This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] cant run hijackthis

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

- No audio from videos, internet etc…before i could end a process in CMD withoutany system beeps, now everytime i try to end a process i get a beep
- some sort of song runs in the background
- sometimes my wifi works, when it doesnt i have to use winsock to fix it
- some of my programs do not wok, i get invalid win32 process error (winrar for example was working fine until this virus took over)

I can't run Combofix or the other program. For combofix I get "C:\32788R22FWJFW\swres.exe is an invalid Win32 process" error. I click "ok" & it kept on appearing. I kept on clicking OK until combo fix launched. However, after laucnhing it stated "Access Denied" in the blue window.

I ran housecall and it found 2000+ infections, but most of them could not be deleted/cured.

Also, i am unable to launch hijackthis due to invalid win32 process error.
Hi gochi, welcome to the forum.

Do not run any tools such as combofix, smitfraudfix, sdfix, etc without supervision. These are very powerful tools and can damge your system if used improperly.

Please be advised, as I'm still in training, all my replies will have to be approved by a teacher or expert before I can post them. This may cause some delays, but I will do my best to keep them as short as possible.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.
I will post back soon with additional instructions.


Thanks
Hi gochi,

Do you recall what the infection name was that Housecall detected?

Let's see if this scantool will work.

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please include the contents of the following in your next reply:

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
Thanks
Hi,

Yes, unfortunatley I have even a bigger problem which needs to be addressed before we continue with this issue.

Spybot succesfully removed all infections. My computer then restarted, and everytime i try to login into my account i get a BSOD. The error is listed below.


page_fault_in_nonpaged area

STOP: 0X00000050 (0XFFFFFFFE, 0X00000000, 0X872D1ECA, 0X00000000)


I ran malware bytes in SAFE MODE, as i can not login into my account due to this BSOD issue. It found 40 infections and removed the ones which were in memory upon restart. Though, I still can not login into my original account.

What do you suggest I do now?
Hi gochi, Since you can get into save mode, please run DDS in safe mode and post both logs in your next reply. I posted the instruction previously. Thanks
Sorry, this should have been posted yesterday. I guess the malware must have been restricting internet access. Anyhow, I've attached 1/2 of the files, the other is posted below. DDS (Ver_09-02-01.01) - NTFSx86 NETWORK Run by [removed] at 10:09:28.42 on Sun 02/22/2009 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.705 [GMT -8:00] AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Updated) FW: Norton Internet Worm Protection *disabled* ============== Running Processes =============== svchost.exe C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\SYSTEM32\WISPTIS.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\tabbtnu.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\TEMP\BN5.tmp C:\WINDOWS\System32\svchost.exe svchost.exe C:\WINDOWS\TEMP\VRT6.tmp C:\WINDOWS\System32\reader_s.exe C:\WINDOWS\System32\svchost.exe C:\Documents and Settings\Administrator.TOSHIBA-USER\Desktop\dds.scr C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\TEMP\BN23.tmp ============== Pseudo HJT Report =============== mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\temp\init.exe,c:\windows\system32\c++.exe,c:\windows\system32\deviceemulator.exe,c:\windows\system32\c++.exe,c:\windows\system32\codeblocks.exe,c:\windows\system32\makehm.exe, BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll BHO: : {3806939d-ab28-4f2c-a46b-f39bcca6b7b7} - c:\windows\system32\azwhhkf.dll BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll BHO: NoExplorer - No File TB: {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - No File TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\toscdspd.exe mRun: [TabletWizard] c:\windows\help\SplshWrp.exe mRun: [TabletTip] "c:\program files\common files\microsoft shared\ink\tabtip.exe" /resume mRun: [00THotkey] c:\windows\system32\00THotkey.exe mRun: [CrossMenu] c:\program files\toshiba\crossmenu\CrossMenu.exe mRun: [TRot.exe] c:\program files\toshiba\toshiba rotation utility\TRot.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [SkyTel] SkyTel.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [AGRSMMSG] AGRSMMSG.exe mRun: [TosHKCW.exe] "c:\program files\toshiba\wireless hotkey\TosHKCW.exe" mRun: [NDSTray.exe] NDSTray.exe mRun: [TMESRV.EXE] c:\program files\toshiba\tme3\TMESRV31.EXE /Logon mRun: [TMERzCtl.EXE] c:\program files\toshiba\tme3\TMERzCtl.EXE /Service mRun: [TOSDCR] TOSDCR.EXE mRun: [TFncKy] TFncKy.exe mRun: [TAudEffect] c:\program files\toshiba\taudeffect\TAudEff.exe /run mRun: [Apoint] c:\program files\apoint2k\Apoint.exe mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE mRun: [TAcelMgr] c:\program files\toshiba\acceleration utilities\tacelmgr\TAcelMgr.exe mRun: [TSkrMain] c:\program files\toshiba\acceleration utilities\shaker\TSkrMain.exe mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe" mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /installquiet /nodetect mRun: [TPSMain] TPSMain.exe mRun: [TPSODDCtl] TPSODDCtl.exe mRun: [PSQLLauncher] "c:\program files\protector suite ql\launcher.exe" /startup mRun: [TouchED] c:\program files\toshiba\touched\TouchED.Exe mRun: [SunJavaUpdateSched] c:\program files\java\jre1.5.0_06\bin\jusched.exe mRun: [CFSServ.exe] CFSServ.exe -NoClient mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\isuspm.exe" -scheduler mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe" mRun: [HP Software Update] "c:\program files\hewlett-packard\hp software update\HPWuSchd.exe" mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe mRun: [SearchSettings] c:\program files\search settings\SearchSettings.exe mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k mRun: [Explorer] c:\windows\system32\msrstart.exe mRun: [reader_s] c:\windows\system32\reader_s.exe mRun: [services] c:\windows\services.exe mRunOnce: [SpybotDeletingA8244] command /c del "c:\windows\system32\noytcyr.exe_old" mRunOnce: [SpybotDeletingC5056] cmd /c del "c:\windows\system32\noytcyr.exe_old" mRunOnce: [SpybotDeletingA7126] command /c del "c:\windows\system32\roytctm.exe_old" mRunOnce: [SpybotDeletingC6673] cmd /c del "c:\windows\system32\roytctm.exe_old" mRunOnce: [SpybotDeletingA9857] command /c del "c:\windows\system32\tdydowkc.exe_old" mRunOnce: [SpybotDeletingC1151] cmd /c del "c:\windows\system32\tdydowkc.exe_old" mRunOnce: [SpybotDeletingA4418] command /c del "c:\windows\system32\wsldoekd.exe_old" mRunOnce: [SpybotDeletingC6257] cmd /c del "c:\windows\system32\wsldoekd.exe_old" mRunOnce: [SpybotSnD] "c:\program files\spybot - search & destroy\SpybotSD.exe" /autocheck mRunOnce: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript dRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background dRun: [bndephdj.exe] c:\windows\bndephdj.exe dRun: [IDMan] c:\program files\internet download manager\IDMan.exe /onboot dRun: [jrfvdoob.exe] c:\windows\jrfvdoob.exe dRun: [nttpbtav.exe] c:\windows\nttpbtav.exe dRun: [jrfvnoxo.exe] c:\windows\jrfvnoxo.exe dRun: [zzjxgygp.exe] c:\windows\zzjxgygp.exe dRun: [zzjxmmnr.exe] c:\windows\zzjxmmnr.exe dRun: [rvexysbq.exe] c:\windows\rvexysbq.exe dRun: [reader_s] c:\documents and settings\administrator.toshiba-user\reader_s.exe mExplorerRun: [xccinit] c:\windows\system32\inf\rundll33.exe c:\windows\xccdf16_090131a.dll xccd16 mExplorerRun: [services] c:\windows\services.exe StartupFolder: c:\docume~1\admini~1.tos\startm~1\programs\startup\iehome.lnk - c:\documents and settings\default user\local settings\temp\iehome.bat StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~2.lnk - c:\program files\microsoft office\office11\ONENOTEM.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ramasst.lnk - c:\windows\system32\RAMASST.exe dPolicies-explorer: NoSetActiveDesktop = 1 (0x1) IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\npjpi150_06.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} - hxxp://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/webplayer/stage6/windows/DivXBrowserPlugin.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll Notify: dundopoh - azwhhkf.dll Notify: loginkey - c:\program files\common files\microsoft shared\ink\loginkey.dll Notify: mornijr - mornijr32.dll Notify: psfus - psqlpwd.dll Notify: TabBtnWL - TabBtnWL.dll Notify: tpgwlnotify - tpgwlnot.dll Notify: TSigNP - TSigNP.dll AppInit_DLLs: rjnkoo.dll zwcocr.dll klunms.dll LSA: Notification Packages = scecli psqlpwd ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\admini~1.tos\applic~1\mozilla\firefox\profiles\urp91nhb.default\ FF - plugin: c:\program files\dyyno\dyyno player\npvlc.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava11.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava12.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava13.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava14.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava32.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJPI150_06.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPOJI610.dll FF - HiddenExtension: XUL Cache: {28A43220-ACD9-4EA3-AF3E-D64001B99293} - c:\documents and settings\user.toshiba-user.000\local settings\application data\{28A43220-ACD9-4EA3-AF3E-D64001B99293} FF - HiddenExtension: XUL Cache: {1B8CFE73-0C1D-423C-9963-99D07F7ADD0C} - c:\documents and settings\fef\local settings\application data\{1b8cfe73-0c1d-423c-9963-99d07f7add0c}\ ============= SERVICES / DRIVERS =============== R0 ati2hnxx;ati2hnxx;c:\windows\system32\drivers\ati2hnxx.sys [2009-2-8 32768] R0 jbnirdxs;jbnirdxs;c:\windows\system32\drivers\jbnirdxs.sys [2009-2-17 33920] R0 lcibmaqt;lcibmaqt;c:\windows\system32\drivers\lcibmaqt.sys [2006-5-20 23424] R0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\drivers\thpdrv.sys [2004-12-27 16384] R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\drivers\Thpevm.sys [2006-5-20 6144] R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2007-12-21 33800] R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2006-5-20 35968] R3 TBtnKey;TOSHIBA Tablet PC Buttons Type N HID Driver;c:\windows\system32\drivers\TBtnKey.sys [2006-5-20 8832] R3 WacomPen;Wacom Serial Pen HID Driver;c:\windows\system32\drivers\wacompen.sys [2006-5-20 13568] S0 tkntfyso;tkntfyso;c:\windows\system32\drivers\tkntfyso.sys –> c:\windows\system32\drivers\tkntfyso.sys [?] S1 cd8ba438;cd8ba438;c:\windows\system32\drivers\cd8ba438.sys [2009-1-30 0] S1 ethaavkr;ethaavkr;c:\windows\system32\drivers\ethaavkr.sys [2009-1-30 137856] S1 ethwysgx;ethwysgx;c:\windows\system32\drivers\ethwysgx.sys [2009-1-30 137856] S1 is-076KMdrv;is-076KMdrv;c:\windows\system32\drivers\53245071.sys [2009-2-18 148496] S1 is-27SBKdrv;is-27SBKdrv;c:\windows\system32\drivers\75134492.sys [2009-2-21 148496] S1 is-BEE8Fdrv;is-BEE8Fdrv;c:\windows\system32\drivers\58358673.sys [2009-2-21 148496] S1 TMEI3E;TMEI3E;c:\windows\system32\drivers\TMEI3E.sys [2006-5-20 5888] S2 ekrn;Eset Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2007-12-21 468224] S2 FdRedir;FdRedir;c:\program files\common files\protector suite ql\drivers\FdRedir.sys [2006-5-5 13568] S2 FileDisk2;FileDisk Protector Kernel Driver;c:\program files\common files\protector suite ql\drivers\filedisk.sys [2006-5-5 33024] S2 ICF;ICF;c:\windows\system32\svchost.exe:ext.exe [] S2 noytcyr;noytcyr;c:\windows\system32\noytcyr.exe –> c:\windows\system32\noytcyr.exe [?] S2 roytctm;roytctm;c:\windows\system32\roytctm.exe –> c:\windows\system32\roytctm.exe [?] S2 smihlp;SMI helper driver;c:\program files\protector suite ql\smihlp.sys [2006-5-5 3456] S2 tdydowkc;tdydowkc;c:\windows\system32\tdydowkc.exe –> c:\windows\system32\tdydowkc.exe [?] S2 Tmesrv;Tmesrv3;c:\program files\toshiba\tme3\TMESRV31.exe [2006-5-20 147456] S2 wsldoekd;wsldoekd;c:\windows\system32\wsldoekd.exe –> c:\windows\system32\wsldoekd.exe [?] S3 protect;protect;c:\windows\system32\drivers\protect.sys [2009-2-21 18944] S3 restore;restore;\??\c:\windows\system32\drivers\restore.sys –> c:\windows\system32\drivers\restore.sys [?] S3 tcpsr;tcpsr;c:\windows\system32\drivers\tcpsr.sys [2009-2-22 6528] S3 TEchoCan;Toshiba Audio Effect;c:\windows\system32\drivers\TEchoCan.sys [2006-5-20 641152] ============== File Associations =============== txtfile="c:\windows\system32\nxtepad.exe" "%1" =============== Created Last 30 ================ 2009-02-22 10:09 6,528 a——- c:\windows\system32\drivers\tcpsr.sys 2009-02-22 10:09 37,376 a——- c:\windows\system32\20.tmp 2009-02-22 10:08 67,585 a——- c:\windows\system32\16.tmp 2009-02-22 10:08 24,577 a——- c:\windows\system32\10.tmp 2009-02-22 10:06 24,254 a——- c:\windows\system32\1E.tmp 2009-02-22 10:06 67,585 a——- c:\windows\system32\14.tmp 2009-02-22 10:06 168 a——- c:\windows\system32\D.tmp 2009-02-21 18:11 37,376 a——- c:\windows\system32\1F.tmp 2009-02-21 18:11 67,585 a——- c:\windows\system32\1D.tmp 2009-02-21 18:11 168 a——- c:\windows\system32\1A.tmp 2009-02-21 17:38 37,888 a——- c:\windows\system32\E.tmp 2009-02-21 17:38 67,585 a——- c:\windows\system32\B.tmp 2009-02-21 17:38 25,601 a——- c:\windows\system32\8.tmp 2009-02-21 17:38 168 a——- c:\windows\system32\6.tmp 2009-02-21 16:50 37,376 a——- c:\windows\system32\1B.tmp 2009-02-21 16:50 67,585 a——- c:\windows\system32\19.tmp 2009-02-21 16:50 63,488 a——- c:\windows\system32\c++.exe 2009-02-21 16:50 24,577 a——- c:\windows\system32\18.tmp 2009-02-21 16:50 168 a——- c:\windows\system32\17.tmp 2009-02-21 16:44 552 a——- c:\windows\system32\d3d8caps.dat 2009-02-21 16:43 –d—– c:\docume~1\admini~1.tos\applic~1\Xfire 2009-02-21 16:12 67,585 a——- c:\windows\system32\13.tmp 2009-02-21 16:12 0 a——- c:\windows\system32\15.tmp 2009-02-21 16:12 24,577 a——- c:\windows\system32\12.tmp 2009-02-21 16:12 168 a——- c:\windows\system32\11.tmp 2009-02-21 16:12 67,585 a——- c:\windows\system32\C.tmp 2009-02-21 16:12 168 a——- c:\windows\system32\A.tmp 2009-02-21 15:26 148,496 a——- c:\windows\system32\drivers\58358673.sys 2009-02-21 15:25 24,254 a——- c:\windows\system32\9.tmp 2009-02-21 15:25 18,944 a—h— c:\windows\system32\drivers\protect.sys 2009-02-21 15:25 67,585 a——- c:\windows\system32\7.tmp 2009-02-21 15:25 168 a——- c:\windows\system32\4.tmp 2009-02-21 13:12 –d—– c:\windows\LastGood.Tmp 2009-02-21 13:12 148,496 a——- c:\windows\system32\drivers\75134492.sys 2009-02-21 13:01 43,009 a——- c:\windows\services.ex_ 2009-02-21 13:01 30,208 a——- c:\documents and settings\administrator.toshiba-user\reader_s.exe 2009-02-21 13:01 30,208 a——- c:\windows\system32\reader_s.exe 2009-02-21 13:01 63,488 a——- c:\windows\system32\regwiz.exe 2009-02-21 13:01 67,585 a——- c:\windows\system32\5.tmp 2009-02-21 13:01 168 a——- c:\windows\system32\3.tmp 2009-02-18 18:28 148,496 a——- c:\windows\system32\drivers\53245071.sys 2009-02-18 17:55 61,440 a——- c:\windows\system32\drivers\weciu.sys 2009-02-18 17:35 6 a——- c:\windows\_id.dat 2009-02-18 15:37 3,584 a——- c:\windows\system32\1D8.tmp 2009-02-18 15:36 168 a——- c:\windows\system32\1D0.tmp 2009-02-18 09:09 406,016 a——- c:\windows\system32\tmpxccacj0.exe 2009-02-17 15:42 63,488 ——– c:\windows\system32\clickfile.exe 2009-02-17 15:30 33,920 a——- c:\windows\system32\drivers\jbnirdxs.sys 2009-02-16 20:15 52 a——- c:\windows\system32\xcchit32.ini.ssyq 2009-02-16 20:11 676,352 a——- c:\windows\system32\rtl60.bpl 2009-02-16 20:11 159,232 a——- c:\windows\system32\w.exe 2009-02-16 18:19 –d—– c:\program files\Xfire 2009-02-16 14:28 130 a——- c:\windows\adobe.bat 2009-02-16 09:14 199 a——- c:\windows\system32\xcchit32.ini 2009-02-16 09:13 36,352 a——- c:\windows\xccdf16_090131a.dll 2009-02-16 09:13 251,392 a——- c:\windows\xccdf32_090131a.dll 2009-02-16 09:12 155,216 a——- c:\windows\system\xccef090131.exe 2009-02-16 09:12 580 a——- c:\windows\xccwinsys.ini 2009-02-16 09:12 –d—– c:\windows\system32\inf 2009-02-15 22:34 1,394 a——- C:\microbio font changed[1].LNK 2009-02-15 22:34 1,179 a——- C:\7R9CVR6M.LNK 2009-02-15 20:02 168,448 a——- c:\windows\system32\unrar.dll 2009-02-15 20:02 –d—– c:\program files\K-Lite Codec Pack 2009-02-15 16:24 134,144 a——- c:\windows\igedunumu.dll 2009-02-15 15:21 301,728 a——- C:\montage4.mp4.sfk 2009-02-14 14:58 –d—– C:\ComboFix 2009-02-14 14:58 406,016 a——- c:\windows\system32\CF14649.exe 2009-02-14 14:57 406,016 a——- c:\windows\system32\CF14557.exe 2009-02-14 14:55 406,016 a——- c:\windows\system32\CF14025.exe 2009-02-14 14:46 16,896 a——- c:\windows\system32\mornijr.dll 2009-02-14 12:56 –d—– C:\leet 2009-02-13 23:31 406,016 a——- c:\windows\system32\CF29687.exe 2009-02-13 23:29 406,016 a——- c:\windows\system32\CF28936.exe 2009-02-13 19:18 3,584 a——- c:\windows\zzjxldkq.exe 2009-02-13 10:04 16,896 a——- c:\windows\system32\mornijr32.dll 2009-02-12 16:47 182,912 ac—— c:\windows\system32\dllcache\ndis.sys 2009-02-10 16:14 42,320 a——- c:\windows\system32\xfcodec.dll 2009-02-09 00:10 134,144 a——- c:\windows\ugaciroj.dll 2009-02-08 23:53 32,768 a——- c:\windows\system32\drivers\ati2hnxx.sys 2009-02-08 23:51 63,488 a——- c:\windows\system32\undname.exe 2009-02-08 23:51 41,472 a——- c:\windows\Ctumimaxeqayofik.dll 2009-02-08 11:05 3,584 a——- c:\windows\xllggvow.exe 2009-02-07 15:13 –d—– c:\program files\common files\eSellerate 2009-02-07 15:13 –d—– c:\program files\NewBlue 2009-02-06 16:33 –d—– c:\program files\Vstplugins 2009-02-06 16:33 –d—– c:\program files\Sony 2009-02-06 16:32 –d—– c:\program files\Sony Setup 2009-02-06 14:57 –d—– c:\windows\system32\QuickTime 2009-02-06 13:49 –d—– c:\program files\Trend Micro 2009-02-06 12:54 –d—– C:\i386 2009-02-05 21:22 –d—– c:\docume~1\admini~1.tos\applic~1\Malwarebytes 2009-02-05 21:01 63,488 a——- c:\windows\system32\deviceemulator.exe 2009-02-05 15:12 63,488 a——- c:\windows\system32\pdbcopy.exe 2009-02-03 20:51 529 a——- c:\windows\system32\winlogon2.exe 2009-02-03 15:08 67,072 —-h— c:\windows\system32\secupdat.dat 2009-02-03 15:01 –d—– c:\program files\XPPoliceAntivirus 2009-02-03 15:01 75,782 a——- c:\windows\system32\xp-dc-av.exe 2009-02-02 22:26 63,488 a——- c:\windows\system32\actcontroller.exe 2009-02-02 22:18 63,488 a——- c:\windows\system32\i386kd.exe 2009-02-02 22:18 46,080 a——- c:\windows\system32\gcc.exe 2009-02-02 22:17 63,488 a——- c:\windows\system32\vmware-ufad.exe 2009-02-02 21:57 63,488 a——- c:\windows\system32\hhupd.exe 2009-02-02 21:25 63,488 a——- c:\windows\system32\makehm.exe 2009-02-02 21:15 63,488 a——- c:\windows\system32\idaw64.exe 2009-02-02 21:14 63,488 a——- c:\windows\system32\codeblocks.exe 2009-02-02 19:25 –d—– c:\program files\BitZipper 2009-02-02 18:23 63,488 a——- c:\windows\system32\7z.exe 2009-02-02 18:12 527 a——- c:\windows\system32\win32hlp.cnf 2009-02-02 17:34 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-02-02 17:34 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-02 17:34 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-02-02 17:34 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-02-02 16:59 102,411 a——- c:\windows\system32\126_av.exe 2009-02-02 16:56 63,488 a——- c:\windows\system32\ndetect.exe 2009-02-01 19:00 –d—– c:\docume~1\admini~1.tos\applic~1\Intel 2009-02-01 19:00 –d—– c:\documents and settings\Administrator.TOSHIBA-USER 2009-02-01 17:54 122,368 ac—— c:\windows\system32\dllcache\userinit.exe 2009-02-01 13:29 135,680 a——- c:\windows\umakunodijipatax.dll 2009-02-01 13:16 57,856 a——- c:\windows\system32\chert13-303374.exe 2009-02-01 13:06 –d—– c:\docume~1\alluse~1\applic~1\PrevxCSI 2009-02-01 13:01 44,032 a——- c:\windows\system32\303374.exe 2009-01-30 18:42 137,856 a——- c:\windows\system32\drivers\ethwysgx.sys 2009-01-30 15:58 0 a——- c:\windows\system32\drivers\cd8ba438.sys 2009-01-30 15:57 137,856 a——- c:\windows\system32\drivers\ethaavkr.sys 2009-01-30 15:57 380,424 a——- C:\otdfi.exe 2009-01-30 15:57 37,376 a——- C:\bkha.exe 2009-01-30 15:57 99,840 a——- C:\asyoclq.exe 2009-01-30 15:57 2 a——- C:\-1795546807 2009-01-30 14:17 0 a—h— c:\windows\SwSys2.bmp 2009-01-30 14:17 0 a—h— c:\windows\SwSys1.bmp 2009-01-30 14:16 –d—– c:\program files\Search Settings 2009-01-27 19:34 180,224 a——- c:\windows\system32\WinVd32.sys 2009-01-27 19:34 16,384 a——- c:\windows\system32\WinFl32.sys 2009-01-27 19:34 –d—– c:\program files\Folder Lock 6 2009-01-26 19:44 –d—– c:\program files\Xilisoft 2009-01-25 12:21 –d—– c:\program files\common files\DVDVideoSoft ==================== Find3M ==================== 2009-02-22 10:09 31,744 a——- c:\windows\system32\svchost.exe 2009-02-17 15:27 122,368 a——- c:\windows\system32\userinit.exe 2009-02-12 16:47 182,912 a——- c:\windows\system32\drivers\ndis.sys 2009-02-02 16:56 136,758 a——- c:\windows\pchealth\helpctr\config\cache\Professional_32_1033.dat 2009-02-02 16:56 94,291 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-01-22 06:49 206,256 a——- c:\windows\system32\idmmbc.dll ============= FINISH: 10:10:29.67 ===============

Attachments:

Hi Gochi,

Identity Theft

Your system has been infected by one or more Rootkits/Backdoor Trojans and at least one KEYLOGGER.

A keylogger program can capture all user keystrokes (including confidential details such username, password, credit card number, etc.)

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files.

There are also several capable of connecting with a remote server.

Its very possible that anything could have been installed on your computer by the remote attacker, including opening other backdoors and installing rootkits. While we can attempt to clean what we see in your logs, we cannot guarantee that your computer will be completely in the clear since we have no way of knowing that has been done to the computer. Your computer could be completely compromised at this moment. It may be prudent to backup your information, reformat, and reinstall.

More information on Remote Access Trojans can be found here.

I strongly suggest you do the following immediately:
  • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.
You may also have a Virut infection. This type of infection is virtually impossible to kill without a format and reinstall.

If, however, you decide that the computer is not used for any sensitive work, or if you do not wish to reformat at this time, I can help you clean your computer to the best of my abilities. I must remind you that i cannot guarantee that your computer will be completely clean afterwards since we have no way of knowing what has been done to it.

To help you make your decision, here are a few related articles that i suggest you read:

  • Danger: Remote Access Trojans.
  • When should I re-format? How should I reinstall?
  • How Do I Handle Possible Identify Theft, Internet Fraud and Credit Card Fraud?

Should you have any questions, please feel free to ask.

Please let me know what you decide to do in your next post.

Thanks

Hi Gochi,

Identity Theft

Your system has been infected by one or more Rootkits/Backdoor Trojans and at least one KEYLOGGER.

A keylogger program can capture all user keystrokes (including confidential details such username, password, credit card number, etc.)

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files.

There are also several capable of connecting with a remote server.

Its very possible that anything could have been installed on your computer by the remote attacker, including opening other backdoors and installing rootkits. While we can attempt to clean what we see in your logs, we cannot guarantee that your computer will be completely in the clear since we have no way of knowing that has been done to the computer. Your computer could be completely compromised at this moment. It may be prudent to backup your information, reformat, and reinstall.

More information on Remote Access Trojans can be found here.

I strongly suggest you do the following immediately:

  • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.
You may also have a Virut infection. This type of infection is virtually impossible to kill without a format and reinstall.

If, however, you decide that the computer is not used for any sensitive work, or if you do not wish to reformat at this time, I can help you clean your computer to the best of my abilities. I must remind you that i cannot guarantee that your computer will be completely clean afterwards since we have no way of knowing what has been done to it.

To help you make your decision, here are a few related articles that i suggest you read:

  • Danger: Remote Access Trojans.
  • When should I re-format? How should I reinstall?
  • How Do I Handle Possible Identify Theft, Internet Fraud and Credit Card Fraud?

Should you have any questions, please feel free to ask.

Please let me know what you decide to do in your next post.

Thanks


Well I have not done any online banking or anything related to that, recently. My email account's are the only thing that requires a pass/username to function, so I can alter them.

I have misplaced my CD and I would have formated/reinstalled had I not misplaced it. If there is a way to format/reinstall without the CD then I'd be willing to do tht, however, since I do not have the CD, it would be in my best interest to try to clean this laptop. I am running Windows XP Pro- Tablet Edittion.

thanks
Hi Gochi, let's see if we can find out what we're up against.

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file paths, one at a time into the "Suspicious files to scan" box on the top of the page:
  • wait for the results before submitting the next file
  • Please clearly identify the results for each file.

    c:\windows\system32\svchost.exe
    c:\windows\system32\userinit.exe
    c:\windows\system32\makehm.exe
    c:\windows\system32\7z.exe
    c:\windows\system32\reader_s.exe


  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

If the samples come back as Virut, then I'm afraid the best we can do, is get your machine to the point where you will be able to copy important files to a USB/CD. You will need to format.

We will need access to a clean computer in order to download the tools we will need. One with a CD burner would be best.

Please post the VirSCAN results in your next reply and we'll take it from there.

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI