Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: HELP!!!! cftmona  (Read 5516 times)

0 Members and 1 Guest are viewing this topic.

erocktattoo

    Topic Starter


    Beginner

    HELP!!!! cftmona
    « on: May 14, 2008, 05:38:12 PM »
    I get this picture on my desktop when I start my computer:





    The image is located in my system32 folder and is named cftmonb, the cftmona file is next to it and was created the same time as this image. I cant delete the cftmona and the image restores itself at each startup if I delete it. HELP!!!
    Pics of files on my drive:


    I am using an HP Pavillion dv8000 and running Windows XP.

    I got a pop up that said cftmona is trying to get an internet connection so I checked off "never allow".

    Should I use killbox to delete these files?

    patio

    • Moderator


    • Genius
    • Maud' Dib
    • Thanked: 1769
      • Yes
    • Experience: Beginner
    • OS: Windows 7
    Re: HELP!!!! cftmona
    « Reply #1 on: May 14, 2008, 05:48:53 PM »
    " Anyone who goes to a psychiatrist should have his head examined. "

    erocktattoo

      Topic Starter


      Beginner

      Re: HELP!!!! cftmona
      « Reply #2 on: May 14, 2008, 07:38:05 PM »
      Heres the log file:

      SUPERAntiSpyware Scan Log
      http://www.superantispyware.com

      Generated 05/14/2008 at 09:26 PM

      Application Version : 4.0.1154

      Core Rules Database Version : 3461
      Trace Rules Database Version: 1452

      Scan type       : Quick Scan
      Total Scan Time : 00:52:25

      Memory items scanned      : 611
      Memory threats detected   : 1
      Registry items scanned    : 460
      Registry threats detected : 2
      File items scanned        : 107800
      File threats detected     : 3

      Trojan.Unclassified/CTFMONA
         C:\WINDOWS\SYSTEM32\CTFMONA.EXE
         C:\WINDOWS\SYSTEM32\CTFMONA.EXE
         [ctfmona] C:\WINDOWS\SYSTEM32\CTFMONA.EXE

      Adware.Vundo Variant
         HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{CA4F0D8D-5F2B-4F16-838A-8D52249EAB21}

      Trojan.Unknown Origin
         C:\DOCUMENTS AND SETTINGS\ERICK\DESKTOP\CTFMON\CTFMONB.BMP
         C:\WINDOWS\SYSTEM32\CTFMONB.BMP

      evilfantasy

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Calm like a bomb
      • Thanked: 493
      • Experience: Experienced
      • OS: Windows 11
      Re: HELP!!!! cftmona
      « Reply #3 on: May 14, 2008, 08:09:50 PM »
      Two more logs needed.

      erocktattoo

        Topic Starter


        Beginner

        Re: HELP!!!! cftmona
        « Reply #4 on: May 14, 2008, 10:47:31 PM »
        Here's the malware log:

        Malwarebytes' Anti-Malware 1.12
        Database version: 750

        Scan type: Full Scan (C:\|)
        Objects scanned: 259605
        Time elapsed: 1 hour(s), 23 minute(s), 42 second(s)

        Memory Processes Infected: 0
        Memory Modules Infected: 0
        Registry Keys Infected: 2
        Registry Values Infected: 0
        Registry Data Items Infected: 0
        Folders Infected: 0
        Files Infected: 13

        Memory Processes Infected:
        (No malicious items detected)

        Memory Modules Infected:
        (No malicious items detected)

        Registry Keys Infected:
        HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer

        Bars\{1fe2ebe5-42ff-4586-a144-ca420c84ff6a} (Adware.ISM) -> Quarantined and

        deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) ->

        Quarantined and deleted successfully.

        Registry Values Infected:
        (No malicious items detected)

        Registry Data Items Infected:
        (No malicious items detected)

        Folders Infected:
        (No malicious items detected)

        Files Infected:
        C:\RECYCLER\NPROTECT\00140831 (Trojan.FakeAlert) -> Quarantined and deleted

        successfully.
        C:\RECYCLER\NPROTECT\00140832 (Malware.Trace) -> Quarantined and deleted

        successfully.
        C:\RECYCLER\NPROTECT\00140833 (Trojan.FakeAlert) -> Quarantined and deleted

        successfully.
        C:\RECYCLER\NPROTECT\00140834 (Malware.Trace) -> Quarantined and deleted

        successfully.
        C:\RECYCLER\NPROTECT\00140835.EXE (Trojan.FakeAlert) -> Quarantined and

        deleted successfully.
        C:\RECYCLER\NPROTECT\00140836.BMP (Malware.Trace) -> Quarantined and

        deleted successfully.
        C:\RECYCLER\NPROTECT\00140837.BMP (Malware.Trace) -> Quarantined and

        deleted successfully.
        C:\System Volume Information\_restore{92EC12A7-009B-4D77-899D-

        FF91068A8284}\RP2\A0000020.scr (Trojan.Agent) -> Quarantined and deleted

        successfully.
        C:\WINDOWS\system32\blackster.scr (Trojan.Agent) -> Quarantined and deleted

        successfully.
        C:\WINDOWS\system32\winivstr.exe (Trojan.FakeAlert) -> Quarantined and

        deleted successfully.
        C:\Documents and Settings\Erick\Local Settings\Temp\.tt2.tmp

        (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Erick\Local Settings\Temp\.tt3.tmp

        (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Documents and Settings\Erick\Local Settings\Temp\.tt4.tmp

        (Trojan.Downloader) -> Quarantined and deleted successfully.

        erocktattoo

          Topic Starter


          Beginner

          Re: HELP!!!! cftmona
          « Reply #5 on: May 14, 2008, 11:17:12 PM »
          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 1:15:39 AM, on 5/15/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
          c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
          c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
          C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F

          -2F227FCA9A08}\PIFSvc.exe
          c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
          c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
          C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\RUNDLL32.EXE
          C:\Program Files\Common Files\Apple\Mobile Device

          Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          C:\Program Files\Common Files\Symantec Shared\ccApp.exe
          C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
          C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
          C:\WINDOWS\eHome\ehRecvr.exe
          C:\WINDOWS\eHome\ehSched.exe
          C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
          C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
          C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
          c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
          C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
          C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
          C:\WINDOWS\system32\nvsvc32.exe
          C:\WINDOWS\system32\HPZipm12.exe
          C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Vongo\VongoService.exe
          C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
          C:\WINDOWS\system32\mqsvc.exe
          C:\WINDOWS\system32\mqtgsvc.exe
          C:\WINDOWS\system32\dllhost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Vongo\Tray.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =

          http://us.rd.yahoo.com/customize/ie/defaults/sp/ymj/*http://www.yahoo.com
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

          http://www.yahoo.com/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

          http://ie.redirect.hp.com/svs/rdr?

          TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

          http://us.rd.yahoo.com/customize/ie/defaults/su/ymj/*http://www.yahoo.com
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =

          http://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/e

          xt/search/search.html
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

          http://us.rd.yahoo.com/customize/ie/defaults/sp/ymj/*http://www.yahoo.com
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =

          http://us.rd.yahoo.com/customize/ie/defaults/su/ymj/*http://www.yahoo.com
          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =

          http://ie.redirect.hp.com/svs/rdr?

          TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -

          C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Program

          Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
          O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} -

          c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program

          files\google\googletoolbar1.dll
          O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -

          C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32

          \NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32

          \NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
          O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
          O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut]

          CHDAudPropShortcut.exe
          O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec

          Shared\ccApp.exe"
          O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch

          Buttons\QlbCtrl.exe /Start
          O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common

          Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}

          \PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec

          Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
          O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch

          Jukebox\mm_tray.exe"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe"

          -atboottime
          O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common

          Files\InstallShield\UpdateService\ISUSPM.exe" -startup
          O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_05

          \bin\jusched.exe
          O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program

          Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
          O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe

          (User 'SYSTEM')
          O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe

          (User 'Default user')
          O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program

          Files\Vongo\Tray.exe (User 'Default user')
          O4 - Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe
          O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Adobe

          Acrobat 6.0\Distillr\acrotray.exe
          O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common

          Files\Adobe\Calibration\Adobe Gamma Loader.exe
          O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program

          Files\Hp\Digital Imaging\bin\hpqthb08.exe
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft

          Office\Office\OSA9.EXE
          O8 - Extra context menu item: &Google Search - res://C:\Program

          Files\Google\GoogleToolbar1.dll/cmsearch.html
          O8 - Extra context menu item: &Translate English Word - res://C:\Program

          Files\Google\GoogleToolbar1.dll/cmwordtrans.html
          O8 - Extra context menu item: Backward Links - res://C:\Program

          Files\Google\GoogleToolbar1.dll/cmbacklinks.html
          O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program

          Files\Google\GoogleToolbar1.dll/cmcache.html
          O8 - Extra context menu item: E&xport to Microsoft Excel -

          res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
          O8 - Extra context menu item: Similar Pages - res://C:\Program

          Files\Google\GoogleToolbar1.dll/cmsimilar.html
          O8 - Extra context menu item: Translate Page into English -

          res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

          C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-

          00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

          C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} -

          C:\Program Files\UltimateBet\UltimateBet.exe
          O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-

          2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
          O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} -

          C:\PROGRA~1\AIM\aim.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

          C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-

          00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?

          TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
          O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin

          Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -

          http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client

          /muweb_site.cab?1210812860062
          O20 - Winlogon Notify: !SASWinLogon - C:\Program

          Files\SUPERAntiSpyware\SASWINLO.dll
          O20 - Winlogon Notify: tuvttqn - tuvttqn.dll (file missing)
          O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common

          Files\Adobe Systems Shared\Service\Adobelmsvc.exe
          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common

          Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation -

          C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -

          c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
          O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc)

          - Symantec Corporation - c:\Program Files\Norton Internet

          Security\ccPwdSvc.exe
          O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation -

          c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
          O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation

          - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
          O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program

          Files\Norton Internet Security\comHost.exe
          O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. -

          C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision

          Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel

          32\IDriverT.exe
          O23 - Service: iPod Service - Apple Inc. - C:\Program

          Files\iPod\bin\iPodService.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service

          (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common

          Files\LightScribe\LSSrvc.exe
          O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1

          \Symantec\LIVEUP~1\LUCOMS~1.EXE
          O23 - Service: LiveUpdate Notice Service - Symantec Corporation -

          C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F

          -2F227FCA9A08}\PIFSvc.exe
          O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec

          Corporation - c:\Program Files\Norton Internet Security\Norton

          AntiVirus\navapsvc.exe
          O23 - Service: Norton Unerase Protection (NProtectService) - Symantec

          Corporation - C:\Program Files\Norton SystemWorks\Norton

          Utilities\NPROTECT.EXE
          O23 - Service: Norton Protection Center Service (NSCService) - Symantec

          Corporation - C:\Program Files\Common Files\Symantec Shared\Security

          Console\NSCSRVCE.EXE
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -

          C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
          O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation -

          c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
          O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec

          Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
          O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation -

          c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
          O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1

          \NORTON~2\SPEEDD~1\nopdb.exe
          O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common

          Files\Symantec Shared\CCPD-LC\symlcsvc.exe
          O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program

          Files\Vongo\VongoService.exe

          --
          End of file - 11940 bytes

          Broni


            Mastermind
          • Kraków my love :)
          • Thanked: 614
            • Computer Help Forum
          • Computer: Specs
          • Experience: Experienced
          • OS: Windows 8
          Re: HELP!!!! cftmona
          « Reply #6 on: May 14, 2008, 11:20:11 PM »
          Before evilfantasy gets back to this thread, re-run HJT, and make sure "word wrap" in Notepad is disabled, because the log is hard to read.

          erocktattoo

            Topic Starter


            Beginner

            Re: HELP!!!! cftmona
            « Reply #7 on: May 14, 2008, 11:30:17 PM »
            Here's the one without wordwrap! sorry!

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 1:28:36 AM, on 5/15/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
            c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
            c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
            C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
            c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
            c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
            C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\RUNDLL32.EXE
            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            C:\Program Files\Common Files\Symantec Shared\ccApp.exe
            C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
            C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
            C:\WINDOWS\eHome\ehRecvr.exe
            C:\WINDOWS\eHome\ehSched.exe
            C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
            C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
            c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
            C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
            C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
            C:\WINDOWS\system32\nvsvc32.exe
            C:\WINDOWS\system32\HPZipm12.exe
            C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Vongo\VongoService.exe
            C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
            C:\WINDOWS\system32\mqsvc.exe
            C:\WINDOWS\system32\mqtgsvc.exe
            C:\WINDOWS\system32\dllhost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Vongo\Tray.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/ymj/*http://www.yahoo.com
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/ymj/*http://www.yahoo.com
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/ymj/*http://www.yahoo.com
            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/ymj/*http://www.yahoo.com
            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
            O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
            O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
            O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
            O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
            O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
            O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
            O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
            O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
            O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
            O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
            O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
            O4 - Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe
            O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
            O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
            O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
            O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
            O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
            O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
            O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
            O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
            O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
            O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
            O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
            O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1210812860062
            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
            O20 - Winlogon Notify: tuvttqn - tuvttqn.dll (file missing)
            O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
            O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
            O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
            O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
            O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
            O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
            O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
            O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
            O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
            O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
            O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
            O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
            O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
            O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
            O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe

            --
            End of file - 11940 bytes

            CBMatt

            • Mod & Malware Specialist


            • Prodigy

            • Sad and lonely...and loving every minute of it.
            • Thanked: 167
              • Yes
            • Experience: Experienced
            • OS: Windows 7
            Re: HELP!!!! cftmona
            « Reply #8 on: May 15, 2008, 05:49:52 AM »
            The only thing that stands out is this entry in your HJT...

            O20 - Winlogon Notify: tuvttqn - tuvttqn.dll (file missing)

            You should run HijackThis again, close all browser windows, check the above entry, and click on Fix Checked.  Although this particular infection doesn't appear to be active anymore, just to be on the safe side, you should follow these steps...

            1. Download VundoFix and save it to your desktop.
            2. Run VundoFix and click on Scan For Vundo.
            3. Once it's done scanning, click on Remove Vundo.
            4. When it prompts you to remove the files, click on Yes.
            5. Your desktop will go blank as it's removing files.  Don't worry, this is normal.
            6. It will prompt you to restart your computer, so click OK.
            7. When your computer is turned back on, your problem should be gone.
            8. The program normally produces a Vundofix.txt file.  Please locate this file and paste the contents in your next post.




            That aside, your log doesn't look very bad and it looks like the scans took care of the problematic files.  Are you still having issues?
            Quote
            An undefined problem has an infinite number of solutions.
            —Robert A. Humphrey

            erocktattoo

              Topic Starter


              Beginner

              Re: HELP!!!! cftmona
              « Reply #9 on: May 15, 2008, 11:29:04 AM »
              No issues. Everything seems to be runing good, actually a lot better! Thank you, YOU GUYS ROCK!!! I'm reccomending this site to everyone I know!!!

              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: HELP!!!! cftmona
              « Reply #10 on: May 15, 2008, 11:32:01 AM »
              Quote
              8. The program normally produces a Vundofix.txt file.  Please locate this file and paste the contents in your next post.

              There was an entry in the log that needed taken care of.

              Post a fresh Hijackthis log as well please.

              erocktattoo

                Topic Starter


                Beginner

                Re: HELP!!!! cftmona
                « Reply #11 on: May 15, 2008, 11:47:58 AM »

                VundoFix V7.0.3

                Scan started at 1:33:57 PM 5/15/2008

                Listing files found while scanning....

                No infected files were found.



                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 1:42:32 PM, on 5/15/2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                C:\WINDOWS\system32\RUNDLL32.EXE
                C:\WINDOWS\eHome\ehRecvr.exe
                C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
                C:\WINDOWS\eHome\ehSched.exe
                C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
                C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
                c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
                C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
                C:\WINDOWS\system32\nvsvc32.exe
                C:\WINDOWS\system32\HPZipm12.exe
                C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Vongo\VongoService.exe
                C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                C:\WINDOWS\system32\mqsvc.exe
                C:\WINDOWS\system32\mqtgsvc.exe
                C:\WINDOWS\system32\dllhost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                C:\Program Files\Vongo\Tray.exe
                C:\Program Files\Messenger\msmsgs.exe
                C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/ymj/*http://www.yahoo.com
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/ymj/*http://www.yahoo.com
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/ymj/*http://www.yahoo.com
                R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/ymj/*http://www.yahoo.com
                R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
                O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
                O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
                O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
                O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
                O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
                O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
                O4 - Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe
                O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
                O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
                O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
                O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
                O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
                O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
                O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
                O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
                O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
                O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
                O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
                O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
                O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
                O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1210812860062
                O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
                O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
                O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
                O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
                O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
                O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe

                --
                End of file - 11830 bytes

                evilfantasy

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Calm like a bomb
                • Thanked: 493
                • Experience: Experienced
                • OS: Windows 11
                Re: HELP!!!! cftmona
                « Reply #12 on: May 15, 2008, 11:54:13 AM »
                Looks good. A few more things to finish up with.

                Set a New Restore Point to prevent possible reinfection from an old one
                Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
                • Go to Start > Programs > Accessories > System Tools and click System Restore
                • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
                • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
                • Next go to Start > Run and type Cleanmgr
                • Click OK
                • Click the More Options Tab.
                • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
                .
                Use the Secunia Software Inspector to check for out of date software.
                • Click Start Now
                • Check the box next to Enable thorough system inspection.
                • Click Start
                • Allow the scan to finish and scroll down to see if any updates are needed.
                • Update anything listed.
                .
                Learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place?

                Let us know if anything else comes up.

                erocktattoo

                  Topic Starter


                  Beginner

                  Re: HELP!!!! cftmona
                  « Reply #13 on: May 15, 2008, 12:45:52 PM »
                  COOL!!! Thanks again everyone!!! :D