Computer Security & Viruses/system error

Advertisement


Question
QUESTION: I am receiving an error as soon as i switch on my computer:
------------------------
RUNDLL
---------------------------
Error loading C:WINDOWSsystem32winsys16_061230.dll

Access is denied.


---------------------------
OK   
---------------------------
The second question :While scaning the objects detected are C:Tally   ally72.exe
   C:Tally   ally72.exe.BAK
I would be glad if you could help me out with this.

ANSWER: Hi Ritika

It looks like you have a worm on your PC.  Please go to the following link and download HijackThis:

http://www.download.com/HijackThis/3000-8022_4-10227353.html

Download to your desktop or other convenient location, and run HJTSetup.exe to install. Once installed open HijackThis by clicking Start -> Program Files -> HijackThis.
1. Click the button labeled Do a system scan and save a logfile.
2. HijackThis will quickly scan your system, and then open two new windows. The results of the HijackThis scan, and hijackthis.log in Notepad. Save hijackthis.log. By default it will be saved to C:\HijackThis, or you can chose “Save As…”, and save to another location.
3. Hijackthis.log contains the info that’s required for analysis. Highlight the entire contents. Copy and paste the contents into a follow-up here. DO NOT fix anything.  I will get back to you with instructions.

---------- FOLLOW-UP ----------

QUESTION: hi, Brian, this is a follow up question with reference to your answer to run Hijack this.Following are the contents:
_______________________________________________________

Logfile of HijackThis v1.99.1
Scan saved at 10:13:26 AM, on 11/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
c:\program files\a-squared free\a2service.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
E:\SOFTWARE DOWNLOAD OFF\trade tiger download 2 nov\TradeTiger.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\USER\LOCALS~1\Temp\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\USERINIT.EXE,rundll32.exe C:\WINDOWS\system32\winsys16_061230.dll start
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=111707 serial=DR12CUK-5333492-PGW lang=EN
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{01061CD7-2DF7-4581-B96D-F646BF69F32E}: NameServer = 203.187.192.15 203.109.127.23
O17 - HKLM\System\CCS\Services\Tcpip\..\{2E22C57D-66FF-45D8-B47A-765783E49C29}: NameServer = 203.187.192.15,203.187.192.12
O17 - HKLM\System\CS1\Services\Tcpip\..\{01061CD7-2DF7-4581-B96D-F646BF69F32E}: NameServer = 203.187.192.15 203.109.127.23
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - c:\program files\a-squared free\a2service.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Indexing Helps (Indexingbox) - Unknown owner - %WINDIR%\system\svchest.exe (file missing)




ANSWER: Hi Ritika

Download ATF Cleaner from here:
http://www.atribune.org/ccount/click.php?id=1
Double-click ATF-Cleaner.exe to run the program.

Under Main choose: 'Select All' (cookies optional)
Click the 'Empty Selected' button.

Next, download ComboFix To Your Desktop from here:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Double click combofix.exe & follow the prompts.
A window will open with a warning.
Type 'Y', press Enter.
When the scan completes it will open a text window.
Caution - do not touch your mouse and keyboard until the scan completes.
The scan temporarily disables your desktop, and if interrupted, it may freeze your desktop. If this occurs, simply reboot.
Combofix will automatically save the log file to C:\combofix.txt

Finally, please download SUPERAntiSpyware Home Edition here:
http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE

Install it and double-click the icon on your desktop to run it.
It will ask if you want to update the program definitions, click 'Yes'.
Now reboot your PC to 'Safe Mode':
Click Start and then click Shut Down.

In the drop-down list of the Shut Down Windows dialog box, click Restart, and then click OK.

As your computer restarts but before Windows launches, press F8.  

Use the arrow keys to highlight 'safe mode', and then press ENTER.

Now Click on SUPERAntiSpyware
Under Configuration and Preferences, click 'Preferences'.
Click the Scanning Control tab.
Under Scanner Options make sure the following are checked:

   * Close browsers before scanning
   * Scan for tracking cookies
   * Terminate memory threats before quarantining.
   * Ignore System Restore/Volume Information on ME and XP

Please leave the others unchecked.
Click the Close button to leave the control center screen.

On the main screen, under Scan for Harmful Software click Scan your computer.
On the left check C:\Fixed Drive.
On the right, under Complete Scan, choose Perform Complete Scan.
Click Next to start the scan. Please be patient while it scans your computer.
After the scan is complete a summary box will appear. Click OK.
Make sure everything in the white box has a check next to it, then click Next.
It will quarantine what it found and if it asks if you want to reboot, click Yes.

After reboot, run HijackThis again and save a new log.
Click the SUPERAntispyware icon on your desktop.
   * Click Preferences . Click the Statistics/Logs tab .
   * Under Scanner Logs , double-click SUPERAntiSpyware Scan Log .
   * It will open in your default text editor (such as Notepad/Wordpad).
   * Please highlight everything , then right-click and choose copy.
   * Exit the program.

Paste that Scan log, along with the new HijackThis log, and the ComboFix log into a follow-up here so that I can look it over.

Brian

---------- FOLLOW-UP ----------

QUESTION: Hi,brain , this is the 2nd follow up ,I am  pasting all the information you require :
--------------------------------------------------------
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/17/2007 at 01:01 PM

Application Version : 3.9.1008

Core Rules Database Version : 3259
Trace Rules Database Version: 1270

Scan type       : Complete Scan
Total Scan Time : 00:28:13

Memory items scanned      : 358
Memory threats detected   : 0
Registry items scanned    : 5243
Registry threats detected : 0
File items scanned        : 28534
File threats detected     : 5

Adware.Tracking Cookie
  C:\Documents and Settings\USER\Cookies\user@atdmt[1].txt
  C:\Documents and Settings\USER\Cookies\user@media.adrevolver[1].txt
  C:\Documents and Settings\USER\Cookies\user@zedo[1].txt
  C:\Documents and Settings\USER\Cookies\user@doubleclick[1].txt
  C:\Documents and Settings\USER\Cookies\user@msnportal.112.2o7[1].txt
_______________________

Logfile of HijackThis v1.99.1
Scan saved at 1:09:58 PM, on 11/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
c:\program files\a-squared free\a2service.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\USER\LOCALS~1\Temp\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=120207 serial=DR12CUK-5333492-PGW lang=EN
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2E22C57D-66FF-45D8-B47A-765783E49C29}: NameServer = 203.187.192.15,203.187.192.12
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - c:\program files\a-squared free\a2service.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe

_______________________________

ComboFix 07-11-08.1 - USER 2007-11-17 11:14:49.1 - NTFSx86
Running from: C:\Documents and Settings\USER\Desktop\ComboFix.exe
* Created a new restore point
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\mywinsys.ini
C:\WINDOWS\system\svchest.reg

.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\Indexingbox


(((((((((((((((((((((((((   Files Created from 2007-10-17 to 2007-11-17  )))))))))))))))))))))))))))))))
.

2007-11-17 11:13   51,200   --a------   C:\WINDOWS\NirCmd.exe
2007-11-11 15:43   <DIR>   d--------   C:\Documents and Settings\USER\Application Data\dvdcss
2007-11-06 13:22   221,184   --a------   C:\WINDOWS\system32\wmpns.dll
2007-11-02 16:53   <DIR>   d--------   C:\Program Files\Common Files\Corel
2007-11-02 16:52   <DIR>   d--------   C:\Program Files\Corel
2007-11-02 15:47   <DIR>   d--------   C:\Documents and Settings\USER\DoctorWeb
2007-10-29 16:08   26,496   --a--c---   C:\WINDOWS\system32\dllcache\usbstor.sys
2007-10-27 21:05   <DIR>   d--------   C:\Documents and Settings\USER\Application Data\CyberLink
2007-10-24 18:52   <DIR>   d--------   C:\Program Files\Sharekhan
2007-10-23 23:26   808   --a------   C:\NTDETECT.EXE
2007-10-20 21:26   1,156   --a------   C:\WINDOWS\mozver.dat
2007-10-20 21:18   <DIR>   d--------   C:\Program Files\Common Files\NSV
2007-10-18 10:28   <DIR>   d--------   C:\SpeedTradePlus
2007-10-17 17:30   <DIR>   d--------   C:\WINDOWS\system32\DRM
2007-10-17 01:07   <DIR>   d--------   C:\Documents and Settings\USER\Application Data\vlc

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-17 04:38   ---------   d-----w   C:\Documents and Settings\USER\Application Data\AVG7
2007-11-15 04:45   ---------   d-----w   C:\Program Files\a-squared Free
2007-11-02 10:50   ---------   d-----w   C:\Program Files\Winamp
2007-11-02 10:20   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\avg7
2007-11-02 05:10   31,440   ----a-w   C:\WINDOWS\system32\TSP32E.DLL
2007-10-22 04:28   ---------   d-----w   C:\Documents and Settings\USER\Application Data\AdobeUM
2007-10-15 06:42   ---------   d-----w   C:\Documents and Settings\USER\Application Data\Corel
2007-10-13 13:15   ---------   d-----w   C:\Program Files\Ahead
2007-10-13 12:29   ---------   d-----w   C:\Program Files\Yahoo!
2007-10-13 12:29   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-10-13 12:28   ---------   d-----w   C:\Program Files\MSN Messenger
2007-10-13 12:24   ---------   d-----w   C:\Program Files\Real
2007-10-13 12:24   ---------   d-----w   C:\Program Files\Common Files\Real
2007-10-13 12:22   ---------   d-----w   C:\Program Files\VideoLAN
2007-10-13 12:21   ---------   d-----w   C:\Program Files\Java
2007-10-13 12:21   ---------   d-----w   C:\Program Files\Common Files\Java
2007-10-13 12:19   ---------   d-----w   C:\Program Files\Common Files\Adobe
2007-10-13 12:16   ---------   d-----w   C:\Program Files\ACDSee32
2007-10-13 12:13   ---------   d--h--w   C:\Program Files\InstallShield Installation Information
2007-10-13 12:13   ---------   d-----w   C:\Program Files\CyberLink
2007-10-13 12:13   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\CyberLink
2007-10-13 12:12   ---------   d-----w   C:\Program Files\Common Files\Nero
2007-10-13 12:11   ---------   d-----w   C:\Program Files\Common Files\Ahead
2007-10-13 12:07   ---------   d-----w   C:\Program Files\Common Files\InstallShield
2007-10-13 11:54   ---------   d-----w   C:\Program Files\Microsoft.NET
2007-10-13 11:54   ---------   d-----w   C:\Program Files\Microsoft ActiveSync
2007-10-13 11:54   ---------   d-----w   C:\Program Files\Common Files\L&H
2007-10-13 11:53   ---------   d-----w   C:\Program Files\Microsoft Works
2007-10-13 11:48   499,712   ----a-w   C:\WINDOWS\system32\msvcp71.dll
2007-10-13 11:48   348,160   ----a-w   C:\WINDOWS\system32\msvcr71.dll
2007-10-13 11:48   ---------   d-----w   C:\Documents and Settings\LocalService\Application Data\AVG7
2007-10-13 11:48   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-13 11:40   ---------   d-----w   C:\Program Files\ViewSonic
2007-10-13 11:40   ---------   d-----w   C:\Documents and Settings\USER\Application Data\Leadertech
2007-10-13 11:30   ---------   d-----w   C:\Program Files\Realtek
2007-10-13 11:28   ---------   d-----w   C:\Program Files\Intel
2007-10-13 11:21   ---------   d-----w   C:\Program Files\microsoft frontpage
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-11-15 09:59]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe" [2004-06-03 22:05]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2007-10-13 17:54]
"CorelDRAW Graphics Suite 11b"="C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe" [2003-11-25 13:39]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2006-07-29 19:34]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
ALCMTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
C:\WINDOWS\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
C:\WINDOWS\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
C:\WINDOWS\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
RTHDCPL.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
SkyTel.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe


.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-17 11:18:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-17 11:19:51 - machine was rebooted
.
  --- E O F ---


Thanks once again !!!  

Answer
Hi Ritika

Your logs look good now.  You had a trojan and some spyware on the computer which were detected and deleted.  Are you still receiving the errors?  If you are, let me know.  If not, you may remove SuperAntiSpyware and the other tools you used.  Good luck!

Brian

Computer Security & Viruses

All Answers


Answers by Expert:


Ask Experts

Volunteer


Brian Benosky

Expertise

I will help you in eradicating malware and all forms of virus/trojans/adware. I can answer all PC-related hardware issues. I can also troubleshoot Windows OS errors (all versions) and other software problems. HijackThis logs are a MUST for virus related help. If you do not know how to do this, I have posted easy-to-follow instructions on the Ask a Question page. Every computer infection is different, so I will give you personal instructions on how to remove the malware, not a 'pat' answer. You can be assured of a prompt, polite, and knowledgeable response in all regards.

Experience

I have over 25 years experience in using, building, and repairing computers. I have helped over two thousand people here on AllExperts, with consistent Top Feedback Scores. Please look at my answers here: http://en.allexperts.com/q/Computer-Security-Viruses-1737/indexExp_84308.htm I am also a Top Contributor of General Computing answers in Yahoo! Questions.

Education/Credentials
College Educated Self-taught Computer Skills

©2012 About.com, a part of The New York Times Company. All rights reserved.