econ1 Posted August 3, 2010 ID:294591 Share Posted August 3, 2010 The Hijack log does not show the proxy override setting, but each time I log on, I getProxyOverride" -> <local>;cgi*.ebay.com;disney.go.com;msa_e1.ebay.com;rhapsody_app*.listen.comThe ark.txt is probably defective. I think I saved it too early, but each time I tried to do it again, the program crashed my computer before I could save anything.Any help would be greatly appreciated. I have spent many hours trying to figure this out.MichaelI can't figure out how to upload the hijack log, so I am including the text. Sorry.Logfile of Trend Micro HijackThis v2.0.4Scan saved at 6:02:12 PM, on 8/2/2010Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\ibmpmsvc.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Microsoft Security Essentials\MsMpEng.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Microsoft Shared\Ink\KeyboardSurrogate.exeC:\Program Files\Intel\WiFi\bin\S24EvMon.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\SYSTEM32\WISPTIS.EXEC:\Program Files\LENOVO\HOTKEY\TPHKSVC.exeC:\WINDOWS\system32\IPSSVC.EXEC:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exeC:\Program Files\Common Files\Acronis\Schedule2\schedul2.exeC:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exeC:\Program Files\ThinkPad\Tablet Shortcut\ASR\ASRSVC.exeC:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exeC:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exeC:\Program Files\ThinkPad\Utilities\DOZESVC.EXEC:\Program Files\Intel\WiFi\bin\EvtEng.exeC:\WINDOWS\System32\tabbtnu.exeC:\Program Files\Soluto\soluto.exeC:\Program Files\Google\Update\1.2.183.29\GoogleCrashHandler.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Java\jre6\bin\jqs.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\LENOVO\HOTKEY\CAMMUTE.exeC:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exeC:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exeC:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exeC:\Program Files\Common Files\Motive\McciCMService.exeC:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exeC:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exeC:\Program Files\Common Files\Microsoft Shared\Ink\TCServer.exeC:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exeC:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exeC:\Program Files\Common Files\Microsoft Shared\Ink\TabTip.exeC:\Program Files\Soluto\SolutoService.exeC:\WINDOWS\system32\rundll32.exeC:\PROGRA~1\Lenovo\NPDIRECT\TPFNF7SP.exec:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exeC:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\TpShocks.exec:\program files\lenovo\system update\suservice.exeC:\WINDOWS\system32\igfxext.exeC:\Program Files\ThinkPad\Tablet Shortcut\TSMService.exeC:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.ExeC:\Program Files\Lenovo\HOTKEY\TPONSCR.exeC:\Program Files\Lenovo\Zoom\TpScrex.exeC:\WINDOWS\system32\igfxsrvc.exeC:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exeC:\Program Files\ThinkPad\Tablet Shortcut\TSMRESIDENT.EXEC:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exeC:\WINDOWS\system32\TpKmpSVC.exeC:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exeC:\Program Files\Lenovo\Rescue and Recovery\rrservice.exeC:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exeC:\Program Files\Common Files\InstallShield\UpdateService\issch.exeC:\PROGRA~1\THINKV~2\PrdCtr\LPMLCHK.exec:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exeC:\Program Files\Lenovo\Rescue and Recovery\UpdateMonitor.exeC:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXEC:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exeC:\Program Files\Lenovo\Client Security Solution\cssauth.exeC:\PROGRA~1\THINKV~2\AMSG\Amsg.exeC:\Program Files\Analog Devices\Core\smax4pnp.exeC:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exeC:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exeC:\WINDOWS\system32\hkcmd.exeC:\WINDOWS\system32\igfxpers.exeC:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exeC:\Program Files\Microsoft Security Essentials\msseces.exeC:\Program Files\Spybot - Search & Destroy\TeaTimer.exeC:\Program Files\Microsoft ActiveSync\wcescomm.exeC:\Program Files\interMute\AdSubtract\AdSub.exeC:\WINDOWS\system32\ntvdm.exeC:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exeC:\PROGRA~1\MI3AA1~1\rapimgr.exeC:\Program Files\Microsoft Office\Office12\WINWORD.EXEC:\Program Files\putty.exeC:\Program Files\Microsoft Office\Office12\OUTLOOK.EXEC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\Mozilla Firefox\plugin-container.exeC:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exeC:\Program Files\Trend Micro\HiJackThis\HiJackThis.exeC:\Program Files\Winamp\winamp.exeR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:1047R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 0x00000000 (0)F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Program Files\Soluto\soluto.exe /userinitO2 - BHO: (no name) - AutorunsDisabled - (no file)O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllO2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\IPSBHO.DLLO2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dllO2 - BHO: Password Manager Browser Helper Object - {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dllO2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dllO2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dllO2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dllO2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dllO2 - BHO: (no name) - {F040E541-A427-4CF7-85D8-75E3E0F476C5} - (no file)O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dllO3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)O3 - Toolbar: AdSubtract Toolbar - {F14AABDD-0232-4e5a-9B52-4178AC0A62B5} - C:\WINDOWS\system32\adsubtb.dllO4 - HKLM\..\Run: [TabletWizard] C:\WINDOWS\help\SplshWrp.exeO4 - HKLM\..\Run: [TabletTip] "C:\Program Files\Common Files\microsoft shared\ink\tabtip.exe" /resumeO4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitorO4 - HKLM\..\Run: [bLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLogO4 - HKLM\..\Run: [TPFNF7] C:\PROGRA~1\Lenovo\NPDIRECT\TPFNF7SP.exe /rO4 - HKLM\..\Run: [TrackPointSrv] C:\Program Files\Lenovo\TrackPoint\tp4serv.exeO4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exeO4 - HKLM\..\Run: [TpShocks] TpShocks.exeO4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.ExeO4 - HKLM\..\Run: [TSMResident] "C:\Program Files\ThinkPad\Tablet Shortcut\TSMRESIDENT.EXE" /rO4 - HKLM\..\Run: [soundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /trayO4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exeO4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startupO4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -startO4 - HKLM\..\Run: [LPMailChecker] C:\PROGRA~1\THINKV~2\PrdCtr\LPMLCHK.exeO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helperO4 - HKLM\..\Run: [DNS7reminder] "C:\Program Files\Nuance\NaturallySpeaking10\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\Nuance\NaturallySpeaking10\Ereg.iniO4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silentO4 - HKLM\..\Run: [AMSG] C:\PROGRA~1\THINKV~2\AMSG\Amsg.exe /startupO4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exeO4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exeO4 - HKLM\..\Run: [LENTBCTL] "C:\Program Files\ThinkPad\Tablet Shortcut\LENTBCTL.EXE" /rO4 - HKLM\..\Run: [TabletButton] "C:\Program Files\ThinkPad\Tablet Shortcut\TabletButton.EXE" /STARTUPO4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXEO4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exeO4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exeO4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttrayO4 - HKLM\..\Run: [MSSE] "C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkeyO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exeO4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"O4 - HKCU\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs"O4 - HKUS\S-1-5-19\..\Run: [TabletWizard] %windir%\help\wizard.hta (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [TabletWizard] %windir%\help\wizard.hta (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')O4 - Startup: AdSubtract.lnk = C:\Program Files\interMute\AdSubtract\AdSub.exeO4 - Startup: AutorunsDisabledO8 - Extra context menu item: AdSubtract: Bypass Site - res://C:\Program Files\interMute\AdSubtract\AdSub.exe/360O8 - Extra context menu item: AdSubtract: Cloak Image - res://C:\Program Files\interMute\AdSubtract\AdSub.exe/361O8 - Extra context menu item: AdSubtract: Report Site - res://C:\Program Files\interMute\AdSubtract\AdSub.exe/359O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dllO9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dllO9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dllO9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dllO9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLLO9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htmO9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htmO9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: (no name) - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dllO9 - Extra 'Tools' menuitem: Lenovo Password Manager... - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dllO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - http://site.ebrary.com/lib/berkeley/suppor...s/ebraryRdr.cabO16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} (IASRunner Class) - http://www-307.ibm.com/pc/support/acpir.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1240377929750O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1240377904218O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/flash...ent/swflash.cabO16 - DPF: {E0FEE963-BB53-4215-81AD-B28C77384644} (WebBrowserType Class) - https://pattcw.att.motive.com/wizlet/DSLAct...etInstaller.cabO18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dllO20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)O20 - Winlogon Notify: AutorunsDisabled - Invalid registry foundO22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dllO22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dllO23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exeO23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exeO23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exeO23 - Service: ASR Service (ASRSVC) - Lenovo Group Limited - C:\Program Files\ThinkPad\Tablet Shortcut\ASR\ASRSVC.exeO23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exeO23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exeO23 - Service: Lenovo Doze Mode Service (DozeSvc) - Lenovo. - C:\Program Files\ThinkPad\Utilities\DOZESVC.EXEO23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exeO23 - Service: Google Update Service (gupdate1c9c9e97f109188) (gupdate1c9c9e97f109188) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exeO23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo. - C:\WINDOWS\system32\ibmpmsvc.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exeO23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXEO23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exeO23 - Service: Lenovo Camera Mute (LENOVO.CAMMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\CAMMUTE.exeO23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exeO23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exeO23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exeO23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exeO23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exeO23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exeO23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exeO23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exeO23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exeO23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exeO23 - Service: Power Manager DBC Service - Unknown owner - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXEO23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exeO23 - Service: Intel® PROSet/Wireless WiFi Service (S24EventMonitor) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\S24EvMon.exeO23 - Service: Soluto PCGenome Core Service (SolutoService) - Soluto - C:\Program Files\Soluto\SolutoService.exeO23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exeO23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exeO23 - Service: TABLET Service (TabletSVC) - Lenovo Group Limited - C:\Program Files\ThinkPad\Tablet Shortcut\TSMService.exeO23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exeO23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exeO23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exeO23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exeO23 - Service: TSS Core Service (TSSCoreService) - Lenovo - C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exeO23 - Service: TVT Backup Protection Service - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exeO23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exeO23 - Service: TVT Scheduler - Lenovo Group Limited - c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exeO23 - Service: TVT Windows Update Monitor (TVT_UpdateMonitor) - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\UpdateMonitor.exe--End of file - 19763 bytesattach.zipDDS.txtmbam_log_2010_02_01__07_47_25_.txt Link to post Share on other sites More sharing options...
MrCharlie Posted August 3, 2010 ID:294641 Share Posted August 3, 2010 Welcome to the forum.Please disable Spybots TeaTimer:http://russelltexas.com/malware/teatimer.htmWhen we are all done, you can enable with this small app:http://home.kpn.nl/stefsmeenk/ResetTeaTimer.exe[*]Close all programs leaving only HijackThis running. Place a check against each of the following, making sure you get them all and not any others by mistake:R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:1047R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 0x00000000 (0)O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)O2 - BHO: (no name) - {F040E541-A427-4CF7-85D8-75E3E0F476C5} - (no file)O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')Click on Fix Checked when finished and exit HijackThis.---------------------------------------------------Download ComboFix from one of these locations:Link 1Link 2 ComboFix Guide* IMPORTANT !!! Save ComboFix.exe to your DesktopDisable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon and choose disable/exit. More info HEREThey may interfere with the running of ComboFix.Double click on ComboFix.exe & follow the prompts.Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7. Note: If you have SP3, use the SP2 package.If Vista or Windows 7, skip the Recovery Console partComboFix will check to see if the Microsoft Windows Recovery Console is installed. It's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:Click on Yes, to continue scanning for malware.When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.Notes:1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please let me know. 4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.5.Give it atleast 20-30 minutes to finish if needed.MrC Link to post Share on other sites More sharing options...
econ1 Posted August 3, 2010 Author ID:295030 Share Posted August 3, 2010 I thought that I followed the directions. The first time I restarted, there was no sign of the virus. The next time, it reappeared.Any more suggestions? Link to post Share on other sites More sharing options...
MrCharlie Posted August 3, 2010 ID:295048 Share Posted August 3, 2010 Can you post the log from ComboFix please, MrC Link to post Share on other sites More sharing options...
econ1 Posted August 4, 2010 Author ID:295153 Share Posted August 4, 2010 ComboFix 10-08-03.01 - Administrator 08/03/2010 13:41:25.1.2 - x86Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2006.1018 [GMT -7:00]Running from: f:\00000\ComboFix.exeAV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}AV: Norton AntiVirus *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}.((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))).c:\documents and settings\Administrator\Application Data\putty.exec:\documents and settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnkc:\windows\system32\Thumbs.dbc:\windows\TEMP\logishrd\LVPrcInj02.dll.((((((((((((((((((((((((( Files Created from 2010-07-03 to 2010-08-03 ))))))))))))))))))))))))))))))).2010-08-02 16:49 . 2010-06-01 17:37 221568 ------w- c:\windows\system32\MpSigStub.exe2010-08-02 16:45 . 2010-08-02 16:46 -------- d-----w- c:\program files\Microsoft Security Essentials2010-07-28 20:34 . 2010-07-28 20:34 -------- d-----w- c:\program files\ATT-HSI2010-07-28 20:34 . 2010-07-28 20:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Motive2010-07-28 20:34 . 2010-07-28 20:34 -------- d-----w- c:\program files\Common Files\Motive2010-07-28 00:09 . 2010-07-28 00:09 -------- d-----w- c:\documents and settings\Administrator\Application Data\MSNInstaller2010-07-27 21:19 . 2010-07-27 21:19 -------- d-----w- c:\program files\Trend Micro2010-07-15 00:35 . 2007-03-01 05:24 451072 ------w- C:\putty.exe2010-07-14 22:21 . 2010-07-14 22:21 -------- d-----w- c:\program files\Conduits Pocket Player2010-07-11 04:15 . 2010-08-03 20:48 7301720 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat2010-07-06 21:50 . 2010-07-06 21:50 -------- d-----w- c:\documents and settings\LocalService\Application Data\Intel2010-07-06 21:50 . 2010-07-06 21:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Intel2010-07-06 21:50 . 2010-07-06 21:50 -------- d-----w- c:\documents and settings\Administrator\Application Data\Intel2010-07-06 21:50 . 2010-07-06 21:50 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Intel2010-07-04 23:59 . 2010-07-04 23:59 -------- d-----w- c:\program files\ParaGraph.(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2010-08-03 03:05 . 2008-03-19 11:44 -------- d-----w- c:\program files\Mozilla Thunderbird2010-08-02 02:15 . 2009-10-12 03:32 664 ----a-w- c:\windows\system32\d3d9caps.dat2010-07-29 04:53 . 2008-08-26 21:44 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP2010-07-28 22:56 . 2008-03-23 14:33 3114 ------w- c:\documents and settings\Administrator\Application Data\SAS7_000.DAT2010-07-27 23:49 . 2009-12-16 05:58 -------- d-----w- c:\program files\PC-Doctor2010-07-27 23:49 . 2008-12-18 04:15 -------- d-----w- c:\documents and settings\All Users\Application Data\PCDr2010-07-27 21:19 . 2010-07-27 21:19 388096 ------r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe2010-07-14 22:21 . 2008-03-13 15:37 -------- d--h--w- c:\program files\InstallShield Installation Information2010-07-13 21:53 . 2008-03-13 16:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help2010-07-06 21:51 . 2008-03-13 15:37 -------- d-----w- c:\program files\ThinkPad2010-07-06 21:49 . 2008-03-13 15:37 -------- d-----w- c:\program files\Intel2010-07-05 00:18 . 2008-03-20 01:23 -------- d-----w- c:\program files\Microsoft ActiveSync2010-06-27 00:55 . 2010-06-27 00:55 -------- d-----w- c:\program files\Digital Line Detect2010-06-27 00:55 . 2010-06-27 00:55 -------- d-----w- c:\program files\NetWaiting2010-06-27 00:54 . 2008-03-13 15:41 -------- d-----w- c:\program files\CONEXANT2010-06-20 00:04 . 2010-06-19 23:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Soluto2010-06-20 00:04 . 2008-03-13 16:15 69232 ------w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT2010-06-20 00:03 . 2010-06-19 23:57 -------- d-----w- c:\program files\Soluto2010-06-19 23:55 . 2010-06-19 23:57 926568 ------w- c:\documents and settings\All Users\Application Data\Soluto\Installer\SolutoInstaller.exe2010-06-18 01:00 . 2009-04-24 01:55 -------- d-----w- c:\documents and settings\Administrator\Application Data\Winamp2010-06-15 21:46 . 2010-06-19 23:57 179656 ------w- c:\windows\system32\drivers\PCGenFAM.sys2010-06-15 19:01 . 2010-06-15 19:00 -------- d-----w- c:\program files\Common Files\Adobe2010-06-14 14:31 . 2006-04-30 23:11 744448 ------w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe2010-06-05 16:19 . 2009-01-07 18:53 -------- d-----w- c:\program files\Microsoft Silverlight2010-06-02 21:49 . 2010-06-27 00:53 301624 ------w- c:\windows\system32\UCI32M57.dll2010-06-02 21:49 . 2007-03-14 09:40 19384 ------w- c:\windows\system32\drivers\mdmxsdk.sys2010-06-02 21:49 . 2007-03-14 09:40 100920 ------w- c:\windows\system32\mdmxsdk.dll2010-06-02 21:49 . 2007-03-14 09:40 993464 ------w- c:\windows\system32\drivers\HSF_DPV.sys2010-06-02 21:49 . 2007-03-14 09:39 738360 ------w- c:\windows\system32\drivers\HSF_CNXT.sys2010-06-02 21:49 . 2007-03-14 09:40 217016 ------w- c:\windows\system32\drivers\HSFHWAZL.sys2010-06-02 05:55 . 2010-06-02 05:55 1023061 ------w- C:\perelmancopyedits_my.zip2010-05-12 08:25 . 2010-02-04 00:52 24304 ------w- c:\windows\system32\drivers\DOZEHDD.SYS2010-05-12 08:25 . 2008-03-13 15:37 4442 ------w- c:\windows\system32\drivers\TPPWRIF.SYS2010-05-12 08:25 . 2008-03-13 15:37 196608 ------w- c:\windows\PWMBTHLP.EXE2010-05-06 10:41 . 2006-04-30 22:51 916480 ------w- c:\windows\system32\wininet.dll2010-05-06 02:24 . 2010-05-06 02:22 38784 ------w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe2009-04-24 01:52 . 2008-03-20 01:20 5048 ------w- c:\program files\Winamp.ini2009-04-24 01:52 . 2008-03-20 01:19 212 ------w- c:\program files\winamp.m3u2008-10-24 04:16 . 2008-04-07 01:34 454656 ------w- c:\program files\putty.exe2008-01-18 02:26 . 2008-03-20 01:20 5543 ------w- c:\program files\studio.xnf2004-05-05 05:16 . 2008-03-20 01:19 3213 ------w- c:\program files\winampmb.htm2004-05-05 05:16 . 2008-03-20 01:19 272 ------w- c:\program files\Winamp.lks2004-03-26 14:54 . 2008-03-20 01:19 4587 ------w- c:\program files\Winamp.q12004-03-26 14:54 . 2008-03-20 01:20 43364 ------w- c:\program files\UninstWA.exe2004-02-05 05:36 . 2008-03-20 01:20 5887 ------w- c:\program files\whatsnew.txt2004-02-05 05:35 . 2008-03-20 01:20 968192 ------w- c:\program files\winamp.exe2003-12-13 00:50 . 2008-03-20 01:19 33792 ------w- c:\program files\winampa.exe2003-10-29 00:34 . 2008-03-20 01:20 110592 ------w- c:\program files\PXSDKPLS.dll2001-11-15 18:45 . 2008-03-20 01:20 38912 ------w- c:\program files\demo.mp32008-06-30 20:44 . 2009-04-30 19:13 324976 ------w- c:\program files\mozilla firefox\components\coFFPlgn.dll.ComboFix.txt Link to post Share on other sites More sharing options...
MrCharlie Posted August 4, 2010 ID:295324 Share Posted August 4, 2010 1. Close any open browsers.2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. 3. Open notepad and copy/paste the text in the quotebox below into it:DDS::uInternet Settings,ProxyServer = http=localhost:1046uInternet Settings,ProxyOverride =Save this as CFScript.txt, in the same location as ComboFix.exeRefering to the picture above, drag CFScript into ComboFix.exeCAUTION: Do not mouse-click ComboFix while it is running. It may cause it to stall.After reboot, (in case it asks to reboot)......When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.----------------------------------------------Please read carefully and follow these steps. Download TDSSKiller and save it to your Desktop.Doubleclick on TDSSKiller.exe to run the application, then on Start Scan.If an infected file is detected, the default action will be Cure, click on Continue.If a suspicious file is detected, the default action will be Skip, click on Continue.It may ask you to reboot the computer to complete the process. Click on Reboot Now. After the reboot (if it required) you'll find the log in C:\Please post it back here along with the log from ComboFix, MrC Link to post Share on other sites More sharing options...
econ1 Posted August 4, 2010 Author ID:295406 Share Posted August 4, 2010 Thanks. The registry seems ok now, except that I think that it was ok after the first reboot yesterday.Also, Ansi.sys does not work even though config.sys readsDEVICE=C:\WINDOWS\COMMAND\ANSI.SYSTDSSKiller.2.4.0.0_04.08.2010_08.24.03_log.txtComboFix.txt Link to post Share on other sites More sharing options...
MrCharlie Posted August 4, 2010 ID:295448 Share Posted August 4, 2010 I forget what those settings are from, but why do you want them gone?What are the symptoms?Here's where those settings are at:Open up Internet Explorer, and when the program is open, click on the Tools menu and then select Internet Options.Another way to get to your Internet Properties:Go to your Start Button > Run > copy and paste this in: inetcpl.cpl > Click OKNow click on the Connections Now click on the Lan Settings Make any changes thereLet me know, MrC Link to post Share on other sites More sharing options...
econ1 Posted August 4, 2010 Author ID:295545 Share Posted August 4, 2010 I know how to change the settings for a proxy server, but1. It is a nuisance to do it every time I log on.2. I am suspicious that the virus or whatever sets the proxy server in the registry to an address with ebay and disney & other companies. I assume it does that to do something bad.Thanks. Link to post Share on other sites More sharing options...
MrCharlie Posted August 4, 2010 ID:295565 Share Posted August 4, 2010 What are the symptoms that these entries give you when present?It could be one of your malware programs is preventing the fix or a program that you have keeps reinstalling them.------------------------------------Please do this:Download Security Check by screen317 from HERE or HERE.Save it to your Desktop.Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.A Notepad document should open automatically called checkup.txt; please post the contents of that document.MrC Link to post Share on other sites More sharing options...
econ1 Posted August 4, 2010 Author ID:295586 Share Posted August 4, 2010 It does not show anything. If nothing happens when I reboot tonight, I will not respond, thanking you right now.If not, I will pester you again tomorrow. Results of screen317's Security Check version 0.99.5 Windows XP Service Pack 3 Internet Explorer 8 `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Enabled! Norton AntiVirus Microsoft Security Essentials Antivirus up to date! (On Access scanning disabled!) ``````````````````````````````` Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware HijackThis 2.0.2 CCleaner Java 6 Update 15 Out of date Java installed! Adobe Flash Player 10.1.53.64 Adobe Reader 9.3.3 Chinese Simplified Fonts Support For Adobe Reader 9 Japanese Fonts Support For Adobe Reader 9 ```````````````````````````````` Process Check: objlist.exe by Laurent Norton ccSvcHst.exe Malwarebytes' Anti-Malware mbamservice.exe Malwarebytes' Anti-Malware mbamgui.exe Microsoft Small Business Business Contact Manager BcmSqlStartupSvc.exe ````````````````````````````````DNS Vulnerability Check: GREAT! (Not vulnerable to DNS cache poisoning) ``````````End of Log```````````` Link to post Share on other sites More sharing options...
MrCharlie Posted August 4, 2010 ID:295592 Share Posted August 4, 2010 Make sure you update your Java!-------------------------I found some info on those settings I think....Check the links below: (it's not malware, belongs to IE8)http://msdn.microsoft.com/en-us/library/dd...2(v=VS.85).aspxhttp://msdn.microsoft.com/en-us/library/dd565648(VS.85).aspxLet me know, MrC Link to post Share on other sites More sharing options...
econ1 Posted August 4, 2010 Author ID:295671 Share Posted August 4, 2010 The first 2 times I restarted, no problem. Now it has returned. Even worse, I do all of my research and writing with an old DOS program. For some reason, ANSI.SYS Link to post Share on other sites More sharing options...
econ1 Posted August 4, 2010 Author ID:295675 Share Posted August 4, 2010 The first 2 times I restarted, no problem. Now it has returned. Even worse, I do all of my research and writing with an old DOS program. For some reason, ANSI.SYS no longer works. I cannot figure out why. It appears in my config.sys program. Link to post Share on other sites More sharing options...
MrCharlie Posted August 5, 2010 ID:295718 Share Posted August 5, 2010 Did you read the 2 links I gave you? Please read through them.Here's how to change the settings: (I don't have IE8 so I can't confirm this)Select the Tools > Internet Options menu item.Select the Security tab. Select the Local intranet zone andEnsure that Enable Protected Mode is unchecked.Click the "Microsoft.com" link.------------------------------------ComboFix creates a restore point just before it runs, go to your system restore and restore the computer back to a point just before ComboFix ran.08/03/2010 13:41:25<----this is the first time you ran it.See if that restores the function that doesn't work now.MrC Link to post Share on other sites More sharing options...
MrCharlie Posted August 5, 2010 ID:295731 Share Posted August 5, 2010 Shouldn't it be in config.nt?Found this:Found the answer to my own question - so if anybody elseneeds to know - of the MANY copies of config.nt to befound you have to specifically modify the one contained inC:\windows\system32 - picking up Config.nt from any ofit's sources, (I386 is fine) and include the device=c:\I386\anis.sys line in the version of config.nt in the system32folder - all this has wasted about 3 hours so far...Thanks Link to post Share on other sites More sharing options...
econ1 Posted August 5, 2010 Author ID:295756 Share Posted August 5, 2010 There was no combofix restore file that I could find. I restored going back one month.I think that the last program I used was what did the damage. I don't know if I should start over since it did not really fix my problem. I will try to change the IE settings now. Link to post Share on other sites More sharing options...
MrCharlie Posted August 5, 2010 ID:296243 Share Posted August 5, 2010 The link below show you how to restore IE 8 back to defaults:http://support.microsoft.com/kb/923737MrC Link to post Share on other sites More sharing options...
Staff screen317 Posted August 29, 2010 Staff ID:306352 Share Posted August 29, 2010 Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.Other members who need assistance please start your own topic in a new thread. Thanks! Link to post Share on other sites More sharing options...
Recommended Posts