle\Studio 11\LaunchList2.exe" [2007-03-21 145496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-04-01 5562368]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-04-01 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-08-18 77824]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 75520]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 564496]
"Jet Detection"="c:\program files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 28672]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-11-20 178688]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"Tweak UI"="TWEAKUI.CPL" [2000-06-18 c:\windows\system32\TWEAKUI.CPL]
"CTHelper"="CTHELPER.EXE" [2003-08-28 c:\windows\system32\CTHELPER.EXE]
"nwiz"="nwiz.exe" [2005-04-01 c:\windows\system32\nwiz.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-27 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-10-13 21:58 352256 c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= vdrcodec.dll
"VIDC.MJPG"= Pvmjpg30.dll
"VIDC.PIM1"= pclepim1.dll
"VIDC.PIXL"= pclepixl.dll
"VIDC.NTN1"= Nuvision.ax
"msacm.ctmp3"= c:\windows\system32\ctmp3.acm
"VIDC.MJPX"= PICVideo MJPEG Codec

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AresChatServer"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Morpheus\\Morpheus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\PlayOnline\\SquareEnix\\PlayOnlineViewer\\pol.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\umi.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"27693:TCP"= 27693:TCP:SolidNetworkManager
"27693:UDP"= 27693:UDP:SolidNetworkManager
"32397:TCP"= 32397:TCP:*:Disabled:SolidNetworkManager
"32397:UDP"= 32397:UDP:*:Disabled:SolidNetworkManager

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)

R1 SSHDRV65;SSHDRV65;\??\c:\windows\system32\drivers\SSHDRV65.sys [2005-06-15 120320]
R1 SSHDRV85;SSHDRV85;\??\c:\windows\system32\drivers\SSHDRV85.sys [2002-01-02 78848]
R2 ACDaemon;ArcSoft Connect Daemon;c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2008-09-23 109056]
R2 LF30FS;LF30FS;\??\c:\program files\Everstrike Software\Lock Folder XP 3.6\LF30XP.sys [2004-11-19 101488]
R3 LVRS;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs.sys [2008-07-12 628760]
R3 uscbs109;uscbs109;c:\windows\system32\DRIVERS\uscbs109.sys [2005-12-05 8672]
R3 uscsc109;uscsc109;c:\windows\system32\DRIVERS\uscsc109.sys [2005-12-05 102336]
S2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" []
S2 VRDVC20;Sony VRD-VC20 [Video Capture];c:\windows\system32\Drivers\VRDVC20X.SYS [2006-02-14 02:25:02 31104]
S3 AR5523;Atheros USB Wireless Network Adapter Service;c:\windows\system32\DRIVERS\ar5523.sys []
S3 asbp2poa;asbp2poa; []
S3 ASNDIS5;ASNDIS5 Protocol Driver;\??\c:\windows\system32\ASNDIS5.SYS [2007-01-13 16269]
S3 ATHFMWDL;Atheros USB Wireless Adapter Bootloader driver;c:\windows\system32\Drivers\ATHFMWDL.sys []
S3 NUVision;Pinnacle LINX;c:\windows\system32\DRIVERS\NUVision.sys [2006-09-19 136352]
S3 SjyPkt;SjyPkt;\??\c:\windows\System32\Drivers\SjyPkt.sys [2007-05-10 13532]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{17906ce3-fe56-11d5-99a5-806d6172696f}]
\Shell\AutoRun\command - rundll32.exe url.dll,FileProtocolHandler START.HTM
.
Contents of the 'Scheduled Tasks' folder

2008-09-30 c:\windows\Tasks\Best.job
- c:\documents and settings\Eric\Desktop\Shrek_1_and_2_dvd_rip_s_eng_XviD.torrent []

2008-11-30 c:\windows\Tasks\friday.job
- c:\documents and settings\Eric\My Documents\My Music\My Playlists\Country.wpl [2008-10-01 17:24]

2008-12-01 c:\windows\Tasks\one.job
- c:\documents and settings\Eric\My Documents\My Music\My Playlists\Now.wpl [2008-09-13 19:27]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Aim6 - (no file)
HKLM-Run-pdfSaver3 - (no file)
HKLM-Run-NWEReboot - (no file)
HKLM-Run-LFAgent - (no file)



**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2008-12-01 16:52:58
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...
scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(892)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
Completion time: 2008-12-01 16:54:48
ComboFix-quarantined-files.txt 2008-12-01 22:53:56
ComboFix2.txt 2008-12-01 22:28:03

Pre-Run: 51,429,597,184 bytes free
Post-Run: 51,395,948,544 bytes free

370 --- E O F --- 2007-08-26 06:47:50

Elcskater
Novice
Novice

Posts Posts : 11
Joined Joined : 2008-12-01
OS OS : windows xp
Points Points : 29320
# Likes # Likes : 0

View user profile

Back to top Go down

Solved Re: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

Post by Belahzur on Mon Dec 01, 2008 5:03 pm

Hello.
Looking alot better.
One leftover I missed.

Now open a new notepad file.
Input this into the notepad file:

Driver::
Viewpoint Manager Service

Folder::
c:\program files\fhuuifg

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{17906ce3-fe56-11d5-99a5-806d6172696f}]

Save this as CFScript.txt, save it to your desktop also.
Then drag and drop CFScript.txt into combofix as seen below:


This will open combofix.exe again, agree to it's terms and allow it to run, it may want to reboot after it's done. Post the resulting log back here.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245121
# Likes # Likes : 1

View user profile

Back to top Go down

Solved Re: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

Post by Elcskater on Mon Dec 01, 2008 5:21 pm

ComboFix 08-12-01.01 - Eric 2008-12-01 17:08:19.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.654 [GMT -6:00]
Running from: c:\documents and settings\Eric\Desktop\-Combo-Fix-.exe
Command switches used :: c:\documents and settings\Eric\Desktop\CFscript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\fhuuifg
c:\program files\fhuuifg\procsys.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_VIEWPOINT_MANAGER_SERVICE
-------\Service_Viewpoint Manager Service


((((((((((((((((((((((((( Files Created from 2008-11-01 to 2008-12-01 )))))))))))))))))))))))))))))))
.

2008-12-01 17:07 . 2008-12-01 17:13 d-------- C:\-Combo-Fix-
2008-12-01 14:03 . 2008-12-01 14:32 d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-01 14:03 . 2008-12-01 14:03 d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-01 14:03 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-01 14:03 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-01 01:07 . 2008-12-01 17:11 54,156 --ah----- c:\windows\QTFont.qfn
2008-12-01 01:07 . 2008-12-01 17:10 1,409 --a------ c:\windows\QTFont.for
2008-11-23 20:36 . 2008-11-23 20:36 d-------- c:\program files\Common Files\Software Update Utility
2008-11-23 20:36 . 2008-11-23 20:36 d-------- c:\documents and settings\All Users\Application Data\acccore
2008-11-23 05:46 . 2008-11-23 05:47 d-------- c:\documents and settings\Eric\Application Data\Move Networks
2008-11-15 03:59 . 2008-11-15 03:59 d-------- c:\program files\Microsoft Silverlight

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-01 23:11 0 ----a-w c:\windows\system32\drivers\logiflt.iad
2008-12-01 22:53 --------- d-----w c:\program files\SMCWUSBT-G EZ Connect TM g 108 Mbps 802.11g Wireless USB 2.0 Adapter
2008-12-01 22:53 --------- d-----w c:\program files\Microsoft AntiSpyware
2008-12-01 22:19 502,272 ----a-w c:\windows\system32\winlogon.exe
2008-12-01 21:06 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-01 07:49 0 ----a-w c:\windows\system32\drivers\lvuvc.hs
2008-12-01 07:00 --------- d-----w c:\program files\Spyware Doctor
2008-12-01 05:17 44,312 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-01 05:17 3,600,416 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\ArcSoft
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\Ahead
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\AdobeUM
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\Acreon
2008-12-01 05:16 --------- d-----w c:\documents and settings\Eric\Application Data\acccore
2008-12-01 05:12 295,424 ----a-w c:\windows\system32\termsrv.dll
2008-11-27 11:33 --------- d-----w c:\documents and settings\Eric\Application Data\LimeWire
2008-11-24 04:06 --------- d-----w c:\documents and settings\Eric\Application Data\Azureus
2008-11-24 02:36 --------- d-----w c:\program files\AIM6
2008-11-24 02:35 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2008-11-24 02:34 --------- d-----w c:\documents and settings\All Users\Application Data\AOL Downloads
2008-11-21 16:43 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-25 04:45 --------- d-----w c:\documents and settings\Eric\Application Data\Vso
2008-10-25 02:23 --------- d-----w c:\program files\LimeWire
2008-10-24 09:42 --------- d-----w c:\program files\Everstrike Software
2008-10-24 09:42 --------- d-----w c:\program files\Common Files\Everstrike Software
2008-10-24 09:38 --------- d-----w c:\program files\Folder Password Protect
2008-10-23 00:15 --------- d-----w c:\program files\Axon Data
2008-10-22 00:49 --------- d-----w c:\documents and settings\All Users\Application Data\Pinnacle Studio
2008-10-22 00:49 --------- d-----w c:\documents and settings\All Users\Application Data\Pinnacle
2008-10-22 00:44 --------- d-----w c:\program files\Pinnacle
2008-10-22 00:24 --------- d-----w c:\documents and settings\Eric\Application Data\InstallShield
2008-10-21 22:25 --------- d-----w c:\program files\MagicISO
2008-10-19 21:57 --------- d-----w c:\program files\Ventrilo
2008-10-19 21:57 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-10-14 03:58 --------- d-----w c:\program files\SUPERAntiSpyware
2008-10-14 03:55 --------- d-----w c:\program files\ZoneAlarmSB
2008-10-14 03:51 --------- d-----w c:\documents and settings\All Users\Application Data\MailFrontier
2008-10-14 03:50 --------- d-----w c:\program files\Zone Labs
2008-10-13 08:36 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2008-10-13 08:34 --------- d-----w c:\program files\Lavasoft
2008-10-13 08:19 --------- d-----w c:\documents and settings\Eric\Application Data\Lavasoft
2008-10-13 05:56 --------- d-----w c:\program files\AML Products
2008-10-13 04:53 --------- d-----w c:\program files\StreamCast
2008-10-13 03:44 --------- d-----w c:\documents and settings\Eric\Application Data\PC Tools
2008-10-13 02:39 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-12 23:01 --------- d-----w c:\documents and settings\All Users\Application Data\AntiVir PersonalEdition classic
2008-10-12 22:07 --------- d-----w c:\documents and settings\All Users\Application Data\pkbwfgrq
2008-10-09 00:20 --------- d-----w c:\program files\Morpheus
2008-10-04 02:44 --------- d-----w c:\documents and settings\Eric\Application Data\dvdcss
2007-06-20 07:45 47,360 -c--a-w c:\documents and settings\Eric\Application Data\pcouffin.sys
.

------- Sigcheck -------

2008-11-30 23:12 295424 40ffc19a8d4875e9e19cecdc76ef9201 c:\windows\system32\termsrv.dll
2004-08-04 06:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\system32\dllcache\termsrv.dll
.
((((((((((((((((((((((((((((( [You must be registered and logged in to see this link.] )))))))))))))))))))))))))))))))))))))))))
.
+ 2001-07-09 18:50:42 155,648 ----a-w c:\windows\system32\NeroCheck.exe
- 2008-12-01 22:18:00 62,344 ----a-w c:\windows\system32\perfc009.dat
+ 2008-12-01 22:26:00 62,344 ----a-w c:\windows\system32\perfc009.dat
- 2008-12-01 22:18:00 401,064 ----a-w c:\windows\system32\perfh009.dat
+ 2008-12-01 22:26:00 401,064 ----a-w c:\windows\system32\perfh009.dat
+ 2004-03-10 23:26:10 406,016 -c--a-w c:\windows\system32\PSDrvCheck.exe
+ 2000-05-11 08:00:00 90,112 ----a-w c:\windows\UpdReg.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-10-13 1576176]
"LaunchList"="c:\program files\Pinnacle\Studio 11\LaunchList2.exe" [2007-03-21 145496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-04-01 5562368]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-04-01 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-08-18 77824]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 75520]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 564496]
"Jet Detection"="c:\program files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 28672]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-11-20 178688]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"Tweak UI"="TWEAKUI.CPL" [2000-06-18 c:\windows\system32\TWEAKUI.CPL]
"CTHelper"="CTHELPER.EXE" [2003-08-28 c:\windows\system32\CTHELPER.EXE]
"nwiz"="nwiz.exe" [2005-04-01 c:\windows\system32\nwiz.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]

Continued...

Elcskater
Novice
Novice

Posts Posts : 11
Joined Joined : 2008-12-01
OS OS : windows xp
Points Points : 29320
# Likes # Likes : 0

View user profile

Back to top Go down

Solved Re: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

Post by Elcskater on Mon Dec 01, 2008 5:22 pm

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-27 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-10-13 21:58 352256 c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= vdrcodec.dll
"VIDC.MJPG"= Pvmjpg30.dll
"VIDC.PIM1"= pclepim1.dll
"VIDC.PIXL"= pclepixl.dll
"VIDC.NTN1"= Nuvision.ax
"msacm.ctmp3"= c:\windows\system32\ctmp3.acm
"VIDC.MJPX"= PICVideo MJPEG Codec

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AresChatServer"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Morpheus\\Morpheus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\PlayOnline\\SquareEnix\\PlayOnlineViewer\\pol.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\umi.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"27693:TCP"= 27693:TCP:SolidNetworkManager
"27693:UDP"= 27693:UDP:SolidNetworkManager
"32397:TCP"= 32397:TCP:*:Disabled:SolidNetworkManager
"32397:UDP"= 32397:UDP:*:Disabled:SolidNetworkManager

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)

R1 SSHDRV65;SSHDRV65;\??\c:\windows\system32\drivers\SSHDRV65.sys [2005-06-15 120320]
R1 SSHDRV85;SSHDRV85;\??\c:\windows\system32\drivers\SSHDRV85.sys [2002-01-02 78848]
R2 ACDaemon;ArcSoft Connect Daemon;c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2008-09-23 109056]
R2 LF30FS;LF30FS;\??\c:\program files\Everstrike Software\Lock Folder XP 3.6\LF30XP.sys [2004-11-19 101488]
R3 LVRS;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs.sys [2008-07-12 628760]
R3 uscbs109;uscbs109;c:\windows\system32\DRIVERS\uscbs109.sys [2005-12-05 8672]
R3 uscsc109;uscsc109;c:\windows\system32\DRIVERS\uscsc109.sys [2005-12-05 102336]
S2 VRDVC20;Sony VRD-VC20 [Video Capture];c:\windows\system32\Drivers\VRDVC20X.SYS [2006-02-14 02:25:02 31104]
S3 AR5523;Atheros USB Wireless Network Adapter Service;c:\windows\system32\DRIVERS\ar5523.sys []
S3 asbp2poa;asbp2poa; []
S3 ASNDIS5;ASNDIS5 Protocol Driver;\??\c:\windows\system32\ASNDIS5.SYS [2007-01-13 16269]
S3 ATHFMWDL;Atheros USB Wireless Adapter Bootloader driver;c:\windows\system32\Drivers\ATHFMWDL.sys []
S3 NUVision;Pinnacle LINX;c:\windows\system32\DRIVERS\NUVision.sys [2006-09-19 136352]
S3 SjyPkt;SjyPkt;\??\c:\windows\System32\Drivers\SjyPkt.sys [2007-05-10 13532]
.
Contents of the 'Scheduled Tasks' folder

2008-09-30 c:\windows\Tasks\Best.job
- c:\documents and settings\Eric\Desktop\Shrek_1_and_2_dvd_rip_s_eng_XviD.torrent []

2008-11-30 c:\windows\Tasks\friday.job
- c:\documents and settings\Eric\My Documents\My Music\My Playlists\Country.wpl [2008-10-01 17:24]

2008-12-01 c:\windows\Tasks\one.job
- c:\documents and settings\Eric\My Documents\My Music\My Playlists\Now.wpl [2008-09-13 19:27]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2008-12-01 17:11:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(892)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ZoneLabs\vsmon.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\system32\msiexec.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
c:\program files\AIM6\aim6.exe
c:\program files\AIM6\aolsoftware.exe
c:\program files\AIM6\aolsoftware.exe
.
**************************************************************************
.
Completion time: 2008-12-01 17:17:03 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-01 23:16:18
ComboFix2.txt 2008-12-01 22:54:49
ComboFix3.txt 2008-12-01 22:28:03

Pre-Run: 51,380,654,080 bytes free
Post-Run: 51,363,348,480 bytes free

245 --- E O F --- 2007-08-26 06:47:50

Elcskater
Novice
Novice

Posts Posts : 11
Joined Joined : 2008-12-01
OS OS : windows xp
Points Points : 29320
# Likes # Likes : 0

View user profile

Back to top Go down

Solved Re: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

Post by Belahzur on Mon Dec 01, 2008 5:23 pm

Looks good, how is the machine now?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245121
# Likes # Likes : 1

View user profile

Back to top Go down

Solved Re: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

Post by Elcskater on Mon Dec 01, 2008 5:25 pm

Its running fine now. Thanks for all the help. I really appreciate it. Thank You!

Elcskater
Novice
Novice

Posts Posts : 11
Joined Joined : 2008-12-01
OS OS : windows xp
Points Points : 29320
# Likes # Likes : 0

View user profile

Back to top Go down

Solved Re: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

Post by Belahzur on Mon Dec 01, 2008 5:32 pm

Glad to hear it. Smile
Before I can let you go, we need to get you secured.

Your version of Java is outdated and needs to be updated to take advantage of fixes that have eliminated security vulnerabilities.
Updating Java:

  • Download the latest version of [You must be registered and logged in to see this link.].
  • Select the first option where it says "Java SE Runtime Environment (JRE) 6 Update 10".
  • Click the "Download" button to the right.
  • In the Window that opens, select your platform and language, check the "agree" box, and click Continue.
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add or Remove Programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    - Examples of older versions in Add or Remove Programs:
    - Java 2 Runtime Environment, SE v1.4.2
    - J2SE Runtime Environment 5.0
    - J2SE Runtime Environment 5.0 Update 2
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u10-windows-i586-p.exe that you downloaded to install the newest version.
Please make sure the new version of Java is installed before you run JavaRa.

Please download JavaRa from [You must be registered and logged in to see this link.]

  • First, unzip it.
  • Then run JavaRa.
  • Select English from the drop down menu and press Select.
  • This will open JavaRa.
  • Press Remove older versions
  • Press yes to the prompt.
  • It will make a log file of what it's removed.
  • Copy and paste the log back here.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245121
# Likes # Likes : 1

View user profile

Back to top Go down

Solved Re: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

Post by Elcskater on Mon Dec 01, 2008 6:00 pm

JavaRa Logfile.


JavaRa 1.11 Removal Log.

Report follows after line.

------------------------------------

The JavaRa removal process was started on Mon Dec 01 17:58:24 2008

Found and removed: C:\Program Files\Java\jre1.5.0_11

Found and removed: Software\JavaSoft\Java2D\1.5.0_02

Found and removed: Software\JavaSoft\Java2D\1.5.0_04

Found and removed: Software\JavaSoft\Java2D\1.5.0_11

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D511001

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D511001

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D511001

Found and removed: SOFTWARE\Classes\JavaPlugin.150_11

Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_11

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_11

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D511001

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D511001

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150110}

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_11

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_11\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core1.zip

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core2.zip

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core3.zip

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

------------------------------------

Finished reporting.

Elcskater
Novice
Novice

Posts Posts : 11
Joined Joined : 2008-12-01
OS OS : windows xp
Points Points : 29320
# Likes # Likes : 0

View user profile

Back to top Go down

Solved Re: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

Post by Belahzur on Mon Dec 01, 2008 6:04 pm

We need to make a new restore point.

To turn off System Restore, follow these steps:
1. Click Start, right-click My Computer, and then click Properties.
2. Click the System Restore tab.
3. Click the Turn off System Restore check box (or the Turn off System Restore on all drives check box), and then click OK.
4. Click Yes when you receive the prompt to the turn off System Restore.

Now we need to make a new restore point.
To turn on System Restore, follow these steps:
1. Click Start, right-click My Computer, and then click Properties.
2. Click the System Restore tab.
3. Click the Turn off System Restore check box (To turn on System Restore), and then click OK.


Below I have included a number of recommendations for how to protect your computer in order to prevent future malware infections. Please take these recommendations seriously; these few simple steps can stave off the vast majority of spyware problems. As happy as we are to help you, for your sake we would rather not have repeat customers. Goofy

1) Please navigate to [You must be registered and logged in to see this link.] and download all the "critical updates" for Windows. This can patch many of the security holes through which attackers can gain access to your computer.

Please either enable Automatic Updates under Start -> Control Panel -> Automatic Updates , or get into the habit of checking for Windows updates regularly. I cannot stress enough how important this is.

2) In order to protect yourself against spyware, you should consider installing and running the following free programs:

[You must be registered and logged in to see this link.]
A tutorial on using Ad-Aware to remove spyware from your computer may be found [You must be registered and logged in to see this link.].

[You must be registered and logged in to see this link.]
A tutorial on using Spybot to remove spyware from your computer may be found [You must be registered and logged in to see this link.]. Please also remember to enable Spybot's "Immunize" and "TeaTimer" features.

[You must be registered and logged in to see this link.]
A tutorial on using SpywareBlaster to prevent spyware from ever installing on your computer may be found [You must be registered and logged in to see this link.].

[You must be registered and logged in to see this link.]
A tutorial on using SpywareGuard for realtime protection against spyware and hijackers may be found [You must be registered and logged in to see this link.].

Make sure to keep these programs up-to-date and to run them regularly, as this can prevent a great deal of spyware hassle.

3) Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in popup blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from here:
[You must be registered and logged in to see this link.]

4) Also make sure to run your antivirus software regularly, and to keep it up-to-date.

5) Finally, consider maintaining a firewall. Some good free firewalls are [You must be registered and logged in to see this link.], or
[You must be registered and logged in to see this link.]
A tutorial on understanding and using firewalls may be found [You must be registered and logged in to see this link.].

Please also read Tony Klein's excellent article: [You must be registered and logged in to see this link.]

Hopefully this should take care of your problems! Good luck. Big Grin


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245121
# Likes # Likes : 1

View user profile

Back to top Go down

Solved Re: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

Post by Elcskater on Mon Dec 01, 2008 6:24 pm

Alrighty, all set, thanks again for all the help ^_^

Elcskater
Novice
Novice

Posts Posts : 11
Joined Joined : 2008-12-01
OS OS : windows xp
Points Points : 29320
# Likes # Likes : 0

View user profile

Back to top Go down

Solved Re: Spyware.Ispynow Hijackthis log and uninstall log included. Please help

Post by Doctor Inferno on Mon Dec 08, 2008 9:35 pm

Since this issue is resolved, this topic is closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.


Please be a GeekPolice fan on [You must be registered and logged in to see this link.]



Have we helped you? [You must be registered and logged in to see this link.] | Doctor by day, ninja by night.

Doctor Inferno
Administrator
Administrator

Posts Posts : 11976
Joined Joined : 2007-12-26
Gender Gender : Male
OS OS : Windows 7 Home Premium and Ultimate X64
Protection Protection : Kaspersky PURE and Malwarebytes' Anti-Malware
Points Points : 104650
# Likes # Likes : 0

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum