This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Taken Over!

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer over the past few days has begun to act out and is not behaving at all. It's surfing web pages on its own, not allowing me into safe mode, disconnecting me from the internet (i have to change the modem port in order to redial) and other odd behavior. I tried SpyBot first with little result, so I downloaded HighJackThis and ran a scan. Here is the log it gave me:

Logfile of HijackThis v1.99.1
Scan saved at 12:19:00 PM, on 9/5/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\winupdates\winupdates.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\csrs.exe
C:\dihd.exe
C:\dfndrff_16.exe
C:\kybrdff_15.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\wswrpurA.exe
C:\Program Files\Common Files\{3A410EF0-0298-1033-0404-000323200001}\Update.exe
C:\Program Files\CMFibula\CMFibula.exe
C:\WINDOWS\System32\wuauclt.exe
C:\PROGRA~1\COMMON~1\rwir\rwirm.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\COMMON~1\rwir\rwira.exe
C:\Documents and Settings\Tru\Desktop\Mozilla Firefox\firefox.exe
C:\mp.exe
C:\Documents and Settings\Tru\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.soundblaster.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by AOL test browser
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\ttrjl.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [winupdate] C:\Program Files\winupdate\winupdate.exe /auto
O4 - HKLM\..\Run: [p2pnetworking] p2pnetworking.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Client Server Runtime Process] C:\WINDOWS\System32\csrs.exe
O4 - HKLM\..\Run: [Advanced DHTML Enable] C:\dihd.exe
O4 - HKLM\..\Run: [defender] C:\\dfndrff_16.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_15.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [win3208297734219] C:\WINDOWS\win3208297734219.exe
O4 - HKLM\..\Run: [wswrpurA] C:\WINDOWS\wswrpurA.exe
O4 - HKLM\..\Run: [gyb10656] RUNDLL32.EXE w00e1c25.dll,n 004106520000000300e1c25
O4 - HKLM\..\Run: [{10-0E-EF-F0-ZN}] C:\windows\system32\oldsregs.exe GEN001
O4 - HKLM\..\Run: [dcewlx] C:\WINDOWS\System32\ekafma.exe reg_run
O4 - HKLM\..\RunServices: [p2pnetworking] p2pnetworking.exe
O4 - HKCU\..\Run: [CMFibula] "C:\Program Files\CMFibula\CMFibula.exe"
O4 - HKCU\..\Run: [rwir] C:\PROGRA~1\COMMON~1\rwir\rwirm.exe
O4 - HKCU\..\Run: [aylxn] C:\WINDOWS\System32\ekafma.exe reg_run
O4 - Startup: TA_Start.lnk = C:\WINDOWS\SYSTEM32\dwdsregt.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{02BBA9CD-D817-4C0D-AE27-61520B5AF6A6}: NameServer = 216.66.108.26 216.66.108.34
O17 - HKLM\System\CS1\Services\Tcpip\..\{02BBA9CD-D817-4C0D-AE27-61520B5AF6A6}: NameServer = 216.66.108.26 216.66.108.34
O20 - Winlogon Notify: Reliability - C:\WINDOWS\system32\d0j0la1m1d.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

Thank you for any help! I'm dumbfounded as to how to continue…
Welcome to the forum :wavey:

Download combofix.exe from the link below:

Combofix.exe

Save it to your desktop.

Run it.

When finished, it will produce a log for you.

Post that log in your next reply, along with a new HijackThis! log.
:)


Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Okay, great Micah, thanks for the help.

Here's the ComboFix log:

Tru - 06-09-05 18:19:37.30
ComboFix 06.09.04BT - Running from: C:\Documents and Settings\[removed]\Desktop

Microsoft Windows XP [Version 5.1.2600]

((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))

REGISTRY ENTRIES REMOVED:

[HKEY_CLASSES_ROOT\CLSID\{B80DAADF-5AB1-42CB-AA31-8F3CD4AA03A8}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B80DAADF-5AB1-42CB-AA31-8F3CD4AA03A8}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B80DAADF-5AB1-42CB-AA31-8F3CD4AA03A8}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B80DAADF-5AB1-42CB-AA31-8F3CD4AA03A8}\InprocServer32]
@="C:\\WINDOWS\\system32\\mhexch40.dll"
"ThreadingModel"="Apartment"

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


FILES REMOVED:

C:\WINDOWS\SYSTEM32\mhexch40.dll
C:\WINDOWS\SYSTEM32\fp8s03l7e.dll


Granting sedebugprivilege to Administrators … successful


((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log )))))))))))))))))))))))))))))))))))))))))))))))))))


* * * POST-RUN - Files in the Quarantine folder * * * * * * * * * * * * * * * * * * * * * * * * *


06-09-05 06:55 53 eqqnpb.dat.qoo

DO NOT DELETE ANY FILES FROM THIS DIRECTORY UNLESS INSTRUCTED TO


((((((((((((((((((((((((((((((((((((((((((( E-Give / Ssk's Log )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Documents and Settings\Tru\Application Data\Sskdmns.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\keyboard1.dat
C:\dfndrff_16.exe
C:\kybrdff_15.exe
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\cmd.com
C:\WINDOWS\system32\netstat.com
C:\WINDOWS\system32\ping.com
C:\WINDOWS\system32\regedit.com
C:\WINDOWS\system32\taskkill.com
C:\WINDOWS\system32\tracert.com
C:\WINDOWS\system32\WinNB58.dll
C:\WINDOWS\offun.exe
C:\Program Files\batty2
C:\Program Files\winupdate
C:\Program Files\winupdates
C:\Program Files\cmfibula
C:\Program Files\Common Files\{3A410EF0-0298-1033-0404-000323200001}


((((((((((((((((((((((((((((((( Files Created from 2006-08-05 to 2006-09-05 ))))))))))))))))))))))))))))))))))


2006-09-05 17:18 90,112 –a—— C:\WINDOWS\SYSTEM32\AVASTSS.scr
2006-09-05 17:18 635,520 –a—— C:\WINDOWS\SYSTEM32\aswBoot.exe
2006-09-05 17:18 499,712 –a—— C:\WINDOWS\SYSTEM32\MSVCP71.dll
2006-09-05 17:18 348,160 –a—— C:\WINDOWS\SYSTEM32\MSVCR71.dll
2006-09-05 17:18 1,060,864 –a—— C:\WINDOWS\SYSTEM32\MFC71.dll
2006-09-05 11:45 32,529 –a—— C:\mp.exe
2006-09-05 06:57 1,233 –a—— C:\WINDOWS\SYSTEM32\gyb10656.sys
2006-09-05 06:56 61,952 –a—— C:\WINDOWS\SYSTEM32\gyb10656.dll
2006-09-05 06:55 983,728 -r-hs—- C:\WINDOWS\wswrpur.exe
2006-09-05 06:55 186,223 –a—— C:\WINDOWS\srvtxnszzi.exe
2006-09-05 06:55 1,074,816 -r-hs—- C:\WINDOWS\wswrpurA.exe
2006-09-04 07:37 90,112 –a—— C:\WINDOWS\SYSTEM32\epcomdd.dll
2006-09-04 07:37 86,016 –a—— C:\WINDOWS\SYSTEM32\Epfb5cpl.dll
2006-09-04 07:37 53,248 –a—— C:\WINDOWS\SYSTEM32\ESICM.dll
2006-09-04 07:37 47,104 –a—— C:\WINDOWS\SYSTEM32\escimgn.dll
2006-09-04 07:37 35,840 –a—— C:\WINDOWS\SYSTEM32\escwian.dll
2006-09-04 07:37 33,280 –a—— C:\WINDOWS\SYSTEM32\esccm.dll
2006-09-04 07:37 32,256 –a—— C:\WINDOWS\SYSTEM32\escwiab.dll
2006-09-04 07:37 27,648 –a—— C:\WINDOWS\SYSTEM32\escimg.dll
2006-09-04 07:37 23,552 –a—— C:\WINDOWS\SYSTEM32\esccmn.dll
2006-09-04 07:37 176,128 –a—— C:\WINDOWS\SYSTEM32\ESDTR.dll
2006-09-04 07:37 126,976 –a—— C:\WINDOWS\SYSTEM32\Esint23.dll
2006-09-03 12:55 420,632 –a—— C:\WINDOWS\SYSTEM32\wuapi.dll
2006-09-03 12:55 39,704 –a—— C:\WINDOWS\SYSTEM32\wups.dll
2006-09-03 12:55 186,136 –a—— C:\WINDOWS\SYSTEM32\wuaueng1.dll
2006-09-03 12:55 167,704 –a—— C:\WINDOWS\SYSTEM32\wuauclt1.exe
2006-09-03 12:55 120,288 –a—— C:\WINDOWS\SYSTEM32\wuweb.dll
2006-09-03 12:55 118,552 –a—— C:\WINDOWS\SYSTEM32\wucltui.dll
2006-09-03 09:55 48,190 –a—— C:\WINDOWS\RDFX4.exe
2006-09-02 13:59 20,480 –a—— C:\dihd.exe
2006-09-01 13:13 1,233 –a—— C:\WINDOWS\SYSTEM32\zzze27e8.sys
2006-09-01 13:12 61,952 –a—— C:\WINDOWS\SYSTEM32\zzze27e8.dll
2006-09-01 13:10 854,816 -r-hs—- C:\WINDOWS\uprsnrkA.exe
2006-09-01 13:10 543 –a—— C:\WINDOWS\cfhmd.dll
2006-08-26 22:39 41,240 –a—— C:\WINDOWS\SYSTEM32\wups(2).dll
2006-08-21 13:48 53,248 –a—— C:\WINDOWS\uni_ehhhh.exe
2006-08-07 08:17 61,440 –a—— C:\WINDOWS\SYSTEM32\BattyRun2.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-09-05 17:17 ——– d——– C:\Program Files\Alwil Software
2006-09-05 17:07 2 —hs—- C:\WINDOWS\SYSTEM32\tasklist.com
2006-09-03 20:16 ——– d——– C:\Documents and Settings\Tru\Application Data\Sun
2006-09-03 20:11 ——– d——– C:\Program Files\Java
2006-09-01 13:16 ——– d——– C:\Program Files\whInstall
2006-08-31 16:45 ——– d——– C:\Program Files\America Online 8.0a
2006-08-25 19:02 ——– d——– C:\Program Files\Mozilla Firefox
2006-08-23 11:37 ——– d——– C:\Program Files\Google
2006-08-22 10:12 ——– d——– C:\Documents and Settings\Tru\Application Data\Macromedia
2006-08-18 18:45 ——– d——– C:\Program Files\Minefield(2)
2006-08-18 17:45 ——– d——– C:\Program Files\Netscape
2006-08-05 08:25 87424 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswmon2.sys
2006-08-05 08:25 85952 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswmon.sys
2006-08-05 08:24 16352 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswRdr.sys
2006-08-05 08:22 36176 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswTdi.sys
2006-08-05 08:20 24304 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aavmker4.sys


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WINDVDPatch"="CTHELPER.EXE"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"Jet Detection"="\"C:\\Program Files\\Creative\\SBAudigy\\PROGRAM\\ADGJDet.exe\""
"CTStartup"="C:\\Program Files\\Creative\\Splash Screen\\CTEaxSpl.EXE /run"
"iTunesHelper"="C:\\Program Files\\iTunes\\iTunesHelper.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Advanced DHTML Enable"="C:\\dihd.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"wswrpurA"="C:\\WINDOWS\\wswrpurA.exe"
"gyb10656"="RUNDLL32.EXE w00e1c25.dll,n 004106520000000300e1c25"
"{10-0E-EF-F0-ZN}"="C:\\windows\\system32\\oldsregs.exe GEN001"
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CMFibula"="\"C:\\Program Files\\CMFibula\\CMFibula.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
@=""
"NoDriveTypeAutoRun"=hex:5f,00,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonce\CTStartup]
"CTStartup"="\"C:\\Program Files\\Creative\\Splash Screen\\CTEaxSpl.EXE\" /play"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=hex:5f,00,00,00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e4,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""



Completion time: Tue 09/05/2006 18:25:15.59
ComboFix.txt


and the HighhackThis one:

Logfile of HijackThis v1.99.1
Scan saved at 6:26:16 PM, on 9/5/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\dihd.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\wswrpurA.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Documents and Settings\Tru\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.soundblaster.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by AOL test browser
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Advanced DHTML Enable] C:\dihd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [wswrpurA] C:\WINDOWS\wswrpurA.exe
O4 - HKLM\..\Run: [gyb10656] RUNDLL32.EXE w00e1c25.dll,n 004106520000000300e1c25
O4 - HKLM\..\Run: [{10-0E-EF-F0-ZN}] C:\windows\system32\oldsregs.exe GEN001
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [CMFibula] "C:\Program Files\CMFibula\CMFibula.exe"
O4 - Startup: TA_Start.lnk = C:\WINDOWS\SYSTEM32\dwdsregt.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank

O4 - HKLM\..\Run: [Advanced DHTML Enable] C:\dihd.exe

O4 - HKLM\..\Run: [wswrpurA] C:\WINDOWS\wswrpurA.exe

O4 - HKLM\..\Run: [gyb10656] RUNDLL32.EXE w00e1c25.dll,n 004106520000000300e1c25

O4 - HKLM\..\Run: [{10-0E-EF-F0-ZN}] C:\windows\system32\oldsregs.exe GEN001

O4 - HKCU\..\Run: [CMFibula] "C:\Program Files\CMFibula\CMFibula.exe"

O4 - Startup: TA_Start.lnk = C:\WINDOWS\SYSTEM32\dwdsregt.exe

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O15 - Trusted Zone: http://click.getmirar.com (HKLM)

O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)

O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)

O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)

Then click "Fix checked" and close Hijack This!.

Reboot in "safe" mode.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\dihd.exe <— file

c:\program files\cmfibula <— FOLDER

c:\windows\system32\dwdsregt.exe <— file

c:\windows\wswrpura.exe <— file

w00e1c25.dll <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new HijackThis! log file into this thread. :)
Ok Micah,

I did what you said to do.

Here's the new log for Hijack This:

Logfile of HijackThis v1.99.1
Scan saved at 8:20:20 PM, on 9/5/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Tru\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.soundblaster.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by AOL test browser
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
I'd like you to run this online virus scan:

Trend-Micro Housecall
Put on 'Autoclean' and delete what it can't clean.

Unless it finds something it can't take care of, you should be "good to go".

Thank you for choosing TomCoyote for your malware removal solutions.

M68 :)

Securing Your PC After An Attack
This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI