This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] I need help please

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When I search in google everything looks normal. But when I click on any one of the links it redirects to some other page not related. :pullhair: I've downloaded Hijackthis 1.0.0.1 but it won't run :pullhair:
Hi,

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Thanks.
DDS (Ver_09-03-16.01) - NTFSx86 Run by [removed] at 14:22:41.87 on Sun 03/15/2009 Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_12 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.448 [GMT -7:00] AV: ThreatFire *On-access scanning enabled* (Updated) ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Common Files\InterVideo\FastTVSync\FastTVSync.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\ThreatFire\TFTray.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\Program Files\Windows Desktop Search\WindowsSearch.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\ThreatFire\TFService.exe C:\Program Files\Windows Media Player\WMPNetwk.exe C:\WINDOWS\system32\SearchIndexer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Internet Explorer\Iexplore.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\Documents and Settings\slims toy\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uSearch Page = hxxp://google.icq.com uDefault_Page_URL =

Attachments:

Hi,

LimeWire
You have LimeWire, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm
See Clean/Infected P2P Programs here

I would recommend that you uninstall LimeWire, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.


Click Start >> Control Panel >> Add/Remove Programs. Find each item below on the list and click Remove:
J2SE Runtime Environment 5.0 Update 1
J2SE Runtime Environment 5.0 Update 6
Java™ 6 Update 2
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7
Java™ SE Runtime Environment 6 Update 1



If you did not install or do not use New.Net then have a look here on how to remove it:
NewDotNet Removal Procedure 4


Please download OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :reg
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "xhrmy"=-

    :services
    gxc113b
    gxc113p

    :files
    c:\windows\system32\drivers\gxc113b.sys
    c:\windows\system32\drivers\gxc113p.sys
    c:\windows\Xhrmy.exe

    :Commands
    [emptytemp]
    [Reboot]

  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.
Let me know how things are running now.

Thanks.
Sorry I thought I got that carp** off my pc a while ago…daughter bad! Its gone now. Oh and thanks for helping me. ========== REGISTRY ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\xhrmy deleted successfully. ========== SERVICES/DRIVERS ========== Unable to stop service gxc113b . Unable to stop service gxc113p . ========== FILES ========== c:\windows\system32\drivers\gxc113b.sys moved successfully. c:\windows\system32\drivers\gxc113p.sys moved successfully. File/Folder c:\windows\Xhrmy.exe not found. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\SLIMST~1\LOCALS~1\Temp\etilqs_w0XnOeGIuwIIBuqBoAva scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\{A4D05ACB-500A-4B85-B9DA-86ECF40CA819}\BIT3E.tmp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_60c.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\slims toy\Local Settings\Application Data\Mozilla\Firefox\Profiles\21d66om7.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\slims toy\Local Settings\Application Data\Mozilla\Firefox\Profiles\21d66om7.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\slims toy\Local Settings\Application Data\Mozilla\Firefox\Profiles\21d66om7.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\slims toy\Local Settings\Application Data\Mozilla\Firefox\Profiles\21d66om7.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\slims toy\Local Settings\Application Data\Mozilla\Firefox\Profiles\21d66om7.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\slims toy\Local Settings\Application Data\Mozilla\Firefox\Profiles\21d66om7.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03162009_161128
Thanks for that, just waiting on the MalwareBytes' log now. Let me know how things are running as well, after MalwareBytes'.
OK, please try this instead.

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2
Link 3

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a HijackThis log so we can continue cleaning the system.

Thanks.
ComboFix 09-03-15.01 - slims toy 2009-03-18 3:38:02.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.607 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: ThreatFire *On-access scanning disabled* (Updated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\slims toy\Local Settings\Application Data\jjptap.dat
c:\documents and settings\slims toy\Local Settings\Application Data\jjptap_nav.dat
c:\documents and settings\slims toy\Local Settings\Application Data\jjptap_navps.dat
c:\program files\Gold VIP Club Casino
c:\program files\Gold VIP Club Casino\_patch\package_list.ini
c:\program files\Gold VIP Club Casino\_patch\package_list.ini.crc
c:\program files\Gold VIP Club Casino\fonts\albw.ttf
c:\program files\Gold VIP Club Casino\installed\Fonts - Latin
c:\program files\Gold VIP Club Casino\installed\Fonts - Latin.ini
c:\program files\Gold VIP Club Casino\installed\packages
c:\program files\INSTALL.LOG
c:\windows\system32\drivers\UAClqjngxiq.sys
c:\windows\system32\MabryObj.dll
c:\windows\system32\nvs2.inf
c:\windows\system32\UACdnosvxbn.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACkmaswesi.dll
c:\windows\system32\UACllovbgkd.log
c:\windows\system32\UACoamwuyyr.dll
c:\windows\system32\UACpaygbhwy.log
c:\windows\system32\UACpcxnrrhf.dll
c:\windows\system32\UACpmufxjvk.log
c:\windows\system32\UACrswkbmee.dll
c:\windows\system32\UACtapuyqpp.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-02-18 to 2009-03-18 )))))))))))))))))))))))))))))))
.

2009-03-17 21:47 . 2009-02-11 10:19 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-17 21:47 . 2009-02-11 10:19 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-03-17 21:46 . 2009-03-17 21:46 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-17 21:30 . 2009-03-17 21:47 d——– c:\program files\Malwarebytes' Anti-Malware
2009-03-16 16:11 . 2009-03-16 16:11 d——– C:\_OTMoveIt
2009-03-14 20:15 . 2009-03-14 20:15 d——– c:\program files\ERUNT
2009-03-14 19:13 . 2009-03-14 19:13 129 –a—— c:\windows\system32\MRT.INI
2009-03-14 18:35 . 2009-03-14 18:35 d——– c:\documents and settings\Guest\Application Data\Windows Desktop Search
2009-03-14 18:35 . 2004-09-29 11:27 d——– c:\documents and settings\Guest\Application Data\Symantec
2009-03-14 18:35 . 2004-09-29 12:50 d——– c:\documents and settings\Guest\Application Data\InterVideo
2009-03-14 18:35 . 2008-05-12 10:20 d——– c:\documents and settings\Guest\Application Data\Gtek
2009-03-14 18:35 . 2009-03-14 18:35 d——– c:\documents and settings\Guest
2009-03-14 17:26 . 2003-02-02 20:06 153,088 –a—— c:\windows\system32\UNRAR3.dll
2009-03-14 14:14 . 2008-06-29 06:54 262,144 –a—— c:\program files\Uninstall Ask Toolbar.dll
2009-03-14 10:04 . 2009-03-14 10:04 54,156 –ah—– c:\windows\QTFont.qfn
2009-03-14 10:04 . 2009-03-14 10:04 1,409 –a—— c:\windows\QTFont.for

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-18 10:45 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-18 02:46 102,664 —-a-w c:\windows\system32\drivers\tmcomm.sys
2009-03-18 02:35 ——— d—–w c:\program files\Common Files\Real
2009-03-14 21:15 ——— d—–w c:\program files\Xvid
2009-03-14 21:13 ——— d—–w c:\documents and settings\All Users\Application Data\McAfee
2009-03-14 21:13 ——— d—–w c:\documents and settings\All Users\Application Data\AOL
2009-03-14 21:08 ——— d—–w c:\documents and settings\slims toy\Application Data\U3
2009-03-14 16:38 ——— d—–w c:\program files\SUPERAntiSpyware
2009-03-14 16:38 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-03-11 02:13 ——— d—–w c:\program files\Java
2009-03-11 01:55 ——— d—–w c:\program files\ThreatFire
2009-03-03 19:19 51,472 —-a-w c:\windows\system32\drivers\TfFsMon.sys
2009-03-03 19:19 39,184 —-a-w c:\windows\system32\drivers\TfSysMon.sys
2009-03-03 19:19 33,040 —-a-w c:\windows\system32\drivers\TfNetMon.sys
2009-03-03 19:19 12,560 —-a-w c:\windows\system32\drivers\TfKbMon.sys
2009-02-27 01:54 ——— d—–w c:\program files\Microsoft Silverlight
2009-01-27 21:39 ——— dc-h–w c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-01-27 14:07 ——— d—–w c:\program files\Lavasoft
2009-01-27 14:05 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2009-01-20 01:14 ——— d—–w c:\program files\ewido anti-malware
2009-01-20 01:12 ——— d—–w c:\program files\CCleaner
2008-08-29 01:40 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082820080829\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EarthLink Installer"="/C" [X]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"FastTVSync"="c:\program files\Common Files\InterVideo\FastTVSync\FastTVSync.exe" [2004-03-11 245760]
"StorageGuard"="c:\program files\VERITAS Software\Update Manager\sgtray.exe" [2002-06-18 155648]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2002-07-25 106551]
"ThreatFire"="c:\program files\ThreatFire\TFTray.exe" [2009-03-03 263440]
"SoundMan"="SOUNDMAN.EXE" [2004-08-31 c:\windows\SOUNDMAN.EXE]

c:\documents and settings\slims toy\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.PIM1"= pclepim1.dll
"VIDC.D263"= xl_x263dec.dll
"vidc.VP40"= vp4vfw.dll
"vidc.VP50"= vp5vfw.dll
"VIDC.CSCD"= camcodec.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.e

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MyWebSearch Email Plugin.lnk]

[HKLM\~\startupfolder\C:^Documents and Settings^slims toy^Start Menu^Programs^Startup^MyWebSearch Email Plugin.lnk]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Launchpad
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BioniXWallpaper

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EarthLink Installer]
/C [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mirabilis ICQ
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xhrmy
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
–a—— 2002-07-25 03:50 106551 c:\windows\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FastTVSync]
–a—— 2004-03-11 03:55 245760 c:\program files\Common Files\InterVideo\FastTVSync\FastTVSync.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 11:50 155648 c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\phc700]
–a—— 2005-07-20 19:56 339968 c:\windows\vphc700.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
–a—— 2002-06-18 01:01 155648 c:\program files\VERITAS Software\Update Manager\sgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2004-08-31 07:48 67584 c:\windows\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"=
"c:\\RedFaction\\RF.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Documents and Settings\\slims toy\\My Documents\\nes\\emulator\\nes\\NESTCL95.EXE"=
"c:\\Program Files\\Quake III Arena\\quake3.exe"=
"c:\\Program Files\\Infogrames\\Line of Sight - Vietnam Demo\\Vietnamd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=

R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2008-05-20 51472]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2008-05-20 39184]
R2 ThreatFire;ThreatFire;c:\program files\ThreatFire\TFService.exe service –> c:\program files\ThreatFire\TFService.exe service [?]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2008-05-31 24652]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2008-05-20 33040]
S0 gxc113b;gxc113b;c:\windows\system32\DRIVERS\gxc113b.sys –> c:\windows\system32\DRIVERS\gxc113b.sys [?]
S0 gxc113p;gxc113p;c:\windows\system32\Drivers\gxc113p.sys –> c:\windows\system32\Drivers\gxc113p.sys [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys –> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S3 BulkUsb;rylm100.sys;c:\windows\system32\drivers\rylm100.sys [2008-02-16 12400]
S3 phc700;USB PC Camera (phc700);c:\windows\system32\drivers\phc700.sys [2006-08-26 541568]

— Other Services/Drivers In Memory —

*Deregistered* - mchInjDrv

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2009-02-24 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe []

2009-03-18 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2008-04-09 13:22]

2009-03-18 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-ATIPTA - c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
HKLM-Run-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
HKLM-Run-Symantec NetDriver Monitor - c:\progra~1\SYMNET~1\SNDMon.exe
HKLM-Run-RealTray - c:\program files\Real\RealPlayer\RealPlay.exe
HKLM-Run-Pure Networks Port Magic - c:\progra~1\PURENE~1\PORTMA~1\PortAOL.exe
HKLM-Run-Mirabilis ICQ - c:\program files\ICQ\NDetect.exe
MSConfigStartUp-AOL Fast Start - c:\program files\America Online 9.0a\AOL.EXE
MSConfigStartUp-AOLDialer - c:\program files\Common Files\AOL\ACS\AOLDial.exe
MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
MSConfigStartUp-HostManager - c:\program files\Common Files\AOL\1127533932\ee\AOLSoftware.exe
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\qttask.exe
MSConfigStartUp-RealTray - c:\program files\Real\RealPlayer\RealPlay.exe
MSConfigStartUp-Symantec NetDriver Monitor - c:\progra~1\SYMNET~1\SNDMon.exe
MSConfigStartUp-New - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: &ICQ Toolbar Search - c:\program files\ICQToolbar\toolbaru.dll/SEARCH.HTML
IE: Read with DeskBot
Trusted Zone: microsoft.com\v4.windowsupdate
Trusted Zone: okdhm.com\www
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\slims toy\Application Data\Mozilla\Firefox\Profiles\21d66om7.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - prefs.js: network.proxy.type - 1
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npagent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-18 03:45:39
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(668)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\WRLogonNTF.dll
c:\program files\ThreatFire\TFWAH.dll
c:\program files\ThreatFire\TFNI.dll

- - - - - - - > 'lsass.exe'(724)
c:\program files\ThreatFire\TFWAH.dll

- - - - - - - > 'explorer.exe'(2024)
c:\program files\ThreatFire\TFWAH.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\ThreatFire\TFService.exe
c:\program files\Webroot\Spy Sweeper\SpySweeper.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\searchindexer.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-03-18 3:54:08 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-18 10:50:45

Pre-Run: 94,021,767,168 bytes free
Post-Run: 93,871,280,128 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

264 — E O F — 2009-03-16 23:03:58
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:02:07 AM, on 3/18/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\InterVideo\FastTVSync\FastTVSync.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ThreatFire\TFService.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [FastTVSync] "C:\Program Files\Common Files\InterVideo\FastTVSync\FastTVSync.exe"
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [EarthLink Installer] " /C
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Microsoft AntiSpyware helper - {3EB801A0-BD9A-48B2-82AB-583DBF358C40} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {3EB801A0-BD9A-48B2-82AB-583DBF358C40} - (no file) (HKCU)
O15 - Trusted Zone: http://www.okdhm.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u…can_unicode.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1176570166687
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1176570477812
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

–
End of file - 6382 bytes
Hi,

Please run OTMoveIt3 again with the following code:
:reg
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EarthLink Installer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EarthLink Installer"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{4982D40A-C53B-4615-B15B-B5B5E98D167C}"=-

:services
gxc113b
gxc113p

:files
c:\windows\system32\drivers\gxc113b.sys
c:\windows\system32\drivers\gxc113p.sys

:Commands
[emptytemp]
[Reboot]

After it reboots, please try and run MalwareBytes' again. It *should* work now.

Also, let me know how the computer is running.

Thanks.
Now it only boots up to the windows logo screen even in safe mode. This happened after OTmoveit3 was done……..great huh.
Hi,

I don't know where that came from. Please restart your computer and tap F8 as if you were going into safe mode. Instead of selecting Safe Mode, please select Last Known Good Configuration and see if that allows you to boot normally.

Have you ever had a problem like this before, either before or during this infection?

Thanks.
I've tried to reboot in all modes but It just stops at the same point which is right before the desktop screen would open. And no I've never had a problem with this at all never even had a virus. :pullhair:
This is very strange, nothing in that last OTMoveIt3 fix could have caused this.

OK, when you start your computer, you should be presented with two options:
Microsoft Windows Recovery Console
Microsoft Windows XP Home Edition

(This should be happening since you ran ComboFix).

Have you tried the Recovery Console, if so does it work? It should just be a command line prompt if it works (it should look say something like C:\WINDOWS>). If it does work and you get to the command prompt, please type the following:
cd erdnt\subs
and then press Enter. If this works, the prompt should change to:
C:\WINDOWS\ERDNT\sUBs>

Next, type:
batch erdnt.con and press Enter. This should being a copying process. When the process is finished and you return to a prompt, please type Exit and hit Enter. Let me know if that allows you to boot.

If the Recovery Console isn't work at all, let me know. Also let me know if you have a Windows Installation Disk at all.

Thanks.
Well I had use my recovery disc and wipe everything out. but I did do a backup 2 months ago of all my data on an 200gb external hard drive so I'm ok. I have no clue what happened but I sure do thank you for all the help you people on here are awesome. Thanks again :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI