Link to home
Start Free TrialLog in
Avatar of locke2005
locke2005Flag for Brazil

asked on

my HijackThis log file

Logfile of HijackThis v1.99.1
Scan saved at 11:37:02, on 20/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe
C:\Arquivos de programas\Java\jre1.6.0_01\bin\jusched.exe
C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Driver Cache\explorer.exe
C:\Arquivos de programas\eMule\eMule.exe
C:\Arquivos de programas\HijackThis\HijackThis.exe
C:\Arquivos de programas\Mozilla Firefox\firefox.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsoft.com/intl/br/access/allinone.asp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Arquivos de programas\ICQToolbar\toolbaru.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\Arquivos de programas\ICQToolbar\toolbaru.dll
O2 - BHO: Facilitador de Leitor de Link Adobe PDF - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Arquivos comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Arquivos de programas\Free Download Manager\iefdmcks.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Arquivos de programas\ICQToolbar\toolbaru.dll
O4 - HKLM\..\Run: [avast!] C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Arquivos de programas\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [WhenUSave] "C:\Arquivos de programas\Save\Save.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Arquivos de programas\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Arquivos de programas\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Pesquisar - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARQUIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Arquivos de programas\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Arquivos de programas\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: DirectX Service (Rixyw) - Unknown owner - C:\WINDOWS\system32\directx.exe
SOLUTION
Avatar of davidwainwright
davidwainwright

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Avatar of rindi
rindi
Flag of Switzerland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of locke2005

ASKER

O4 - HKCU\..\Run: [WhenUSave] "C:\Arquivos de programas\Save\Save.exe" disappeared! Also, my computer is pop-ing IE browser windows of anti-virus and anti-spyware sites.
How do I block everything that I allowed on Mcafee Anti-virus?
I don't know mcafee enough, but I guess you could completely uninstall it, then reinstall mcafee.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
"Instead of Windows loading as normal, a menu with options should appear;"

The options that appear are something like:

Floopy Disk
IDE 0
IDE 1
Network
I used msconfig to go to safe mode. In safe mode, I started the script and, after 100% checked, "Acess Denied" appeared about 5 times. My anti-virus (Mcafee VirusScan) did not give me the alternative to "Grant Access".
***SDFix report removed by rpggamergirl, Zone Advisor***
I think the problem was the 5 accesses denied...
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
***Combofix log removed by rpggamergirl, Zone Advisor***
The message saying wpptrvnn.dll is not loading is gone (that's good). My computer is not poping up IE windows of anti-virus and anti-spywaresites (that's good). When Windows finishes loading, an error message says: "Explorer.EXE - No Disk", "There is no disk in unit. Insert a disk in unit A:.", "Cancel/Try again/Continue" (that's bad). What now?
oh-oh

the site br.errorsafe.com has just poped-up
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
"and for the error-safe infection:
http://www.error-safe-removal.com.removal-instructions.com/removeError_Safe.html"

In order to use the removal feature of Spyhunter, you must purchase a full version.
***Combofix log removed by rpggamergirl, Zone Advisor***
07/30/2007
07/30/07 06:58:40 [Info]: BlackLight Engine 1.0.64 initialized
07/30/07 06:58:40 [Info]: OS: 5.1 build 2600 (Service Pack 2)
07/30/07 06:58:40 [Note]: 7019 4
07/30/07 06:58:40 [Note]: 7005 0
07/30/07 06:58:44 [Note]: 7006 0
07/30/07 06:58:44 [Note]: 7011 1424
07/30/07 06:58:44 [Note]: 7026 0
07/30/07 06:58:44 [Note]: 7026 0
07/30/07 06:58:51 [Note]: FSRAW library version 1.7.1022
07/30/07 07:00:47 [Note]: 2000 1012
07/30/07 07:00:57 [Note]: 7007 0
PS 1: when I was running ComboFix with CFScript (I saved it as .txt), Mcafee asked me about 5 times to block or allow changes and about 4 times I was fast enough to select allow before Windows shutted down.

PS 2: after I finished running ComboFix, there was a ComboFix (without space) and a Combo Fix (with space) in the folder where I saved ComboFix.
That is the old combofix log,
can we look at the latest combofix log please.

Also run vundofix, these are actually vundo/conhook infection.
***Combofix log removed by rpggamergirl, Zone Advisor***
In order to remove *the selected objects*, you need to register your XoftSpySe now.

http://www.imagehosting.com/show.php/974936_1.jpg.html
http://www.imagehosting.com/show.php/974947_2.jpg.html

PS 3 it is really .jpg.html
By the way, when I was scanning with SpyScanner or XoftSpy, it scanned files of sites that I did not visit! The virus or spyware or trojan horse (what is it?), just created or even downloaded files. That was really scary...
I am runned VundoFix.

"Done searching for files."

"No infected files were found."
I *runned* VundoFix. By the way, 1st and 2nd time I runned it, no infected files were found!
My computer is behaving as if there is no infection. What is going on??? I am totally confused!!!
These could've been the vundo files that showing in your image link. When the infection is no longer active vundofix won't find anything eventhough some bad reg entries are still present. Combofix deleted a lot ot vundo files.


These two bad registry entries that combofix reported below are harmless:
this one below is a disabled startup entry in msconfig and the bad file is already gone.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MemoryManager]
rundll32.exe "C:\WINDOWS\system32\jqhtxgyf.dll",forkonce

this one below is an 02 line in Hijackthis which you can fix, the file is already missing.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{033A4CF7-5AFC-401D-9502-46D567E9CF27}]
                  C:\WINDOWS\system32\ssttr.dll



>>By the way, when I was scanning with SpyScanner or XoftSpy, it scanned files of sites that I did not visit!<<
You mean bad sites showing in your status bar while it is scanning? like how Spybot S&D checks for bots.
could just be checking if those threats are present in your system.
Not really sure about SpyHunter, it used to be listed as a rogue program.


>>My computer is behaving as if there is no infection. What is going on??? I am totally confused!!!<<
You mean pc seems normal, no problems?
You have deleted a lot bad files remember? What is confusing?
Avatar of justchat_1
justchat_1

XoftSpySE would have removed error safe
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Increased points to 500, because you deserve it!
Good to know that the problem is solved.

And we're glad to help, :)

Thanks for the points and excellent grading!