This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Your system is infected! Fake desktop backround.

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

Recently our computer got infected with some sort of fake backround, which replaced my old backround with an error message saying my system was infected and not to use the computer until the spyware was removed. It also installed some sort of anti virus program on the computer which I found and deleted from program files and the registry. I ran a quick scan with SUPERantispyware and it removed the fake backround, but when I go into my desktop properties I am still unable to change my backround from there… so I guess the infection is still present on my system somewhere. Any help would be appreciated, I downloaded HijackThis as it seems to help you guys in removing infections although I can't make heads or tails of it.

:unsure:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:40:47, on 14/09/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
c:\program files\avg\avg8\avgcsrvx.exe
c:\program files\avg\avg8\avgrsx.exe
C:\WINDOWS\Explorer.EXE
c:\program files\creative\shared files\module loader\dllml.exe
c:\program files\creative\sound blaster x-fi\volume panel\volpanel.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
c:\program files\intel\intel matrix storage manager\iaanotif.exe
c:\program files\dell\media experience\dmxlauncher.exe
c:\windows\system32\dla\dlactrlw.exe
c:\windows\system32\cthelper.exe
c:\program files\creative\sound blaster x-fi\dvdaudio\ctdvddet.exe
c:\program files\common files\real\update_ob\realsched.exe
c:\program files\common files\pcsuite\datalayer\datalayer.exe
c:\windows\system32\ctxfihlp.exe
c:\windows\system32\rundll32.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
c:\windows\system32\ctfmon.exe
c:\program files\netgear\wg111v2\wg111v2.exe
c:\program files\opera\opera.exe
C:\Program Files\Java\jre6\bin\jusched.exe
c:\program files\trend micro\hijackthis\hijackthis.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.ie/ig/dell?hl=en&client=dell-row&channel=ie&ibd=1070526
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ie/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.ie/ig/dell?hl=en&client=dell-row&channel=ie&ibd=1070526
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.ie/ig/dell?hl=en&cli…amp;ibd=1070526
R3 - URLSearchHook: (no name) - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\drivers\svchost.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0EEDB912-C5FA-486F-8334-57288578C627} - (no file)
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {050C8642-C1A9-480b-95A1-55FECB2B8C9A} - (no file)
O3 - Toolbar: (no name) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - (no file)
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ISUSPM] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [EPSON Stylus DX8400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICEE.EXE /FU "C:\WINDOWS\TEMP\E_S1C9.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: winupd32.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
O8 - Extra context menu item: Download with &Shareaza - res://C:\Program Files\Gnutella Turbo\Plugins\RazaWebHook.dll/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

–
End of file - 9752 bytes
Due, in part, to the large numbers of HJT logs being posted, there are four things that you need to be aware of.

1) If you have already posted this log at another forum, you need to post here that you have done so and this topic will be closed.
Multiple posting not only ties up valuable resources, but could also result is some unpleasant side-effects for your system if you follow two sets of instructions at the same time.
If, during research, an identical log is identified at another forum, this thread will be closed.

2) If you don't post a meaningful reply to any of my posts within five days, this thread will be closed. Due to limited free time I can only have so many open threads at any one time and if yours isn't active, somebody else's will be.
If, by omission, the thread hasn't be closed after five days and you post, it will just serve as a reminder to me to close it.
Please note that "I just dropped in to say Hi!" isn't a meaningful reply!

3) Malware removal is a tricky business, and malware writers don't tend to worry about the damage their creations do, so it is advisable to back-up all important files BEFORE we start. Although most cases have a successful conclusion, on occasion things don't go according to plan and it is better to be prepared for the worst.

4) Back-ups can get lost or damaged, so make two if the files are that important to you!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pay a visit to the ESET Online Scanner - IE is preferred for this.
  • Click the ESET Online Scanner button, read the info in the new window, check the appropriate box and click Start.
  • Accept the ActiveX download, and allow it to install.
  • Once this has been completed, you will see the Computer Scan settings page - ensure that you uncheck the "Remove found threats" box and then click Start.
  • The virus signature database will now need to be downloaded, so don't forget to instruct your firewall to permit it if it asks.
  • The above will take a little time, so now is a good time to fire up the kettle and open the biccies.
  • Once the scan has completed you will be shown the results - assuming that the scanner has found anything.
  • Click List of found threats and then Export to text file… and save the log somewhere convenient.
  • You can then close out the scanner - don't bother uninstalling it as you may need to use it again.
  • Please post the contents of this file in your next reply, or let me know that nothing was identified.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download Sec-Info2.zip from here and save it to your Desktop. You will need to extract the file.

Right click on the zipped folder and from the menu that appears, click on Extract All…
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish


You should now see a folder with a file in it - double click Sec-info2.vbs to run it.
Once you have been informed that the script has completed, a text file called Sec-Info.txt should be created in the same folder - you may need to wait a couple of seconds for it to appear..
Please copy and paste the contents of the text file into your next reply and then you can delete both of the folders and their contents.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download RootRepeal from one of the locations below and save it to your Desktop:
Location 1
Location 2
Location 3
  • Double click RootRepeal.exe to fire up the tool and OK any Windows confirmation if necessary.
  • Ensure that the Report Tab is selected at the bottom.
  • Click the Scan button, check ALL the boxes in the window that appears and then click OK.
  • Check the box next to your main hard drive - usually C: and click OK
  • Put the kettle on and perhaps open a packet of biscuits - the scan will take some time.
  • Once the scan has completed a Notepad window will open with the results in.
  • These results will also be saved to the root of your main drive as \RootRepeal report date time.txt
Let me have a copy of the contents in your next reply.
Hello, Here is the information you wanted. First up, the ESET scan. C:\Documents and Settings\Tom Corrgan\Start Menu\Programs\Startup\winupd32.exe a variant of Win32/Kryptik.PB trojan And here is the Sec-Info. Script run: 15/09/2009 16:02:12 ~~~~~~~~~~~~~~~~~~~~~~~~ Company Name: AVG Technologies AV Name: AVG Anti-Virus Free Version Number: 8.5 On-Access Scanning Enabled: Yes Product up-to-date: Yes ~~~~~~~~~~~~~~~~~~~~~~~~ The Windows Firewall is enabled. ~~~~~~~~~~~~~~~~~~~~~~~~ The Security Center Anti-Virus Alerts are enabled. The Security Center Firewall Alerts are enabled. ~~~~~~~~~~~~~~~~~~~~~~~~ Number of Restore Points found: 3 ~~~~~~~~~~~~~~~~~~~~~~~~ Here is the HJT uninstall file. Adobe Flash Player 10 Plugin Adobe Flash Player ActiveX Adobe Reader 7.0.8 Adobe® Photoshop® Album Starter Edition 3.0 Advanced Decoder Patch Apple Software Update AudibleManager AVG Free 8.5 Baldur's Gate™ II - Shadows of Amn™ BinatoneInternetPhone BitZip (remove only) Call of Duty® 4 - Modern Warfare™ Call of Duty® 4 - Modern Warfare™ 1.4 Patch Call of Duty® 4 - Modern Warfare™ 1.5 Multiplayer Patch CCleaner (remove only) CleanUp! Creative Audio Control Panel Creative MediaSource Creative MediaSource 5 Creative Removable Disk Manager Creative System Information Creative ZEN Vision M Series CryEngine®2 Sandbox™2 Crysis® Dell CinePlayer Dell Driver Reset Tool Dell Support 3.2.1 DivX Web Player Download Manager 2.3.7 EA Download Manager EAX Unified Empire: Total War EPSON Printer Software EPSON Scan EPSON Stylus CX7300_CX8300_DX7400_DX8400 Manual ESET Online Scanner v3 Fallout 2 Unofficial Patch 1.02.25 Fallout 3 Fallout 3 - The Garden of Eden Creation Kit Fallout Mod Manager 0.9.13 Fallout2 Far Cry 2 Francesco's leveled creatures-items mod 4.5b Half-Life 2 Half-Life 2: Episode One Half-Life 2: Episode Two HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Intel® Matrix Storage Manager J2SE Runtime Environment 5.0 Update 6 Java™ 6 Update 13 Kotor Tool Left 4 Dead Mafia Mafia Game Malwarebytes' Anti-Malware Medieval II Total War Medieval II Total War : Kingdoms : Americas Medieval II Total War : Kingdoms : Britannia Medieval II Total War : Kingdoms : Crusades Medieval II Total War : Kingdoms : Teutonic Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Games for Windows - LIVE Microsoft Games for Windows - LIVE Redistributable Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual J# .NET Redistributable Package 1.1 Microsoft Works Microsoft WSE 3.0 Runtime Mozilla Firefox (3.0.10) MSN MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 6.0 Parser (KB925673) NETGEAR WG111v2 wireless USB 2.0 adapter Neverwinter Nights 2 Nokia Lifeblog 2.5 Nokia NSeries Application Installer Nokia NSeries Content Copier Nokia NSeries Multimedia Player Nokia NSeries One Touch Access Nokia NSeries System Utilities Nokia PC Suite Nokia Software Launcher Nokia Software Updater NVIDIA Drivers NVIDIA PhysX Oblivion Oblivion - Construction Set Oblivion mod manager 1.1.8 OpenAL Opera 9.64 PC Connectivity Solution Planescape - Torment Portal PunkBuster Services Python 2.5 QuickTime RealPlayer Rhapsody Player Engine Roxio DLA Roxio MyDVD LE Roxio RecordNow Audio Roxio RecordNow Copy Roxio RecordNow Data Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Sid Meier's Pirates! Sonic Activation Module Sound Blaster X-Fi SPORE™ Star Wars Jedi Knight Jedi Academy Star Wars® Knights of the Old Republic® II: The Sith Lords™ Star Wars™: Knights of the Old Republic ™ Stardock Central Steam SUPERAntiSpyware Free Edition System Requirements Lab Team Fortress 2 The Chronicles of Riddick: Escape From Butcher Bay The Sims™ 3 The Witcher The Witcher Adventure Editor Tomb Raider - Underworld Tomb Raider: Legend 1.0 TS3 Install Helper Monkey TuxGuitar 1.0 Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB971930) USB Driver VC80CRTRedist - 8.0.50727.762 VOIP080 Vyzex Pocket POD Windows Driver Package - Nokia (WUDFRd) WPD (03/19/2007 6.83.31.1) Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player 11 Windows Presentation Foundation Windows XP Service Pack 3 WinRAR archiver wxPython [removed] (ansi) for Python 2.5 XP Codec Pack ZENcast Organizer And finally here is the root repeal log. When I started up root repeal I get an error message saying "Error - invalid PE image found!". I just thought I would mention that in case it is important. ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/09/15 16:33 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ——————- Name: dump_iaStor.sys Image Path: C:\WINDOWS\System32\Drivers\dump_iaStor.sys Address: 0xA409F000 Size: 749568 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xA2BF8000 Size: 49152 File Visible: No Signed: - Status: - Hidden/Locked Files ——————- Path: c:\programdata\electronic arts\eadm\cache\logs\core.html Status: Size mismatch (API: 147145, Raw: 146409) Path: c:\documents and settings\tom corrgan\application data\opera\opera\profile\global.dat Status: Size mismatch (API: 2037, Raw: 1841) Path: C:\Documents and Settings\Tom Corrgan\Local Settings\Application Data\Opera\Opera\profile\cache4\vlink4.dat Status: Locked to the Windows API! Path: C:\Documents and Settings\Tom Corrgan\Local Settings\Application Data\Opera\Opera\profile\vps\0000\adoc.bx-g Status: Invisible to the Windows API! Path: C:\Documents and Settings\Tom Corrgan\Local Settings\Application Data\Opera\Opera\profile\vps\0000\url.ax-g Status: Invisible to the Windows API! Path: C:\Documents and Settings\Tom Corrgan\Local Settings\Application Data\Opera\Opera\profile\vps\0000\w.ax-g Status: Invisible to the Windows API! Path: c:\documents and settings\tom corrgan\local settings\application data\opera\opera\profile\vps\0000\w.ax-j Status: Allocation size mismatch (API: 28672, Raw: 32768) SSDT ——————- #: 257 Function Name: NtTerminateProcess Status: Hooked by "C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys" at address 0xa42850b0 ==EOF==
Take a trip to this webpage for download links and instructions for running Combofix by sUBs: http://www.bleepingcomputer.com/combofix/how-to-use-combofix *
  • Please be aware that this tool may require the PC to be rebooted so close any programs you have open before you start.
  • When CF has finished, it will produce a log - C:\ComboFix.txt - copy and paste it into your next reply.
  • Post a fresh HJT log as well.
  • Let me know how the PC is behaving.
* There are two points to note from the instructions page:

1) The Recovery Console.

It is recommended that you install this as, in certain circumstances, it may be the difference between a successful repair and a reformat. If you are uncertain as to whether or not you already have the Recovery Console installed, simply run CF and it will prompt you if it does not detect it.
CF will complete some, but not all, of it's removal tasks without the installation of the Console so, should you choose not to allow the installation, you may not get the results you hoped for.

2) Disabling your Anti-Virus.

CF has been the victim of false-positive detections on occasion and a resident AV may incorrectly identify and delete part of the tool which won't do it much good. If you don't disable your AV, you may not get the results you hoped for!
I'm having a problem running ComboFix. I recieve these error messages when I double click the .exe to run the program. Windows cannot find '32788R22FWJFW\iexplore.exe'. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click search. Windows cannot find '32788R22FWJFW\hidec.exe'. Windows cannot find '32788R22FWJFW\n.pif' Windows cannot find '32788R22FWJFW\nircmd.cfxxe' I turned off Windows firewall and AVG Resident Shield but still no luck running ComboFix. Have I missed something which I have to disable, or is it some infection which is causing ComboFix from running correctly?
Download a fresh copy of ComboFix, but rename it BEFORE you save it. Then see if you get more joy running this one - any name will do, as long as it has .exe at the end.
Unfortunately I'm still recieving the error messages. When the window appeared asking where I wished to save the file I renamed it to something random and saved to the desktop, still no joy.
Download a copy of DDS by sUBs from one of the following locations: Link1; Link2; Link3
  • Double click the tool to run it.
  • You can read the screen that appears, or not - the tool runs anyway.
  • When the tool has finished, two Notepad windows will appear.
  • You need to save both as they will disappear when closed.
  • File > Save As… from the Toolbar will allow you to do this.
  • Copy and Paste both logs into your next reply.
  • Please check after posting that both logs are complete.
Okay, here are the two logs which were asked for. DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 22:34:07.96 on 15/09/2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1513 [GMT 1:00] AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Creative\Shared Files\CTAudSvc.exe svchost.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\system32\CTsvcCDA.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe c:\program files\avg\avg8\avgcsrvx.exe c:\program files\avg\avg8\avgrsx.exe C:\WINDOWS\Explorer.EXE c:\program files\creative\shared files\module loader\dllml.exe c:\program files\creative\sound blaster x-fi\volume panel\volpanel.exe C:\WINDOWS\system32\wscntfy.exe c:\program files\intel\intel matrix storage manager\iaanotif.exe c:\program files\dell\media experience\dmxlauncher.exe c:\windows\system32\dla\dlactrlw.exe c:\windows\system32\cthelper.exe c:\program files\creative\sound blaster x-fi\dvdaudio\ctdvddet.exe c:\program files\common files\real\update_ob\realsched.exe c:\program files\common files\pcsuite\datalayer\datalayer.exe c:\windows\system32\ctxfihlp.exe C:\WINDOWS\SYSTEM32\CTXFISPI.EXE c:\windows\system32\rundll32.exe c:\program files\java\jre6\bin\jusched.exe c:\program files\common files\installshield\updateservice\isuspm.exe C:\Program Files\PC Connectivity Solution\ServiceLayer.exe c:\windows\system32\ctfmon.exe c:\program files\opera\opera.exe c:\documents and settings\tom corrgan\desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://google.ie/ uDefault_Page_URL = www.google.ie/ig/dell?hl=en&client=dell-row&channel=ie&ibd=1070526 uInternet Connection Wizard,ShellNext = hxxp://www.google.ie/ig/dell?hl=en&client=dell-row&channel=ie&ibd=1070526 uURLSearchHooks: H - No File mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\drivers\svchost.exe, BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: {0EEDB912-C5FA-486F-8334-57288578C627} - No File BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - No File BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll {050c8642-c1a9-480b-95a1-55fecb2b8c9a} TB: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - No File uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\isuspm.exe" -scheduler uRun: [igndlm.exe] c:\program files\download manager\DLM.exe /windowsstart /startifwork uRun: [CTSyncU.exe] "c:\program files\creative\sync manager unicode\CTSyncU.exe" uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent uRun: [EPSON Stylus DX8400 Series] c:\windows\system32\spool\drivers\w32x86\3\e_faticee.exe /fu "c:\windows\temp\E_S1C9.tmp" /EF "HKCU" uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [AudioDrvEmulator] "c:\program files\creative\shared files\module loader\dllml.exe" -1 audiodrvemulator "c:\program files\creative\shared files\module loader\audio emulator\AudDrvEm.dll" mRun: [VolPanel] "c:\program files\creative\sound blaster x-fi\volume panel\VolPanel.exe" /r mRun: [UpdReg] c:\windows\UpdReg.EXE mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\Iaanotif.exe mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE mRun: [CTHelper] CTHELPER.EXE mRun: [CTDVDDET] "c:\program files\creative\sound blaster x-fi\dvdaudio\CTDVDDET.EXE" mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [DataLayer] c:\program files\common files\pcsuite\datalayer\DataLayer.exe mRun: [CTxfiHlp] CTXFIHLP.EXE mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\documents and settings\tom corrgan\start menu\programs\startup\winupd32.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg111v2\WG111v2.exe uPolicies-explorer: NoSetActiveDesktop = 1 (0x1) uPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) uPolicies-system: EnableProfileQuota = 1 (0x1) mPolicies-explorer: NoSetActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) IE: &Search IE: Download with &Shareaza - c:\program files\gnutella turbo\plugins\RazaWebHook.dll/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: avgrsstarter - avgrsstx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\tomcor~1\applic~1\mozilla\firefox\profiles\zwsw0nmg.default\ FF - prefs.js: browser.search.selectedEngine - Ask FF - prefs.js: browser.startup.homepage - google.ie FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10615&gct=&gc=1&q= FF - prefs.js: network.proxy.type - 4 FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll FF - plugin: c:\program files\download manager\npfpdlm.dll FF - plugin: c:\program files\opera\program\plugins\npdivx32.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-8-4 335240] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-8-4 27784] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-8-4 108552] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-8-4 908056] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-8-4 297752] R2 ithsgt;ithsgt;c:\windows\system32\drivers\ithsgt.sys [2007-9-21 162432] R2 lilsgt;lilsgt;c:\windows\system32\drivers\lilsgt.sys [2007-9-21 12032] R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [2008-10-8 171032] R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [2008-10-8 1324056] R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [2008-10-8 72728] R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [2006-3-27 167808] RUnknown SASENUM;SASENUM; [x] RUnknown SASKUTIL;SASKUTIL; [x] S0 etbcxd;etbcxd;c:\windows\system32\drivers\bqtularb.sys –> c:\windows\system32\drivers\bqtularb.sys [?] S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2008-12-22 79360] S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [2008-10-8 171032] S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [2008-10-8 1324056] S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [2008-10-8 72728] S3 XDva037;XDva037;\??\c:\windows\system32\xdva037.sys –> c:\windows\system32\XDva037.sys [?] =============== Created Last 30 ================ 2009-09-15 01:00 –d—– c:\program files\ESET 2009-09-14 01:08 191,768 a——- c:\windows\system32\AcroIEHelpe006.dll 2009-09-14 01:07 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com 2009-09-14 01:07 –d—– c:\program files\SUPERAntiSpyware 2009-09-14 01:07 –d—– c:\docume~1\tomcor~1\applic~1\SUPERAntiSpyware.com 2009-09-13 23:26 –d—– c:\program files\Trend Micro 2009-09-13 23:19 –d—– c:\program files\CleanUp! 2009-09-13 06:27 0 a——- c:\windows\system32\41.exe 2009-09-13 06:27 24 a——- c:\windows\system32\user.cfg 2009-09-09 21:13 153,088 ——– c:\windows\system32\dllcache\triedit.dll 2009-08-31 02:57 –d—– c:\program files\common files\DivX Shared 2009-08-26 19:05 588 a——- c:\windows\system32\settingsbkup.sfm 2009-08-26 19:05 588 a——- c:\windows\system32\settings.sfm 2009-08-17 16:10 1,089,593 ——– c:\windows\system32\dllcache\ntprint.cat ==================== Find3M ==================== 2009-09-12 03:42 993,792 a——- c:\windows\system32\dllcache\kernel32.dll 2009-09-12 03:42 22,568 a——- c:\windows\system32\wincode.dat 2009-09-12 03:42 21,504 a——- c:\windows\system32\powrprof.dll 2009-09-12 03:42 6,394 a——- c:\windows\system32\krncode.dat 2009-09-12 03:42 1,575 a——- c:\windows\system32\pwrcode.dat 2009-09-12 03:42 919,552 a——- c:\windows\system32\wininet.dll 2009-09-12 03:42 919,552 a——- c:\windows\system32\dllcache\wininet.dll 2009-08-26 18:05 993,792 a——- c:\windows\system32\sysk.tmp 2009-08-26 18:05 919,552 a——- c:\windows\system32\sysw.tmp 2009-08-26 18:05 21,504 a——- c:\windows\system32\sysp.tmp 2009-08-14 19:42 1,082,616 a——- c:\windows\system32\GameOverlayUI.exe 2009-08-14 19:42 551,408 a——- c:\windows\system32\mss32_s.dll 2009-08-14 19:42 3,348,976 a——- c:\windows\system32\steamclient.dll 2009-08-14 19:42 402,680 a——- c:\windows\system32\vstdlib_s.dll 2009-08-14 19:42 275,704 a——- c:\windows\system32\tier0_s.dll 2009-08-14 19:42 242,936 a——- c:\windows\system32\GameOverlayRenderer.dll 2009-08-14 19:42 122,864 a——- c:\windows\system32\CSERHelper.dll 2009-08-14 19:42 2,888,976 a——- c:\windows\system32\Steam.dll 2009-08-14 19:42 3,101,944 a——- c:\windows\system32\SteamUI.dll 2009-08-14 19:42 283,336 a——- c:\windows\system32\WriteMiniDump.exe 2009-08-07 19:51 15,308,424 a——- c:\windows\system32\xlive.dll 2009-08-07 19:51 13,642,888 a——- c:\windows\system32\xlivefnt.dll 2009-08-05 10:01 204,800 a——- c:\windows\system32\mswebdvd.dll 2009-08-05 10:01 204,800 ——– c:\windows\system32\dllcache\mswebdvd.dll 2009-08-04 14:45 108,552 a——- c:\windows\system32\drivers\avgtdix.sys 2009-08-04 14:45 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-08-04 14:45 335,240 a——- c:\windows\system32\drivers\avgldx86.sys 2009-08-03 00:09 2,087 a——- c:\windows\system32\urhtps.dat 2009-07-19 18:48 11,067,392 ——– c:\windows\system32\dllcache\ieframe.dll 2009-07-19 14:18 5,937,152 ——– c:\windows\system32\dllcache\mshtml.dll 2009-07-17 20:01 58,880 a——- c:\windows\system32\atl.dll 2009-07-17 20:01 58,880 ——– c:\windows\system32\dllcache\atl.dll 2009-07-13 23:43 10,841,088 a——- c:\windows\system32\dllcache\wmp.dll 2009-07-13 23:43 286,208 a——- c:\windows\system32\wmpdxm.dll 2009-07-13 23:43 286,208 a——- c:\windows\system32\dllcache\wmpdxm.dll 2009-07-10 14:27 1,315,328 ——– c:\windows\system32\dllcache\msoe.dll 2009-07-03 18:09 915,456 a——- c:\windows\system32\osysw.dat 2009-07-03 18:09 12,800 ——– c:\windows\system32\dllcache\xpshims.dll 2009-07-03 18:09 1,208,832 ——– c:\windows\system32\dllcache\urlmon.dll 2009-07-03 18:09 206,848 ——– c:\windows\system32\dllcache\occache.dll 2009-07-03 18:09 594,432 ——– c:\windows\system32\dllcache\msfeeds.dll 2009-07-03 18:09 55,296 ——– c:\windows\system32\dllcache\msfeedsbs.dll 2009-07-03 18:09 1,985,536 ——– c:\windows\system32\dllcache\iertutil.dll 2009-07-03 18:09 25,600 ——– c:\windows\system32\dllcache\jsproxy.dll 2009-07-03 18:09 246,272 ——– c:\windows\system32\dllcache\ieproxy.dll 2009-07-03 18:09 184,320 ——– c:\windows\system32\dllcache\iepeers.dll 2009-07-03 18:09 386,048 ——– c:\windows\system32\dllcache\iedkcs32.dll 2009-07-03 12:01 173,056 ——– c:\windows\system32\dllcache\ie4uinit.exe 2009-06-25 09:25 730,112 a——- c:\windows\system32\lsasrv.dll 2009-06-25 09:25 301,568 a——- c:\windows\system32\kerberos.dll 2009-06-25 09:25 147,456 a——- c:\windows\system32\schannel.dll 2009-06-25 09:25 136,192 a——- c:\windows\system32\msv1_0.dll 2009-06-25 09:25 56,832 a——- c:\windows\system32\secur32.dll 2009-06-25 09:25 54,272 a——- c:\windows\system32\wdigest.dll 2009-06-25 09:25 730,112 ——– c:\windows\system32\dllcache\lsasrv.dll 2009-06-25 09:25 301,568 ——– c:\windows\system32\dllcache\kerberos.dll 2009-06-25 09:25 147,456 ——– c:\windows\system32\dllcache\schannel.dll 2009-06-25 09:25 136,192 ——– c:\windows\system32\dllcache\msv1_0.dll 2009-06-25 09:25 56,832 ——– c:\windows\system32\dllcache\secur32.dll 2009-06-25 09:25 54,272 ——– c:\windows\system32\dllcache\wdigest.dll 2009-06-24 12:18 92,928 ——– c:\windows\system32\dllcache\ksecdd.sys 2009-06-22 07:44 726,528 a——- c:\windows\system32\dllcache\jscript.dll 2008-12-25 21:41 22,328 a——- c:\docume~1\tomcor~1\applic~1\PnkBstrK.sys 2008-08-04 16:25 604 a——- c:\docume~1\tomcor~1\applic~1\wklnhst.dat 2007-07-16 01:15 1 ac—— c:\documents and settings\tom corrgan\SI.bin 2007-11-11 16:38 88 —shr– c:\windows\system32\8469EBF268.sys 2007-11-11 16:39 3,764 ac-sh— c:\windows\system32\KGyGaAvL.sys ============= FINISH: 22:34:29.04 =============== And the second one… UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-07-30.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume2 Install Date: 29/05/2007 15:23:30 System Uptime: 15/09/2009 20:56:09 (2 hours ago) Motherboard: Dell Inc. | | 0CT017 Processor: Intel® Core™2 CPU 6600 @ 2.40GHz | Microprocessor | 2394/1066mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 295 GiB total, 122.809 GiB free. D: is CDROM () E: is Removable F: is Removable G: is Removable H: is Removable ==== Disabled Device Manager Items ============= Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: Intel® 82566DC Gigabit Network Connection Device ID: PCI\VEN_8086&DEV_104B&SUBSYS_01DB1028&REV_02\3&172E68DD&0&C8 Manufacturer: Intel Name: Intel® 82566DC Gigabit Network Connection PNP Device ID: PCI\VEN_8086&DEV_104B&SUBSYS_01DB1028&REV_02\3&172E68DD&0&C8 Service: e1express ==== System Restore Points =================== RP891: 04/08/2009 18:03:54 - System Checkpoint RP892: 04/08/2009 18:40:04 - Avg8 Update RP893: 05/08/2009 19:00:24 - System Checkpoint ==== Installed Programs ====================== Adobe Flash Player 10 Plugin Adobe Flash Player ActiveX Adobe Reader 7.0.8 Adobe® Photoshop® Album Starter Edition 3.0 Advanced Decoder Patch Apple Software Update AudibleManager AVG Free 8.5 Baldur's Gate™ II - Shadows of Amn™ BinatoneInternetPhone BitZip (remove only) Call of Duty® 4 - Modern Warfare™ Call of Duty® 4 - Modern Warfare™ 1.4 Patch Call of Duty® 4 - Modern Warfare™ 1.5 Multiplayer Patch Call of Duty® 4 - Modern Warfare™ 1.5 Patch CCleaner (remove only) CleanUp! Creative Audio Control Panel Creative MediaSource Creative MediaSource 5 Creative Removable Disk Manager Creative System Information Creative ZEN Vision M Series CryEngine®2 Sandbox™2 Crysis® Dell CinePlayer Dell Driver Reset Tool Dell Support 3.2.1 Dell System Restore DivX Web Player Download Manager 2.3.7 EA Download Manager EAX Unified Empire: Total War EPSON Printer Software EPSON Scan EPSON Stylus CX7300_CX8300_DX7400_DX8400 Manual ESET Online Scanner v3 Fallout 2 Unofficial Patch 1.02.25 Fallout 3 Fallout 3 - The Garden of Eden Creation Kit Fallout Mod Manager 0.9.13 Fallout2 Far Cry 2 Francesco's leveled creatures-items mod 4.5b Half-Life 2 Half-Life 2: Episode One Half-Life 2: Episode Two HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows XP (KB954550-v5) Intel® Matrix Storage Manager Intel® PRO Network Connections J2SE Runtime Environment 5.0 Update 6 Java™ 6 Update 13 Kotor Tool Left 4 Dead Mafia Mafia Game Malwarebytes' Anti-Malware Medieval II Total War Medieval II Total War : Kingdoms : Americas Medieval II Total War : Kingdoms : Britannia Medieval II Total War : Kingdoms : Crusades Medieval II Total War : Kingdoms : Teutonic Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Games for Windows - LIVE Microsoft Games for Windows - LIVE Redistributable Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual J# .NET Redistributable Package 1.1 Microsoft Works Microsoft WSE 3.0 Runtime Mozilla Firefox (3.0.10) MSN MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 6.0 Parser (KB925673) NETGEAR WG111v2 wireless USB 2.0 adapter Neverwinter Nights 2 Nokia Lifeblog 2.5 Nokia NSeries Application Installer Nokia NSeries Content Copier Nokia NSeries Multimedia Player Nokia NSeries One Touch Access Nokia NSeries System Utilities Nokia PC Suite Nokia Software Launcher Nokia Software Updater NVIDIA Drivers NVIDIA PhysX Oblivion Oblivion - Construction Set Oblivion mod manager 1.1.8 OpenAL Opera 9.64 PC Connectivity Solution Planescape - Torment Portal PunkBuster Services Python 2.5 QuickTime RealPlayer Rhapsody Player Engine Roxio DLA Roxio MyDVD LE Roxio RecordNow Audio Roxio RecordNow Copy Roxio RecordNow Data Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB923689) Sid Meier's Pirates! Sonic Activation Module Sound Blaster X-Fi SPORE™ Star Wars Jedi Knight Jedi Academy Star Wars® Knights of the Old Republic® II: The Sith Lords™ Star Wars™: Knights of the Old Republic ™ Stardock Central Steam System Requirements Lab Team Fortress 2 The Chronicles of Riddick: Escape From Butcher Bay The Sims™ 3 The Witcher The Witcher Adventure Editor Tomb Raider - Underworld Tomb Raider: Legend 1.0 TS3 Install Helper Monkey TuxGuitar 1.0 Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB971930) USB Driver Vampire - The Masquerade Bloodlines VC80CRTRedist - 8.0.50727.762 VOIP080 Vyzex Pocket POD WebFldrs XP Windows Driver Package - Nokia (WUDFRd) WPD (03/19/2007 6.83.31.1) Windows Genuine Advantage Notifications (KB905474) Windows Installer 3.1 (KB893803) Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 11 Windows Presentation Foundation Windows XP Service Pack 3 WinRAR archiver wxPython [removed] (ansi) for Python 2.5 XML Paper Specification Shared Components Pack 1.0 XP Codec Pack ZENcast Organizer ==== Event Viewer Messages From Past Week ======== 14/09/2009 16:42:47, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046} 14/09/2009 03:00:22, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AvgLdx86 AvgMfx86 AvgTdiX Beep Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SASDIFSV SASKUTIL Tcpip WS2IFSL 14/09/2009 02:50:04, error: Service Control Manager [7023] - The Automatic Updates service terminated with the following error: %%2147952506 13/09/2009 22:39:16, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 13/09/2009 22:38:26, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 13/09/2009 18:43:35, error: iaStor [9] - The device, \Device\Ide\iaStor0, did not respond within the timeout period. 13/09/2009 17:28:23, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AvgLdx86 AvgMfx86 AvgTdiX Beep Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip WS2IFSL 13/09/2009 17:28:23, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 13/09/2009 17:28:23, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 13/09/2009 17:28:23, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 13/09/2009 17:28:23, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 13/09/2009 17:27:00, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 13/09/2009 17:26:53, error: sfsync02 [12] - 13/09/2009 17:26:50, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 10/09/2009 22:47:56, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Beep 10/09/2009 22:00:00, error: Schedule [7901] - The At47.job command failed to start due to the following error: %%2147942402 10/09/2009 21:00:00, error: Schedule [7901] - The At46.job command failed to start due to the following error: %%2147942402 10/09/2009 20:00:00, error: Schedule [7901] - The At45.job command failed to start due to the following error: %%2147942402 10/09/2009 19:00:00, error: Schedule [7901] - The At44.job command failed to start due to the following error: %%2147942402 10/09/2009 18:00:00, error: Schedule [7901] - The At43.job command failed to start due to the following error: %%2147942402 10/09/2009 17:00:00, error: Schedule [7901] - The At42.job command failed to start due to the following error: %%2147942402 10/09/2009 16:00:00, error: Schedule [7901] - The At41.job command failed to start due to the following error: %%2147942402 10/09/2009 15:00:00, error: Schedule [7901] - The At40.job command failed to start due to the following error: %%2147942402 10/09/2009 14:00:00, error: Schedule [7901] - The At39.job command failed to start due to the following error: %%2147942402 10/09/2009 13:00:00, error: Schedule [7901] - The At38.job command failed to start due to the following error: %%2147942402 10/09/2009 12:00:00, error: Schedule [7901] - The At37.job command failed to start due to the following error: %%2147942402 10/09/2009 11:00:00, error: Schedule [7901] - The At36.job command failed to start due to the following error: %%2147942402 10/09/2009 10:00:00, error: Schedule [7901] - The At35.job command failed to start due to the following error: %%2147942402 10/09/2009 09:00:00, error: Schedule [7901] - The At34.job command failed to start due to the following error: %%2147942402 10/09/2009 08:00:00, error: Schedule [7901] - The At33.job command failed to start due to the following error: %%2147942402 10/09/2009 07:00:00, error: Schedule [7901] - The At32.job command failed to start due to the following error: %%2147942402 10/09/2009 06:00:00, error: Schedule [7901] - The At31.job command failed to start due to the following error: %%2147942402 10/09/2009 05:00:00, error: Schedule [7901] - The At30.job command failed to start due to the following error: %%2147942402 10/09/2009 04:00:00, error: Schedule [7901] - The At29.job command failed to start due to the following error: %%2147942402 10/09/2009 03:00:00, error: Schedule [7901] - The At28.job command failed to start due to the following error: %%2147942402 10/09/2009 02:00:00, error: Schedule [7901] - The At27.job command failed to start due to the following error: %%2147942402 10/09/2009 01:00:00, error: Schedule [7901] - The At26.job command failed to start due to the following error: %%2147942402 10/09/2009 00:33:00, error: Schedule [7901] - The At25.job command failed to start due to the following error: %%2147942402 09/09/2009 23:00:00, error: Schedule [7901] - The At48.job command failed to start due to the following error: %%2147942402 ==== End Of File ===========================
You may need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **

1) Run HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

R3 - URLSearchHook: (no name) - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - (no file)

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\drivers\svchost.exe,

O2 - BHO: (no name) - {0EEDB912-C5FA-486F-8334-57288578C627} - (no file)
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)
O2 - BHO: (no name) - {050C8642-C1A9-480b-95A1-55FECB2B8C9A} - (no file)

O3 - Toolbar: (no name) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - (no file)

O4 - Startup: winupd32.exe


CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

2) Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
3) Remove any/all of the following files/folders that you can find:

Files

c:\windows\system32\drivers\bqtularb.sys
C:\WINDOWS\system32\drivers\svchost.exe


As an example:
To delete C:\WINDOWS\system32\filetogo.bye
Double click the My Computer icon on your Desktop.
Double click on Local Disc (C:)
Double click on the Windows folder,
Double click on the System 32 folder,
Right click on filetogo.bye and from the menu that appears, click on 'Delete'


Files

winupd32.exe

Click on Start,
Click on Search
Click on 'All files and folders'
In the 'All or part of the file name:' textbox, enter the above file name(s) and click on Search
Right click on any entries that are found and from the menu that appears, click on Delete


Folders

4) Boot into normal mode.

See if you can download and run ComboFix now. If you can, work through the previous instructions and post accordingly; if not, just let me know.
Unfortunately I'm still unable to run ComboFix. My computer must be in a worse state than I thought. When running HJT I was unable to find this file which you asked me to fix in HJT. I did fix the others though. O2 - BHO: (no name) - {050C8642-C1A9-480b-95A1-55FECB2B8C9A} - (no file) I found a few svchost.exe files, but none were in the system32/drivers folder so I thought it would be best to ask before I deleted anything outside that drivers folder. Nor could I find the bqtularb.sys.

I found a few svchost.exe files, but none were in the system32/drivers folder so I thought it would be best to ask before I deleted anything outside that drivers folder.

Some malicious files like to use legitimate names so you need to be careful about where it is as well as what it's called. If you can't find the files then something got there first, possibly your anti-virus.

OK, we'll have a peek for a couple of files that I think need attention and if this doesn't solve anything i'll see if somebody else has a better idea.
Go to Start > Run…, enter cmd into the textbox and click OK - this should open a Command Window.
Copy and paste the following into the window and hit :

dir /a /s \wininet.dll > "%userprofile%\desktop\output.txt"

This should drop a textfile called output.txt on your Desktop - i'd like a copy of it's contents.
Here you go, and thanks again for the help. Volume in drive C has no label. Volume Serial Number is 74C8-DF54 Directory of C:\i386 20/02/2007 10:52 665,600 wininet.dll 1 File(s) 665,600 bytes Directory of C:\WINDOWS\$hf_mig$\KB912945\SP2QFE 12/09/2009 03:42 919,552 wininet.dll 1 File(s) 919,552 bytes Directory of C:\WINDOWS\$hf_mig$\KB928090\SP2QFE 12/09/2009 03:42 919,552 wininet.dll 1 File(s) 919,552 bytes Directory of C:\WINDOWS\$hf_mig$\KB950759\SP3GDR 12/09/2009 03:42 919,552 wininet.dll 1 File(s) 919,552 bytes Directory of C:\WINDOWS\$hf_mig$\KB950759\SP3QFE 12/09/2009 03:42 919,552 wininet.dll 1 File(s) 919,552 bytes Directory of C:\WINDOWS\$hf_mig$\KB953838\SP3GDR 12/09/2009 03:42 919,552 wininet.dll 1 File(s) 919,552 bytes Directory of C:\WINDOWS\$hf_mig$\KB953838\SP3QFE 12/09/2009 03:42 919,552 wininet.dll 1 File(s) 919,552 bytes Directory of C:\WINDOWS\$hf_mig$\KB956390\SP3QFE 12/09/2009 03:42 919,552 wininet.dll 1 File(s) 919,552 bytes Directory of C:\WINDOWS\$hf_mig$\KB958215\SP3QFE 12/09/2009 03:42 919,552 wininet.dll 1 File(s) 919,552 bytes Directory of C:\WINDOWS\$hf_mig$\KB963027\SP3QFE 12/09/2009 03:42 919,552 wininet.dll 1 File(s) 919,552 bytes Directory of C:\WINDOWS\$hf_mig$\KB969897\SP3QFE 12/09/2009 03:42 919,552 wininet.dll 1 File(s) 919,552 bytes Directory of C:\WINDOWS\$hf_mig$\KB969897-IE8\SP3QFE 12/09/2009 03:42 919,552 wininet.dll 1 File(s) 919,552 bytes Directory of C:\WINDOWS\$hf_mig$\KB972260-IE8\SP3QFE 12/09/2009 03:42 919,552 wininet.dll 1 File(s) 919,552 bytes Directory of C:\WINDOWS\$NtServicePackUninstall$ 12/09/2009 03:42 919,552 wininet.dll 1 File(s) 919,552 bytes Directory of C:\WINDOWS\ie8 12/09/2009 03:42 919,552 wininet.dll 1 File(s) 919,552 bytes Directory of C:\WINDOWS\ie8updates\KB969897-IE8 12/09/2009 03:42 919,552 wininet.dll 1 File(s) 919,552 bytes Directory of C:\WINDOWS\ie8updates\KB972260-IE8 12/09/2009 03:42 919,552 wininet.dll 1 File(s) 919,552 bytes Directory of C:\WINDOWS\ServicePackFiles\i386 12/09/2009 03:42 919,552 wininet.dll 1 File(s) 919,552 bytes Directory of C:\WINDOWS\SoftwareDistribution\Download\97fe76a20161cb86e78057600e7c82a0\SP3GDR 12/09/2009 03:42 919,552 wininet.dll 1 File(s) 919,552 bytes Directory of C:\WINDOWS\SoftwareDistribution\Download\97fe76a20161cb86e78057600e7c82a0\SP3QFE 12/09/2009 03:42 919,552 wininet.dll 1 File(s) 919,552 bytes Directory of C:\WINDOWS\system32 12/09/2009 03:42 919,552 wininet.dll 1 File(s) 919,552 bytes Directory of C:\WINDOWS\system32\dllcache 12/09/2009 03:42 919,552 wininet.dll 1 File(s) 919,552 bytes Total Files Listed: 22 File(s) 19,976,192 bytes 0 Dir(s) 131,889,774,592 bytes free
You have an entry in your log that points to a file on your PC that I would like to have checked - if it is still present.

Please go to Jotti's and click on the Browse… button at the top and navigate to the following file and then click on Submit:

C:\WINDOWS\system32\wininet.dll

When all the scans have been completed, please copy and paste the results into your next reply.

If this site is busy, try VirusTotal: Click the Browse … button, navigate to the file and double click it and then click the Send button.

You may need to set Windows to show All Hidden Files and Folders - Instructions can be found here.
* These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after you have done.
*

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI