This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Help Please with my Hijack log

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have some sort of virus where anytime I try to open up anything to to with an antivirus program I get a broken internet link.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:23:05 AM, on 5/28/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\vVX1000.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Documents and Settings\JohnMary\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\AVG\AVG8\avgui.exe
C:\Documents and Settings\JohnMary\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\JohnMary\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\JohnMary\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\JohnMary\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\JohnMary\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\JohnMary\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\JohnMary\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://signup.primus.ca/index.php3?acct_type=z
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirec…amp;gc=1&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirec…amp;gc=1&q=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirec…p;gc=1&q=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Primus Canada
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\JohnMary\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://signup.primus.ca/index.php3?acct_type=z
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EFBF61C2-C881-4A5D-8B73-15FFA04406BB}: NameServer = 216.254.141.13 209.90.160.220
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

–
End of file - 7322 bytes
Hi,

Please do the following:

Please download DDS from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.


NEXT


Download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.
Here are the two reports you asked for one is copied the other is attached


DDS (Ver_09-05-14.01) - NTFSx86
Run by [removed] at 15:57:57.81 on Thu 05/28/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.80 [GMT -7:00]

AV: AVG Anti-Virus *On-access scanning enabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Documents and Settings\JohnMary\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\vVX1000.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Documents and Settings\JohnMary\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\JohnMary\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\JohnMary\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\VideoLAN\VLC\vlc.exe
C:\Documents and Settings\JohnMary\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\JohnMary\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Microsoft Works\MSWorks.exe
C:\WINDOWS\system32\SPOOL\DRIVERS\W32X86\3\LXCZPSWX.EXE
C:\WINDOWS\system32\SPOOL\DRIVERS\W32X86\3\LXCZJSWX.EXE
C:\Documents and Settings\JohnMary\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\BitTornado\downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://google.com/
uSearch Page = hxxp://www.google.com
uWindow Title = Microsoft Internet Explorer provided by Primus Canada
uSearch Bar = hxxp://www.google.com/ie
mDefault_Page_URL = https://signup.primus.ca/index.php3?acct_type=z
mDefault_Search_URL = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101703&gct=&gc=1&q=
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101703&gct=&gc=1&q=%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: DefaultSearchHook Class: {c94e154b-1459-4a47-966b-4b843befc7db} - c:\program files\asksearch\bin\DefaultSearch.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Google Update] "c:\documents and settings\johnmary\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [Skype] "c:\program files\skype\\phone\Skype.exe" /nosplash /minimized
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe
mRun: [SoundMAX] "c:\program files\analog devices\soundmax\Smax4.exe" /tray
mRun: [Lexmark 1200 Series] "c:\program files\lexmark 1200 series\lxczbmgr.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [VX1000] c:\windows\vVX1000.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\docume~1\johnmary\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab
DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
TCP: {EFBF61C2-C881-4A5D-8B73-15FFA04406BB} = 216.254.141.13 209.90.160.220
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
AppInit_DLLs: avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

============= SERVICES / DRIVERS ===============

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-5-27 12936]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-5-27 98440]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-5-27 26824]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-5-27 90632]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-5-27 874776]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-5-27 231704]
S2 dfchc;Boot Security;c:\windows\system32\svchost.exe -k netsvcs [2002-8-29 14336]

=============== Created Last 30 ================


==================== Find3M ====================

2009-05-26 21:38 76,487 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-03-17 14:24 111,632 a——- c:\windows\VX1000.dll
2009-03-17 14:24 721,936 a——- c:\windows\vVX1000.exe
2009-03-17 14:24 218,128 a——- c:\windows\vVX1000.dll
2009-03-17 14:24 189,456 a——- c:\windows\system32\cVX1000.dll
2009-03-17 14:24 185,360 a——- c:\windows\system32\LCCoin20.dll
2009-03-06 18:32 279,888 a——- c:\program files\musicnotes.dll
2009-03-03 16:17 410,984 a——- c:\windows\system32\deploytk.dll
2009-02-19 18:14 604 a—h— c:\program files\STLL Notifier
2006-07-05 03:55 156,089 a–shr– c:\windows\system32\gntspgrv.dll

============= FINISH: 15:59:51.81 ===============

Attachments:

Here is the other scan you asked for


GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-05-28 17:06:54
Windows 5.1.2600 Service Pack 2


—- Kernel code sections - GMER 1.0.15 —-

? C:\DOCUME~1\JohnMary\LOCALS~1\Temp\catchme.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\System32\svchost.exe[1156] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes JMP 00EAADCD
.text C:\WINDOWS\System32\svchost.exe[1156] NETAPI32.dll!NetpwPathCanonicalize 5B86A259 5 Bytes JMP 00EAAD64
.text C:\WINDOWS\System32\svchost.exe[1212] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes JMP 007FADCD

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Ip ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Services - GMER 1.0.15 —-

Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] dfchc <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\dfchc@DisplayName Boot Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\dfchc@Type 32
Reg HKLM\SYSTEM\CurrentControlSet\Services\dfchc@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\dfchc@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\dfchc@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\CurrentControlSet\Services\dfchc@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\Services\dfchc@Description Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Reg HKLM\SYSTEM\CurrentControlSet\Services\dfchc\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\dfchc\Parameters@ServiceDll C:\WINDOWS\system32\gntspgrv.dll
Reg HKLM\SYSTEM\ControlSet004\Services\dfchc@DisplayName Boot Security
Reg HKLM\SYSTEM\ControlSet004\Services\dfchc@Type 32
Reg HKLM\SYSTEM\ControlSet004\Services\dfchc@Start 2
Reg HKLM\SYSTEM\ControlSet004\Services\dfchc@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet004\Services\dfchc@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet004\Services\dfchc@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet004\Services\dfchc@Description Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.
Reg HKLM\SYSTEM\ControlSet004\Services\dfchc\Parameters
Reg HKLM\SYSTEM\ControlSet004\Services\dfchc\Parameters@ServiceDll C:\WINDOWS\system32\gntspgrv.dll

—- EOF - GMER 1.0.15 —-
Hi,

Please do the following:

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
ComboFix 09-05-28.02 - JohnMary 05/28/2009 19:24.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.125 [GMT -7:00]
Running from: c:\program files\BitTornado\downloads\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning enabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\sysogg.dll

.
((((((((((((((((((((((((( Files Created from 2009-04-28 to 2009-05-29 )))))))))))))))))))))))))))))))
.

2009-05-28 20:23 . 2009-03-26 23:49 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-28 20:23 . 2009-03-26 23:49 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-28 20:02 . 2009-05-28 20:02 ——– d—–w c:\documents and settings\JohnMary\Application Data\Malwarebytes
2009-05-28 20:01 . 2009-05-28 20:01 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-28 20:01 . 2009-05-28 20:23 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-28 17:24 . 2009-05-28 17:24 577024 -c–a-w c:\windows\system32\dllcache\user32.dll
2009-05-28 17:22 . 2009-05-28 17:22 ——– d—–w c:\windows\ERUNT
2009-05-28 17:07 . 2009-05-28 17:07 ——– d—–w c:\windows\system32\NtmsData
2009-05-28 15:22 . 2009-05-28 15:22 ——– d—–w c:\program files\Trend Micro
2009-05-28 15:15 . 2009-05-28 15:15 ——– d–h–w C:\$AVG8.VAULT$
2009-05-28 01:50 . 2009-05-28 01:50 12936 —-a-w c:\windows\system32\drivers\avgrkx86.sys
2009-05-28 01:50 . 2009-05-28 01:50 10520 —-a-w c:\windows\system32\avgrsstx.dll
2009-05-28 01:50 . 2009-05-28 01:50 90632 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-05-28 01:50 . 2009-05-28 01:50 98440 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-05-28 01:50 . 2009-05-28 01:50 26824 —-a-w c:\windows\system32\drivers\avgmfx86.sys
2009-05-28 01:50 . 2009-05-28 01:50 ——– d—–w c:\windows\system32\drivers\Avg
2009-05-28 01:50 . 2009-05-28 01:50 ——– d—–w c:\documents and settings\JohnMary\Application Data\AVGTOOLBAR
2009-05-28 01:49 . 2009-05-28 01:49 ——– d—–w c:\program files\AVG
2009-05-28 01:49 . 2009-05-28 01:49 ——– d—–w c:\documents and settings\All Users\Application Data\avg8
2009-05-27 06:20 . 2004-08-04 07:56 53760 -c–a-w c:\windows\system32\dllcache\vfwwdm32.dll
2009-05-27 06:20 . 2004-08-04 07:56 53760 —-a-w c:\windows\system32\vfwwdm32.dll
2009-05-27 06:20 . 2009-03-17 21:24 1964432 —-a-w c:\windows\system32\drivers\VX1000.sys
2009-05-27 06:20 . 2009-03-17 21:24 111632 —-a-w c:\windows\VX1000.dll
2009-05-27 06:20 . 2009-03-17 21:24 721936 —-a-w c:\windows\vVX1000.exe
2009-05-27 06:20 . 2009-03-17 21:24 218128 —-a-w c:\windows\vVX1000.dll
2009-05-27 06:20 . 2009-03-17 21:24 189456 —-a-w c:\windows\system32\cVX1000.dll
2009-05-27 06:20 . 2009-03-17 21:24 185360 —-a-w c:\windows\system32\LCCoin20.dll
2009-05-27 06:19 . 2009-05-27 06:20 ——– dc—-w c:\windows\system32\DRVSTORE
2009-05-27 06:17 . 2009-05-27 06:19 ——– d—–w C:\7a80419e8728eb6b4b3602
2009-05-27 06:09 . 2009-05-27 06:09 ——– d—–w c:\windows\system32\drivers\umdf
2009-05-27 06:06 . 2009-05-27 06:06 ——– d—–w c:\program files\MSBuild
2009-05-27 06:06 . 2009-05-28 01:10 198784 —-a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-05-27 06:02 . 2009-05-27 06:17 ——– d—–w c:\windows\system32\XPSViewer
2009-05-27 06:01 . 2009-05-27 06:01 ——– d—–w c:\program files\Reference Assemblies
2009-05-27 06:00 . 2006-06-29 20:07 14048 ——w c:\windows\system32\spmsg2.dll
2009-05-27 05:55 . 2007-07-20 01:14 3727720 —-a-w c:\windows\system32\d3dx9_35.dll
2009-05-27 05:54 . 2009-05-27 08:59 ——– d—–w C:\01cdd72ff3d4154d4c99
2009-05-27 04:36 . 2004-08-04 07:56 221184 —-a-w c:\windows\system32\wmpns.dll
2009-05-27 04:34 . 2004-08-04 07:56 8192 ——w c:\windows\system32\smbinst.exe
2009-05-27 04:33 . 2009-05-27 04:33 ——– d—–w c:\windows\ServicePackFiles
2009-05-27 04:27 . 2009-05-27 04:27 ——– d—–w c:\windows\EHome
2009-05-08 03:00 . 2009-05-08 03:00 ——– d—–w c:\program files\Microsoft ActiveSync
2009-05-08 03:00 . 2009-05-08 03:00 ——– d—–w c:\windows\ShellNew
2009-05-08 02:57 . 2009-05-08 03:01 ——– d—–w c:\program files\Microsoft Works
2009-05-08 02:55 . 2009-05-08 02:55 ——– d—–w c:\program files\Microsoft Works Suite 2003

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-28 18:13 . 2009-03-02 04:05 ——– d—–w c:\documents and settings\JohnMary\Application Data\Skype
2009-05-28 15:03 . 2009-03-02 04:08 ——– d—–w c:\documents and settings\JohnMary\Application Data\skypePM
2009-05-28 01:39 . 2009-02-18 22:12 46392 —-a-w c:\documents and settings\JohnMary\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-27 04:38 . 2009-01-17 02:16 76487 —-a-w c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-05-21 11:53 . 2009-03-28 06:40 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-05-20 17:22 . 2009-02-28 19:57 1 —-a-w c:\documents and settings\JohnMary\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-05-05 19:02 . 2009-03-03 02:45 ——– d—–w c:\documents and settings\JohnMary\Application Data\dvdcss
2009-04-28 16:56 . 2009-02-27 14:36 ——– d—–w c:\program files\Lexmark 1200 Series
2009-04-28 16:25 . 2009-04-28 16:19 ——– d—–w c:\program files\MP3 Converter Simple
2009-04-28 15:10 . 2009-02-19 14:31 ——– d—–w c:\program files\Google
2009-04-28 15:09 . 2009-04-24 22:49 ——– d—–w c:\program files\Common Files\DVDVideoSoft
2009-04-28 15:07 . 2009-04-28 03:18 ——– d—–w c:\program files\Yahoo!
2009-04-15 16:57 . 2009-04-15 16:57 ——– d—–w c:\program files\Common Files\xing shared
2009-04-15 16:57 . 2009-04-15 16:56 ——– d—–w c:\program files\Common Files\Real
2009-04-15 16:56 . 2009-04-15 16:56 ——– d—–w c:\program files\Real
2009-04-15 02:57 . 2009-02-28 19:52 ——– d—–w c:\program files\MasterWriter 2.0
2009-03-25 12:17 . 2009-03-25 12:17 57344 —-a-w c:\documents and settings\JohnMary\Application Data\Sun\Java\Deployment\cache\6.0\50\5b902232-3a0e579e-n\Decora-SSE.dll
2009-03-25 12:17 . 2009-03-25 12:17 57344 —-a-w c:\documents and settings\JohnMary\Application Data\Sun\Java\Deployment\cache\6.0\50\5b902232-11cc7727-n\Decora-SSE.dll
2009-03-25 12:17 . 2009-03-25 12:17 24064 —-a-w c:\documents and settings\JohnMary\Application Data\Sun\Java\Deployment\cache\6.0\15\4e09eacf-5b59ab0d-n\Decora-D3D.dll
2009-03-25 12:17 . 2009-03-25 12:17 499712 —-a-w c:\documents and settings\JohnMary\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-1082694e-n\msvcp71.dll
2009-03-25 12:17 . 2009-03-25 12:17 348160 —-a-w c:\documents and settings\JohnMary\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-1082694e-n\msvcr71.dll
2009-03-25 12:17 . 2009-03-25 12:17 24064 —-a-w c:\documents and settings\JohnMary\Application Data\Sun\Java\Deployment\cache\6.0\15\4e09eacf-1d9a2565-n\Decora-D3D.dll
2009-03-25 12:17 . 2009-03-25 12:17 499712 —-a-w c:\documents and settings\JohnMary\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-1082694e-n\jmc.dll
2009-03-18 20:22 . 2009-03-18 20:22 8854 —-a-r c:\documents and settings\JohnMary\Application Data\Microsoft\Installer\{3E5DA526-F420-45A6-9F27-D2B5246D6823}\Uninstall_Free_Natur_3E5DA526F42045A69F27D2B5246D6823.exe
2009-03-18 20:22 . 2009-03-18 20:22 10134 —-a-r c:\documents and settings\JohnMary\Application Data\Microsoft\Installer\{3E5DA526-F420-45A6-9F27-D2B5246D6823}\ARPPRODUCTICON.exe
2009-03-07 01:32 . 2009-03-07 01:32 279888 —-a-w c:\program files\musicnotes.dll
2009-03-03 23:18 . 2009-03-03 23:18 57344 —-a-w c:\documents and settings\JohnMary\Application Data\Sun\Java\Deployment\cache\6.0\37\3976f065-4daa5445-n\Decora-SSE.dll
2009-03-03 23:18 . 2009-03-03 23:18 24064 —-a-w c:\documents and settings\JohnMary\Application Data\Sun\Java\Deployment\cache\6.0\37\2c4a0065-79a98842-n\Decora-D3D.dll
2009-03-03 23:18 . 2009-03-03 23:18 114688 —-a-w c:\documents and settings\JohnMary\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-319f1024-n\jogl_cg.dll
2009-03-03 23:18 . 2009-03-03 23:18 315392 —-a-w c:\documents and settings\JohnMary\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-319f1024-n\jogl.dll
2009-03-03 23:18 . 2009-03-03 23:18 20480 —-a-w c:\documents and settings\JohnMary\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-319f1024-n\jogl_awt.dll
2009-03-03 23:18 . 2009-03-03 23:18 20480 —-a-w c:\documents and settings\JohnMary\Application Data\Sun\Java\Deployment\cache\6.0\45\4f710eed-7882f7a0-n\gluegen-rt.dll
2009-03-03 23:18 . 2009-03-03 23:18 503808 —-a-w c:\documents and settings\JohnMary\Application Data\Sun\Java\Deployment\cache\6.0\38\39ba6e6-1d679496-n\msvcp71.dll
2009-03-03 23:18 . 2009-03-03 23:18 499712 —-a-w c:\documents and settings\JohnMary\Application Data\Sun\Java\Deployment\cache\6.0\38\39ba6e6-1d679496-n\jmc.dll
2009-03-03 23:18 . 2009-03-03 23:18 348160 —-a-w c:\documents and settings\JohnMary\Application Data\Sun\Java\Deployment\cache\6.0\38\39ba6e6-1d679496-n\msvcr71.dll
2009-03-03 23:17 . 2009-03-03 23:17 410984 —-a-w c:\windows\system32\deploytk.dll
2009-03-03 23:16 . 2009-03-03 23:16 152576 —-a-w c:\documents and settings\JohnMary\Application Data\Sun\Java\jre1.6.0_12\lzma.dll
2009-03-02 04:08 . 2009-03-02 04:08 56 —ha-w c:\windows\system32\ezsidmv.dat
2009-02-20 01:14 . 2009-02-20 01:14 604 —ha-w c:\program files\STLL Notifier
2006-07-05 10:55 . 2002-08-29 12:00 156089 –sha-r c:\windows\system32\gntspgrv.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]
"Google Update"="c:\documents and settings\JohnMary\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-18 133104]
"Skype"="c:\program files\Skype\\Phone\Skype.exe" [2009-04-16 24264488]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-06 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 1388544]
"Lexmark 1200 Series"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe" [2006-03-16 57344]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-03 148888]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-15 198160]
"VX1000"="c:\windows\vVX1000.exe" [2009-03-17 721936]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-28 1235736]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-03-26 401040]

c:\documents and settings\JohnMary\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-12-15 384000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
Domestic Security Version 4.87

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTornado\\btdownloadgui.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3212:TCP"= 3212:TCP:jurarc

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [5/27/2009 6:50 PM 12936]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/27/2009 6:50 PM 98440]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/27/2009 6:50 PM 90632]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [5/28/2009 1:23 PM 179856]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [5/28/2009 1:23 PM 15504]
S2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [5/27/2009 6:50 PM 874776]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/27/2009 6:50 PM 231704]
S2 dfchc;Boot Security;c:\windows\system32\svchost.exe -k netsvcs [8/29/2002 5:00 AM 14336]

— Other Services/Drivers In Memory —

*NewlyCreated* - AUJASNKJ
*NewlyCreated* - MBAMPROTECTOR
*NewlyCreated* - MBAMSERVICE
*Deregistered* - aujasnkj

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
dfchc
.
Contents of the 'Scheduled Tasks' folder

2009-05-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-1292428093-1417001333-1004.job
- c:\documents and settings\JohnMary\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-18 19:15]
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-procexp90.Sys


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.com/
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101703&gct=&gc=1&q=%s
TCP: {EFBF61C2-C881-4A5D-8B73-15FFA04406BB} = 216.254.141.13 209.90.160.220
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-28 19:26
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dfchc]
"ServiceDll"="c:\windows\system32\gntspgrv.dll"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(652)
c:\windows\system32\avgrsstx.dll
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(720)
c:\windows\system32\avgrsstx.dll
.
Completion time: 2009-05-29 19:27
ComboFix-quarantined-files.txt 2009-05-29 02:27

Pre-Run: 121,704,177,664 bytes free
Post-Run: 122,338,820,096 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
201 — E O F — 2009-05-27 01:59
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Help_Please_my_Hijack_log_t103527.html&view=findpost&p=563075#entry563075

KillAll::

Collect::
c:\windows\system32\gntspgrv.dll

NetSvc::
dfchc

Registry::
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dfchc]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3212:TCP"=-

Driver::
dfchc

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI