This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Wallpaper "your system is infected"

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My Wallpaper says " Your System is infected! system has been stopped due to a serious malfunction spyware activity has been detected. it is recommended to use spyware removal tool to prevent data loss. do not use the computer before all spyware removed" then there is the Internet Security 2010 that keeps popping up. When I log on to my account on my computer it says that I'm infected with worm.win32.netsky on spyware doctor it says i got 79 infections please help thank you.
Hi,

Please do the following:

Please download exeHelper to your desktop.
  • Double-click on exeHelper.com to run the fix.
  • A black window should pop up, press any key to close once the fix is completed.
  • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
Note If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


NEXT

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
I could only do the first step, the one that I had to download exehelper. when I downloaded DDS and double clicked it, after it was done nothing popped up, only something saying "D.D.S How to post the logs…" the log files DDS.txt and Attach.txt didn't pop up I didn't complete step 2 so I didn't want to move on to step 3. Thank you for helping me.
Hi,

Please run this following program instead. Please run the GMER program and post the log, even if OTL does not run:


Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.
I ran GMER Rootkit Scanner but only services, registry, files (C:\), and ADS were checked because all the others could not be checked or unchecked. OTL didn't work for me.

Attachments:

Hi,

Please do the following:


Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
I did it, but something called windows security alerts popped up out of no where on the system tray (I think thats what it's called). also the your system is infected wallpaper is gone. Thank you.

Attachments:

Hi,

Please do the following:


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Wallpaper_your_system_infected_t109051.html&view=findpost&p=620586#entry620586

Collect::
c:\windows\system32\drivers\cxtpw.sys
C:\kobyh.exe
C:\qllp.exe
C:\osajmkfd.exe
C:\dqhwx.exe

Folder::
c:\program files\InternetSecurity2010
c:\documents and settings\ANYONE\3JMV42N7
c:\documents and settings\CINDY~1\72J13IBS
c:\documents and settings\CINDY~1\Z52HJ6WF
c:\documents and settings\CINDY~1\5UXXRDNS
c:\documents and settings\CINDY~1\3JMV42N7
c:\documents and settings\KoOl DoG\OJHZINK5
c:\documents and settings\KoOl DoG\KSFHMK74
c:\documents and settings\KoOl DoG\IQZUCG6S
c:\documents and settings\KoOl DoG\8XAM1ND8
c:\documents and settings\CINDY~1\M4XSWRZ3
c:\documents and settings\CINDY~1\9AVE884D
c:\documents and settings\CINDY~1\97RH9W9R
c:\documents and settings\CINDY~1\69ITISPZ

DirLook::
C:\spoolerlogs

Registry::
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cxtpw]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5000:TCP"=-
"5001:TCP"=-
"5002:TCP"=-
"5003:TCP"=-
"5004:TCP"=-
"5005:TCP"=-
"5006:TCP"=-
"5007:TCP"=-
"5008:TCP"=-
"5009:TCP"=-
"5010:TCP"=-
"5011:TCP"=-
"5012:TCP"=-
"5013:TCP"=-
"5014:TCP"=-
"5015:TCP"=-
"5016:TCP"=-
"5017:TCP"=-
"5018:TCP"=-
"5019:TCP"=-
"5020:TCP"=-

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.

NEXT

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • ComboFix Log
  • MBAM Log
  • Kaspersky report
ComboFix Log

ComboFix 09-12-29.04 - KoOl DoG 12/29/2009 23:46:04.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.958.460 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\KoOl DoG\Desktop\CFScript.txt
* Resident AV is active


file zipped: C:\dqhwx.exe
file zipped: C:\kobyh.exe
file zipped: C:\osajmkfd.exe
file zipped: C:\qllp.exe
file zipped: c:\windows\system32\drivers\cxtpw.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\ANYONE\3JMV42N7
c:\documents and settings\ANYONE\3JMV42N7\oXMLBranch[1].xml
c:\documents and settings\CINDY~1\3JMV42N7
c:\documents and settings\CINDY~1\5UXXRDNS
c:\documents and settings\CINDY~1\69ITISPZ
c:\documents and settings\CINDY~1\72J13IBS
c:\documents and settings\CINDY~1\72J13IBS\oXMLBranch[1].xml
c:\documents and settings\CINDY~1\97RH9W9R
c:\documents and settings\CINDY~1\9AVE884D
c:\documents and settings\CINDY~1\9AVE884D\oXMLBranch[1].xml
c:\documents and settings\CINDY~1\M4XSWRZ3
c:\documents and settings\CINDY~1\Z52HJ6WF
c:\documents and settings\KoOl DoG\8XAM1ND8
c:\documents and settings\KoOl DoG\IQZUCG6S
c:\documents and settings\KoOl DoG\KSFHMK74
c:\documents and settings\KoOl DoG\OJHZINK5
C:\dqhwx.exe
C:\kobyh.exe
C:\osajmkfd.exe
c:\program files\InternetSecurity2010
C:\qllp.exe
c:\windows\system32\drivers\cxtpw.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_cxtpw
——-\Service_cxtpw


((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-30 )))))))))))))))))))))))))))))))
.

2009-12-24 01:55 . 2009-11-10 15:26 767952 —-a-w- c:\windows\BDTSupport.dll
2009-12-24 01:55 . 2009-11-10 15:28 149456 —-a-w- c:\windows\SGDetectionTool.dll
2009-12-24 01:55 . 2009-11-10 15:28 165840 —-a-w- c:\windows\PCTBDRes.dll
2009-12-24 01:55 . 2009-11-10 15:28 1640400 —-a-w- c:\windows\PCTBDCore.dll
2009-12-24 01:55 . 2009-10-28 06:36 1152444 —-a-w- c:\windows\UDB.zip
2009-12-24 01:55 . 2008-11-26 17:08 131 —-a-w- c:\windows\IDB.zip
2009-12-24 01:53 . 2009-10-30 16:11 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-12-24 01:53 . 2009-11-09 16:20 207792 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2009-12-24 01:53 . 2009-10-06 21:31 87784 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-12-24 01:53 . 2009-09-03 14:45 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2009-12-24 01:53 . 2009-12-29 23:09 ——– d—–w- c:\program files\Spyware Doctor
2009-12-24 01:53 . 2009-12-24 01:56 ——– d—–w- c:\program files\Common Files\PC Tools
2009-12-24 01:53 . 2009-12-24 01:53 ——– d—–w- c:\documents and settings\KoOl DoG\Application Data\PC Tools
2009-12-24 01:53 . 2009-12-24 01:53 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2009-12-23 23:56 . 2009-12-23 23:56 ——– d—–w- C:\spoolerlogs

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-30 04:55 . 2008-05-20 23:04 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-29 23:39 . 2008-11-23 19:08 ——– d—–w- c:\program files\Spyware Terminator
2009-12-29 15:33 . 2008-11-23 19:08 ——– d—–w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2009-12-28 05:28 . 2006-12-26 21:32 ——– d—–w- c:\program files\Lx_cats
2009-12-28 04:39 . 2008-11-23 19:11 ——– d—–w- c:\program files\WinClamAVShield
2009-12-25 15:04 . 2008-11-23 19:09 ——– d—–w- c:\documents and settings\KoOl DoG\Application Data\Spyware Terminator
2009-12-25 02:17 . 2008-11-28 04:37 ——– d—–w- c:\documents and settings\ANYONE\Application Data\Spyware Terminator
2009-12-22 19:31 . 2005-09-19 23:12 ——– d—–w- c:\program files\Hewlett-Packard
2009-12-22 19:31 . 2005-09-19 22:50 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-21 20:27 . 2008-11-26 20:53 ——– d—–w- c:\program files\GIMP-2.0
2009-12-19 17:11 . 2009-05-05 20:46 32768 –sha-w- c:\documents and settings\ANYONE\index.dat
2009-12-19 17:11 . 2009-02-18 18:37 32768 –sha-w- c:\documents and settings\CINDY~1\index.dat
2009-12-19 00:36 . 2009-02-16 21:24 32768 –sha-w- c:\documents and settings\KoOl DoG\index.dat
2009-12-17 02:21 . 2008-09-10 20:50 ——– d—–w- c:\program files\OGPlanet
2009-11-26 18:20 . 2007-07-14 23:43 72320 -c–a-w- c:\documents and settings\ANYONE\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-29 07:45 . 2004-08-04 12:00 916480 ——w- c:\windows\system32\wininet.dll
2009-10-21 06:00 . 2004-08-04 12:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 06:00 . 2004-08-04 12:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 14:58 . 2004-08-04 12:00 263552 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:53 . 2004-08-04 12:00 266752 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:54 . 2004-08-04 12:00 69632 —-a-w- c:\windows\system32\raschap.dll
2009-10-12 13:54 . 2004-08-04 12:00 112128 —-a-w- c:\windows\system32\rastls.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of C:\spoolerlogs —-

2009-12-23 23:56 . 2009-12-23 23:56 14693 —-a-w- c:\spoolerlogs\spooler.xml


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-17 68856]
"NCLaunch"="c:\windows\NCLAUNCH.EXe" [2007-02-18 40960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]
"SMSERIAL"="sm56hlpr.exe" [2005-01-24 544768]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2005-05-11 253952]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 49152]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"StormCodec_Helper"="c:\program files\Ringz Studio\Storm Codec\StormSet.exe" [2005-02-07 94037]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-02-27 180269]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2006-10-21 921600]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"LXCGCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2005-07-20 73728]
"lxcgmon.exe"="c:\program files\Lexmark 2300 Series\lxcgmon.exe" [2005-07-21 200704]
"EzPrint"="c:\program files\Lexmark 2300 Series\ezprint.exe" [2005-08-01 94208]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2005-07-12 299008]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-12-07 30192]
"VerizonServicepoint.exe"="c:\program files\Verizon\VSP\VerizonServicepoint.exe" [2007-11-16 2065648]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-11-23 2246144]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-06 177472]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\WINDOWS\\system32\\lxcgcoms.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxcgpswx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:TCP Port 135

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [12/23/2009 8:53 PM 207792]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [11/23/2008 2:09 PM 142592]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [12/23/2009 8:55 PM 112592]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/10/2007 5:16 PM 24652]
S3 Radialpoint Security Services;Radialpoint Security Services;c:\windows\system32\dllhost.exe [8/4/2004 7:00 AM 5120]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [12/23/2009 8:53 PM 359624]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
IE: Crawler Search - tbr:iemenu
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
LSP: c:\windows\system32\imon.dll
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-29 23:57
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCGCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Syncmgr\ProgressState\K*E*V*I*N*A*N*D*C*I*N*D*Y*_*e&C*i*n*d*y*e&\{00000000-0000-0000-0000-000000000000}]
"Expanded"=dword:00000001
"PushPin"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(580)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(636)
c:\windows\system32\imon.dll
c:\program files\Eset\pr_imon.dll

- - - - - - - > 'explorer.exe'(3464)
c:\windows\system32\WININET.dll
c:\program files\iTunes\iTunesMiniPlayer.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\en.lproj\iTunesMiniPlayerLocalized.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Authentium\AntiVirus\dvpapi.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Eset\nod32krn.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\windows\sm56hlpr.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\lxcgcoms.exe
c:\windows\system32\MsiExec.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-12-30 00:03:14 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-30 05:03
ComboFix2.txt 2009-12-29 23:46

Pre-Run: 128,569,683,968 bytes free
Post-Run: 130,040,459,264 bytes free

- - End Of File - - 0ADA55BBBA2BB4466511D67E21DA246E



MBAM Log

Malwarebytes' Anti-Malware 1.42
Database version: 3454
Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702

12/30/2009 12:15:16 AM
mbam-log-2009-12-30 (00-15-16).txt

Scan type: Quick Scan
Objects scanned: 126499
Time elapsed: 5 minute(s), 7 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\udfa (Backdoor.Bot) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\KoOl DoG\ntload.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\ntload.dll (Trojan.Agent) -> Quarantined and deleted successfully.



I ran the Kaspersky report 2 times and I ended up with white screen, so it didn't work.
Before getting the white screen it said that I had 5 infections.
Hi,

Try this scanner instead:


Go here to run an online scanner from ESET.

  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.


NEXT

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    c:\spoolerlogs\spooler.xml

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.
ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # IEXPLORE.EXE=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=4348c1333570e14dba37d5280c2eb69e # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2009-12-31 06:09:54 # local_time=2009-12-31 01:09:54 (-0500, Eastern Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=1280 16777215 100 0 111323838 111323838 0 0 # compatibility_mode=2560 16777215 100 0 0 0 0 0 # compatibility_mode=7937 16777213 100 100 0 34069430 0 0 # compatibility_mode=8194 67108221 100 100 22443876 100673053 0 0 # scanned=127515 # found=12 # cleaned=0 # scan_time=7862 # nod_component=NOD32MOD_WINNT_CHINESE_ADMIN Build:0x11080314 # nod_component=NOD32MOD_WINNT_CHINESE_BASE Build:0x11080314 # nod_component=NOD32MOD_WINNT_CHINESE_INET Build:0x11080314 # nod_component=NOD32MOD_WINNT_CHINESE_STANDARD Build:0x11080314 C:\Documents and Settings\KoOl DoG\Shared\Fate 2006.zip Win32/TrojanDropper.VB.NAI trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\[4]-Submit_2009-12-29_23.45.56.zip multiple threats 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\InternetSecurity2010\IS2010.exe.vir a variant of Win32/Kryptik.BNY trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\sr882388.exe.vir a variant of Win32/Kryptik.BCA trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\adsldpck.exe.vir a variant of Win32/Kryptik.BCA trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\FastNetSrv.exe.vir Win32/Refpron.DM trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\msaouahn.dll.vir Win32/PSW.WOW.NNZ trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\winlogon86.exe.vir Win32/TrojanDownloader.FakeAlert.AED trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\winsts.sys.vir Win32/Agent.QMG trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\cxtpw.sys.vir a variant of Win32/Rootkit.Kryptik.AF trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\_cxtpw_.sys.zip a variant of Win32/Rootkit.Kryptik.AF trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP1\A0000036.sys a variant of Win32/Rootkit.Kryptik.AF trojan 00000000000000000000000000000000 I For the VirSCAN I did the scan but I couldn't copy to clipboard, the scanner didn't find any malware there is also a note at the bottom saying "This file has been scanned before. Therefore, this file's scan result will not be stored in the database."
Go Start > Run and copy/paste the following single-line command into the Run box and click OK:

cmd /c del /f/a/q "C:\Documents and Settings\KoOl DoG\Shared\Fate 2006.zip"


NEXT

Please post a fresh DDS and Attach.txt and advise how your computer is running now and if there are any outstanding issues.
When you say your icons are "blue" doe you mean they are highlighted with a blue box around them or something else?

Try this:

Go to Start > My Computer > right click My Computer > Properties > Advanced tab

under performance, click settings.

In the Performance Options dialog box, scroll down and check the second last option (Use drop shadows for icon labels on the desktop)

This will get rid of your "Highlighted Icons"

NEXT:

The rest of your log is clean, just some housekeeping to do now.

Please do the following:

Visit ADOBEand download the latest version of Acrobat Reader (version 9.2)
Having the latest updates ensures there are no security vulnerabilities in your system.

NEXT

[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.

  • Download the latest version of Java Runtime Environment (JRE) 6 and save it to your desktop.
  • Scroll down to where it says "Java SE Runtime Environment (JRE) 6 Update 17. The Java SE Runtime Environment (JRE) allows end-users to run Java applications."
  • Click the "Download" button to the right.
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: " I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Now go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u17-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window

    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT


Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]




NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.


    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.

  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
    Here

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
The blue went away. thank you. I have CClearner should I delete it and download ATF cleaner? I use Spyware Terminator and it has a feature similar to WOT so should I delete Spyware Terminator?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI