This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan.gromozon Trojan

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, after going through several weird changes on my PC, including having a hidden account which stopped me logging straight into Window's, I found the above trojan with Counterspy. After reading up on it (oh dear) I decided it would be easier to just do a re-install of Window's.

HOWEVER… after installing Sygate, AVG Free and Counterspy, in that order, I found Gromozon still reported as Trojan.Gromozon Trojan, described as being located in c\Windows\System32\lpt4.ago. I cannot manually find that file, nor will it remove with Counterspy.

:unsure: Very worried, please help???

HJT Log…

Logfile of HijackThis v1.99.1
Scan saved at 5:29:20 PM, on 2/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\Smc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunThreatEngine.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunProtectionServer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Reon\My Documents\Storage\Anti-Spyware Apps\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\Smc.exe -startgui
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKCU\..\Run: [POP Peeper] "C:\Program Files\POP Peeper\POPPeeper.exe" -min
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O17 - HKLM\System\CCS\Services\Tcpip\..\{DB9D41A2-7174-4C47-BC6F-E4B2B7848866}: NameServer = 202.27.184.3,202.27.184.5
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\Smc.exe

Thank you very much for your time, and any advice you could give me.
Lets check to see if the rootkit is still active

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Download Gmer to your Desktop and unzip it to your Desktop.
http://www.gmer.net/gmer.zip

Disconnect from internet and close running programs.
There is a small chance this application may crash your computer so save any work you have open.
Double click gmer.exe.
Let the gmer.sys driver load if asked.
If it gives you a warning at program start about rootkit activity and asks if you want to run scan…say Ok.
If no warning….
Click the rootkit tab
To the right of the program you will see a bunch of boxes that have been checked… leave everything checked and uncheck the Registry box. Then click the Scan button. Wait for the scan to finish.
Once done click the Copy button.
Open Notepad and hit ctrl+v to paste the log. Save the log to your desktop please.

Click the >>> tab. This will open up all available tabs for you.
Click the Autostart tab then the scan button. Once its done click the Copy button.
Open Notepad and hit ctrl+v to paste the log. Save the log to your desktop please.

Post back with the GMER logs, the combofix log and a new HijackThis log
Thank you for your fast response. :D

Combofix… :huh:

"Reon" - 07-02-13 3:15:58 Service Pack 2
ComboFix 07-02-11 - Running from: "E:\Reon\Reget Downloads\reply 1 progs"

((((((((((((((((((((((((((((((( Files Created from 2007-01-13 to 2007-02-13 ))))))))))))))))))))))))))))))))))


2007-02-12 16:21 12,244,687 ——— C:\AVG7QT.DAT
2007-02-12 15:50 d——– C:\DOCUME~1\ALLUSE~1\Application Data\TEMP
2007-02-12 15:37 80 –a—— C:\WINDOWS\gmer_uninstall.cmd
2007-02-12 15:12 d——– C:\DOCUME~1\Reon\Application Data\Adobe
2007-02-12 15:11 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Adobe
2007-02-12 14:58 d——– C:\Program Files\Common Files\Adobe
2007-02-12 13:34 d——– C:\Program Files\POP Peeper
2007-02-12 13:34 d——– C:\DOCUME~1\Reon\Application Data\POP Peeper
2007-02-12 13:25 d——– C:\DOCUME~1\Reon\Application Data\DivX
2007-02-12 13:24 2,560 ——— C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-02-12 13:24 2,432 ——— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-02-12 13:24 129,784 ——— C:\WINDOWS\system32\pxafs.dll
2007-02-12 13:17 36,624 ——— C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-02-12 13:17 118,520 ——— C:\WINDOWS\system32\pxinsi64.exe
2007-02-12 13:17 116,472 ——— C:\WINDOWS\system32\pxcpyi64.exe
2007-02-12 13:17 d——– C:\Program Files\DivX
2007-02-12 12:28 d——– C:\Program Files\Windows Media Connect 2
2007-02-12 12:26 d——– C:\WINDOWS\system32\LogFiles
2007-02-12 12:26 d——– C:\WINDOWS\system32\drivers\UMDF
2007-02-12 12:12 d——– C:\DOCUME~1\Reon\Application Data\Lavasoft
2007-02-12 12:11 d——– C:\Program Files\Lavasoft
2007-02-12 08:44 d——– C:\Program Files\PokerStars
2007-02-12 08:10 d——– C:\Program Files\AC3Filter
2007-02-12 05:54 d——– C:\WINDOWS\Downloaded Installations
2007-02-12 05:54 d——– C:\Program Files\Sunbelt Software
2007-02-12 05:11 d——– C:\WINDOWS\WBEM
2007-02-12 05:11 d——– C:\WINDOWS\system32\en-US
2007-02-12 05:10 d–h-c— C:\WINDOWS\ie7
2007-02-12 05:09 121,856 ——— C:\WINDOWS\system32\xmllite.dll
2007-02-12 05:09 d——– C:\WINDOWS\network diagnostic
2007-02-12 05:08 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Windows Genuine Advantage
2007-02-12 04:32 d–hs—- C:\RECYCLER
2007-02-12 04:26 73,728 –a—— C:\WINDOWS\ALCFDRTM.EXE
2007-02-12 04:21 d——– C:\WINDOWS\Sun
2007-02-12 03:57 d——– C:\Program Files\Azureus
2007-02-12 03:57 d——– C:\DOCUME~1\Reon\Application Data\Azureus
2007-02-12 03:56 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2007-02-12 03:56 d–hs—- C:\DOCUME~1\Reon\UserData
2007-02-12 03:56 d–h—– C:\WINDOWS\$hf_mig$
2007-02-12 03:56 d——– C:\WINDOWS\system32\PreInstall
2007-02-12 03:51 18,432 –a—— C:\WINDOWS\system32\drivers\avgmfx86.sys
2007-02-12 03:46 839,936 –a—— C:\WINDOWS\system32\drivers\avg7core.sys
2007-02-12 03:46 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2007-02-12 03:46 4,960 –a—— C:\WINDOWS\system32\drivers\avgtdi.sys
2007-02-12 03:46 4,224 –a—— C:\WINDOWS\system32\drivers\avg7rsw.sys
2007-02-12 03:46 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2007-02-12 03:46 3,968 –a—— C:\WINDOWS\system32\drivers\avgclean.sys
2007-02-12 03:46 27,776 –a—— C:\WINDOWS\system32\drivers\avg7rsxp.sys
2007-02-12 03:46 d——– C:\Program Files\Grisoft
2007-02-12 03:46 d——– C:\DOCUME~1\Reon\Application Data\AVG7
2007-02-12 03:46 d——– C:\DOCUME~1\LOCALS~1\Application Data\AVG7
2007-02-12 03:46 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Grisoft
2007-02-12 03:46 d——– C:\DOCUME~1\ALLUSE~1\Application Data\avg7
2007-02-12 03:45 d——– C:\WINDOWS\system32\SoftwareDistribution
2007-02-12 03:41 86,800 –a—— C:\WINDOWS\system32\drivers\Teefer.sys
2007-02-12 03:41 86,016 –a—— C:\WINDOWS\system32\setaid.dll
2007-02-12 03:41 8,023 –a—— C:\WINDOWS\system32\drivers\wg3n.sys
2007-02-12 03:41 77,824 –a—— C:\WINDOWS\system32\SSSensor.dll
2007-02-12 03:41 58,536 –a—— C:\WINDOWS\system32\fwsvpn.dll
2007-02-12 03:41 15,360 –a—— C:\WINDOWS\system32\drivers\wpsdrvnt.sys
2007-02-12 03:41 d——– C:\Program Files\Sygate
2007-02-12 03:38 29,603 –a—— C:\WINDOWS\system32\drivers\glauiad.sys
2007-02-12 03:38 d——– C:\Program Files\D-Link
2007-02-12 03:28 d——– C:\WINDOWS\system32\Lang
2007-02-12 03:27 262,144 –a—— C:\DOCUME~1\ALLUSE~1\NTUSER.DAT
2007-02-12 03:27 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2007-02-12 03:27 1,572,864 –ah—– C:\DOCUME~1\Reon\NTUSER.DAT
2007-02-12 03:27 d——– C:\DOCUME~1\Reon\Application Data\Sun
2007-02-12 03:27 d——– C:\DOCUME~1\DEFAUL~1\Application Data\Sun
2007-02-12 03:23 d–hs—- C:\Recycled
2007-02-12 03:22 dr-hs—- C:\cmdcons
2007-02-12 03:21 82,944 –a—— C:\WINDOWS\system32\drivers\wdmaud.sys
2007-02-12 03:21 7,552 –a—— C:\WINDOWS\system32\drivers\MSKSSRV.sys
2007-02-12 03:21 60,800 –a—— C:\WINDOWS\system32\drivers\sysaudio.sys
2007-02-12 03:21 6,400 –a—— C:\WINDOWS\system32\drivers\splitter.sys
2007-02-12 03:21 54,272 –a—— C:\WINDOWS\system32\drivers\swmidi.sys
2007-02-12 03:21 52,864 –a—— C:\WINDOWS\system32\drivers\DMusic.sys
2007-02-12 03:21 516,096 –a—— C:\WINDOWS\system32\ati2sgag.exe
2007-02-12 03:21 5,376 –a—— C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2007-02-12 03:21 4,992 –a—— C:\WINDOWS\system32\drivers\MSPQM.sys
2007-02-12 03:21 2,944 –a—— C:\WINDOWS\system32\drivers\drmkaud.sys
2007-02-12 03:21 172,416 –a—— C:\WINDOWS\system32\drivers\kmixer.sys
2007-02-12 03:21 142,464 –a—— C:\WINDOWS\system32\drivers\aec.sys
2007-02-12 03:21 d——– C:\Program Files\Java
2007-02-12 03:21 d——– C:\Program Files\Common Files\Java
2007-02-12 03:21 d——– C:\Program Files\ATI Technologies
2007-02-12 03:20 60,288 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2007-02-12 03:20 4,096 –a—— C:\WINDOWS\system32\ksuser.dll
2007-02-12 03:19 9,730,560 –a—— C:\WINDOWS\RTLCPL.EXE
2007-02-12 03:19 8,376,832 –a—— C:\WINDOWS\RTHDCPL.exe
2007-02-12 03:19 77,824 –a—— C:\WINDOWS\SoundMan.exe
2007-02-12 03:19 57,344 –a—— C:\WINDOWS\ALCMTR.EXE
2007-02-12 03:19 40,448 –a—— C:\WINDOWS\system32\ChCfg.exe
2007-02-12 03:19 2,557,952 –a—— C:\WINDOWS\ALCWZRD.EXE
2007-02-12 03:19 2,257,920 –a—— C:\WINDOWS\system32\drivers\RtkHDAud.sys
2007-02-12 03:19 192,512 –a—— C:\WINDOWS\system32\RTCOMDLL.dll
2007-02-12 03:19 156,160 –a—— C:\WINDOWS\system32\RtlCPAPI.dll
2007-02-12 03:19 d–h—– C:\Program Files\InstallShield Installation Information
2007-02-12 03:19 d——– C:\Program Files\Realtek
2007-02-12 03:19 d——– C:\Program Files\Common Files\InstallShield
2007-02-11 15:12 d–h—– C:\WINDOWS\I386
2007-02-11 14:58 d–h—– C:\DIVTOOLS
2007-02-11 14:58 d——– C:\APPS
2007-02-11 14:57 d–hs—- C:\DRIVERS
2007-02-11 14:57 d–h—– C:\PNP
2007-02-11 14:18 dr–s—- C:\WINDOWS\assembly
2007-02-11 14:18 d——– C:\WINDOWS\system32\URTTemp
2007-02-11 14:18 d——– C:\WINDOWS\Microsoft.NET
2007-02-11 14:15 7,168 –a—— C:\WINDOWS\system32\hccoin.dll
2007-02-11 14:15 26,624 –a—— C:\WINDOWS\system32\drivers\usbehci.sys
2007-02-11 14:15 20,480 –a—— C:\WINDOWS\system32\drivers\usbuhci.sys
2007-02-11 14:14 61,440 –a—— C:\WINDOWS\SmCfg.exe
2007-02-11 14:14 61,056 –a—— C:\WINDOWS\system32\drivers\ohci1394.sys
2007-02-11 14:14 6,400 –a—— C:\WINDOWS\system32\drivers\enum1394.sys
2007-02-11 14:14 53,248 –a—— C:\WINDOWS\system32\drivers\1394bus.sys
2007-02-11 14:14 475,136 –a—— C:\WINDOWS\system32\SLLights.dll
2007-02-11 14:14 376,832 –a—— C:\WINDOWS\system32\slmh.exe
2007-02-11 14:14 167,936 –a—— C:\WINDOWS\system32\minirec.exe
2007-02-11 14:14 155,648 –a—— C:\WINDOWS\system32\amr_cpl.dll
2007-02-11 14:14 14,976 –a—— C:\WINDOWS\system32\drivers\winddx.sys
2007-02-11 14:14 135,168 –a—— C:\WINDOWS\system32\SLMOHServ.dll
2007-02-11 14:14 13,776 –a—— C:\WINDOWS\system32\drivers\recagent.sys
2007-02-11 14:14 d——– C:\WINDOWS\Modio
2007-02-01 17:56 823,296 –a—— C:\WINDOWS\system32\divx_xx0c.dll
2007-02-01 17:56 823,296 –a—— C:\WINDOWS\system32\divx_xx07.dll
2007-02-01 17:56 802,816 –a—— C:\WINDOWS\system32\divx_xx11.dll
2007-02-01 17:56 639,066 –a—— C:\WINDOWS\system32\DivX.dll
2007-02-01 10:27 524,288 –a—— C:\WINDOWS\system32\DivXsm.exe
2007-01-31 12:15 118,784 –a—— C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2007-01-30 17:56 53,248 –a—— C:\WINDOWS\system32\dpuGUI10.dll
2007-01-30 17:56 344,064 –a—— C:\WINDOWS\system32\dpus11.dll
2007-01-30 17:56 294,912 –a—— C:\WINDOWS\system32\dpu10.dll
2007-01-30 17:56 196,608 –a—— C:\WINDOWS\system32\dtu100.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-02-12 12:42 ——– d——– C:\Program Files\messenger
2007-02-12 05:15 359808 –a—— C:\WINDOWS\system32\drivers\TCPIP.SYS
2007-02-12 03:57 ——– d—s—- C:\DOCUME~1\Reon\Application Data\microsoft
2007-02-12 03:56 ——– d——– C:\DOCUME~1\Reon\Application Data\macromedia
2007-01-30 18:03 3596288 –a—— C:\WINDOWS\system32\qt-dx331.dll
2007-01-30 18:03 200704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-01-30 18:03 1044480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-01-30 17:56 73728 –a—— C:\WINDOWS\system32\dpl100.dll
2007-01-30 17:56 593920 –a—— C:\WINDOWS\system32\dpugui11.dll
2007-01-30 17:56 57344 –a—— C:\WINDOWS\system32\dpv11.dll
2007-01-30 17:56 294912 –a—— C:\WINDOWS\system32\dpu11.dll
2006-12-13 05:24 12288 –a—— C:\WINDOWS\system32\divxwmpexttype.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"AWMON"="\"C:\\PROGRA~1\\Lavasoft\\AD-AWA~1\\Ad-Watch.exe\""
"POP Peeper"="\"C:\\Program Files\\POP Peeper\\POPPeeper.exe\" -min"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
"PHIME2002ASync"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC"
"PHIME2002A"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName"
"SoundMan"="SOUNDMAN.EXE"
"AlcWzrd"="ALCWZRD.EXE"
"Alcmtr"="ALCMTR.EXE"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\Smc.exe -startgui"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"SunServer"="C:\\Program Files\\Sunbelt Software\\CounterSpy\\Consumer\\sunserver.exe"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{076394AD-7FDD-44EF-A075-32C68DBAB99B}"=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Registration reminder 2.job
C:\WINDOWS\tasks\Registration reminder 3.job


********************************************************************

catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes …

scanning hidden services …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-02-13 3:17:06

gmer rootkit scan… <_<

GMER 1.0.12.12027 - http://www.gmer.net
Rootkit scan 2007-02-13 03:29:13
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.12 —-

SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys ZwCreateThread
SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys ZwMapViewOfSection
SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys ZwTerminateProcess

—- Kernel code sections - GMER 1.0.12 —-

.text tcpip.sys!IPTransmit + 10BC EEB21CFA 6 Bytes CALL F7358490 Teefer.sys
.text tcpip.sys!IPTransmit + 2810 EEB2344E 6 Bytes CALL F7358490 Teefer.sys
.text tcpip.sys!ARPRcv + 506D EEB284E0 6 Bytes CALL F7358490 Teefer.sys
.text wanarp.sys F77DA3FD 4 Bytes CALL F73585B4 Teefer.sys
.text wanarp.sys F77DA402 2 Bytes [ 90, 90 ]

—- Devices - GMER 1.0.12 —-

Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [F795F2F0] wpsdrvnt.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [F795F510] wpsdrvnt.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [F795F600] wpsdrvnt.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [F7BB185A] avgtdi.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [F795F2F0] wpsdrvnt.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [F795F510] wpsdrvnt.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [F795F600] wpsdrvnt.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [F7BB185A] avgtdi.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [F795F2F0] wpsdrvnt.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE [F795F510] wpsdrvnt.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [F795F600] wpsdrvnt.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [F7BB185A] avgtdi.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [F795F2F0] wpsdrvnt.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE [F795F510] wpsdrvnt.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL [F795F600] wpsdrvnt.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [F7BB185A] avgtdi.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE [F795F2F0] wpsdrvnt.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSE [F795F510] wpsdrvnt.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL [F795F600] wpsdrvnt.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [F7BB185A] avgtdi.sys

—- EOF - GMER 1.0.12 —-


gmer autostart tab scan… :angry:

GMER 1.0.12.12027 - http://www.gmer.net
Autostart scan 2007-02-13 03:31:00
Windows 5.1.2600 Service Pack 2


HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = C:\WINDOWS\system32\userinit.exe,

HKLM\SYSTEM\CurrentControlSet\Services\ >>>
ATI Smart /*ATI Smart*/@ = C:\WINDOWS\system32\ati2sgag.exe
Avg7Alrt /*AVG7 Alert Manager Server*/@ = C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
Avg7UpdSvc /*AVG7 Update Service*/@ = C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
AVGEMS /*AVG E-mail Scanner*/@ = C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
SmcService /*Sygate Personal Firewall Pro*/@ = C:\Program Files\Sygate\SPF\Smc.exe
Spooler /*Print Spooler*/@ = %SystemRoot%\system32\spoolsv.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@IMJPMIG8.1"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 = "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
@PHIME2002ASyncC:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC = C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
@PHIME2002AC:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName = C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
@SoundManSOUNDMAN.EXE = SOUNDMAN.EXE
@AlcWzrdALCWZRD.EXE = ALCWZRD.EXE
@AlcmtrALCMTR.EXE = ALCMTR.EXE
@ATIPTAC:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe = C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
@SunJavaUpdateSched"C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" = "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
@SmcServiceC:\PROGRA~1\Sygate\SPF\Smc.exe -startgui = C:\PROGRA~1\Sygate\SPF\Smc.exe -startgui
@AVG7_CCC:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP = C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
@SunServerC:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe = C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@ctfmon.exeC:\WINDOWS\system32\ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
@AWMON"C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe" = "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
@POP Peeper"C:\Program Files\POP Peeper\POPPeeper.exe" -min = "C:\Program Files\POP Peeper\POPPeeper.exe" -min

HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad@WPDShServiceObj = C:\WINDOWS\system32\WPDShServiceObj.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks@{076394AD-7FDD-44EF-A075-32C68DBAB99B} = C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunExecuteHook.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Display Panning CPL Extension*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{30D02401-6A81-11d0-8274-00C04FD5AE38} /*IE Search Band*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} /*Shell DocObject Viewer*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FBF23B40-E3F0-101B-8488-00AA003E56F8} /*InternetShortcut*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3C374A40-BAE4-11CF-BF7D-00AA006946EE} /*Microsoft Url History Service*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FF393560-C2A7-11CF-BFF4-444553540000} /*History*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{7BD29E00-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{7BD29E01-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{CFBFAE00-17A6-11D0-99CB-00C04FD64497} /*Microsoft Url Search Hook*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3DC7A020-0ACD-11CF-A9BB-00AA004AE837} /*The Internet*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{871C5380-42A0-1069-A2EA-08002B30309D} /*Internet Name Space*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/C:\WINDOWS\system32\extmgr.dll = C:\WINDOWS\system32\extmgr.dll
@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} /*AVG7 Shell Extension*/C:\Program Files\Grisoft\AVG Free\avgse.dll = C:\Program Files\Grisoft\AVG Free\avgse.dll
@{9F97547E-460A-42C5-AE0C-81C61FFAEBC3} /*AVG7 Find Extension*/C:\Program Files\Grisoft\AVG Free\avgse.dll = C:\Program Files\Grisoft\AVG Free\avgse.dll
@{07C45BB1-4A8C-4642-A1F5-237E7215FF66} /*IE Microsoft BrowserBand*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{1C1EDB47-CE22-4bbb-B608-77B48F83C823} /*IE Fade Task*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{205D7A97-F16D-4691-86EF-F3075DCCA57D} /*IE Menu Desk Bar*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3028902F-6374-48b2-8DC6-9725E775B926} /*IE AutoComplete*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{43886CD5-6529-41c4-A707-7B3C92C05E68} /*IE Navigation Bar*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{44C76ECD-F7FA-411c-9929-1B77BA77F524} /*IE Menu Site*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{4B78D326-D922-44f9-AF2A-07805C2A3560} /*IE Menu Band*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6038EF75-ABFC-4e59-AB6F-12D397F6568D} /*IE Microsoft History AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE} /*IE Tracking Shell Menu*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6CF48EF8-44CD-45d2-8832-A16EA016311B} /*IE IShellFolderBand*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{73CFD649-CD48-4fd8-A272-2070EA56526B} /*IE BandProxy*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8} /*IE MRU AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E} /*IE RSS Feeder Folder*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{9D958C62-3954-4b44-8FAB-C4670C1DB4C2} /*IE Microsoft Shell Folder AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{B31C5FAE-961F-415b-BAF0-E697A5178B94} /*IE Microsoft Multiple AutoComplete List Container*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{BC476F4C-D9D7-4100-8D4E-E043F6DEC409} /*Microsoft Browser Architecture*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A} /*IE Shell Rebar BandSite*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{E6EE9AAC-F76B-4947-8260-A9F136138E11} /*IE Shell Band Site Menu*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{F2CF5485-4E02-4f68-819C-B92DE9277049} /*&Links*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E} /*IE Registry Tree Options Utility*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} /*IE User Assist*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FDE7673D-2E19-4145-8376-BBD58C4BC7BA} /*IE Custom MRU AutoCompleted List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{35786D3C-B075-49b9-88DD-029876E11C01} /*Portable Devices*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} /*Portable Devices Menu*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\AVG7 Shell Extension@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\AVG7 Shell Extension@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll = C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll = C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll

HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://go.microsoft.com/fwlink/?LinkId=69157 = http://go.microsoft.com/fwlink/?LinkId=69157
@Start Pagehttp://go.microsoft.com/fwlink/?LinkId=69157 = http://go.microsoft.com/fwlink/?LinkId=69157
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm

HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://www.google.com/ = http://www.google.com/
@Local PageC:\WINDOWS\system32\blank.htm = C:\WINDOWS\system32\blank.htm

HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
its@CLSID = C:\WINDOWS\system32\itss.dll
mhtml@CLSID = %SystemRoot%\system32\inetcomm.dll
ms-its@CLSID = C:\WINDOWS\system32\itss.dll
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
wia@CLSID = C:\WINDOWS\system32\wiascr.dll

HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DB9D41A2-7174-4C47-BC6F-E4B2B7848866} /*ihug Broadband*/ >>>
@IPAddress10.1.1.29 = 10.1.1.29
@NameServer202.27.184.3,202.27.184.5 = 202.27.184.3,202.27.184.5
@DefaultGateway10.1.1.2 = 10.1.1.2
@Domain =

C:\Documents and Settings\All Users\Start Menu\Programs\Startup >>>
Adobe Reader Speed Launch.lnk = Adobe Reader Speed Launch.lnk
Adobe Reader Synchronizer.lnk = Adobe Reader Synchronizer.lnk

—- EOF - GMER 1.0.12 —-


New HJT log… :huh:

Logfile of HijackThis v1.99.1
Scan saved at 3:34:03 AM, on 2/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\Smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunThreatEngine.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunProtectionServer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe
C:\Program Files\POP Peeper\POPPeeper.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Reon\My Documents\Storage\Anti-Spyware Apps\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\Smc.exe -startgui
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKCU\..\Run: [POP Peeper] "C:\Program Files\POP Peeper\POPPeeper.exe" -min
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O17 - HKLM\System\CCS\Services\Tcpip\..\{DB9D41A2-7174-4C47-BC6F-E4B2B7848866}: NameServer = 202.27.184.3,202.27.184.5
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\Smc.exe

:blink:
The rootkit does not appear to be active, lets remove the file

Copy/paste the following quote box into a new notepad (not wordpad) document. Make sure that wordwrap is turned off.

attrib -r -s -h C:\Windows\System32\lpt4.ago
del \\.\C:\Windows\System32\lpt4.ago


Save it to your Desktop as cleanup.bat. Save it as:
File Type: All Files (not as a text document or it wont work).
Name: cleanup.bat

Locate cleanup.bat on your Desktop and double-click it. A DOS window will open briefly and then close, this is normal

Let me know if that removes the file
Good new's… I think. :D I have since upgraded to CounterspyV2 and it didn't report that file at all (before I did the cleanup.bat thing). I have applied the .bat setting, and will monitor thing's closely. After the re-install, I don't have the hidden Admin account anymore, and my PC is behaving "normally", (lol do they ever?) Thank you so much for your help. It's good to have peace of mind. :)
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI