This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer's mega virused

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi i've posted before but have been busy with exams so my other thread was closed.

Here's an up-to-date log off hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:11:55, on 16/06/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\ALCMTR.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\AOL\1229762181\ee\AOLSoftware.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\WINDOWS\svcho.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\Program Files\AOL Companion\companion.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
c:\program files\common files\aol\1229762181\ee\services\antiSpywareApp\ver2_0_12\AOLSP Scheduler.exe
c:\program files\common files\aol\1229762181\ee\aolsoftware.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.bt.net/digitaldemo
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7070
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
F2 - REG:system.ini: Shell=
O2 - BHO: (no name) - {001B00AE-7860-4251-AB09-F5084B6016EC} - (no file)
O2 - BHO: (no name) - {051C4D78-98FA-4B6D-ADF3-79904CC8B7AF} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {09EABA3C-397E-4F2C-8840-5AD3D8BDDFDB} - (no file)
O2 - BHO: (no name) - {0C8A0741-B54F-4CFA-85F8-494662FE8E41} - (no file)
O2 - BHO: (no name) - {0EDF10DE-12F8-44B7-83F4-E2AFEEDC0183} - (no file)
O2 - BHO: (no name) - {1CE272AD-E408-451E-A08B-B0048D907B33} - (no file)
O2 - BHO: (no name) - {1E1949F7-B16A-47EA-85B2-A89939417F61} - (no file)
O2 - BHO: (no name) - {1EF042BE-1F1F-44AC-B301-E6E794691394} - (no file)
O2 - BHO: (no name) - {1F0DB968-B499-4C0F-84A7-A5D30660E822} - (no file)
O2 - BHO: (no name) - {216187C0-423C-4123-908E-7246D86886A0} - (no file)
O2 - BHO: (no name) - {216D8D75-DEE0-499F-8F87-DDE12FE03DF8} - (no file)
O2 - BHO: (no name) - {27BD3C51-BC2E-49E0-9C6B-F0D0D010CE80} - (no file)
O2 - BHO: (no name) - {2FC7A6B7-EFAA-4AFC-989D-02310398F83A} - (no file)
O2 - BHO: (no name) - {303B270C-AA0A-4DE6-91A7-FD452C9631DC} - (no file)
O2 - BHO: (no name) - {3081BC85-2BB3-4238-BB8E-0D5F930892C3} - (no file)
O2 - BHO: (no name) - {33A4125A-0E9E-4959-B46E-A34689E8DD73} - (no file)
O2 - BHO: (no name) - {340DA371-C36E-4C98-85B4-3A29C3A5A0F9} - (no file)
O2 - BHO: (no name) - {350A958B-8897-4FA6-BA8E-C0202CD3F30E} - (no file)
O2 - BHO: (no name) - {35A71AF0-50BA-4074-93E6-6F097384689F} - (no file)
O2 - BHO: (no name) - {36B0CE3B-2389-48E4-92E4-00ED8579DC74} - (no file)
O2 - BHO: (no name) - {3B31C0ED-586A-408E-9CF3-D12DCD23376E} - (no file)
O2 - BHO: (no name) - {40167E6E-9DF0-423B-9094-9578D043C432} - (no file)
O2 - BHO: (no name) - {444B7843-A646-4525-A5E7-6F4CD7CE0628} - (no file)
O2 - BHO: (no name) - {46AAF4BD-32DD-4E49-91B8-33B70119D9AC} - (no file)
O2 - BHO: (no name) - {46CB60B7-610C-4A58-9E1A-32B16F37B211} - (no file)
O2 - BHO: (no name) - {511512CB-CFAC-49E0-BD1D-F5DF656A1C8A} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {538DF27D-F49D-40B1-9644-A696C2071B78} - (no file)
O2 - BHO: (no name) - {5817FDBD-3462-4B7B-9E8A-7842189010BE} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: (no name) - {633808CA-C1BE-4EA7-9279-1C8282BF07FF} - (no file)
O2 - BHO: (no name) - {67520427-1A9C-44CE-A679-BAC8122D8746} - (no file)
O2 - BHO: (no name) - {690E9E38-8FDB-48C7-8CD1-534E73F2666B} - (no file)
O2 - BHO: (no name) - {69432058-704F-4E6E-B1A4-493C1F3723F3} - C:\WINDOWS\system32\mlJArsRK.dll (file missing)
O2 - BHO: (no name) - {6EF9FD7C-C8B9-4F63-9271-26015961B294} - (no file)
O2 - BHO: (no name) - {74ED29C2-3B04-491F-B00E-3B1383159E91} - (no file)
O2 - BHO: (no name) - {75E0D66C-5620-4BCF-9962-AA78188164EC} - (no file)
O2 - BHO: (no name) - {765402F7-A14D-4279-88A8-EE51096F18D3} - (no file)
O2 - BHO: (no name) - {7A1F6839-AA47-4EF9-A879-E83E6AABB99A} - (no file)
O2 - BHO: (no name) - {7A4C7266-E6EF-4361-8A86-696BD89C7239} - (no file)
O2 - BHO: {39f1a33c-e12f-2159-40a4-fa8051052118} - {81125015-08af-4a04-9512-f21ec33a1f93} - C:\WINDOWS\system32\yzussd.dll
O2 - BHO: (no name) - {841FDACB-8EC2-4512-A9A7-51E090448A11} - (no file)
O2 - BHO: (no name) - {882F2FE5-61B3-4765-845A-485582732E33} - (no file)
O2 - BHO: (no name) - {887A2277-9875-4300-90B0-E56D56791EC3} - (no file)
O2 - BHO: (no name) - {8EDC0272-3960-41BC-91BF-1E3B32615FF0} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {90BE6A4A-895D-46D4-9051-6EE6465390DC} - (no file)
O2 - BHO: (no name) - {9731BF4D-69EA-46F8-9F1E-8AAEA2EDB36E} - (no file)
O2 - BHO: (no name) - {979C9B28-D9DD-45D2-A910-642990B3DACD} - (no file)
O2 - BHO: (no name) - {9C2F459E-AA22-4CD2-B56D-E3D8878117A5} - (no file)
O2 - BHO: (no name) - {9DA61E8E-66C6-4576-8B9D-DCB3EAAF13C2} - (no file)
O2 - BHO: (no name) - {A0584506-0BC5-4623-8702-83E1EB3934D9} - (no file)
O2 - BHO: (no name) - {A0A17DFB-BD47-4618-B187-1A0E1B799EA9} - (no file)
O2 - BHO: (no name) - {A19120DB-8D7D-4BF2-A126-6C58DEEB04AD} - (no file)
O2 - BHO: (no name) - {A230C57E-46FE-4278-88DC-FFC3F296F16C} - (no file)
O2 - BHO: (no name) - {A3081139-B6D2-4DF3-B460-7DC729729457} - (no file)
O2 - BHO: (no name) - {A377CB11-8F15-4DAE-BB3E-ABBD65B1002D} - (no file)
O2 - BHO: (no name) - {A5C775ED-DFA0-417F-A84D-1850A3484F9E} - (no file)
O2 - BHO: (no name) - {A7788911-F6E2-42A1-BEEC-739001DDC8FD} - (no file)
O2 - BHO: (no name) - {A9F1B5BD-99CB-4280-AD15-F59808DE8FAF} - (no file)
O2 - BHO: (no name) - {AC10C684-C169-469F-8F8E-D057CD5FD0B9} - (no file)
O2 - BHO: (no name) - {AF912E8A-CA9E-4A9F-AA86-190C6AE9CFDE} - (no file)
O2 - BHO: (no name) - {B1387124-3580-4FC6-B866-3090489DEE59} - (no file)
O2 - BHO: (no name) - {B23E8909-C3F4-43F7-833A-9403598D6066} - (no file)
O2 - BHO: (no name) - {B309E0DF-A0FB-4391-8DD4-AF1F901AB0C3} - (no file)
O2 - BHO: (no name) - {B324C745-5811-40DF-962D-4BBCE6031155} - (no file)
O2 - BHO: (no name) - {B4672FFB-E4C6-40E2-9013-F8EDAB6F3B89} - (no file)
O2 - BHO: (no name) - {B4AA5C1C-31B4-472C-8B69-1415FC0F9AA4} - (no file)
O2 - BHO: (no name) - {B7F1CA51-A658-4824-8034-538C96E86BE8} - (no file)
O2 - BHO: (no name) - {BB4531ED-E666-4F13-B0D1-BFFAB935B300} - (no file)
O2 - BHO: (no name) - {C85B854A-A280-4B4C-8D36-2D8E3B83F591} - (no file)
O2 - BHO: (no name) - {CF2038DD-3204-4FD1-9AD1-C2B532E42779} - (no file)
O2 - BHO: (no name) - {D1AAECDA-9484-4226-B7E3-B2D718B3D076} - (no file)
O2 - BHO: (no name) - {D32943BD-A447-45DC-9F0A-27FF4E826B30} - (no file)
O2 - BHO: (no name) - {D701BC89-4050-49FC-A78B-933E976411BC} - (no file)
O2 - BHO: (no name) - {D9C33BF9-5318-4B94-9DBC-B6F1F3BB585E} - (no file)
O2 - BHO: (no name) - {DAB439E3-70F7-492A-9E1A-D3612E066DB5} - (no file)
O2 - BHO: (no name) - {DB135C85-892F-44FF-B5BC-25F3CE421C85} - (no file)
O2 - BHO: (no name) - {DBD21D7E-DCD3-477B-B6A7-06123403BC48} - (no file)
O2 - BHO: (no name) - {DDAF548A-4E81-4FF6-A5C7-BF5CA6721465} - (no file)
O2 - BHO: (no name) - {DFA0C81E-4192-4B00-8541-01D024C20998} - (no file)
O2 - BHO: (no name) - {E0E5477E-5B2E-4566-A967-52A27FF39768} - (no file)
O2 - BHO: (no name) - {E21D36C8-AC9B-4A98-8084-8E71BB61B123} - (no file)
O2 - BHO: (no name) - {E5DC1D5C-BC91-459A-85B3-97F481B05B5A} - (no file)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: (no name) - {EAFAFB62-C6FF-4B95-A0C0-756A17327F48} - (no file)
O2 - BHO: (no name) - {F1A449AC-5AC7-4B4D-BD32-DCCB6BE57F89} - (no file)
O2 - BHO: (no name) - {FF715C15-D67C-4CC2-A66D-69426256129F} - (no file)
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1229762181\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Ddoga] rundll32.exe "C:\WINDOWS\azukatikun.dll",e
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [a0fa9d1c] rundll32.exe "C:\WINDOWS\system32\smooroaa.dll",b
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB2047] command /c del "C:\WINDOWS\system32\KRsrAJlm.ini"
O4 - HKCU\..\Policies\Explorer\Run: [svcho] C:\WINDOWS\svcho.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: qifzhn.dll tphjhj.dll dqgwzt.dll qxyudf.dll jjagcy.dll kccmff.dll rfkxuo.dll iuwcfx.dll hufmhz.dll cimdja.dll yzussd.dll C:\WINDOWS\system32\guard32.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe

–
End of file - 16401 bytes



And i have attatched the other things you asked me to before


But i can't attatch the gmer text file so here it is instead:

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-06-16 23:07:32
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.15 —-

Code F8506F92 ZwCreateDirectoryObject
Code F8506D47 ZwCreateFile
Code F85070E2 ZwCreateKey
Code F850724A ZwCreateSection
Code F8507D62 ZwEnumerateKey
Code F85079FB ZwEnumerateValueKey
Code F85085D5 ZwLoadDriver
Code F850703A ZwOpenDirectoryObject
Code F8506ED8 ZwOpenFile
Code F85071A2 ZwOpenKey
Code F850730A ZwOpenSection
Code F85073B2 ZwOpenSymbolicLinkObject
Code F85086B8 ZwQueryDirectoryFile
Code F8507680 ZwQueryDirectoryObject
Code F8508091 ZwQueryValueKey
Code F8506E12 IoCreateFile
Code F8506E88 IoCreateStreamFileObject
Code F8506D46 NtCreateFile
Code F8507249 NtCreateSection
Code F8506ED7 NtOpenFile
Code F85086B7 NtQueryDirectoryFile
Code F8506FE4 ZwCreateDirectoryObject
Code F8506DA5 ZwCreateFile
Code F8507140 ZwCreateKey
Code F85072A8 ZwCreateSection
Code F8507EF6 ZwEnumerateKey
Code F8507BA9 ZwEnumerateValueKey
Code F8508643 ZwLoadDriver
Code F850708C ZwOpenDirectoryObject
Code F8506F33 ZwOpenFile
Code F85071F4 ZwOpenKey
Code F850735C ZwOpenSection
Code F8507404 ZwOpenSymbolicLinkObject
Code F8508764 ZwQueryDirectoryFile
Code F850783A ZwQueryDirectoryObject
Code F8508212 ZwQueryValueKey

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\Tcp cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\Udp cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\RawIp cmdhlp.sys (COMODO Firewall Pro Helper Driver/COMODO)

—- EOF - GMER 1.0.15 —-




errrm… the computer's performance has become slower and there are millions of pop ups when i use the web browsers

please help!

thank you, failtechie!
Hi failtechie, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Where is your antivirus program??



Please disable this program and leave it disabled unil we are done.

SPYBOT TEATIMER
  • Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • On the left hand side, click on Tools, then click on the Resident Icon in the list.
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • Click on the "System Startup" icon in the List
  • Uncheck the "TeaTimer" box and "OK" any prompts.
  • If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
  • Exit Spybot S&D when done.
  • (When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.]


Next

Open hijackthis, do a system scan only and checkmark these lines, if present

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7070
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
F2 - REG:system.ini: Shell=
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.


Next

Please read through the instructions to familiarize yourself with what to expect when the tool runs.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts. Close all other windows/browser first.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do Not run combofix more than once. If you have problems please post back for further instructions.
3.CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please post back with
  • combofix log
How is the computer now?

Thanks
Hi yeah sorry i've been busy with exams and am going on holiday in an hour so havent had time to deal with the computer… would it be possible to keep this thread open until the 2nd July?? I have asked my sister to deal sort this out tonight but i dont know if she'll remember Sorry for the delay. Thank you for your patience! Failtechie
Hello, I've unchecked the resident box in spybot, but I dont understand what "Teatimer" means.. I have clicked on System Startup but I cant find the "Teatimer" box. Is it labelled "TeaTimer"? ( sorry I'm not very good with computers) Please explain
Hi

They should be a line that says something similar to

Resident "Tea timer" (Protection of over-all system settings)active.

UNcheck the box beside it
Hey,
yup thanks I found it :D
Umm the computer's loading at a relatively moderate speed and havent had a popup since the scan (^_^) (yaaay)
Here is the combofix log; (I'm not sure which part I should post so I copied all of it)

ComboFix 09-06-22.0E - HP_Owner 23/06/2009 17:56.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.44.1033.18.511.262 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
FW: COMODO Firewall Pro *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
FW: Norton Internet Worm Protection *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\twain32
C:\Autorun.inf
c:\windows\azukatikun.dll
c:\windows\Hquhofajah.dll
c:\windows\ld01.exe
c:\windows\svcho.exe
c:\windows\syssvc.exe
c:\windows\system32\aereajfm.dll
c:\windows\system32\amlskyoc.dll
c:\windows\system32\avljxegh.dll
c:\windows\system32\bckwfukc.dll
c:\windows\system32\bnaiqtjn.dll
c:\windows\system32\brwbmvdq.dll
c:\windows\system32\buxfsliw.dll
c:\windows\system32\chveyevy.dll
c:\windows\system32\cimdja.dll
c:\windows\system32\coykslma.ini
c:\windows\system32\ctevhrtm.dll
c:\windows\system32\cwkrhdee.ini
c:\windows\system32\dmrfsevm.dll
c:\windows\system32\dpcybytt.ini
c:\windows\system32\dqgwzt.dll
c:\windows\system32\drivers\UACd.sys
c:\windows\system32\eedhrkwc.dll
c:\windows\system32\enctrhry.dll
c:\windows\system32\enydnfai.dll
c:\windows\system32\eqavjbvo.dll
c:\windows\system32\espbjsvx.ini
c:\windows\system32\fbeaqofy.ini
c:\windows\system32\fgibtnqp.dll
c:\windows\system32\flpjekga.dll
c:\windows\system32\fsivjyyb.dll
c:\windows\system32\ftansiup.ini
c:\windows\system32\fugnsxim.ini
c:\windows\system32\fysfmkxp.dll
c:\windows\system32\gdkbupgs.dll
c:\windows\system32\gkknjfgm.ini
c:\windows\system32\grebla.dll
c:\windows\system32\hgexjlva.ini
c:\windows\system32\hs3i7jdgfd.dll
c:\windows\system32\htcxqdot.dll
c:\windows\system32\hufmhz.dll
c:\windows\system32\hulgamtp.dll
c:\windows\system32\huwsepqx.dll
c:\windows\system32\iaplqqer.ini
c:\windows\system32\iguhfh.dll
c:\windows\system32\imprdqux.dll
c:\windows\system32\itnhjeoy.dll
c:\windows\system32\iuwcfx.dll
c:\windows\System32\jjagcy.dll
c:\windows\system32\jrftennt.dll
c:\windows\system32\kccmff.dll
c:\windows\system32\krbqtigm.ini
c:\windows\system32\kyfekvol.dll
c:\windows\system32\ldxyjvfo.ini
c:\windows\system32\ltuniflr.ini
c:\windows\system32\lvfwkvsb.ini
c:\windows\system32\mcrh.tmp
c:\windows\system32\meamhhho.dll
c:\windows\system32\mfjaerea.ini
c:\windows\system32\mgfjnkkg.dll
c:\windows\system32\mgitqbrk.dll
c:\windows\system32\mixsnguf.dll
c:\windows\system32\mqvdtmds.ini
c:\windows\system32\mrgvmlgr.dll
c:\windows\system32\mstssbvp.ini
c:\windows\system32\mtrhvetc.ini
c:\windows\system32\mukruhwu.dll
c:\windows\system32\muwcepgn.dll
c:\windows\system32\nfr.assembly
c:\windows\system32\nfr.gpref
c:\windows\system32\ngpecwum.ini
c:\windows\system32\njtqianb.ini
c:\windows\system32\nsluwkod.dll
c:\windows\system32\nykeegcx.ini
c:\windows\system32\oaxborre.dll
c:\windows\system32\ofvjyxdl.dll
c:\windows\system32\orjelleg.dll
c:\windows\system32\ovbjvaqe.ini
c:\windows\system32\pjynqswq.dll
c:\windows\system32\puisnatf.dll
c:\windows\system32\pvbsstsm.dll
c:\windows\system32\qdvmbwrb.ini
c:\windows\system32\qifzhn.dll
c:\windows\system32\qrfhylkt.dll
c:\windows\system32\qtssvmts.ini
c:\windows\system32\qwsqnyjp.ini
c:\windows\system32\qxyudf.dll
c:\windows\system32\reqqlpai.dll
c:\windows\system32\rfkxuo.dll
c:\windows\system32\rglmvgrm.ini
c:\windows\system32\rlfinutl.dll
c:\windows\system32\rtqllumv.ini
c:\windows\system32\sdmtdvqm.dll
c:\windows\system32\seneka.dat
c:\windows\system32\senekadf.dat
c:\windows\system32\senekalog.dat
c:\windows\system32\stmvsstq.dll
c:\windows\system32\svoicvxm.dll
c:\windows\system32\tmhtkxhw.ini
c:\windows\system32\tnnetfrj.ini
c:\windows\system32\todqxcth.ini
c:\windows\system32\tphjhj.dll
c:\windows\system32\ttybycpd.dll
c:\windows\system32\uksudlvj.dll
c:\windows\system32\usmrgdej.dll
c:\windows\system32\vadumz.dll
c:\windows\system32\vgkiwisr.dll
c:\windows\system32\vmullqtr.dll
c:\windows\system32\whxkthmt.dll
c:\windows\system32\wtaydcpl.dll
c:\windows\system32\wukuraqx.ini
c:\windows\system32\xcgeekyn.dll
c:\windows\system32\xqarukuw.dll
c:\windows\system32\xvsjbpse.dll
c:\windows\system32\yaycseuv.dll
c:\windows\system32\yfoqaebf.dll
c:\windows\system32\yoejhnti.ini
c:\windows\system32\yrhrtcne.ini
c:\windows\system32\yzussd.dll
c:\windows\ubokojot.dll
D:\Autorun.inf
D:\Desktop.ini

—– BITS: Possible infected sites —–

hxxp://b9n.org
c:\windows\system32\userinit.exe . . . is infected!!

c:\windows\system32\userinit.exe . . . is infected!!

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_IPRIP


((((((((((((((((((((((((( Files Created from 2009-05-23 to 2009-06-23 )))))))))))))))))))))))))))))))
.

2009-05-30 14:20 . 2009-05-30 14:20 ——– d—–w- c:\windows\WinRAR
2009-05-30 12:25 . 2009-05-30 12:25 ——– d–h–w- c:\windows\PIF

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-21 16:58 . 2008-12-20 10:47 ——– d—–w- c:\documents and settings\HP_Owner\Application Data\AdobeUM
2009-06-05 21:39 . 2008-12-20 09:11 ——– d—–w- c:\documents and settings\HP_Owner\Application Data\.ABC
2009-05-19 18:35 . 2009-05-19 18:35 ——– d—–w- c:\program files\Trend Micro
2009-04-09 20:32 . 2009-04-09 20:32 87056 —-a-w- c:\windows\system32\drivers\cmdguard.sys
2009-04-09 20:32 . 2009-04-09 20:32 79760 —-a-w- c:\windows\system32\drivers\inspect.sys
2009-04-09 20:32 . 2009-04-09 20:32 24208 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-04-09 20:32 . 2009-04-09 20:32 143104 —-a-w- c:\windows\system32\guard32.dll
.

——- Sigcheck ——-

[-] 2009-03-05 07:45 8704 EAB8C03DC9A5396FC30A3C848B3B6126 c:\windows\system32\userinit.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_03\bin\jusched.exe" [2005-01-01 32881]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2008-12-18 26112]
"PS2"="c:\windows\system32\ps2.exe" [2004-10-25 90112]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-11 61440]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-20 155648]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HPHUPD06"="c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 49152]
"HostManager"="c:\program files\Common Files\AOL\1229762181\ee\AOLSoftware.exe" [2006-09-26 50736]
"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" [2009-04-09 1655552]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-09-09 344064]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2007-12-07 71008]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-07-29 77824]
"SiSPower"="SiSPower.dll" - c:\windows\system32\SiSPower.dll [2004-09-24 49152]
"AlcWzrd"="ALCWZRD.EXE" - c:\windows\ALCWZRD.EXE [2004-07-29 2551808]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-06-29 88363]

c:\documents and settings\HP_Owner\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
AOL 9.0 Tray Icon.lnk - c:\program files\AOL 9.0\aoltray.exe [2008-12-19 156784]
AOL Companion.lnk - c:\program files\AOL Companion\companion.exe [2008-12-19 250992]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-29 241664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"userinit"="c:\windows\explorer.exe,"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"=
"c:\\Program Files\\AOL 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\1229762181\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\ABC\\abc.exe"=
"c:\\Program Files\\THQ\\Dawn of War - Soulstorm\\Soulstorm.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
"7070:TCP"= 7070:TCP:nfr

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [09/04/2009 21:32 87056]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [09/04/2009 21:32 24208]
R3 PhTVTune;ASUS WDM TV Tuner;c:\windows\system32\drivers\PhTVTune.sys [01/01/2005 10:48 24544]
S0 pggrkatg;pggrkatg;c:\windows\system32\drivers\rrwpczyg.sys []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
- - - - ORPHANS REMOVED - - - -

BHO-{001B00AE-7860-4251-AB09-F5084B6016EC} - (no file)
BHO-{051C4D78-98FA-4B6D-ADF3-79904CC8B7AF} - (no file)
BHO-{09EABA3C-397E-4F2C-8840-5AD3D8BDDFDB} - (no file)
BHO-{0C8A0741-B54F-4CFA-85F8-494662FE8E41} - (no file)
BHO-{0EDF10DE-12F8-44B7-83F4-E2AFEEDC0183} - (no file)
BHO-{1CE272AD-E408-451E-A08B-B0048D907B33} - (no file)
BHO-{1E1949F7-B16A-47EA-85B2-A89939417F61} - (no file)
BHO-{1EF042BE-1F1F-44AC-B301-E6E794691394} - (no file)
BHO-{1F0DB968-B499-4C0F-84A7-A5D30660E822} - (no file)
BHO-{216187C0-423C-4123-908E-7246D86886A0} - (no file)
BHO-{216D8D75-DEE0-499F-8F87-DDE12FE03DF8} - (no file)
BHO-{27BD3C51-BC2E-49E0-9C6B-F0D0D010CE80} - (no file)
BHO-{2FC7A6B7-EFAA-4AFC-989D-02310398F83A} - (no file)
BHO-{303B270C-AA0A-4DE6-91A7-FD452C9631DC} - (no file)
BHO-{3081BC85-2BB3-4238-BB8E-0D5F930892C3} - (no file)
BHO-{33A4125A-0E9E-4959-B46E-A34689E8DD73} - (no file)
BHO-{340DA371-C36E-4C98-85B4-3A29C3A5A0F9} - (no file)
BHO-{350A958B-8897-4FA6-BA8E-C0202CD3F30E} - (no file)
BHO-{35A71AF0-50BA-4074-93E6-6F097384689F} - (no file)
BHO-{36B0CE3B-2389-48E4-92E4-00ED8579DC74} - (no file)
BHO-{3B31C0ED-586A-408E-9CF3-D12DCD23376E} - (no file)
BHO-{40167E6E-9DF0-423B-9094-9578D043C432} - (no file)
BHO-{444B7843-A646-4525-A5E7-6F4CD7CE0628} - (no file)
BHO-{46AAF4BD-32DD-4E49-91B8-33B70119D9AC} - (no file)
BHO-{46CB60B7-610C-4A58-9E1A-32B16F37B211} - (no file)
BHO-{511512CB-CFAC-49E0-BD1D-F5DF656A1C8A} - (no file)
BHO-{538DF27D-F49D-40B1-9644-A696C2071B78} - (no file)
BHO-{5817FDBD-3462-4B7B-9E8A-7842189010BE} - (no file)
BHO-{633808CA-C1BE-4EA7-9279-1C8282BF07FF} - (no file)
BHO-{67520427-1A9C-44CE-A679-BAC8122D8746} - (no file)
BHO-{690E9E38-8FDB-48C7-8CD1-534E73F2666B} - (no file)
BHO-{69432058-704F-4E6E-B1A4-493C1F3723F3} - c:\windows\system32\mlJArsRK.dll
BHO-{6EF9FD7C-C8B9-4F63-9271-26015961B294} - (no file)
BHO-{74ED29C2-3B04-491F-B00E-3B1383159E91} - (no file)
BHO-{75E0D66C-5620-4BCF-9962-AA78188164EC} - (no file)
BHO-{765402F7-A14D-4279-88A8-EE51096F18D3} - (no file)
BHO-{7A1F6839-AA47-4EF9-A879-E83E6AABB99A} - (no file)
BHO-{7A4C7266-E6EF-4361-8A86-696BD89C7239} - (no file)
BHO-{81125015-08af-4a04-9512-f21ec33a1f93} - c:\windows\system32\yzussd.dll
BHO-{841FDACB-8EC2-4512-A9A7-51E090448A11} - (no file)
BHO-{882F2FE5-61B3-4765-845A-485582732E33} - (no file)
BHO-{887A2277-9875-4300-90B0-E56D56791EC3} - (no file)
BHO-{8EDC0272-3960-41BC-91BF-1E3B32615FF0} - (no file)
BHO-{90BE6A4A-895D-46D4-9051-6EE6465390DC} - (no file)
BHO-{9731BF4D-69EA-46F8-9F1E-8AAEA2EDB36E} - (no file)
BHO-{979C9B28-D9DD-45D2-A910-642990B3DACD} - (no file)
BHO-{9C2F459E-AA22-4CD2-B56D-E3D8878117A5} - (no file)
BHO-{9DA61E8E-66C6-4576-8B9D-DCB3EAAF13C2} - (no file)
BHO-{A0584506-0BC5-4623-8702-83E1EB3934D9} - (no file)
BHO-{A0A17DFB-BD47-4618-B187-1A0E1B799EA9} - (no file)
BHO-{A19120DB-8D7D-4BF2-A126-6C58DEEB04AD} - (no file)
BHO-{A230C57E-46FE-4278-88DC-FFC3F296F16C} - (no file)
BHO-{A3081139-B6D2-4DF3-B460-7DC729729457} - (no file)
BHO-{A377CB11-8F15-4DAE-BB3E-ABBD65B1002D} - (no file)
BHO-{A5C775ED-DFA0-417F-A84D-1850A3484F9E} - (no file)
BHO-{A7788911-F6E2-42A1-BEEC-739001DDC8FD} - (no file)
BHO-{A9F1B5BD-99CB-4280-AD15-F59808DE8FAF} - (no file)
BHO-{AC10C684-C169-469F-8F8E-D057CD5FD0B9} - (no file)
BHO-{AF912E8A-CA9E-4A9F-AA86-190C6AE9CFDE} - (no file)
BHO-{B1387124-3580-4FC6-B866-3090489DEE59} - (no file)
BHO-{B23E8909-C3F4-43F7-833A-9403598D6066} - (no file)
BHO-{B309E0DF-A0FB-4391-8DD4-AF1F901AB0C3} - (no file)
BHO-{B324C745-5811-40DF-962D-4BBCE6031155} - (no file)
BHO-{B4672FFB-E4C6-40E2-9013-F8EDAB6F3B89} - (no file)
BHO-{B4AA5C1C-31B4-472C-8B69-1415FC0F9AA4} - (no file)
BHO-{B7F1CA51-A658-4824-8034-538C96E86BE8} - (no file)
BHO-{BB4531ED-E666-4F13-B0D1-BFFAB935B300} - (no file)
BHO-{C85B854A-A280-4B4C-8D36-2D8E3B83F591} - (no file)
BHO-{CF2038DD-3204-4FD1-9AD1-C2B532E42779} - (no file)
BHO-{D1AAECDA-9484-4226-B7E3-B2D718B3D076} - (no file)
BHO-{D32943BD-A447-45DC-9F0A-27FF4E826B30} - (no file)
BHO-{D701BC89-4050-49FC-A78B-933E976411BC} - (no file)
BHO-{D9C33BF9-5318-4B94-9DBC-B6F1F3BB585E} - (no file)
BHO-{DAB439E3-70F7-492A-9E1A-D3612E066DB5} - (no file)
BHO-{DB135C85-892F-44FF-B5BC-25F3CE421C85} - (no file)
BHO-{DBD21D7E-DCD3-477B-B6A7-06123403BC48} - (no file)
BHO-{DDAF548A-4E81-4FF6-A5C7-BF5CA6721465} - (no file)
BHO-{DFA0C81E-4192-4B00-8541-01D024C20998} - (no file)
BHO-{E0E5477E-5B2E-4566-A967-52A27FF39768} - (no file)
BHO-{E21D36C8-AC9B-4A98-8084-8E71BB61B123} - (no file)
BHO-{E5DC1D5C-BC91-459A-85B3-97F481B05B5A} - (no file)
BHO-{EAFAFB62-C6FF-4B95-A0C0-756A17327F48} - (no file)
BHO-{F1A449AC-5AC7-4B4D-BD32-DCCB6BE57F89} - (no file)
BHO-{FF715C15-D67C-4CC2-A66D-69426256129F} - (no file)
HKLM-Run-Ddoga - c:\windows\azukatikun.dll
HKLM-Run-a0fa9d1c - c:\windows\system32\smooroaa.dll
HKLM-Run-VTTimer - VTTimer.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_GB&c;=Q105&bd;=pavilion&pf;=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_GB&c;=Q105&bd;=pavilion&pf;=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_GB&c;=Q105&bd;=pavilion&pf;=desktop
uInternet Connection Wizard,ShellNext = hxxp://www.bt.net/digitaldemo
IE: &AOL; Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-23 18:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\system32\drivers\rrwpczyg.sys 25088 bytes executable
c:\docume~1\HP_Owner\LOCALS~1\Temp\RGI9.tmp 7075 bytes

scan completed successfully
hidden files: 2

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(664)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2508)
c:\program files\Common Files\AOL\ACS\WLHook.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\msi.dll
c:\windows\system32\hnetcfg.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\COMODO\Firewall\cmdagent.exe
c:\windows\system32\tcpsvcs.exe
c:\windows\system32\wscntfy.exe
c:\program files\AOL 9.0\waol.exe
c:\program files\Common Files\AOL\1229762181\ee\services\antiSpywareApp\ver2_0_12\AOLSP Scheduler.exe
c:\program files\AOL 9.0\shellmon.exe
c:\program files\Common Files\AOL\aoltpspd.exe
.
**************************************************************************
.
Completion time: 2009-06-23 18:08 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-23 17:08

Pre-Run: 135,492,616,192 bytes free
Post-Run: 135,430,344,704 bytes free

368
Hi failtechie or jun23,

No you didn't do anything wrong. You may have come up against a windows security situation. Does this new account have a name?

A couple of questions.

1.can you get into the computer in Safe Mode?

To boot the computer into Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
Did you get in?

2.More importantly do you have an XP CD?

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI