I cant even run hijack this, i open it and within about 3 seconds it just closes its self down! any ideas? and if i can get it to work i would love to post my results from the hijack this log.
I cant run system restore either as it doesnt work
Ive got IE-BAR and some chinese thing in my add/remove programmes when I remove them and restart they are back again
I was told my someone to run "combofix"? this is what that did:
Ben Pritchard - 06-08-24 8:46:08.57
ComboFix 06.08.24 - Running from: C:\Program Files\Mozilla Firefox
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\regedit.com
C:\WINDOWS\system32\regedit.com
((((((((((((((((((((((((((((((( Files Created from 2006-07-24 to 2006-08-24 ))))))))))))))))))))))))))))))))))
2006-08-24 08:44 55,808 --a------ C:\WINDOWS\SYSTEM32\myrx.dll
2006-08-23 21:27 50,939 -r-hs---- C:\WINDOWS\WINLOGON.EXE
2006-08-23 21:27 50,939 -r-hs---- C:\WINDOWS\SYSTEM32\regedit.com
2006-08-23 20:09 147,456 --a------ C:\WINDOWS\SYSTEM32\Vbzip11.dll
2006-08-23 20:09 143,360 --a------ C:\WINDOWS\SYSTEM32\vbuzip10.dll
2006-08-23 20:09 10,752 --a------ C:\WINDOWS\SYSTEM32\aamd532.dll
2006-08-23 17:47 15,872 -r-hs---- C:\WINDOWS\SYSTEM32\Downdll.dll
2006-08-23 17:33 31,232 ---hs---- C:\WINDOWS\SYSTEM32\Realplayer.exe
2006-08-23 17:33 16,384 --------- C:\WINDOWS\SYSTEM32\brlmon.dll
2006-08-23 08:18 65,536 --a------ C:\WINDOWS\SYSTEM32\100setup.exe
2006-08-23 08:18 62,464 --a------ C:\WINDOWS\SYSTEM32\wsetup.exe
2006-08-23 08:18 61,440 --a------ C:\WINDOWS\SYSTEM32\mnt32.exe
2006-08-23 08:18 118,784 --a------ C:\WINDOWS\SYSTEM32\arpa.exe
2006-08-22 20:37 50,939 -r-hs---- C:\WINDOWS\SYSTEM32\rundll32.com
2006-08-22 20:37 50,939 -r-hs---- C:\WINDOWS\SYSTEM32\MSCONFIG.COM
2006-08-22 20:37 50,939 -r-hs---- C:\WINDOWS\SYSTEM32\finder.com
2006-08-22 20:37 50,939 -r-hs---- C:\WINDOWS\SYSTEM32\dxdiag.com
2006-08-22 20:37 50,939 -r-hs---- C:\WINDOWS\SYSTEM32\command.pif
2006-08-22 20:37 50,939 -r-hs---- C:\WINDOWS\finder.com
2006-08-22 20:37 50,939 -r-hs---- C:\WINDOWS\explorer.com
2006-08-22 20:37 50,939 -r-hs---- C:\WINDOWS\ExERoute.exe
2006-08-22 20:37 50,939 --------- C:\WINDOWS\1.com
2006-08-22 20:37 37,428 --a------ C:\WINDOWS\SYSTEM32\internst.exe
2006-08-22 20:37 13,905 --a------ C:\WINDOWS\SYSTEM32\intranet.exe
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) )))
2006-08-24 08:45 -------- d-------- C:\Program Files\Mozilla Firefox
2006-08-24 08:44 -------- d-------- C:\Program Files\DeskAdTop
2006-08-24 08:44 -------- d-------- C:\Program Files\Common Files\Symantec Shared
2006-08-23 21:28 -------- d-------- C:\Program Files\Common Files
2006-08-23 20:42 -------- d-------- C:\Program Files\Free Spyware Scanner
2006-08-23 18:00 -------- d-------- C:\Documents and Settings\Ben Pritchard\Application Data\ppstream
2006-08-23 17:59 -------- d-------- C:\Program Files\IrfanView
2006-08-23 17:33 -------- d-------- C:\Program Files\Tencent
2006-08-22 21:09 -------- d-------- C:\Documents and Settings\Ben Pritchard\Application Data\PPLive
2006-08-22 21:08 -------- d-------- C:\Program Files\Common Files\Synacast
2006-08-22 20:37 50939 -r-hs---- C:\Program Files\Common Files\iexplore.pif
2006-08-22 20:37 -------- d-------- C:\Program Files\Internet Explorer
2006-08-22 16:54 -------- d-------- C:\Program Files\SpywareBlaster
2006-08-20 16:38 -------- d-------- C:\Program Files\Mozilla Thunderbird
2006-08-20 16:02 -------- d-------- C:\Documents and Settings\Ben Pritchard\Application Data\SopCast
2006-08-20 16:01 -------- d-------- C:\Program Files\SopCast
2006-08-11 09:05 777472 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\avg7core.sys
2006-08-11 09:05 27904 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\avg7rsxp.sys
2006-08-07 08:27 -------- d-------- C:\Program Files\Windows Media Player
2006-08-05 08:27 -------- d-------- C:\Program Files\Messenger
2006-08-05 08:25 -------- d-------- C:\Program Files\Windows NT
2006-08-05 08:25 -------- d-------- C:\Program Files\Outlook Express
2006-08-05 08:25 -------- d-------- C:\Program Files\NetMeeting
2006-08-05 08:25 -------- d-------- C:\Program Files\Movie Maker
2006-08-05 08:25 -------- d-------- C:\Program Files\Common Files\System
2006-08-04 14:40 -------- d---s---- C:\Documents and Settings\Ben Pritchard\Application Data\Microsoft
2006-07-24 09:15 -------- d-------- C:\Program Files\MSN Messenger
2006-07-24 09:15 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-07-23 15:29 -------- d-------- C:\Program Files\Yahoo!
2006-07-14 17:14 -------- d-------- C:\Program Files\RAM Def
2006-07-14 17:09 -------- d-------- C:\Program Files\Bazooka Scanner
2006-07-14 17:09 -------- d-------- C:\Program Files\Advanced Spyware Remover
2006-06-23 09:28 761344 --a------ C:\WINDOWS\SYSTEM32\wininet(2).dll
2006-06-16 14:34 48936 --a------ C:\WINDOWS\SYSTEM32\sirenacm.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"IgfxTray"="C:\\WINDOWS\\System32\\igfxtray.ex e"
"HotKeysCmds"="C:\\WINDOWS\\System32\\hkcmd.ex e"
"BCMSMMSG"="BCMSMMSG.exe"
"DVDSentry"="C:\\WINDOWS\\System32\\DSentry.ex e"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"ccRegVfy"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccRegVfy.exe\""
"CloneCDElbyCDFL"="\"C:\\Program Files\\Elaborate Bytes\\CloneCD\\ElbyCheck.exe\" /L ElbyCDFL"
"CloneCDTray"="\"C:\\Program Files\\Elaborate Bytes\\CloneCD\\CloneCDTray.exe\""
"AdaptecDirectCD"="\"C:\\Program Files\\Roxio\\Easy CD Creator 5\\DirectCD\\DirectCD.exe\""
"MOUSE"="C:\\WINDOWS\\System32\\Mousexp.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc. exe /STARTUP"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"intranet"="C:\\WINDOWS\\System32\\intranet.ex e"
"Realplayer.exe"="C:\\WINDOWS\\System32\\Realplaye r.exe"
"Spy Watcher"="\"C:\\PROGRA~1\\FREESP~1\\SpyWatcher.exe \" -S"
"Torjan Program"="C:\\WINDOWS\\WINLOGON.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"Realplayer.exe"="C:\\WINDOWS\\System32\\Realplaye r.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Runservices]
"Torjan Program"="C:\\WINDOWS\\WINLOGON.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\policies\explorer\Run]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="about:Home"
"SubscribedURL"="about:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,e6,00,00,00,00,00,00,00 ,9a,03,00,00,20,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00 ,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,e6,00,00,00,00 ,00,00,00,9a,03,00,00,20,03,\
00,00,04,00,00,c0
"RestoredStateInfo"=hex:18,00,00,00,e6,00,00,00,00 ,00,00,00,9a,03,00,00,20,03,\
00,00,01,00,00,00
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EX E"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw. exe /RUNONCE"
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\Cur rentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EX E"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw. exe /RUNONCE"
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\polic ies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\services]
"Messenger"=dword:00000002
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
C:\WINDOWS\tasks\Symantec NetDetect.job
Completion time: 24/08/2006 8:48:09.17
ComboFix.txt
Not sure if that helps, AVG is fiunding trojans all the time and adaware etc keeps finding numerous spyware, winampe.exe etc - please help!!!











