This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Dropper.Delf and Adware.IEHlpr

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Done, Here ya go.. ChuckD - 06-09-15 14:22:29.26 Service Pack 2 ComboFix 06.09.14 - Running from: C:\Documents and Settings\[removed]\Desktop ((((((((((((((((((((((((((((((( Files Created from 2006-08-15 to 2006-09-15 )))))))))))))))))))))))))))))))))) 2006-09-15 11:16 193,536 –a—— C:\WINDOWS\system32\COMBoHEvent.dll 2006-09-15 07:21 1,836 –a—— C:\WINDOWS\dhcg.dll 2006-09-15 06:09 28,270 –a—— C:\WINDOWS\system32\nlenmac.dll 2006-09-13 15:06 78,336 –a—— C:\WINDOWS\system32\COMEventHelper.dll 2006-09-12 08:11 107,132 –a—— C:\WINDOWS\UninstallFirefox.exe 2006-09-08 14:28 166 –a—— C:\win_pop_flag_1__1.bat 2006-09-08 14:28 124 –a—— C:\WINDOWS\system32\Deleteme.bat 2006-09-08 13:54 81,920 –a—— C:\WINDOWS\system32\ontwps.dll 2006-09-08 13:54 28,124 –a—— C:\WINDOWS\system32\yptappm.dll 2006-09-08 13:54 168 –a—— C:\WINDOWS\system32\fctmlu.dll 2006-09-08 13:54 102,400 –a—— C:\WINDOWS\system32\xresut.dll 2006-09-08 13:49 47,104 –a—— C:\WINDOWS\system32\ppgaxea.dll 2006-09-08 13:49 38,912 –a—— C:\WINDOWS\system32\alxklt.dll 2006-09-08 13:49 185,905 –a—— C:\WINDOWS\23.exe 2006-09-08 11:23 399,360 –a—— C:\WINDOWS\178.exe 2006-09-08 11:22 20,212 –a—— C:\WINDOWS\kuwoo024.exe 2006-09-08 11:21 65,536 –a—— C:\WINDOWS\101577.exe 2006-09-08 07:50 90,112 –a—— C:\WINDOWS\system32\AVASTSS.scr 2006-09-08 07:50 635,520 –a—— C:\WINDOWS\system32\aswBoot.exe 2006-09-08 07:30 11,682,968 –a—— C:\setupeng.exe 2006-09-08 07:24 40,149 –a—— C:\WINDOWS\bind_40106.exe 2006-09-07 17:16 303,732 –a—— C:\WINDOWS\system32\nssncp.dll 2006-09-07 17:16 102,324 –a—— C:\WINDOWS\system32\nsss.dll 2006-09-07 17:15 148,992 –a—— C:\WINDOWS\system32\spflist.exe 2006-09-07 17:14 47,958 –a—— C:\WINDOWS\199019003.exe 2006-09-07 17:14 28,709 –a—— C:\WINDOWS\system32\nippzppd.dll 2006-09-07 17:12 40,149 –a—— C:\WINDOWS\bind_40107.exe 2006-09-07 17:11 135,168 –a—— C:\WINDOWS\system32\igfxres.dll 2006-09-07 16:32 24,661 –a—— C:\WINDOWS\system32\spxcoins.dll 2006-09-07 16:32 13,312 –a—— C:\WINDOWS\system32\irclass.dll 2006-09-07 15:13 324 –a—— C:\WINDOWS\system32\COMEventHelper.bat 2006-09-07 14:05 0 –a—— C:\WINDOWS\ef26ev.dll 2006-09-07 14:00 680,960 –a—— C:\WINDOWS\system32\dayi.dll 2006-09-07 14:00 28 –a—— C:\WINDOWS\system32\SystemID.dll 2006-09-07 14:00 240,128 –a—— C:\WINDOWS\system32\COMAdEvent.dll 2006-09-07 14:00 19 –a—— C:\WINDOWS\system32\C1C003E6.dll 2006-09-07 14:00 159,232 –a—— C:\wenzi29.exe 2006-09-07 12:04 40,149 –a—— C:\bind_40125.exe 2006-09-07 11:03 213,839 –a—— C:\kw_rg_lyric_038.exe 2006-09-04 20:30 18,944 –a—— C:\WINDOWS\system32\19.exe 2006-08-31 03:56 5,800 –a—— C:\WINDOWS\system32\nt.sys 2006-08-25 00:12 141,828 –a—— C:\WINDOWS\system32\SystemDll.dll (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-09-15 14:18 ——– d——– C:\Program Files\Mozilla Firefox 2006-09-15 11:11 ——– d——– C:\Program Files\Zone Labs 2006-09-15 10:18 ——– d——– C:\Program Files\ewido anti-spyware 4.0 2006-09-14 15:27 ——– d——– C:\Program Files\Kingsoft 2006-09-14 15:27 ——– d——– C:\Documents and Settings\ChuckD\Application Data\Kingsoft 2006-09-14 10:26 178506 –a—— C:\WINDOWS\system32\drivers\cdnprot.sys 2006-09-14 10:26 14566 –a—— C:\WINDOWS\system32\drivers\cdntran.sys 2006-09-13 07:46 ——– d——– C:\Program Files\WinRAR 2006-09-12 08:11 ——– d——– C:\Documents and Settings\ChuckD\Application Data\Mozilla 2006-09-08 13:43 ——– d——– C:\Program Files\Common Files\UPDATE2 2006-09-08 13:42 ——– d——– C:\Program Files\kuzhan 2006-09-08 11:27 ——– d——– C:\Program Files\CNNIC 2006-09-08 08:12 ——– d——– C:\Program Files\CUAgent 2006-09-08 07:26 ——– d——– C:\Program Files\Lavasoft 2006-09-08 07:26 ——– d——– C:\Documents and Settings\ChuckD\Application Data\Lavasoft 2006-09-08 07:01 ——– d——– C:\Program Files\pcast 2006-09-08 06:29 ——– d—s—- C:\Documents and Settings\ChuckD\Application Data\Microsoft 2006-09-07 17:19 ——– d——– C:\Program Files\Windows Live Safety Center 2006-09-07 16:51 ——– d——– C:\Program Files\Windows Media Player 2006-09-07 16:48 ——– d——– C:\Program Files\Outlook Express 2006-09-07 16:48 ——– d——– C:\Program Files\Internet Explorer 2006-09-07 16:48 ——– d——– C:\Program Files\Common Files\System 2006-09-07 14:00 ——– d——– C:\Program Files\exports 2006-09-07 12:59 ——– d——– C:\Program Files\Common Files 2006-09-07 11:03 ——– d——– C:\Program Files\KooWo 2006-09-06 08:17 ——– d——– C:\Documents and Settings\ChuckD\Application Data\Google 2006-09-06 06:46 ——– d——– C:\Program Files\Google 2006-08-14 14:26 91648 –a—— C:\WINDOWS\system32\gunzip.exe 2006-08-05 10:25 87424 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys 2006-08-05 10:25 85952 –a—— C:\WINDOWS\system32\drivers\aswmon.sys 2006-08-05 10:24 16352 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys 2006-08-05 10:22 36176 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys 2006-08-05 10:20 24304 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys 2006-07-26 21:39 303104 –a—— C:\WINDOWS\system32\YHBO.dll 2006-07-25 06:34 172032 –a—— C:\WINDOWS\system32\HTTPDll.dll 2006-07-25 06:32 40960 –a—— C:\WINDOWS\system32\lrcsys.exe (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NWTRAY"="NWTRAY.EXE" "igfxtray"="C:\\WINDOWS\\system32\\igfxtray.exe" "avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe" "!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized" "Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI] "NoChange"="1" "Installed"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS] "Installed"="1" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000000 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="http://www.superthinribbons.com/images/Medals/NavyComm.jpg" "SubscribedURL"="http://www.superthinribbons.com/images/Medals/NavyComm.jpg" "FriendlyName"="" "Flags"=dword:00000001 "Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:04,00,00,00 "OriginalStateInfo"=hex:18,00,00,00,ee,00,00,00,3d,01,00,00,a9,00,00,00,07,01,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:18,00,00,00,6c,01,00,00,17,01,00,00,a4,00,00,00,9a,00,\ 00,00,01,00,00,00 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\1] "Source"="http://www.nationmaster.com/wikimir/images/upload.wikimedia.org/wikipedia/commons/thumb/9/98/48px-Flag_of_the_United_States.png" "SubscribedURL"="http://www.nationmaster.com/wikimir/images/upload.wikimedia.org/wikipedia/commons/thumb/9/98/48px-Flag_of_the_United_States.png" "FriendlyName"="" "Flags"=dword:00000001 "Position"=hex:2c,00,00,00,a4,00,00,00,59,00,00,00,a4,00,00,00,9a,00,00,00,ea,\ 03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,00 "OriginalStateInfo"=hex:18,00,00,00,12,02,00,00,23,00,00,00,30,00,00,00,19,00,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:14,6d,44,03,41,c0,b4,74,78,48,20,00,68,de,44,03,20,6d,\ 44,03,73,2b,00,00 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\10] "Source"="http://images.google.com/images?q=tbn:18reT1bjQoUJ:http://www.cordogg.com/images/EGA.gif" "SubscribedURL"="http://images.google.com/images?q=tbn:18reT1bjQoUJ:http://www.cordogg.com/images/EGA.gif" "FriendlyName"="" "Flags"=dword:00000001 "Position"=hex:2c,00,00,00,a4,00,00,00,17,01,00,00,a4,00,00,00,9a,00,00,00,fc,\ 03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,00 "OriginalStateInfo"=hex:18,00,00,00,12,03,00,00,19,01,00,00,59,00,00,00,59,00,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:18,00,00,00,1c,03,00,00,69,02,00,00,88,00,00,00,88,00,\ 00,00,01,00,00,00 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\11] "Source"="http://www.vspa.com/images-vspa/af-medal-bronze-star.jpg" "SubscribedURL"="http://www.vspa.com/images-vspa/af-medal-bronze-star.jpg" "FriendlyName"="" "Flags"=dword:00000001 "Position"=hex:2c,00,00,00,22,02,00,00,6b,00,00,00,a4,00,00,00,9a,00,00,00,fe,\ 03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,00 "OriginalStateInfo"=hex:18,00,00,00,00,01,00,00,2b,01,00,00,8e,00,00,00,00,01,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:14,6d,45,03,41,c0,b4,74,70,aa,24,00,68,de,45,03,20,6d,\ 45,03,d0,b3,00,00 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\12] "Source"="http://images.google.com/images?q=tbn:YRp7UUVaCKVUtM:http://www.vspa.com/images-vspa/af-medal-bronze-star.jpg" "SubscribedURL"="http://images.google.com/images?q=tbn:YRp7UUVaCKVUtM:http://www.vspa.com/images-vspa/af-medal-bronze-star.jpg" "FriendlyName"="" "Flags"=dword:00000001 "Position"=hex:2c,00,00,00,22,02,00,00,29,01,00,00,a4,00,00,00,9a,00,00,00,00,\ 04,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,00 "OriginalStateInfo"=hex:18,00,00,00,ee,00,00,00,47,00,00,00,3b,00,00,00,6b,00,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:14,6d,88,03,41,c0,b4,74,c8,d7,20,00,68,de,88,03,20,6d,\ 88,03,0f,bf,00,00 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\13] "Source"="http://images.google.com/images?q=tbn:GKfG9DHKD3vj4M:home.twcny.rr.com/cod324th/web%2520pages/images/bronze%2520star.jpg" "SubscribedURL"="http://images.google.com/images?q=tbn:GKfG9DHKD3vj4M:home.twcny.rr.com/cod324th/web%2520pages/images/bronze%2520star.jpg" "FriendlyName"="" "Flags"=dword:00000001 "Position"=hex:2c,00,00,00,5a,01,00,00,6b,00,00,00,a4,00,00,00,9a,00,00,00,02,\ 04,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,dc,02,00,00,59,00,00,00,4a,00,00,00,73,00,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:14,6d,ee,03,41,c0,b4,74,10,10,78,03,68,de,ee,03,20,6d,\ ee,03,8f,88,00,00 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\14] "Source"="http://images.google.com/images?q=tbn:eN-_ZZI4bNk6WM:http://rustyknight.topcities.com/images/Bronzestar.jpg" "SubscribedURL"="http://images.google.com/images?q=tbn:eN-_ZZI4bNk6WM:http://rustyknight.topcities.com/images/Bronzestar.jpg" "FriendlyName"="" "Flags"=dword:00000001 "Position"=hex:2c,00,00,00,5a,01,00,00,29,01,00,00,a4,00,00,00,9a,00,00,00,04,\ 04,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,dc,02,00,00,4f,01,00,00,4c,00,00,00,89,00,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:14,6d,5d,04,41,c0,b4,74,a0,af,1d,00,68,de,5d,04,20,6d,\ 5d,04,30,2c,00,00 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\15] "Source"="http://www.desertstormusmc.com/exbadge.JPG" "SubscribedURL"="http://www.desertstormusmc.com/exbadge.JPG" "FriendlyName"="" "Flags"=dword:00000001 "Position"=hex:2c,00,00,00,92,00,00,00,6b,00,00,00,a4,00,00,00,9a,00,00,00,06,\ 04,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,00 "OriginalStateInfo"=hex:18,00,00,00,ee,02,00,00,47,00,00,00,a1,00,00,00,9b,00,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:18,00,00,00,2a,03,00,00,34,02,00,00,5a,00,00,00,5a,00,\ 00,00,01,00,00,40 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\16] "Source"="http://seawolves.org/common/images/medals/purple_heart_medal.gif" "SubscribedURL"="http://seawolves.org/common/images/medals/purple_heart_medal.gif" "FriendlyName"="" "Flags"=dword:00001001 "Position"=hex:2c,00,00,00,ec,01,00,00,a1,00,00,00,a4,00,00,00,9a,00,00,00,08,\ 04,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,00,01,00,00,35,00,00,00,94,00,00,00,e8,00,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:18,00,00,00,77,03,00,00,67,02,00,00,4b,00,00,00,77,00,\ 00,00,01,00,00,40 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\17] "Source"="http://home.twcny.rr.com/cod324th/web%20pages/images/bronze%20star.jpg" "SubscribedURL"="http://home.twcny.rr.com/cod324th/web%20pages/images/bronze%20star.jpg" "FriendlyName"="" "Flags"=dword:00001001 "Position"=hex:2c,00,00,00,ec,01,00,00,5f,01,00,00,a4,00,00,00,9a,00,00,00,0a,\ 04,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,dc,01,00,00,59,00,00,00,bc,00,00,00,25,01,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:18,00,00,00,a1,03,00,00,44,02,00,00,5f,00,00,00,9e,00,\ 00,00,01,00,00,40 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\18] "Source"="http://www.medianetjapan.com/town/internet_computer/derfuhrer/Medal/image145.jpg" "SubscribedURL"="http://www.medianetjapan.com/town/internet_computer/derfuhrer/Medal/image145.jpg" "FriendlyName"="" "Flags"=dword:00001001 "Position"=hex:2c,00,00,00,24,01,00,00,a1,00,00,00,a4,00,00,00,9a,00,00,00,0c,\ 04,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,00 "OriginalStateInfo"=hex:18,00,00,00,00,02,00,00,2b,01,00,00,cd,00,00,00,81,01,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:18,00,00,00,0f,03,00,00,5f,02,00,00,4d,00,00,00,8c,00,\ 00,00,01,00,00,00 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\19] "Source"="http://upload.wikimedia.org/wikipedia/en/thumb/4/4c/NavJumpWings.jpg/225px-NavJumpWings.jpg" "SubscribedURL"="http://upload.wikimedia.org/wikipedia/en/thumb/4/4c/NavJumpWings.jpg/225px-NavJumpWings.jpg" "FriendlyName"="" "Flags"=dword:00001001 "Position"=hex:2c,00,00,00,24,01,00,00,5f,01,00,00,a4,00,00,00,9a,00,00,00,0e,\ 04,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,00 "OriginalStateInfo"=hex:18,00,00,00,ee,01,00,00,47,00,00,00,e1,00,00,00,47,00,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:14,6d,09,02,41,c0,b4,74,f8,3f,9d,03,68,de,09,02,20,6d,\ 09,02,d0,b3,00,00 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\2] "Source"="http://www.cheaperthandirt.com/ctd_images/product_images/1277/FLAG-100.jpg" "SubscribedURL"="http://www.cheaperthandirt.com/ctd_images/product_images/1277/FLAG-100.jpg" "FriendlyName"="" "Flags"=dword:00000001 "Position"=hex:2c,00,00,00,48,01,00,00,7d,00,00,00,a4,00,00,00,9a,00,00,00,ec,\ 03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,12,02,00,00,19,01,00,00,fa,00,00,00,fa,00,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:14,6d,3e,04,41,c0,b4,74,d8,e0,23,00,68,de,3e,04,20,6d,\ 3e,04,73,2b,00,00 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\20] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" "Flags"=dword:00000002 "Position"=hex:2c,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,00,00,10,\ 04,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,00 "OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\ ff,ff,04,00,00,00 "RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\ 00,00,01,00,00,00 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\3] "Source"="http://www.milnet.com/pentagon/usmc-insignia/CHR103.jpg" "SubscribedURL"="http://www.milnet.com/pentagon/usmc-insignia/CHR103.jpg" "FriendlyName"="" "Flags"=dword:00000001 "Position"=hex:2c,00,00,00,48,01,00,00,3b,01,00,00,a4,00,00,00,9a,00,00,00,ee,\ 03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,00 "OriginalStateInfo"=hex:18,00,00,00,12,01,00,00,23,00,00,00,96,00,00,00,96,00,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:14,6d,96,03,41,c0,b4,74,a8,4a,22,00,68,de,96,03,20,6d,\ 96,03,d0,b3,00,00 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\4] "Source"="http://1stbattalion3rdmarines.com/00-marine-images/ranks-1912–/rnks.1937-2002.grn/rank-04-green.gif" "SubscribedURL"="http://1stbattalion3rdmarines.com/00-marine-images/ranks-1912–/rnks.1937-2002.grn/rank-04-green.gif" "FriendlyName"="" "Flags"=dword:00000001 "Position"=hex:2c,00,00,00,63,02,00,00,17,01,00,00,a0,01,00,00,35,01,00,00,f0,\ 03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,00 "OriginalStateInfo"=hex:18,00,00,00,12,01,00,00,19,01,00,00,a0,01,00,00,35,01,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:14,6d,45,03,41,c0,b4,74,a8,4a,22,00,68,de,45,03,20,6d,\ 45,03,d0,b3,00,00 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\5] "Source"="http://www.outinstyle.com/Merchant2/graphics/00000001/1603_thuCOM.jpg" "SubscribedURL"="http://www.outinstyle.com/Merchant2/graphics/00000001/1603_thuCOM.jpg" "FriendlyName"="" "Flags"=dword:00000001 "Position"=hex:2c,00,00,00,80,00,00,00,7d,00,00,00,a4,00,00,00,9a,00,00,00,f2,\ 03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,00 "OriginalStateInfo"=hex:18,00,00,00,00,03,00,00,35,00,00,00,64,00,00,00,38,00,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:14,6d,d0,03,41,c0,b4,74,e0,e6,6c,03,68,de,d0,03,20,6d,\ d0,03,d0,b3,00,00 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\6] "Source"="http://www.gwpda.org/medals/usamedl/s-star.jpg" "SubscribedURL"="http://www.gwpda.org/medals/usamedl/s-star.jpg" "FriendlyName"="" "Flags"=dword:00000001 "Position"=hex:2c,00,00,00,80,00,00,00,3b,01,00,00,a4,00,00,00,9a,00,00,00,f4,\ 03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,00 "OriginalStateInfo"=hex:18,00,00,00,00,03,00,00,2b,01,00,00,a0,00,00,00,25,01,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:14,6d,f0,05,41,c0,b4,74,70,aa,24,00,68,de,f0,05,20,6d,\ f0,05,d0,b3,00,00 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\7] "Source"="http://www.archives.gov/exhibits/tokens_and_treasures/images/medals.jpg" "SubscribedURL"="http://www.archives.gov/exhibits/tokens_and_treasures/images/medals.jpg" "FriendlyName"="" "Flags"=dword:00000001 "Position"=hex:2c,00,00,00,fe,01,00,00,8f,00,00,00,a4,00,00,00,9a,00,00,00,f6,\ 03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,00 "OriginalStateInfo"=hex:18,00,00,00,00,02,00,00,35,00,00,00,dd,01,00,00,3a,01,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:14,6d,96,03,41,c0,b4,74,70,aa,24,00,68,de,96,03,20,6d,\ 96,03,d0,b3,00,00 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\8] "Source"="http://www.hmm-364.org/nmcom.gif" "SubscribedURL"="http://www.hmm-364.org/nmcom.gif" "FriendlyName"="" "Flags"=dword:00000001 "Position"=hex:2c,00,00,00,fe,01,00,00,4d,01,00,00,a4,00,00,00,9a,00,00,00,f8,\ 03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,00 "OriginalStateInfo"=hex:18,00,00,00,ee,02,00,00,3d,01,00,00,5e,00,00,00,d4,00,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:14,6d,e0,05,41,c0,b4,74,60,46,9b,03,68,de,e0,05,20,6d,\ e0,05,d0,b3,00,00 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\9] "Source"="http://www.huntington.in.us/county/veterans/memday2003/Rank/Marine%20Corps%20Rank/sgt.jpg" "SubscribedURL"="http://www.huntington.in.us/county/veterans/memday2003/Rank/Marine%20Corps%20Rank/sgt.jpg" "FriendlyName"="" "Flags"=dword:00000001 "Position"=hex:2c,00,00,00,b3,01,00,00,16,00,00,00,44,00,00,00,46,00,00,00,fa,\ 03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,ee,01,00,00,3d,01,00,00,64,00,00,00,8c,00,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:14,6d,9c,03,41,c0,b4,74,c0,67,6d,03,68,de,9c,03,20,6d,\ 9c,03,59,3b,00,00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 "CompatibleRUPSecurity"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run] "Galaxy"="rundll32.exe C:\\WINDOWS\\system32\\ppgaxea.dll,Su" "Power"="rundll32.exe C:\\WINDOWS\\system32\\alxklt.dll,Start" [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-] "91cast"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Acrobat Assistant.lnk" "backup"="C:\\WINDOWS\\pss\\Acrobat Assistant.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Adobe\\ACROBA~2.0\\Distillr\\AcroTray.exe " "item"="Acrobat Assistant" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Gamma Loader.lnk" "backup"="C:\\WINDOWS\\pss\\Adobe Gamma Loader.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\COMMON~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE " "item"="Adobe Gamma Loader" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk" "backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE " "item"="Adobe Reader Speed Launch" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Microsoft Office.lnk" "backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\MICROS~2\\Office\\OSA9.EXE -b -l" "item"="Microsoft Office" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Symantec Fax Starter Edition Port.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Symantec Fax Starter Edition Port.lnk" "backup"="C:\\WINDOWS\\pss\\Symantec Fax Starter Edition Port.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\MICROS~2\\Office\\1033\\OLFSNT40.EXE " "item"="Symantec Fax Starter Edition Port" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^ChuckD^Start Menu^Programs^Startup^DFIncBackup.lnk] "path"="C:\\Documents and Settings\\ChuckD\\Start Menu\\Programs\\Startup\\DFIncBackup.lnk" "backup"="C:\\WINDOWS\\pss\\DFIncBackup.lnkStartup" "location"="Startup" "command"="C:\\PROGRA~1\\DFINCB~1\\DFINCB~1.EXE " "item"="DFIncBackup" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Alcmtr] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ALCMTR" "hkey"="HKLM" "command"="ALCMTR.EXE" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\avast!] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ashDisp" "hkey"="HKLM" "command"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\CdnCtr] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="cdnup" "hkey"="HKLM" "command"="C:\\Program Files\\CNNIC\\Cdn\\cdnup.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Creative WebCam Tray] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="CAMTRAY" "hkey"="HKLM" "command"="C:\\Program Files\\Creative\\Shared Files\\CAMTRAY.EXE" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\High Definition Audio Property Page Shortcut] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="HDAShCut" "hkey"="HKLM" "command"="HDAShCut.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\HP Software Update] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="HPWuSchd2" "hkey"="HKLM" "command"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\igfxhkcmd] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="hkcmd" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\hkcmd.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\igfxpers] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="igfxpers" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\igfxpers.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\igfxtray] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="igfxtray" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\igfxtray.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\MSMSGS] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="msmsgs" "hkey"="HKCU" "command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\MsnMsgr] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="MsnMsgr" "hkey"="HKCU" "command"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\NWTRAY] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NWTRAY" "hkey"="HKLM" "command"="NWTRAY.EXE" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\RemoteControl] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="PDVDServ" "hkey"="HKLM" "command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\RTHDCPL] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="RTHDCPL" "hkey"="HKLM" "command"="RTHDCPL.EXE" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\SunJavaUpdateSched] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="jusched" "hkey"="HKLM" "command"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\swg] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="GoogleToolbarNotifier" "hkey"="HKCU" "command"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.0.720.3640\\GoogleToolbarNotifier.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\UserFaultCheck] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="dumprep 0 -u" "hkey"="HKLM" "command"="%systemroot%\\system32\\dumprep 0 -u" "inimapping"="0" HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll Completion time: 06-09-15 14:23:30.46 ComboFix.txt Logfile of HijackThis v1.99.1 Scan saved at 14:25, on 06-09-15 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\ewido anti-spyware 4.0\guard.exe C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\WINDOWS\system32\NALNTSRV.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wm.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe c:\windows\system32\inetsrv\csrss.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\NWTRAY.EXE C:\WINDOWS\system32\igfxtray.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\ewido anti-spyware 4.0\ewido.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\ChuckD\Desktop\HijackThis.exe O1 - Hosts: 216.203.115.94 old.kwik-way.com #old dybb mail server O1 - Hosts: 216.203.115.94 old.irontite.com #old irontite mail server O1 - Hosts: 216.203.115.94 old.van-norman.com #old van-norman mail server O1 - Hosts: 66.29.47.60 new.kwik-way.com #new kwik-way mail server O2 - BHO: (no name) - {16B770A0-0E87-4278-B748-2460D64A8386} - (no file) O2 - BHO: Macromedia. Flash8 Object - {C61A70F3-505E-4B90-916F-627A8706B4BC} - c:\WINDOWS\system32\COMBoHEvent.dll O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O10 - Broken Internet access because of LSP provider 'c:\windows\system32\cdnns.dll' missing O17 - HKLM\System\CCS\Services\Tcpip\..\{3DDB8FF4-5BFE-419E-9A46-47BD42B69B49}: NameServer = 216.203.122.200,216.203.112.112 O17 - HKLM\System\CS1\Services\Tcpip\..\{3DDB8FF4-5BFE-419E-9A46-47BD42B69B49}: NameServer = 216.203.122.200,216.203.112.112 O17 - HKLM\System\CS2\Services\Tcpip\..\{3DDB8FF4-5BFE-419E-9A46-47BD42B69B49}: NameServer = 216.203.122.200,216.203.112.112 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\ O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\system32\cusrvc.exe O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\WINDOWS\system32\NALNTSRV.EXE O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe O23 - Service: Novell Workstation Manager (WM) - Novell, Inc. - C:\WINDOWS\system32\wm.exe
Copy and paste the contents of the quote box below into notepad.

Save it as file name: "fixme.reg" (not including the quotes). Save as file type: *All files* and save it on your Desktop.

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
"Galaxy"=-
"Power"=-

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C61A70F3-505E-4B90-916F-627A8706B4BC}\InprocServer32]


Then, locate fixme.reg on your desktop and it.

You will receive a prompt similar to: "Do you wish to merge the information into the registry?".

Answer 'Yes' and wait for a message to appear similar to "Merged Successfully".

Reboot in "safe" mode.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O2 - BHO: (no name) - {16B770A0-0E87-4278-B748-2460D64A8386} - (no file)

O2 - BHO: Macromedia. Flash8 Object - {C61A70F3-505E-4B90-916F-627A8706B4BC} - c:\WINDOWS\system32\COMBoHEvent.dll

Then click "Fix checked" and close Hijack This!.

Reboot in normal mode and "copy/paste" a new HijackThis! log file into this thread.
:)
Following your instructions and everything worked as expected. Here is the new log file. Logfile of HijackThis v1.99.1 Scan saved at 15:55, on 06-09-15 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\ewido anti-spyware 4.0\guard.exe C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\WINDOWS\system32\NALNTSRV.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wm.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\userinit.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\NWTRAY.EXE C:\WINDOWS\system32\igfxtray.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\ewido anti-spyware 4.0\ewido.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Documents and Settings\ChuckD\Desktop\HijackThis.exe O1 - Hosts: 216.203.115.94 old.kwik-way.com #old dybb mail server O1 - Hosts: 216.203.115.94 old.irontite.com #old irontite mail server O1 - Hosts: 216.203.115.94 old.van-norman.com #old van-norman mail server O1 - Hosts: 66.29.47.60 new.kwik-way.com #new kwik-way mail server O2 - BHO: (no name) - {16B770A0-0E87-4278-B748-2460D64A8386} - (no file) O2 - BHO: Macromedia. Flash8 Object - {C61A70F3-505E-4B90-916F-627A8706B4BC} - c:\WINDOWS\system32\COMBoHEvent.dll O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O10 - Broken Internet access because of LSP provider 'c:\windows\system32\cdnns.dll' missing O17 - HKLM\System\CCS\Services\Tcpip\..\{3DDB8FF4-5BFE-419E-9A46-47BD42B69B49}: NameServer = 216.203.122.200,216.203.112.112 O17 - HKLM\System\CS1\Services\Tcpip\..\{3DDB8FF4-5BFE-419E-9A46-47BD42B69B49}: NameServer = 216.203.122.200,216.203.112.112 O17 - HKLM\System\CS2\Services\Tcpip\..\{3DDB8FF4-5BFE-419E-9A46-47BD42B69B49}: NameServer = 216.203.122.200,216.203.112.112 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\ O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\system32\cusrvc.exe O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\WINDOWS\system32\NALNTSRV.EXE O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe O23 - Service: Novell Workstation Manager (WM) - Novell, Inc. - C:\WINDOWS\system32\wm.exe
After posting the above I had some time to spend on this machine trying to resolve these problems. I used the services.msc to look at running services. There was one with goofy characters for a description. It was a "COMEventHelper.dll". So I disabled the service. I could not stop it and after disable on reboot it would run again. So, after disabling it I then used regedit to search for the filename. I found 3 occurances that had high ascii characters for a description. I deleted those registry entries. I also found other entries that looked fine so I left them alone. I then closed the services.msc window and the regedit window and opened HJT and attempted the deletion of those two 04 keys. I then rebooted and ran HJT and got the following log.. :D Logfile of HijackThis v1.99.1 Scan saved at 17:04, on 06-09-15 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\ewido anti-spyware 4.0\guard.exe C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\WINDOWS\system32\NALNTSRV.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wm.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\WINDOWS\system32\NWTRAY.EXE C:\WINDOWS\system32\igfxtray.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\ewido anti-spyware 4.0\ewido.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Documents and Settings\ChuckD\Desktop\HijackThis.exe O1 - Hosts: 216.203.115.94 old.kwik-way.com #old dybb mail server O1 - Hosts: 216.203.115.94 old.irontite.com #old irontite mail server O1 - Hosts: 216.203.115.94 old.van-norman.com #old van-norman mail server O1 - Hosts: 66.29.47.60 new.kwik-way.com #new kwik-way mail server O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O17 - HKLM\System\CCS\Services\Tcpip\..\{3DDB8FF4-5BFE-419E-9A46-47BD42B69B49}: NameServer = 216.203.122.200,216.203.112.112 O17 - HKLM\System\CS1\Services\Tcpip\..\{3DDB8FF4-5BFE-419E-9A46-47BD42B69B49}: NameServer = 216.203.122.200,216.203.112.112 O17 - HKLM\System\CS2\Services\Tcpip\..\{3DDB8FF4-5BFE-419E-9A46-47BD42B69B49}: NameServer = 216.203.122.200,216.203.112.112 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\ O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\system32\cusrvc.exe O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\WINDOWS\system32\NALNTSRV.EXE O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe O23 - Service: Novell Workstation Manager (WM) - Novell, Inc. - C:\WINDOWS\system32\wm.exe I'm not convienced that the system is totally clean, but I think I may have made some headway.
Run this online scan :Kaspersky Virusscanner

Next Click on Launch Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Standard
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
  • Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.

Copy and paste that information from Kapersky in your reply with another HijackThis! log.
KASPERSKY ONLINE SCANNER REPORT
06-09-18 10:05
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 18/09/2006
Kaspersky Anti-Virus database records: 211370


Scan Settings
Scan using the following antivirus database standard
Scan Archives true
Scan Mail Bases true

Scan Target Folders
C:\

Scan Statistics
Total number of scanned objects 45786
Number of viruses found 7
Number of infected objects 38 / 0
Number of suspicious objects 0
Duration of the scan process 00:38:57

Infected Object Name Virus Name Last Action
C:\!KillBox\officeÎļþ¼ìË÷.exe Infected: Trojan-PSW.Win32.Agent.io skipped

C:\!KillBox\Realplayer.exe Infected: Trojan-Downloader.Win32.Agent.aqr skipped

C:\bind_40125.exe/data0001 Infected: Trojan-Downloader.NSIS.Agent.y skipped

C:\bind_40125.exe NSIS: infected - 1 skipped

C:\Documents and Settings\ChuckD\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\ChuckD\Desktop\backups\backup-20060912-081718-453-officeÎļþ¼ìË÷.exe Infected: Trojan-PSW.Win32.Agent.io skipped

C:\Documents and Settings\ChuckD\Desktop\backups\backup-20060912-082843-536-officeÎļþ¼ìË÷.exe Infected: Trojan-PSW.Win32.Agent.io skipped

C:\Documents and Settings\ChuckD\Desktop\backups\backup-20060912-082923-809-officeÎļþ¼ìË÷.exe Infected: Trojan-PSW.Win32.Agent.io skipped

C:\Documents and Settings\ChuckD\Desktop\backups\backup-20060913-093951-305-officeÎļþ¼ìË÷.exe Infected: Trojan-PSW.Win32.Agent.io skipped

C:\Documents and Settings\ChuckD\Desktop\backups\backup-20060913-150031-954-officeÎļþ¼ìË÷.exe Infected: Trojan-PSW.Win32.Agent.io skipped

C:\Documents and Settings\ChuckD\Desktop\backups\backup-20060913-164945-891-officeÎļþ¼ìË÷.exe Infected: Trojan-PSW.Win32.Agent.io skipped

C:\Documents and Settings\ChuckD\Desktop\backups\backup-20060914-101618-793-officeÎļþ¼ìË÷.exe Infected: Trojan-PSW.Win32.Agent.io skipped

C:\Documents and Settings\ChuckD\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\ChuckD\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\ChuckD\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\ChuckD\Local Settings\Temp\v20060914.rar Infected: Trojan-Downloader.Win32.Agent.aqr skipped

C:\Documents and Settings\ChuckD\Local Settings\Temporary Internet Files\Content.IE5\C123GTUJ\v33[1].gif Infected: Trojan-Downloader.Win32.VB.alh skipped

C:\Documents and Settings\ChuckD\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\ChuckD\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\ChuckD\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FMZCP2F4\17[1].exe Infected: Trojan-Downloader.Win32.Agent.aqr skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FMZCP2F4\csrss[1].txt Infected: Backdoor.Win32.Delf.auu skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FMZCP2F4\setup[1].rar/Stream/data0004 Infected: Trojan-Downloader.Win32.Adload.fh skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FMZCP2F4\setup[1].rar/Stream Infected: Trojan-Downloader.Win32.Adload.fh skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FMZCP2F4\setup[1].rar Inno: infected - 2 skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\QU59JEFF\15[1].exe Infected: Trojan-Downloader.Win32.Agent.aqr skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\QU59JEFF\16[1].exe Infected: Trojan-Downloader.Win32.Agent.aqr skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\QU59JEFF\csrss[1].txt Infected: Backdoor.Win32.Delf.auu skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\ZUJ2LJ5F\csrss[1].txt Infected: Backdoor.Win32.Delf.auu skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped

C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped

C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped

C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped

C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped

C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped

C:\Program Files\Alwil Software\Avast4\DATA\moved\[PECompact].vir Infected: Trojan-Downloader.Win32.VB.alh skipped

C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\WINDOWS\23.exe/data0002 Infected: Trojan-Downloader.Win32.Agent.afm skipped

C:\WINDOWS\23.exe NSIS: infected - 1 skipped

C:\WINDOWS\bind_40106.exe/data0001 Infected: Trojan-Downloader.NSIS.Agent.y skipped

C:\WINDOWS\bind_40106.exe NSIS: infected - 1 skipped

C:\WINDOWS\bind_40107.exe/data0001 Infected: Trojan-Downloader.NSIS.Agent.y skipped

C:\WINDOWS\bind_40107.exe NSIS: infected - 1 skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\Internet Logs\CHUCK-XP.ldb Object is locked skipped

C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped

C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped

C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped

C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\EventCache\{C16EA9A8-1968-499D-9786-66ADB59392E2}.bin Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\inetsrv\csrss.exe Infected: Backdoor.Win32.Delf.auu skipped

C:\WINDOWS\system32\inetsrv\Update\BoExplorer.rar/csrss.exe Infected: Backdoor.Win32.Delf.auu skipped

C:\WINDOWS\system32\inetsrv\Update\BoExplorer.rar ZIP: infected - 1 skipped

C:\WINDOWS\system32\novell\nici\SYSTEM\XMGRCFG.KS2 Object is locked skipped

C:\WINDOWS\system32\novell\nici\SYSTEM\XMGRCFG.KS3 Object is locked skipped

C:\WINDOWS\system32\Rsvtub.dll Infected: Trojan-Downloader.Win32.Agent.aqr skipped

C:\WINDOWS\system32\SystemDll.dll/EXE-file Infected: Trojan-PSW.Win32.Agent.io skipped

C:\WINDOWS\system32\SystemDll.dll Embedded EXE: infected - 1 skipped

C:\WINDOWS\system32\SystemDll.dll UPX: infected - 1 skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\Temp\an85.com Infected: Trojan-Downloader.Win32.Agent.aqr skipped

C:\WINDOWS\Temp\Perflib_Perfdata_758.dat Object is locked skipped

C:\WINDOWS\Temp\v20060914.rar Infected: Trojan-Downloader.Win32.Agent.aqr skipped

C:\WINDOWS\Temp\ZLT01147.TMP Object is locked skipped

C:\WINDOWS\Temp\ZLT01be0.TMP Object is locked skipped

C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.


Logfile of HijackThis v1.99.1
Scan saved at 10:06, on 06-09-18
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\NALNTSRV.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wm.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NWTRAY.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\ChuckD\LOCALS~1\Temp\103126.exe
C:\Documents and Settings\ChuckD\Desktop\HijackThis.exe

O1 - Hosts: 216.203.115.94 old.kwik-way.com #old dybb mail server
O1 - Hosts: 216.203.115.94 old.irontite.com #old irontite mail server
O1 - Hosts: 216.203.115.94 old.van-norman.com #old van-norman mail server
O1 - Hosts: 66.29.47.60 new.kwik-way.com #new kwik-way mail server
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3DDB8FF4-5BFE-419E-9A46-47BD42B69B49}: NameServer = 216.203.122.200,216.203.112.112
O17 - HKLM\System\CS1\Services\Tcpip\..\{3DDB8FF4-5BFE-419E-9A46-47BD42B69B49}: NameServer = 216.203.122.200,216.203.112.112
O17 - HKLM\System\CS2\Services\Tcpip\..\{3DDB8FF4-5BFE-419E-9A46-47BD42B69B49}: NameServer = 216.203.122.200,216.203.112.112
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\system32\cusrvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\WINDOWS\system32\NALNTSRV.EXE
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Novell Workstation Manager (WM) - Novell, Inc. - C:\WINDOWS\system32\wm.exe
Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only

Don't run it yet.

Reboot in "safe" mode.

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All.
Click the Empty Selected button.
Close the program.

Delete:

C:\!KillBox <– FOLDER

C:\bind_40125.exe <— file

C:\WINDOWS\23.exe <— file

C:\WINDOWS\bind_40106.exe <— file

C:\WINDOWS\bind_40107.exe <— file

C:\WINDOWS\system32\Rsvtub.dll <— file

C:\WINDOWS\system32\SystemDll.dll <— file

Boot normally.

How is the machine running?
:unsure:

How is the machine running?


Still not wonderful. Pop-ups still occuring from time to time. Usually when opening Windows Explorer or IE. Not as massively as before. And Ewido still claims to find Dropper.Delf.xx or Downloader.Delf.xx whenever a scan is performed.

I did find the \log folder under the \!killbox\ folder when I went to delete the killbox folder. it was a hidden system flagged folder and this user's settings were to hide system files so it wasn't visable. But then I tried to delete the \!killbox folder I couldn't even though it was showing empty to me. So that's how I discovered it.

Right after I deleted the \log folder inside the \!killbox folder (while in safe mode) I got a blue screen with an IRQL_NOT_LESS_OR_EQUAL error. I rebooted into safe mode again to finish the deletes.

There was all a file named 2.exe which was showing up under the users folder\templates\b52fb32 and also under c:\windows that I had noticed trying to access the internet via the firewall software. So I deleted it as well while in safe mode.

All other files deleted with no problem and the machine rebooted normally. I got 2 windows message boxes stating that a file failed to run on bootup. Both mentioned files were goofy named things like apxizlm.dll and the box was just an OK box, so that was probably a good thing.

I'll turn the machine back over to the user now and see if any more pop-ups happen.

Right after booting in normal mode I ran a fast scan using Ewido and below is the log from that scan.

———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 16:20 06-09-18

+ Scan result:



C:\WINDOWS\system32\drivers\fsprot.sys -> Adware.WSearch : Cleaned.
C:\WINDOWS\6efdd5b8\ddn5b.dll -> Downloader.Delf.asz : Cleaned.
[2804] C:\DOCUME~1\ChuckD\TEMPLA~1\b56fbb2\1.dll -> Downloader.Delf.asz : Error during cleaning.
:mozilla.23:C:\Documents and Settings\ChuckD\Application Data\Mozilla\Firefox\Profiles\0djq8tsq.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.25:C:\Documents and Settings\ChuckD\Application Data\Mozilla\Firefox\Profiles\0djq8tsq.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.26:C:\Documents and Settings\ChuckD\Application Data\Mozilla\Firefox\Profiles\0djq8tsq.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.27:C:\Documents and Settings\ChuckD\Application Data\Mozilla\Firefox\Profiles\0djq8tsq.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.36:C:\Documents and Settings\ChuckD\Application Data\Mozilla\Firefox\Profiles\0djq8tsq.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.28:C:\Documents and Settings\ChuckD\Application Data\Mozilla\Firefox\Profiles\0djq8tsq.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.33:C:\Documents and Settings\ChuckD\Application Data\Mozilla\Firefox\Profiles\0djq8tsq.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.34:C:\Documents and Settings\ChuckD\Application Data\Mozilla\Firefox\Profiles\0djq8tsq.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.35:C:\Documents and Settings\ChuckD\Application Data\Mozilla\Firefox\Profiles\0djq8tsq.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.


::Report end

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI