This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Renos.BAH problem

31 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

After hours of tracking this down (I'm a newbie), I finally was able to get Windows Defended to find it and remove it, but everytime I restart, it comes back again. I've run MalwareBytes (i have the pro version), but it never finds anything. Where do I begin to solve this thing? Also, down in the system tray, I keep getting System Infected warnings that don;t look like any warning that I've ever seen. I'm running a dell 4600, Win XP SP3. If anyone can Help, or tell me how to start, I'd really apprciate it.
Hi, and Welcome to WhatTheTech :)

My name is jpshortstuff. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through the instructions before starting to follow them to amek sure you understand everything you have to do.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Thanks.
Thansk for your help!!! Feel like I'm just going round in circles. DDS (Ver_09-02-01.01) - NTFSx86 Run by [removed] at 7:19:44.21 on Wed 02/25/2009 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2558.1757 [GMT -5:00] AV: Norton AntiVirus *On-access scanning enabled* (Updated) FW: Norton AntiVirus *enabled* ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\userinit.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe C:\Program Files\Bonjour\mDNSResponder.exe svchost.exe C:\Program Files\IOGEAR\Bluetooth Software\bin\btwdins.exe C:\WINDOWS\System32\CTsvcCDA.exe C:\WINDOWS\system32\svchost.exe -k hpdevmgmt C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\BCMSMMSG.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\WINDOWS\System32\DSentry.exe C:\Program Files\Common Files\Dell\EUSW\Support.exe C:\Program Files\Dell\Media Experience\PCMService.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\MozyHome\mozybackup.exe C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\Program Files\AirPort\APAgent.exe C:\PROGRA~1\NORTON~3\NORTON~2\NPROTECT.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\PROGRA~1\NORTON~3\NORTON~2\SPEEDD~1\NOPDB.EXE C:\WINDOWS\System32\svchost.exe -k imgsvc C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\IOGEAR\Bluetooth Software\BTTray.exe C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe C:\Program Files\Handspring\HOTSYNC.EXE C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\MozyHome\mozystat.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe C:\PROGRA~1\IOGEAR\BLUETO~1\BTSTAC~1.EXE C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE C:\WINDOWS\system32\svchost.exe -k HPService C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe C:\Program Files\SlimBrowser\sbrowser.exe C:\Documents and Settings\Philip Ingber\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ uWindow Title = Microsoft Internet Explorer uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = 127.0.0.1;localhost;*.local BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hewlett-packard\digital imaging\smart web printing\hpswp_printenhancer.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hewlett-packard\digital imaging\smart web printing\hpswp_BHO.dll TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File TB: {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - No File EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NVMCTRAY.DLL,NvTaskbarInit uRun: [Aim6] uRun: [EasyLinkAdvisor] "c:\program files\linksys easylink advisor\LinksysAgent.exe" /startup uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [BCMSMMSG] BCMSMMSG.exe mRun: [DVDSentry] c:\windows\system32\DSentry.exe mRun: [diagent] "c:\program files\creative\sblive\diagnostics\diagent.exe" startup mRun: [DwlClient] c:\program files\common files\dell\eusw\Support.exe mRun: [PCMService] "c:\program files\dell\media experience\PCMService.exe" mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent mRun: [nwiz] nwiz.exe /install mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [NSWosCheck] "c:\program files\norton systemworks\osCheck.exe" mRun: [osCheck] "c:\program files\norton antivirus\osCheck.exe" mRun: [HP Software Update] c:\program files\hewlett-packard\hp software update\HPWuSchd2.exe mRun: [hpqSRMon] c:\program files\hewlett-packard\digital imaging\bin\hpqSRMon.exe mRun: [AirPort Base Station Agent] "c:\program files\airport\APAgent.exe" mRun: [QuickTime Task] "c:\program files\qt lite\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" dRun: [Symantec NetDriver Warning] c:\progra~1\symnet~1\SNDWarn.exe dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t dRunOnce: [SRUUninstall] "c:\windows\system32\msiexec.exe" /x {6AF90EF6-F7F9-466C-99F4-1774826FBB40} /qn REBOOT=ReallySuppress StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\iogear\bluetooth software\BTTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\datavi~1.lnk - c:\program files\common files\dataviz\DvzIncMsgr.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\handspring\HOTSYNC.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpoddt~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mozyho~1.lnk - c:\program files\mozyhome\mozystat.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\office~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hposol08.exe uPolicies-explorer: NoViewOnDrive = 0 (0x0) mPolicies-explorer: = IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: Send To &Bluetooth - c:\program files\iogear\bluetooth software\btsendto_ie_ctx.htm IE: {5E638779-1818-4754-A595-EF1C63B87A56} - c:\program files\norton systemworks\norton cleanup\WCQuick.lnk IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\iogear\bluetooth software\btsendto_ie.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hewlett-packard\digital imaging\smart web printing\hpswp_BHO.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll Trusted Zone: aol.com\free Trusted Zone: turbotax.com DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: Yahoo! Dominoes - hxxp://download2.games.yahoo.com/games/clients/y/dot9_x.cab DPF: Yahoo! Pyramids - hxxp://origin.games.yahoo.net/games/clients/y/pyt1_x.cab DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB DPF: {01CA75F1-054B-4A63-9221-C6926369EC52} - hxxp://install.homestead.com/~site/InstallFiles/SIFiles/lpxlive/HS_live.cab DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} - hxxp://www.plaxo.com/activex/PlaxoInstall.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} - hxxps://iepdirect.mhric.org/ScriptX/smsx.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - hxxp://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} - hxxp://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB DPF: {38578BF0-0ABB-11D3-9330-0080C6F796A1} - hxxp://www.imgag.com/cp/install/AxCtp.cab DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www2.snapfish.com/SnapfishActivia.cab DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab DPF: {4B48D5DF-9021-45F7-A240-60304302A215} - hxxp://download.microsoft.com/download/b/d/b/bdb4e4ee-63b2-45ff-9d84-33205bf43143/WebCleaner.cab DPF: {5AA5A569-F96F-4628-A528-8B3698F558BB} - hxxp://install.homestead.com/~site/InstallFiles/SIFiles/lpxlive/HS_live.cab DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - hxxp://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey/us/win/QuickTimeInstaller.exe DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} - hxxp://us.games2.yimg.com/download.games.yahoo.com/games/play/client/exentctl_0_0_0_2.ocx DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1124279471546 DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} - hxxp://www.tseweb.nyackschools.com/msrdp.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} - hxxp://www.crucial.com/controls/cpcScanner.cab DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} - hxxps://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - hxxps://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {E62A47D8-74B1-4A93-963A-E5E43B7CC5C2} - hxxp://www.zuvio.com/opnste/UCSearch.CAB DPF: {E856B973-45FD-4559-8F82-EAB539144667} - hxxp://pccheckup.dellfix.com/rel/36/install/gtdownde.cab DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} - hxxp://h30155.www3.hp.com/ediags/hpfix/aio/en/check/qdiagh.cab?326 DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100 Notify: igfxcui - igfxsrvc.dll Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SSODL: SysWin - {6a950a63-e31f-4794-8ddb-858ab1755a2d} - No File SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll SEH: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No File ================= FIREFOX =================== FF - ProfilePath - ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-1-31 64160] R1 mozyFilter;mozyFilter;c:\windows\system32\drivers\mozy.sys [2008-12-8 53752] R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 950096] R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-25 149352] R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-25 149352] R2 IntuitUpdateService;Intuit Update Service;c:\program files\common files\intuit\update service\IntuitUpdateService.exe [2009-1-28 13088] R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2008-12-17 10384] R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-25 149352] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2009-1-5 179856] R2 NProtectService;Norton UnErase Protection;c:\progra~1\norton~3\norton~2\NPROTECT.EXE [2005-11-3 95832] R2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2005-11-6 1251720] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2008-9-2 99376] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-1-5 15504] R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090224.048\NAVENG.SYS [2009-2-25 89104] R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090224.048\NAVEX15.SYS [2009-2-25 876144] R3 vsc32;Virtual Sound Canvas 3.2;c:\windows\system32\drivers\vsc.sys [2007-4-4 951284] S2 mrtRate;mrtRate; [x] S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2007-5-29 23888] S3 getPlus® Helper;getPlus® Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-2-24 33752] S3 MAUSBJL;Service for M-Audio JamLab Driver (WDM);c:\windows\system32\drivers\mausbjl.sys –> c:\windows\system32\drivers\mausbjl.sys [?] S3 wg121;NETGEAR WG121 802.11g Wireless USB2.0 Adapter;c:\windows\system32\drivers\wg121nd5.sys [2008-9-5 337216] =============== Created Last 30 ================ 2009-02-25 06:01 5,058 a——- c:\windows\system32\tmp.reg 2009-02-19 12:03 579,464 a——- c:\windows\system32\SymNeti.dll 2009-02-19 12:03 207,240 a——- c:\windows\system32\SymRedir.dll 2009-02-19 11:31 31,280 a——- c:\windows\system32\drivers\SymIM.sys 2009-02-19 11:31 9,844 a——- c:\windows\system32\drivers\SymRedir.cat 2009-02-19 11:31 1,611 a——- c:\windows\system32\drivers\SymRedir.inf 2009-02-19 11:31 41,008 a——- c:\windows\system32\drivers\symndisv.sys 2009-02-19 11:31 184,496 a——- c:\windows\system32\drivers\symtdi.sys 2009-02-19 11:31 96,560 a——- c:\windows\system32\drivers\symfw.sys 2009-02-19 11:31 38,576 a——- c:\windows\system32\drivers\symids.sys 2009-02-19 11:31 37,424 a——- c:\windows\system32\drivers\symndis.sys 2009-02-19 11:31 22,320 a——- c:\windows\system32\drivers\symredrv.sys 2009-02-19 11:31 13,616 a——- c:\windows\system32\drivers\symdns.sys 2009-02-14 19:53 –d—– c:\program files\common files\AnswerWorks 5.0 2009-01-31 05:43 64,160 a——- c:\windows\system32\drivers\Lbd.sys 2009-01-31 05:41 -cd-h— c:\docume~1\alluse~1\applic~1\{83C91755-2546-441D-AC40-9A6B4B860800} ==================== Find3M ==================== 2009-02-24 05:55 65,536 a——- c:\windows\system32\userinit.exe 2009-02-11 10:19 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-11 10:19 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-02-04 09:45 6 a——- c:\windows\fonts\wfonts.key 2009-01-31 05:43 15,688 a——- c:\windows\system32\lsdelete.exe 2009-01-16 21:35 3,594,752 ——– c:\windows\system32\dllcache\mshtml.dll 2009-01-09 05:15 124,464 a——- c:\windows\system32\drivers\SYMEVENT.SYS 2009-01-09 05:15 10,635 a——- c:\windows\system32\drivers\SYMEVENT.CAT 2009-01-09 05:15 806 a——- c:\windows\system32\drivers\SYMEVENT.INF 2009-01-09 05:15 60,808 a——- c:\windows\system32\S32EVNT1.DLL 2008-12-21 07:41 410,984 a——- c:\windows\system32\deploytk.dll 2008-12-19 04:10 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe 2008-12-19 04:10 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe 2008-12-19 00:25 634,024 ——– c:\windows\system32\dllcache\iexplore.exe 2008-12-19 00:23 161,792 ——– c:\windows\system32\dllcache\ieakui.dll 2008-12-12 11:18 87,336 a——- c:\windows\system32\dns-sd.exe 2008-12-12 11:11 61,440 a——- c:\windows\system32\dnssd.dll 2008-12-11 05:57 333,952 ——– c:\windows\system32\dllcache\srv.sys 2008-06-24 17:37 114,320 a——- c:\docume~1\philip~1\applic~1\GDIPFONTCACHEV1.DAT 2007-08-29 20:58 96 a——- c:\program files\appletfile.props 2006-10-06 07:03 560 a——- c:\docume~1\philip~1\applic~1\ViewerApp.dat 2005-04-28 17:07 32 a—-r– c:\documents and settings\all users\hash.dat 2005-04-05 10:36 38,912 a—h— c:\docume~1\philip~1\applic~1\RBShell550.dll 2005-04-05 10:36 29,184 a—h— c:\docume~1\philip~1\applic~1\RBInternetEncodings550.dll 2005-04-05 10:36 28,160 a—h— c:\docume~1\philip~1\applic~1\MBSLaunchServicesPlugin7339.dll 2004-12-03 17:33 35,121,138 a——- c:\program files\NIS_Retail.EXE 2008-06-26 21:05 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008062620080627\index.dat ============= FINISH: 7:21:15.29 ===============

Attachments:

Hi,

Please click Start >> Control Panel >> Add/Remove Programs. Find the following item on the list and click Remove.
Java™ SE Runtime Environment 6 Update 1


Open Windows Defender.

Click on Tools, General Settings.
Scroll down and uncheck Turn on real-time protection (recommended).
After you uncheck this, click on the Save button and close Windows Defender.

After all of the fixes are complete it is very important that you enable Real-time Protection again.


Please download OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"=-
    "{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}"=-
    "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=-
    "{EF99BD32-C1FB-11D2-892F-0090271D4F88}"=-
    "{C4069E3A-68F1-403E-B40E-20066696354B}"=-
    "{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}"=-
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Explorer Bars]
    "{32683183-48a0-441b-a342-7c2a440a9478}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    "SysWin"=-
    [-HKEY_CLASSES_ROOT\{6a950a63-e31f-4794-8ddb-858ab1755a2d}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=-

    :Commands
    [emptytemp]
    [Reboot]

  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


We need to upload a file to Jotti

1. Click HERE to get to Jotti's site.

2. At the top of the Jotti window, use the Browse button to locate the following file on your system:

C:\WINDOWS\fonts\wfonts.key

3. Once you have located the file, click SUBMIT and the content of the file will be uploaded by the site and analysed.

4. Please provide me with the results of the analysis.


Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply. Please post a new DDS log as well (just DDS.txt).

Thanks.
When I run OTMovit3, after I paste in the commands and get the results in the right pane, the program seizes, becomes non-responsive. I can't copy the results to the clipboard …I checked the OT folders and there are no logs present. Any ideas? About how long does it take to run it?
Hi,

Hmm, it should be rebooting the machine and then making the log. Try disabling SpyBot as well.

You need to disable TeaTimer, so that it doesn't interfere with our fix.

This is a two step process.
First step:
  • Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol)
  • If you have the new version 1.5, click once on Resident Protection, then right-click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.
  • If you have Version 1.4, Click on Exit Spybot S&D Resident
Second step, For both versions :
  • Open Spybot S&D
  • Click Mode, choose Advanced Mode
  • Go to the bottom of the vertical panel on the left, click Tools
  • Then, also in left panel, click Resident shows a red/white shield.
  • If your firewall raises a question, say OK
  • In the Resident protection status frame, Uncheck the box labeled Resident "Tea-Timer"(Protection of over-all system settings) active
  • OK any prompts.
  • Use File, Exit to terminate Spybot
  • Reboot your machine for the changes to take effect.
Then try the OTMI fix again. Make sure all other Windows are closed before you hit MoveIt. If that still doesn't work, give it a go in safe mode. Make sure you give the program time to sort itself out and reboot the machine as well. It should be fairly fast but give it a few minutes if it seems to hang.

Thanks.
Keeps seizing up … waited about 10 minutes then in the title bar it stated non-responsive program …so I'm going to try safe mode (never done that before) …
…safe mode did not work, still hung up, but this time after alot od hard drive activity … still no log in the folder … also, I now seem to have some sort of a driver problem … Found New Hardware window opens up, looking for a new driver, but doesn;t tell me what device it has found … says unknown …. maybe just a coincedence … oh well, work on one problem at a time … any ideas?
..when I search for it, it finds it in the search window, but when I try to find it amongst all of the files in Fonts, I can't seem to see it … going blind!!
Got Jotti to work by entering the pathname directly rather than browing … here are the results Service Service load: 0% 100% File: wfonts.key Status: OK MD5: 53c1fc5ec19f61d2e81e36c99c100aec Packers detected: - Scanner results Scan taken on 25 Feb 2009 16:26:22 (GMT) A-Squared Found nothing AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing CPsecure Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Ikarus Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing Panda Antivirus Found nothing Sophos Antivirus Found nothing VirusBuster Found nothing VBA32 Found nothing Powered by Disclaimer This service is by no means 100% safe. If this scanner says 'OK', it does not necessarily mean the file is clean. There could be a whole new virus on the loose. NEVER rely on one single product only, not even this service, even though it utilizes several products. Therefore, We cannot and will not be held responsible for any damage caused by results presented by this non-profit online service. Scanning can take a while, since several scanners are being used, plus the fact some scanners use very high levels of (time consuming) heuristics. Scanners used are Linux versions, differences with Windows scanners may or may not occur. Some scanners will only report one virus when scanning archives with multiple pieces of malware. Virus definitions are updated every hour. There is a 10Mb limit per file. Please refrain from uploading tons of hex-edited or repacked variants of the same sample. Please do not ask for viruses uploaded here, unless you work for an anti-virus vendor. They are not for trade. This is a legitimate service, not a VX site. Viruses uploaded here will be distributed to antivirus vendors without exception. Read more about this in our privacy policy. If you do not want your files to be distributed, please do not send them at all. Sponsored by HotelScraper.com. ——————————————————————————– Statistics Last file scanned at least one scanner reported something about: videoget.v3.0.2.43-patch.exe (MD5: 565998634f0e2b4dc9499ae286dbf05f, size: 154112 bytes), detected by: Scanner Malware name A-Squared Trojan-Downloader.Win32.Small!IK AntiVir BDS/Generic.131183 ArcaVir X Avast X AVG Antivirus X BitDefender Backdoor.Generic.131183 ClamAV Backdoor.Agent-6 CPsecure BackDoor.Linux.Sckit.h Dr.Web X F-Prot Antivirus W32/Backdoor2.DASK F-Secure Anti-Virus X Ikarus Trojan-Downloader.Win32.Small Kaspersky Anti-Virus X NOD32 a variant of Win32/HackTool.Patcher.A application Norman Virus Control W32/OnLineGames.IAKN Panda Antivirus X Sophos Antivirus Troj/AdbPat-A VirusBuster X VBA32 X
Thanks for the Jotti results.

No idea what's going on with OTMI3. I have notified the developer. We will plod on with a different route. I don't think the driver stuff is related, but we'll see.

Did you make a backup with ERUNT before starting this topic? If not, now is the time to do so. See instructions here if you need to:
http://forums.whatthetech.com/Welcome_New_…ers_t34502.html

Next, please do this:
  • Copy the contents of the Code Box below to Notepad.
  • Name the file as fix.reg
  • Change the Save as Type to All Files
  • and Save it on the desktop
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"=-
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}"=-
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=-
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"=-
"{C4069E3A-68F1-403E-B40E-20066696354B}"=-
"{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}"=-

[-HKEY_CLASSES_ROOT\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}]

[-HKEY_CLASSES_ROOT\CLSID\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}]

[-HKEY_CLASSES_ROOT\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}]

[-HKEY_CLASSES_ROOT\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}]

[-HKEY_CLASSES_ROOT\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}]

[-HKEY_CLASSES_ROOT\CLSID\{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Explorer Bars]
"{32683183-48a0-441b-a342-7c2a440a9478}"

[-HKEY_CLASSES_ROOT\CLSID\{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SysWin"=-

[-HKEY_CLASSES_ROOT\CLSID\{6a950a63-e31f-4794-8ddb-858ab1755a2d}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=-

[-HKEY_CLASSES_ROOT\CLSID\{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}]
Make sure there are NO blank lines before REGEDIT4, and a blank line at the end.

Then right-click on the fix.reg file and click merge, say yes to any prompts.


Please reboot and then continue with my instructions from GMER onwards. I also want a fresh DDS log.

Thanks.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI