This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] AntivirusPro 2009

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My sons computer is infectd wih avp2009. I came to this forum after I tried to remove it myself. I used malwarebytes anti malware and that removed a lot of stuff, but it (or something else) came back. I then used esets online scanner. Same results. Found some and popups retrned after. He had no AV so I installed AVG free. It located about 10 trojans (vundo). Thats when I came here. I have ran the atf cleaner and mbam as the instructions said. Here is the log for mbam.

Malwarebytes' Anti-Malware 1.34
Database version: 1811
Windows 5.0.2195 Service Pack 4

2/28/2009 9:21:37 AM
mbam-log-2009-02-28 (09-21-37).txt

Scan type: Quick Scan
Objects scanned: 55845
Time elapsed: 15 minute(s), 21 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINNT\system32\iifecdcB.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINNT\system32\ljJYQIBU.dll (Trojan.Vundo) -> Quarantined and deleted successfully.


And here is the HJT log.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:01:24 AM, on 2/28/2009
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINNT\system32\CTSvcCDA.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\ptssvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Creative\ShareDLL\MediaDet.Exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O1 - Hosts: 91.207.117.244 browser-security.microsoft.com
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ttool] C:\WINNT\9129837.exe
O4 - HKCU\..\Run: [afc0sefjvvti9b4hoozoii6yy4usncc0yhz7pqk] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\gf8fkb8.exe
O4 - HKCU\..\Run: [jr5rlu80mm386owqut] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\x1jzxuwcj.exe
O4 - HKCU\..\Run: [c8zsqlhuaxnx2lgjphsel1s2klxx18qw43r6nfvsw26fbsr2y] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\j0d5bskx634.exe
O4 - HKCU\..\Run: [jxvxs5uaqxzx94izpp7axvx2wq2lv3mdzgjuadyi5qo0izk] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\q873566xh.exe
O4 - HKCU\..\Run: [tq1bnko6rc710u04i0fppxz8obctmf32ixfjntil337nzv] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\hr5xeu00qr.exe
O4 - HKCU\..\Run: [c9ecqf1ywpq9yurgftr57baroxl770s3el3wtrmk] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\c4oqrvwndic.exe
O4 - HKCU\..\Run: [ouo2wrbf5criwaeerc0qaiq90y64] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\lnu7j5w1q.exe
O4 - HKCU\..\Run: [etvyntcm7qypatk] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\akretw6bd.exe
O4 - HKCU\..\Run: [z57xkb9i6egl4kjronla1ehviuu030wemqpshm0jjzpxd3z] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\scfsoatdx.exe
O4 - HKCU\..\Run: [r36v1007yw0qpn0235t5gkceq8hdgqtcnn5x54] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\y41fy8ja.exe
O4 - HKCU\..\Run: [wci2vora6ky6aefhyejyftxu6cvqgul50igpu2omndxz5] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\x7hrpai.exe
O4 - HKCU\..\Run: [gpr29jmzf61q5a890u27l60gfn7e2ok] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\c0kdaoolvm.exe
O4 - HKCU\..\Run: [k7jzrripm3h] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\xyp9bw01.exe
O4 - HKCU\..\Run: [gzsgnbzn8zdk6945vbq7817y] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\emi9s2nxy0.exe
O4 - HKCU\..\Run: [voq4j673jbag1nrkv76jhfwn2iywjtw74evqtt47k6hn] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\piebt6r3xgd0.exe
O4 - HKCU\..\Run: [ys6h3bl0qeql37brk1nbp7u6yvv149mpakc] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\l6ywntu2.exe
O4 - HKCU\..\Run: [xcbrowf92dwv5] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\hsqh97.exe
O4 - HKCU\..\Run: [mx1v9v7lybfp4988dw18vddwli9x2z958] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\igd0y74nb2.exe
O4 - HKCU\..\Run: [z4akkh820z3rqxlfbp7hmcif378y099jxnacvxt] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\e0cs79kc77y8u.exe
O4 - HKCU\..\Run: [x6dhidqld0qrq56ua] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\dtwtbcq56e5.exe
O4 - HKCU\..\Run: [p9kjbtyfu3i3ihdafmarw6] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\n0t98jivylvih.exe
O4 - HKCU\..\Run: [vcepfx72bd7exjabbrf5k7e1an3rb4xmpmevv8] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\mcdat1ypgc5.exe
O4 - HKCU\..\Run: [dlte97dwxla] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\do6t8eb.exe
O4 - HKCU\..\Run: [xya3awkyt8vhzlue48cwrm91vyhj] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\ptjypk2qfno1m.exe
O4 - HKCU\..\Run: [m5jh3jgj2r4i8axxyru9ihjpphvufy7is44an0szl7jz] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\ne9mgk31dz.exe
O4 - HKCU\..\Run: [us40amutdxw0v27zjs28oi9c8v] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\ro9c4gspi9tt.exe
O4 - HKCU\..\Run: [xenz2kq3lzacsiw1v8cezu4qtju591ld2b3b7ecfic8gb50kgl] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\yngensm1yl.exe
O4 - HKCU\..\Run: [crkr95qmsfrdzq6srpfe5rr8v4x2ow6cdwa87] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\kbsvlkw.exe
O4 - HKUS\.DEFAULT\..\Run: [StartupLog] iwnujdss2.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [Sakemsneql] simenu.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
O15 - Trusted Zone: http://us.mcafee.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/…_2/axofupld.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = MyDomain
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = MyDomain
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = MyDomain
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: karna.dat
O20 - Winlogon Notify: avgrsstarter - C:\WINNT\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\system32\CTSvcCDA.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: HFP Service (hfprog) - Unknown owner - C:\WINNT\system32\hfp.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: ptssvc - KODAK - C:\Program Files\Kodak\Kodak EasyShare software\bin\ptssvc.exe
O24 - Desktop Component 0: (no name) - http://mail.yimg.com/us.js.yimg.com/combo?…h/mg/uhbt2v4.js

–
End of file - 8423 bytes
Hi dstang1979, welcome to the forum.

Please be advised, as I'm still in training, all my replies will have to be approved by a teacher or expert before I can post them. This may cause some delays, but I will do my best to keep them as short as possible.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.
I will post back soon with additional instructions.


Thanks
Hi dstang1979,

Please be adviced, 1 or more infections have been identified with having backdoor capabilities.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

I suggest you do the following immediately:
  • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.

First

Open Control Panel > Add/Remove Programs, uninstall if present
  • AntivirusPro 2009
  • PartyPoker.net



Next

Open hijackthis, do a system scan only and checkmark these lines, if present

O4 - HKCU\..\Run: [ttool] C:\WINNT\9129837.exe
O4 - HKCU\..\Run: [afc0sefjvvti9b4hoozoii6yy4usncc0yhz7pqk] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\gf8fkb8.exe
O4 - HKCU\..\Run: [jr5rlu80mm386owqut] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\x1jzxuwcj.exe
O4 - HKCU\..\Run: [c8zsqlhuaxnx2lgjphsel1s2klxx18qw43r6nfvsw26fbsr2y] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\j0d5bskx634.exe
O4 - HKCU\..\Run: [jxvxs5uaqxzx94izpp7axvx2wq2lv3mdzgjuadyi5qo0izk] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\q873566xh.exe
O4 - HKCU\..\Run: [tq1bnko6rc710u04i0fppxz8obctmf32ixfjntil337nzv] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\hr5xeu00qr.exe
O4 - HKCU\..\Run: [c9ecqf1ywpq9yurgftr57baroxl770s3el3wtrmk] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\c4oqrvwndic.exe
O4 - HKCU\..\Run: [ouo2wrbf5criwaeerc0qaiq90y64] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\lnu7j5w1q.exe
O4 - HKCU\..\Run: [etvyntcm7qypatk] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\akretw6bd.exe
O4 - HKCU\..\Run: [z57xkb9i6egl4kjronla1ehviuu030wemqpshm0jjzpxd3z] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\scfsoatdx.exe
O4 - HKCU\..\Run: [r36v1007yw0qpn0235t5gkceq8hdgqtcnn5x54] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\y41fy8ja.exe
O4 - HKCU\..\Run: [wci2vora6ky6aefhyejyftxu6cvqgul50igpu2omndxz5] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\x7hrpai.exe
O4 - HKCU\..\Run: [gpr29jmzf61q5a890u27l60gfn7e2ok] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\c0kdaoolvm.exe
O4 - HKCU\..\Run: [k7jzrripm3h] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\xyp9bw01.exe
O4 - HKCU\..\Run: [gzsgnbzn8zdk6945vbq7817y] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\emi9s2nxy0.exe
O4 - HKCU\..\Run: [voq4j673jbag1nrkv76jhfwn2iywjtw74evqtt47k6hn] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\piebt6r3xgd0.exe
O4 - HKCU\..\Run: [ys6h3bl0qeql37brk1nbp7u6yvv149mpakc] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\l6ywntu2.exe
O4 - HKCU\..\Run: [xcbrowf92dwv5] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\hsqh97.exe
O4 - HKCU\..\Run: [mx1v9v7lybfp4988dw18vddwli9x2z958] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\igd0y74nb2.exe
O4 - HKCU\..\Run: [z4akkh820z3rqxlfbp7hmcif378y099jxnacvxt] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\e0cs79kc77y8u.exe
O4 - HKCU\..\Run: [x6dhidqld0qrq56ua] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\dtwtbcq56e5.exe
O4 - HKCU\..\Run: [p9kjbtyfu3i3ihdafmarw6] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\n0t98jivylvih.exe
O4 - HKCU\..\Run: [vcepfx72bd7exjabbrf5k7e1an3rb4xmpmevv8] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\mcdat1ypgc5.exe
O4 - HKCU\..\Run: [dlte97dwxla] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\do6t8eb.exe
O4 - HKCU\..\Run: [xya3awkyt8vhzlue48cwrm91vyhj] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\ptjypk2qfno1m.exe
O4 - HKCU\..\Run: [m5jh3jgj2r4i8axxyru9ihjpphvufy7is44an0szl7jz] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\ne9mgk31dz.exe
O4 - HKCU\..\Run: [us40amutdxw0v27zjs28oi9c8v] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\ro9c4gspi9tt.exe
O4 - HKCU\..\Run: [xenz2kq3lzacsiw1v8cezu4qtju591ld2b3b7ecfic8gb50kgl] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\yngensm1yl.exe
O4 - HKCU\..\Run: [crkr95qmsfrdzq6srpfe5rr8v4x2ow6cdwa87] C:\DOCUME~1\HARRISON\LOCALS~1\Temp\kbsvlkw.exe
O4 - HKUS\.DEFAULT\..\Run: [StartupLog] iwnujdss2.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [Sakemsneql] simenu.exe (User 'Default user')
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O20 - AppInit_DLLs: karna.dat


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.




Next, please use ATF again.

Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.

*Note your computer may boot a little slower the first couple of times.*



You will need to use Internet Explorer for this scan.
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computerr under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Desktop is a good place.
  • Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply along with a new HJT log.
Please post back with
  • Kaspersky log
  • new HJT log taken after all othe steps are completed.
Tell us how your computer is now.

Thanks
Thanks oldman960. I have followed your instructions, and here are the results.

Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:39:09 AM, on 3/2/2009
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINNT\system32\CTSvcCDA.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\ptssvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINNT\system32\mspmspsv.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\Program Files\Creative\ShareDLL\MediaDet.Exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AVG\AVG8\aAvgApi.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O1 - Hosts: 91.207.117.244 browser-security.microsoft.com
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
O15 - Trusted Zone: http://us.mcafee.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/…_2/axofupld.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = MyDomain
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = MyDomain
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = MyDomain
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINNT\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\system32\CTSvcCDA.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: HFP Service (hfprog) - Unknown owner - C:\WINNT\system32\hfp.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: ptssvc - KODAK - C:\Program Files\Kodak\Kodak EasyShare software\bin\ptssvc.exe
O24 - Desktop Component 0: (no name) - http://mail.yimg.com/us.js.yimg.com/combo?…h/mg/uhbt2v4.js

–
End of file - 5070 bytes



Kaspersky log:

——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Monday, March 2, 2009
Operating System: Microsoft Windows 2000 Professional Service Pack 4 (build 2195)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Sunday, March 01, 2009 21:53:25
Records in database: 1860452
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\

Scan statistics:
Files scanned: 88076
Threat name: 4
Infected objects: 11
Suspicious objects: 0
Duration of the scan: 07:50:47


File name / Threat name / Threats count
C:\Documents and Settings\HARRISON\My Documents\Dustin\Apps\Weatherbug 6.0 Setup.EXE Infected: not-a-virus:AdWare.Win32.MyWay.j 1
C:\WINNT\Downloaded Installations\{90F203F9-7331-4CDC-993B-1261B9157E80}\Bikinis Thongs Lingerie Screensaver.msi Infected: not-a-virus:AdWare.Win32.NavExcel 3
C:\WINNT\system32\hfp.exe Infected: Trojan-Spy.Win32.EmailSpyPro.e 1
G:\Documents and Settings\HARRISON\Local Settings\Temp\Temporary Internet Files\Content.IE5\K1ER45UF\frame[1].htm Infected: Trojan.JS.Seeker 1
G:\Documents and Settings\HARRISON\My Documents\Ron\Apps\Weatherbug 6.0 Setup.EXE Infected: not-a-virus:AdWare.Win32.MyWay.j 1
G:\WINNT\Downloaded Installations\{90F203F9-7331-4CDC-993B-1261B9157E80}\Bikinis Thongs Lingerie Screensaver.msi Infected: not-a-virus:AdWare.Win32.NavExcel 3
G:\WINNT\system32\hfp.exe Infected: Trojan-Spy.Win32.EmailSpyPro.e 1

The selected area was scanned.
Hi dstang1979,

What is your G:\ drive?



Open hijackthis, do a system scan only and checkmark these lines, if present

O1 - Hosts: 91.207.117.244 browser-security.microsoft.com

Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.

If there isn't any reason to have http://us.mcafee.com in the Trusted Zone you can add this line to the above fix.

O15 - Trusted Zone: http://us.mcafee.com




Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it.
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
    • Do Not copy the word CODE
    • please note the fix starts with the :

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\Documents and Settings\HARRISON\My Documents\Dustin\Apps\Weatherbug 6.0 Setup.EXE 
    C:\WINNT\Downloaded Installations\{90F203F9-7331-4CDC-993B-1261B9157E80}\Bikinis Thongs Lingerie Screensaver.msi 
    G:\Documents and Settings\HARRISON\Local Settings\Temp\Temporary Internet Files\Content.IE5\K1ER45UF\frame[1].htm 
    G:\Documents and Settings\HARRISON\My Documents\Ron\Apps\Weatherbug 6.0 Setup.EXE 
    G:\WINNT\Downloaded Installations\{90F203F9-7331-4CDC-993B-1261B9157E80}\Bikinis Thongs Lingerie Screensaver.msi 
    C:\WINNT\9129837.exe
    C:\simenu.exe /s
    C:\karna.dat /s
    
    :Commands
    [Purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please post back with
  • OTMOVEIT3 log
  • combofix log
  • new HJT log taken after all other steps have been completed.
Let us know how the computer is now.

Thanks
Hi oldman960. I was visiting my son out of state while working on ridding his computer of its infections. I had to return home. I told him to let me know when he wanted to finish this and he hasn't called. So, I suppose for now we are done. I thank you for your help so far. This forum has helped me fix my computers before and it is a real benefit to all of us victims. If he calls me sometime I will be back. Later……..

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI