jcm26003
asked on
Caps reversed
I think I have a virus or spyware but can't find any info on how to get rid of it. My caps lock will reverse at random times and stay that way until my computer is restarted. My mouse also highlights everything when I try to select an item. I have switched keyboards and the mouse but the problem still persists. How do I get rid of this?
Could it be related to sticky-keys? You could try disabling all the special functions for type-aiding. Press the shift key 5 times in repetition and then click the Settings button. Uncheck all the boxes and maybe drill down to make sure sub-level boxes are also cleared.
ASKER
Already tried that. Nothing will disable the sticky-keys.
ASKER
Here is a link to someone else's description of the same problem. It's identical to what's happening on mine.
http://forums.techguy.org/general-security/793177-reverse-caps-lock-clicking-links.html
http://forums.techguy.org/general-security/793177-reverse-caps-lock-clicking-links.html
Could you please tell us what antivirus and antispyware solutions do you use on your PC? Do you use Spybot with TeaTimer enabled??
Also, do you have any Windows Customization software installed?? with addins for MS Office?
ASKER
No customized software or addins. I use AVG anti-virus and Spyware Terminator.
Can you scan with SuperAntiSpyware (www.superantispyware.com) and let us know what you find on your PC?
ASKER
Scanning now. I'll let you know.
What happens if you go into Safe Mode? Same results?
ASKER
I quarantined/removed 247 threats using "superantispyware." For the time being everything is working fine. I don't know though if it's because of the reboot or if I actually got rid of it. I'll keep you posted. If it happens again I'll start up in safe mode and see if it has the same problem.
Thats good! Keep us posted.
ASKER
I AM NOW BACK TO ALL CAPS> I WAS ON MY COMPUTER ALL DAY> IT TOOK ABOUT SIX OR SEVEN HOURS AND NOW IT"S BACK AT IT> GRRRR> NOW WHAT?
I see.... I suggest that you download ComboFix from: http://www.bleepingcomputer.com/combofix/how-to-use-combofix and save it with a different name like jabba.exe, then disable your existing antivirus and anti-spyware programs and run it. After ComboFix creates a log, then send us that log, reenable your antivirus and anti-spyware protection and run a full SuperAntiSpyware scan again.
ASKER
Here's the ComboFix log.
ComboFix 09-05-20.A1 - John ****** 05/21/2009 15:04.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18. 511.266 [GMT -4:00]
Running from: c:\documents and settings\John ******\Desktop\jabba.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-5 2D74245D6B F}
.
(((((((((((((((((((((((((( (((((((((( ((( Other Deletions )))))))))))))))))))))))))) )))))))))) )))))))))) )))
.
C:\check_LSA7.txt
c:\docume~1\JOHN**~1\LOCAL S~1\Temp\t mp1.tmp
c:\docume~1\JOHN**~1\LOCAL S~1\Temp\t mp2.tmp
c:\documents and settings\All Users\Application Data\SalesMonitor
c:\documents and settings\All Users\Application Data\WinAntiSpyware 2007
c:\documents and settings\All Users\Application Data\WinAntiSpyware 2007\Data\Abbr
c:\documents and settings\All Users\Application Data\WinAntiSpyware 2007\Data\ProductCode
c:\program files\Insider
c:\program files\Words
c:\program files\Words\list.txt
c:\program files\Words\script.txt
c:\temp\fse
c:\temp\sanR24
c:\windows\cookies.ini
c:\windows\IE4 Error Log.txt
c:\windows\system32\axyxtn lk.ini
c:\windows\system32\bqphgb wi.ini
c:\windows\system32\cccdd. ini
c:\windows\system32\cccdd. ini2
c:\windows\system32\dccdd. bak1
c:\windows\system32\dccdd. bak2
c:\windows\system32\dccdd. ini
c:\windows\system32\dccdd. ini2
c:\windows\system32\dccdd. tmp
c:\windows\system32\ddeeg. bak1
c:\windows\system32\ddeeg. bak2
c:\windows\system32\ddeeg. ini
c:\windows\system32\dgyhxd ex.ini
c:\windows\system32\f10WtR
c:\windows\system32\guehfd fw.ini
c:\windows\system32\iDlo01
c:\windows\system32\idqdqw cw.ini
c:\windows\system32\mcrh.t mp
c:\windows\system32\pac.tx t
c:\windows\system32\qxkxgd fs.ini
c:\windows\system32\tmp.re g
c:\windows\system32\tstwa. bak2
c:\windows\system32\tstwa. ini2
c:\windows\system32\tstwa. tmp
c:\windows\system32\uepuns br.ini
c:\windows\system32\Ultra. dll
c:\windows\system32\vtddpq qg.ini
c:\windows\system32\vvvwa. ini
c:\windows\system32\wknngo tu.ini
c:\windows\system32\xskhaf wd.ini
.
(((((((((((((((((((((((((( (((((((((( ((( Drivers/Services )))))))))))))))))))))))))) )))))))))) )))))))))) )))
.
-------\Legacy_DOMAINSERVI CE
-------\Legacy_FOPN
((((((((((((((((((((((((( Files Created from 2009-04-21 to 2009-05-21 )))))))))))))))))))))))))) )))))
.
2009-05-19 18:36 . 2009-05-19 18:36 -------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-19 18:34 . 2009-05-19 18:35 -------- d-----w c:\program files\SUPERAntiSpyware
2009-05-19 18:34 . 2009-05-19 18:34 -------- d-----w c:\documents and settings\John ******\Application Data\SUPERAntiSpyware.com
2009-05-19 18:34 . 2009-05-19 18:34 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-05-14 13:30 . 2009-05-14 13:31 -------- d-----w c:\program files\WinClamAVShield
2009-05-14 12:33 . 2009-05-14 12:33 -------- d-----w c:\program files\Crawler
2009-05-13 15:32 . 2009-05-13 15:32 -------- d-----w c:\documents and settings\NetworkService\Lo cal Settings\Application Data\Softonic_English
2009-05-12 20:08 . 2009-05-20 19:10 -------- d-----w c:\documents and settings\John ******\.gimp-2.6
2009-05-12 20:06 . 2009-05-12 20:08 -------- d-----w c:\documents and settings\John ******\.gegl-0.0
2009-05-12 20:06 . 2009-05-12 20:06 -------- d-----w c:\documents and settings\John ******\Local Settings\Application Data\Conduit
2009-05-12 20:06 . 2009-05-12 20:06 -------- d-----w c:\program files\Conduit
2009-05-12 20:06 . 2009-05-12 20:08 -------- d-----w c:\documents and settings\John ******\Local Settings\Application Data\Softonic_English
2009-05-12 20:06 . 2009-05-12 20:06 -------- d-----w c:\program files\Softonic_English
2009-05-12 20:01 . 2009-05-12 20:02 -------- d-----w c:\program files\GIMP-2.0
2009-04-28 16:05 . 2009-04-28 16:05 286720 ----a-w c:\windows\system32\swb_un inst.exe
2009-04-28 16:05 . 2009-04-28 16:05 -------- d-----w c:\program files\Instant Pre-Marital Inventory
2009-04-28 14:35 . 2009-04-28 19:43 -------- d-----w c:\documents and settings\All Users\Application Data\Yahoo! Companion
.
(((((((((((((((((((((((((( (((((((((( (((( Find3M Report )))))))))))))))))))))))))) )))))))))) )))))))))) ))))))
.
2009-05-21 18:47 . 2005-08-07 04:01 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-21 13:45 . 2007-11-07 19:04 -------- d-----w c:\program files\Spyware Terminator
2009-05-19 17:07 . 2009-03-26 13:46 11952 ----a-w c:\windows\system32\avgrss tx.dll
2009-05-19 17:07 . 2009-03-26 13:46 325896 ----a-w c:\windows\system32\driver s\avgldx86 .sys
2009-05-19 17:05 . 2009-03-26 13:46 108552 ----a-w c:\windows\system32\driver s\avgtdix. sys
2009-05-14 12:24 . 2005-08-07 03:59 -------- d-----w c:\program files\Java
2009-05-14 12:17 . 2006-11-03 22:48 -------- d-----w c:\program files\PCBugDoctor
2009-05-06 18:43 . 2005-08-30 18:15 114176 ----a-w c:\documents and settings\John ******\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-28 14:35 . 2005-08-17 16:43 -------- d-----w c:\program files\Yahoo!
2009-04-02 15:10 . 2006-06-18 19:21 -------- d-----w c:\program files\iTunes
2009-04-02 15:10 . 2005-09-21 15:26 -------- d-----w c:\program files\Google
2009-04-02 14:04 . 2009-04-02 14:04 -------- d-----w c:\program files\iPod
2009-04-02 13:48 . 2005-08-07 04:12 -------- d-----w c:\program files\QuickTime
2009-04-02 13:40 . 2009-04-02 13:39 -------- d-----w c:\program files\Apple Software Update
2009-04-02 13:38 . 2009-04-02 13:38 -------- d-----w c:\program files\Common Files\Apple
2009-03-26 13:45 . 2009-03-26 13:45 -------- d-----w c:\program files\AVG
2009-03-09 09:19 . 2008-12-10 20:46 410984 ----a-w c:\windows\system32\deploy tk.dll
2009-03-06 14:22 . 2004-08-10 17:51 284160 ----a-w c:\windows\system32\pdh.dl l
2009-03-03 00:18 . 2004-08-10 17:51 826368 ----a-w c:\windows\system32\winine t.dll
2007-11-14 21:29 . 2007-11-14 21:28 6872 --sha-w c:\windows\system32\yybeg. tmp
.
(((((((((((((((((((((((((( (((((((((( ( Reg Loading Points )))))))))))))))))))))))))) )))))))))) )))))))))) ))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Brow ser Helper Objects\{930f1200-f5f1-487 0-bac6-e23 3ec8e7023} ]
2009-03-10 15:47 2079256 ----a-w c:\program files\Softonic_English\tbS oft.dll
[HKEY_CURRENT_USER\SOFTWAR E\Microsof t\Windows\ CurrentVer sion\Run]
"ctfmon.exe"="c:\windows\s ystem32\ct fmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe " [2008-04-14 1695232]
"swg"="c:\program files\Google\GoogleToolbar Notifier\G oogleToolb arNotifier .exe" [2007-06-25 68856]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtectio n.exe" [2009-02-23 111856]
"SUPERAntiSpyware"="c:\pro gram files\SUPERAntiSpyware\SUP ERAntiSpyw are.exe" [2009-05-14 1830128]
[HKEY_LOCAL_MACHINE\SOFTWA RE\Microso ft\Windows \CurrentVe rsion\Run]
"Motive SmartBridge"="c:\progra~1\ VERIZO~1\H ELPSU~1\SM ARTB~1\Mot iveSB.exe" [2003-12-10 380928]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\reals ched.exe" [2005-09-21 180269]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"AVG8_TRAY"="c:\progra~1\A VG\AVG8\av gtray.exe" [2009-05-19 1947928]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe " [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper. exe" [2009-03-13 342312]
"YSearchProtection"="c:\pr ogram files\Yahoo!\Search Protection\SearchProtectio n.exe" [2009-02-23 111856]
"SunJavaUpdateSched"="c:\p rogram files\Java\jre6\bin\jusche d.exe" [2009-03-09 148888]
"SpywareTerminator"="c:\pr ogram files\Spyware Terminator\SpywareTerminat orShield.e xe" [2007-11-07 2834432]
[HKEY_USERS\.DEFAULT\Softw are\Micros oft\Window s\CurrentV ersion\Run ]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM .exe" [2007-08-14 5562368]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
[hkey_local_machine\softwa re\microso ft\windows \currentve rsion\expl orer\Shell ExecuteHoo ks]
"{5AE067D3-9AFB-48E0-853A- EBB7F4A000 DA}"= "c:\program files\SUPERAntiSpyware\SAS SEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\softwa re\microso ft\windows nt\currentversion\winlogon \notify\!S ASWinLogon ]
2008-12-22 16:05 356352 ----a-w c:\program files\SUPERAntiSpyware\SAS WINLO.dll
[HKEY_LOCAL_MACHINE\softwa re\microso ft\windows nt\currentversion\winlogon \notify\av grsstarter ]
2009-05-19 17:07 11952 ----a-w c:\windows\system32\avgrss tx.dll
[HKLM\~\startupfolder\C:^D ocuments and Settings^All Users^Start Menu^Programs^Startup^Amer ica Online 9.0 Tray Icon.lnk]
[HKLM\~\startupfolder\C:^D ocuments and Settings^All Users^Start Menu^Programs^Startup^Digi tal Line Detect.lnk]
[HKLM\~\startupfolder\C:^D ocuments and Settings^All Users^Start Menu^Programs^Startup^Micr osoft Office.lnk]
[HKLM\~\startupfolder\C:^D ocuments and Settings^All Users^Start Menu^Programs^Startup^Quic kBooks Update Agent.lnk]
[HKLM\~\startupfolder\C:^D ocuments and Settings^All Users^Start Menu^Programs^Startup^Veri zon Online Help & Support.lnk]
[HKLM\~\startupfolder\C:^D ocuments and Settings^All Users^Start Menu^Programs^Startup^Veri zon Support Service.lnk]
HKEY_LOCAL_MACHINE\softwar e\microsof t\shared tools\msconfig\startupreg\ ccApp
HKEY_LOCAL_MACHINE\softwar e\microsof t\shared tools\msconfig\startupreg\ IS CfgWiz
HKEY_LOCAL_MACHINE\softwar e\microsof t\shared tools\msconfig\startupreg\ SSC_UserPr ompt
[HKLM\~\services\sharedacc ess\parame ters\firew allpolicy\ standardpr ofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedacc ess\parame ters\firew allpolicy\ standardpr ofile\Auth orizedAppl ications\L ist]
"%windir%\\system32\\sessm gr.exe"=
"c:\\WINDOWS\\system32\\sp ool\\drive rs\\w32x86 \\3\\SAGEN T4.EXE"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolloa d.exe"=
"c:\\Program Files\\Common Files\\AOL\\1141843405\\ee \\aolsoftw are.exe"=
"c:\\Program Files\\Common Files\\AOL\\1141843405\\ee \\aim6.exe "=
"c:\\Program Files\\Yahoo!\\Messenger\\ YahooMesse nger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe" =
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.e xe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall. exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Messenger\\msmsgs.e xe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.e xe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.e xe"=
"c:\\Program Files\\iTunes\\iTunes.exe" =
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\dr ivers\avgl dx86.sys [3/26/2009 09:46 AM 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\syst em32\drive rs\avgtdix .sys [3/26/2009 09:46 AM 108552]
R1 SASDIFSV;SASDIFSV;c:\progr am files\SUPERAntiSpyware\sas difsv.sys [5/14/2009 02:22 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\progr am files\SUPERAntiSpyware\SAS KUTIL.SYS [5/14/2009 02:22 PM 72944]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\driv ers\sp_rsd rv2.sys [9/14/2007 09:40 PM 138752]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\A VG8\avgwds vc.exe [3/26/2009 09:45 AM 298776]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\Vie wpointServ ice.exe [5/2/2007 04:12 PM 24652]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SAS ENUM.SYS [5/14/2009 02:22 PM 7408]
S3 VQ630;VQ630 Dual Mode Digital Camera;c:\windows\system32 \drivers\v qppcam.sys [7/15/2002 10:20 AM 468384]
S3 VQ630BLK;VQ630 Dual Mode Digital Camera(Bulk);c:\windows\sy stem32\dri vers\vqbul k.sys [11/29/2001 08:11 AM 28536]
S4 WinDefend;Windows Defender Service;c:\program files\Windows Defender\MsMpEng.exe [4/3/2006 06:12 PM 14032]
.
Contents of the 'Scheduled Tasks' folder
2009-05-20 c:\windows\Tasks\AppleSoft wareUpdate .job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-05-21 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterServi ce.exe [2007-01-26 13:45]
2009-05-20 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-04-03 22:12]
.
- - - - ORPHANS REMOVED - - - -
BHO-{53b2c80b-1f9b-4348-81 ce-ff6cf5f 2ace1} - (no file)
BHO-{59AA5B93-4140-4081-B1 EC-8B0E58E A90AC} - (no file)
BHO-{6C1C4556-E2C4-4F2D-99 79-F8118AA 09375} - (no file)
BHO-{7FE56D3C-1F30-4978-99 6F-0A6E816 48996} - (no file)
BHO-{ADCF7E27-F13D-45FA-B8 67-E0609B5 1EC58} - (no file)
BHO-{C28A3379-3901-4DA0-84 06-4FF9B9F 57F75} - (no file)
HKCU-Run-Aim6 - (no file)
HKLM-Run-RegistryMechanic - (no file)
Notify-ddccyww - ddccyww.dll
Notify-xxyvsts - xxyvsts.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.christ4today.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourc eid=ie7&rl s=com.micr osoft:en-U S&ie=utf8& oe=utf8
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/cus tomize/ie/ defaults/s b/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/cus tomize/ie/ defaults/s u/msgr9/*http://www.yahoo.com
IE: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\ search.htm l
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch .htm
IE: Crawler Search - tbr:iemenu
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFIC E11\EXCEL. EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict .htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap. htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms. htm
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B 719FE26E37 7} - c:\program files\Google\Google Toolbar\Component\fastsear ch_A8904FB 862BD9564. dll
Handler: tbr - {4D25FB7A-8902-4291-960E-9 ADA051CFBB F} - c:\progra~1\Crawler\Toolba r\ctbr.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\cla sses\xmlds o.cab
DPF: {051D0E35-F4E3-4C8D-B411-A B0875F4C68 3} - hxxp://install.anark.com/c lient/vers ion4/windo ws-ie/en/A MClient.ca b
DPF: {52A5CD24-64C6-4BAF-A4EC-4 D13F451763 F} - hxxps://www.cuworld.com/PIC/inner_pic/packages/CUworld.cab
.
************************** ********** ********** ********** ********** ********
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-21 15:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************** ********** ********** ********** ********** ********
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(676)
c:\program files\SUPERAntiSpyware\SAS WINLO.dll
c:\windows\system32\Ati2ev xx.dll
- - - - - - - > 'explorer.exe'(2468)
c:\progra~1\VERIZO~1\HELPS U~1\SMARTB ~1\SBHook. dll
c:\windows\system32\WPDShS erviceObj. dll
c:\windows\system32\Portab leDeviceTy pes.dll
c:\windows\system32\Portab leDeviceAp i.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2ev xx.exe
c:\windows\system32\ati2ev xx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev iceService .exe
c:\program files\Java\jre6\bin\jqs.ex e
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Dell\NicConfigSvc\Ni cConfigSvc .exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgns x.exe
c:\program files\Yahoo!\SoftwareUpdat e\YahooAUS ervice.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\windows\system32\wscntf y.exe
c:\program files\iPod\bin\iPodService .exe
.
************************** ********** ********** ********** ********** ********
.
Completion time: 2009-05-21 15:20 - machine was rebooted
ComboFix-quarantined-files .txt 2009-05-21 19:20
Pre-Run: 854,228,992 bytes free
Post-Run: 1,967,407,104 bytes free
WindowsXP-KB310994-SP2-Hom e-BootDisk -ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdi sk(0)parti tion(2)\WI NDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="M icrosoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)par tition(2)\ WINDOWS="M icrosoft Windows XP Home Edition" /noexecute=optin /fastdetect
263 --- E O F --- 2009-05-13 07:22
ComboFix 09-05-20.A1 - John ****** 05/21/2009 15:04.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.
Running from: c:\documents and settings\John ******\Desktop\jabba.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-5
.
((((((((((((((((((((((((((
.
C:\check_LSA7.txt
c:\docume~1\JOHN**~1\LOCAL
c:\docume~1\JOHN**~1\LOCAL
c:\documents and settings\All Users\Application Data\SalesMonitor
c:\documents and settings\All Users\Application Data\WinAntiSpyware 2007
c:\documents and settings\All Users\Application Data\WinAntiSpyware 2007\Data\Abbr
c:\documents and settings\All Users\Application Data\WinAntiSpyware 2007\Data\ProductCode
c:\program files\Insider
c:\program files\Words
c:\program files\Words\list.txt
c:\program files\Words\script.txt
c:\temp\fse
c:\temp\sanR24
c:\windows\cookies.ini
c:\windows\IE4 Error Log.txt
c:\windows\system32\axyxtn
c:\windows\system32\bqphgb
c:\windows\system32\cccdd.
c:\windows\system32\cccdd.
c:\windows\system32\dccdd.
c:\windows\system32\dccdd.
c:\windows\system32\dccdd.
c:\windows\system32\dccdd.
c:\windows\system32\dccdd.
c:\windows\system32\ddeeg.
c:\windows\system32\ddeeg.
c:\windows\system32\ddeeg.
c:\windows\system32\dgyhxd
c:\windows\system32\f10WtR
c:\windows\system32\guehfd
c:\windows\system32\iDlo01
c:\windows\system32\idqdqw
c:\windows\system32\mcrh.t
c:\windows\system32\pac.tx
c:\windows\system32\qxkxgd
c:\windows\system32\tmp.re
c:\windows\system32\tstwa.
c:\windows\system32\tstwa.
c:\windows\system32\tstwa.
c:\windows\system32\uepuns
c:\windows\system32\Ultra.
c:\windows\system32\vtddpq
c:\windows\system32\vvvwa.
c:\windows\system32\wknngo
c:\windows\system32\xskhaf
.
((((((((((((((((((((((((((
.
-------\Legacy_DOMAINSERVI
-------\Legacy_FOPN
((((((((((((((((((((((((( Files Created from 2009-04-21 to 2009-05-21 ))))))))))))))))))))))))))
.
2009-05-19 18:36 . 2009-05-19 18:36 -------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-19 18:34 . 2009-05-19 18:35 -------- d-----w c:\program files\SUPERAntiSpyware
2009-05-19 18:34 . 2009-05-19 18:34 -------- d-----w c:\documents and settings\John ******\Application Data\SUPERAntiSpyware.com
2009-05-19 18:34 . 2009-05-19 18:34 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-05-14 13:30 . 2009-05-14 13:31 -------- d-----w c:\program files\WinClamAVShield
2009-05-14 12:33 . 2009-05-14 12:33 -------- d-----w c:\program files\Crawler
2009-05-13 15:32 . 2009-05-13 15:32 -------- d-----w c:\documents and settings\NetworkService\Lo
2009-05-12 20:08 . 2009-05-20 19:10 -------- d-----w c:\documents and settings\John ******\.gimp-2.6
2009-05-12 20:06 . 2009-05-12 20:08 -------- d-----w c:\documents and settings\John ******\.gegl-0.0
2009-05-12 20:06 . 2009-05-12 20:06 -------- d-----w c:\documents and settings\John ******\Local Settings\Application Data\Conduit
2009-05-12 20:06 . 2009-05-12 20:06 -------- d-----w c:\program files\Conduit
2009-05-12 20:06 . 2009-05-12 20:08 -------- d-----w c:\documents and settings\John ******\Local Settings\Application Data\Softonic_English
2009-05-12 20:06 . 2009-05-12 20:06 -------- d-----w c:\program files\Softonic_English
2009-05-12 20:01 . 2009-05-12 20:02 -------- d-----w c:\program files\GIMP-2.0
2009-04-28 16:05 . 2009-04-28 16:05 286720 ----a-w c:\windows\system32\swb_un
2009-04-28 16:05 . 2009-04-28 16:05 -------- d-----w c:\program files\Instant Pre-Marital Inventory
2009-04-28 14:35 . 2009-04-28 19:43 -------- d-----w c:\documents and settings\All Users\Application Data\Yahoo! Companion
.
((((((((((((((((((((((((((
.
2009-05-21 18:47 . 2005-08-07 04:01 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-21 13:45 . 2007-11-07 19:04 -------- d-----w c:\program files\Spyware Terminator
2009-05-19 17:07 . 2009-03-26 13:46 11952 ----a-w c:\windows\system32\avgrss
2009-05-19 17:07 . 2009-03-26 13:46 325896 ----a-w c:\windows\system32\driver
2009-05-19 17:05 . 2009-03-26 13:46 108552 ----a-w c:\windows\system32\driver
2009-05-14 12:24 . 2005-08-07 03:59 -------- d-----w c:\program files\Java
2009-05-14 12:17 . 2006-11-03 22:48 -------- d-----w c:\program files\PCBugDoctor
2009-05-06 18:43 . 2005-08-30 18:15 114176 ----a-w c:\documents and settings\John ******\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-28 14:35 . 2005-08-17 16:43 -------- d-----w c:\program files\Yahoo!
2009-04-02 15:10 . 2006-06-18 19:21 -------- d-----w c:\program files\iTunes
2009-04-02 15:10 . 2005-09-21 15:26 -------- d-----w c:\program files\Google
2009-04-02 14:04 . 2009-04-02 14:04 -------- d-----w c:\program files\iPod
2009-04-02 13:48 . 2005-08-07 04:12 -------- d-----w c:\program files\QuickTime
2009-04-02 13:40 . 2009-04-02 13:39 -------- d-----w c:\program files\Apple Software Update
2009-04-02 13:38 . 2009-04-02 13:38 -------- d-----w c:\program files\Common Files\Apple
2009-03-26 13:45 . 2009-03-26 13:45 -------- d-----w c:\program files\AVG
2009-03-09 09:19 . 2008-12-10 20:46 410984 ----a-w c:\windows\system32\deploy
2009-03-06 14:22 . 2004-08-10 17:51 284160 ----a-w c:\windows\system32\pdh.dl
2009-03-03 00:18 . 2004-08-10 17:51 826368 ----a-w c:\windows\system32\winine
2007-11-14 21:29 . 2007-11-14 21:28 6872 --sha-w c:\windows\system32\yybeg.
.
((((((((((((((((((((((((((
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Brow
2009-03-10 15:47 2079256 ----a-w c:\program files\Softonic_English\tbS
[HKEY_CURRENT_USER\SOFTWAR
"ctfmon.exe"="c:\windows\s
"MSMSGS"="c:\program files\Messenger\msmsgs.exe
"swg"="c:\program files\Google\GoogleToolbar
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtectio
"SUPERAntiSpyware"="c:\pro
[HKEY_LOCAL_MACHINE\SOFTWA
"Motive SmartBridge"="c:\progra~1\
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\reals
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"AVG8_TRAY"="c:\progra~1\A
"QuickTime Task"="c:\program files\QuickTime\qttask.exe
"iTunesHelper"="c:\program
"YSearchProtection"="c:\pr
"SunJavaUpdateSched"="c:\p
"SpywareTerminator"="c:\pr
[HKEY_USERS\.DEFAULT\Softw
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
[hkey_local_machine\softwa
"{5AE067D3-9AFB-48E0-853A-
[HKEY_LOCAL_MACHINE\softwa
2008-12-22 16:05 356352 ----a-w c:\program files\SUPERAntiSpyware\SAS
[HKEY_LOCAL_MACHINE\softwa
2009-05-19 17:07 11952 ----a-w c:\windows\system32\avgrss
[HKLM\~\startupfolder\C:^D
[HKLM\~\startupfolder\C:^D
[HKLM\~\startupfolder\C:^D
[HKLM\~\startupfolder\C:^D
[HKLM\~\startupfolder\C:^D
[HKLM\~\startupfolder\C:^D
HKEY_LOCAL_MACHINE\softwar
HKEY_LOCAL_MACHINE\softwar
HKEY_LOCAL_MACHINE\softwar
[HKLM\~\services\sharedacc
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedacc
"%windir%\\system32\\sessm
"c:\\WINDOWS\\system32\\sp
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolloa
"c:\\Program Files\\Common Files\\AOL\\1141843405\\ee
"c:\\Program Files\\Common Files\\AOL\\1141843405\\ee
"c:\\Program Files\\Yahoo!\\Messenger\\
"%windir%\\Network Diagnostic\\xpnetdiag.exe"
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.e
"c:\\Program Files\\Windows Live\\Messenger\\livecall.
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Messenger\\msmsgs.e
"c:\\Program Files\\AVG\\AVG8\\avgupd.e
"c:\\Program Files\\AVG\\AVG8\\avgnsx.e
"c:\\Program Files\\iTunes\\iTunes.exe"
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\dr
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\syst
R1 SASDIFSV;SASDIFSV;c:\progr
R1 SASKUTIL;SASKUTIL;c:\progr
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\driv
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\A
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\Vie
R3 SASENUM;SASENUM;c:\program
S3 VQ630;VQ630 Dual Mode Digital Camera;c:\windows\system32
S3 VQ630BLK;VQ630 Dual Mode Digital Camera(Bulk);c:\windows\sy
S4 WinDefend;Windows Defender Service;c:\program files\Windows Defender\MsMpEng.exe [4/3/2006 06:12 PM 14032]
.
Contents of the 'Scheduled Tasks' folder
2009-05-20 c:\windows\Tasks\AppleSoft
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-05-21 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google
2009-05-20 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-04-03 22:12]
.
- - - - ORPHANS REMOVED - - - -
BHO-{53b2c80b-1f9b-4348-81
BHO-{59AA5B93-4140-4081-B1
BHO-{6C1C4556-E2C4-4F2D-99
BHO-{7FE56D3C-1F30-4978-99
BHO-{ADCF7E27-F13D-45FA-B8
BHO-{C28A3379-3901-4DA0-84
HKCU-Run-Aim6 - (no file)
HKLM-Run-RegistryMechanic - (no file)
Notify-ddccyww - ddccyww.dll
Notify-xxyvsts - xxyvsts.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.christ4today.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourc
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/cus
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/cus
IE: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch
IE: Crawler Search - tbr:iemenu
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFIC
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B
Handler: tbr - {4D25FB7A-8902-4291-960E-9
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\cla
DPF: {051D0E35-F4E3-4C8D-B411-A
DPF: {52A5CD24-64C6-4BAF-A4EC-4
.
**************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-21 15:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(676)
c:\program files\SUPERAntiSpyware\SAS
c:\windows\system32\Ati2ev
- - - - - - - > 'explorer.exe'(2468)
c:\progra~1\VERIZO~1\HELPS
c:\windows\system32\WPDShS
c:\windows\system32\Portab
c:\windows\system32\Portab
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2ev
c:\windows\system32\ati2ev
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
c:\program files\Java\jre6\bin\jqs.ex
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Dell\NicConfigSvc\Ni
c:\program files\Spyware Terminator\sp_rsser.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgns
c:\program files\Yahoo!\SoftwareUpdat
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\windows\system32\wscntf
c:\program files\iPod\bin\iPodService
.
**************************
.
Completion time: 2009-05-21 15:20 - machine was rebooted
ComboFix-quarantined-files
Pre-Run: 854,228,992 bytes free
Post-Run: 1,967,407,104 bytes free
WindowsXP-KB310994-SP2-Hom
[boot loader]
timeout=2
default=multi(0)disk(0)rdi
[operating systems]
c:\cmdcons\BOOTSECT.DAT="M
multi(0)disk(0)rdisk(0)par
263 --- E O F --- 2009-05-13 07:22
Thanks for sending the log. Its best to do a SuperAntiSpyware scan now, I will analyse the ComboFix log in the meanwhile.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
This seemed to do the trick. I left my computer running for several days while out of town. So far so good. I'll be back if there is any more trouble.
ASKER
Oh. And thank you!
Thanks for the feedback, glad I could be of help :).
You can uninstall ComboFix as follows >
Start > Run > then type "ComboFix /u" (with no quotes, and space between x and / )
Then hit enter. This will uninstall ComboFix, reset your clock settings, re-hide system hidden files, re-hide the file extensions and reset System Restore.
You can uninstall ComboFix as follows >
Start > Run > then type "ComboFix /u" (with no quotes, and space between x and / )
Then hit enter. This will uninstall ComboFix, reset your clock settings, re-hide system hidden files, re-hide the file extensions and reset System Restore.