This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help?

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i get popups even when the internet isnt open





Logfile of HijackThis v1.99.1
Scan saved at 4:46:47 PM, on 4/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\WINDOWS\system32\v7.exe
C:\WINDOWS\system32\adirka.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
c:\program files\internet explorer\iexplore.exe
C:\Documents and Settings\chad1\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Shell Doc Object and Control Helper Class - {00009E9F-DDD7-AA59-AA7D-AA4B7D6BE000} - C:\WINDOWS\system32\shdocvs.dll
O2 - BHO: Shell Browser Object Class - {00534B55-3155-CA4F-B41D-0E922121D03C} - C:\WINDOWS\system32\browsemu.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - C:\WINDOWS\system32\tmp1.tmp.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {9dba956d-17cf-4be2-9aae-c2355b98e95c} - C:\WINDOWS\system32\kbdext.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\mliijh.dll",setvm
O4 - HKLM\..\Run: [VaCtrls] v7
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
O4 - HKLM\..\Run: [sysinter] C:\WINDOWS\system32\adirss.exe
O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\system32\rpcc.exe
O4 - HKLM\..\Run: [winctl] winctl.exe /install
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [adirka] C:\WINDOWS\system32\adirka.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'rsvp32_2.dll' missing
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - AppInit_DLLs:
O20 - Winlogon Notify: kbdext - C:\WINDOWS\SYSTEM32\kbdext.dll
O21 - SSODL: DCOM Server 20509 - {2C1CD3D7-86AC-4068-93BC-A02304B20509} - C:\WINDOWS\system32\ukmr.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ieupdater22 (Microsoft IEUpdater22) - Unknown owner - C:\Documents and Settings\chad1\ie_updater.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Hi, welcome to tomCoyote!

You have a nasty keylogger in your system.

You are strongly advised to do the following immediately:

1. Disconnect infected computer from the internet and from any networked computers until the computer can be cleaned.

2. Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.

3. From a clean computer, change *all* your online passwords – for ISP login, email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.

Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passords and transaction information.


*
Download haxfix.exe
and save it to your desktop.
  • Double click on haxfix.exe to install haxfix. (standard installation path is c:\program Files\haxfix)
  • Checkmark "Create a desktop icon"
  • Click "Next"
  • When the installation is completed, make sure that the checkmark "Launch HaxFix" is placed
  • Click "Finish"
A red "dos window" (dos box) will open with options:
1. Make logfile
2. Run auto fix
3. Run manual fix
E. Exit Haxfix
  • Select option 1. Make logfile by typing 1 and then pressing Enter
  • Haxfix will start scanning the computer. When it is finished a logfile will open: haxlog.txt
  • Copy the contents of that logfile and paste it into this thread. (c:\haxfix.txt)
sorry to be a pain, just making sure….. so i can download that, then i disconnect from internet, do what was said then ill be ok?
That's ok. Just make sure you follow the first set of instructions (change passwords etc..) then download and run haxfix. I can't guarantee you anything as of now, your system is VERY infected with a lot of things and even nasty ones..I'll try my best for you :)
ok there it is HAXFIX logfile - by Marckie version 4.39 Tue 04/03/2007 22:45:28.01 — Checking for Haxdoor — checking for a3d files a3d files not found checking for matching notify keys matching notify keys found kbde checking for matching services no matching services found checking for matching safeboot services no matching safeboot services found checking for other Haxdoor-files no other Haxdoor-files found — Checking for Goldun — checking for SSODL keys no ssodl keys found checking for notify keys no notify keys found checking for services no services found checking for other Goldun-files no other Goldun-files found checking iexplore.exe iexplore.exe is not infected Finished!
i downloaded avast and it found 114 infected files. some in the keyboard program and some in the windows files. i really dont know what to do and im ready to throw my pc out the window lol.
Hi,

*Please download VundoFix.exe to your Desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES.
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.



*Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log

*Please download FindAWF by noahdfear and save it to your desktop:
  • Please double-click FindAWF.exe to run it.
  • If a security alert shows, allow the program to run.
  • When the tool has completed, a report will open in Notepad.
  • Please post the results of the awf.txt in your next reply.
On your next reply, please include a fresh HijackThis log, vundofix log, sdfix log and the awf.txt
hijackthis….
Logfile of HijackThis v1.99.1
Scan saved at 10:04:08 AM, on 4/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
C:\WINDOWS\system32\v7.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\clcl3.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\WINDOWS\system32\wuauclt.exe
c:\program files\internet explorer\iexplore.exe
C:\Documents and Settings\chad1\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7EADEE2A-49EE-4A7F-AA95-3463611DD56D} - C:\WINDOWS\system32\ddaby.dll (file missing)
O2 - BHO: BHO - {9BB5B49C-0D59-418d-A6A5-F6373B8FEF64} - C:\Program Files\BHO Plugin\plugin1.dll
O2 - BHO: (no name) - {9dba956d-17cf-4be2-9aae-c2355b98e95c} - C:\WINDOWS\system32\kbdext.dll (file missing)
O2 - BHO: (no name) - {B9697716-61E6-4FBC-89FD-EAC504D9EFE3} - C:\WINDOWS\system32\wvusstu.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [VaCtrls] v7
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\system32\rpcc.exe
O4 - HKLM\..\Run: [winctl] winctl.exe /install
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\pmlihe.dll",setvm
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [clcl3] C:\WINDOWS\system32\clcl3.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O21 - SSODL: DCOM Server 20509 - {2C1CD3D7-86AC-4068-93BC-A02304B20509} - C:\WINDOWS\system32\ukmr.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

vundo…..
VundoFix V6.3.19

Checking Java version…

Java version is 1.5.0.11

Scan started at 9:39:15 AM 4/6/2007

Listing files found while scanning….

C:\WINDOWS\system32\ddaby.dll
C:\WINDOWS\system32\kbdext.dll
C:\WINDOWS\system32\tmpB.tmp.dll
C:\WINDOWS\system32\wvusstu.dll
C:\WINDOWS\system32\ybadd.bak1
C:\WINDOWS\system32\ybadd.ini

Beginning removal…

Attempting to delete C:\WINDOWS\system32\ddaby.dll
C:\WINDOWS\system32\ddaby.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\kbdext.dll
C:\WINDOWS\system32\kbdext.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tmpB.tmp.dll
C:\WINDOWS\system32\tmpB.tmp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wvusstu.dll
C:\WINDOWS\system32\wvusstu.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\ybadd.bak1
C:\WINDOWS\system32\ybadd.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\ybadd.ini
C:\WINDOWS\system32\ybadd.ini Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.3.19

Checking Java version…

Java version is 1.5.0.11

Scan started at 9:44:56 AM 4/6/2007

Listing files found while scanning….

C:\WINDOWS\system32\wvusstu.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\wvusstu.dll
C:\WINDOWS\system32\wvusstu.dll Has been deleted!

Performing Repairs to the registry.
Done!

SD……

SDFix: Version 1.77

Run by [removed]
Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix\SDFix

Safe Mode:
Checking Services:

Name:
Client IP-IPX
Microsoft IEUpdater22
Runtime
TCP and UDP Supp0rt

ImagePath:
"C:\WINDOWS\system32\svchosts.exe" -e mc-110-12-0000501
C:\Documents and Settings\chad1\ie_updater.exe /start
\??\C:\WINDOWS\System32\drivers\runtime.sys
C:\WINDOWS\system32\tccpip.exe /winnt

Client IP-IPX - Deleted
Microsoft IEUpdater22 - Deleted
Runtime - Deleted
TCP and UDP Supp0rt - Deleted



Restoring Windows Registry Values
Restoring Windows Default Hosts File


Rebooting…

Normal Mode:
Checking Files:

Below files will be copied to Backups folder then removed:

C:\WINDOWS\SYSTEM32\PFB0E0~1.DLL - Deleted
C:\WINDOWS\SYSTEM32\PFCA7F~1.DLL - Deleted
C:\WINDOWS\SYSTEM32\SFXZMT~1.DLL - Deleted
C:\WINDOWS\SYSTEM32\SFXZMT~2.DLL - Deleted
C:\WINDOWS\SYSTEM32\SFXZMT~3.DLL - Deleted
C:\WINDOWS\SYSTEM32\SFXZMT~4.DLL - Deleted
C:\WINDOWS\SYSTEM32\MSDTC_32.EXE - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun1.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun2.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun4.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun5.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun6.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun1.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun10.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun11.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun12.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun2.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun3.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun4.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun7.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun8.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun9.exe - Deleted
C:\WINDOWS\Temp\stdrun1.exe - Deleted
C:\WINDOWS\Temp\stdrun2.exe - Deleted
C:\WINDOWS\Temp\stdrun4.exe - Deleted
C:\WINDOWS\Temp\stdrun5.exe - Deleted
C:\WINDOWS\Temp\stdrun6.exe - Deleted
C:\WINDOWS\system32\ma.exe.exe - Deleted
C:\WINDOWS\system32\pep.exe.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp1.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp12.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp13.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp14.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp15.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp17.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp1C.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp1D.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp1E.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp1F.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp2.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp25.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp2E.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp3.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp35.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp4.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp4A.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp4D.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp5.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp57.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp59.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp6.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp63.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp64.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp71.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp8.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmp9E.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmpA.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmpB.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmpC.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmpD83.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmpD84.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmpD85.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmpD86.tmp.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\tmpF.tmp.exe - Deleted
C:\Documents and Settings\chad1\ie_updater.exe - Deleted
C:\DOCUME~1\chad1\LOCALS~1\Temp\abc123.pid - Deleted
C:\svhost.exe - Deleted
C:\WINDOWS\lcass.exe - Deleted
C:\WINDOWS\system32\adirka.exe - Deleted
C:\WINDOWS\system32\cmnocfg.xml - Deleted
C:\WINDOWS\system32\comcbx2.dll - Deleted
C:\WINDOWS\system32\comcs32c.dll - Deleted
C:\WINDOWS\system32\commnet8.dll - Deleted
C:\WINDOWS\system32\defrasw.dll - Deleted
C:\WINDOWS\system32\dsuiexq.dll - Deleted
C:\WINDOWS\system32\hnetviw.dll - Deleted
C:\WINDOWS\system32\ldinfo.ldr - Deleted
C:\WINDOWS\system32\rpcc.exe - Deleted
C:\WINDOWS\system32\srvswc2.dll - Deleted
C:\WINDOWS\system32\srvswc3.dll - Deleted
C:\WINDOWS\system32\svehost.exe - Deleted
C:\WINDOWS\system32\unsvchosts.exe - Deleted
C:\WINDOWS\system32\wincom32.ini - Deleted
C:\WINDOWS\Temp\kaw - Deleted



ADS Check:

Checking if ADS is attached to system32 Folder
C:\WINDOWS\system32
No streams found.

Checking if ADS is attached to svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.



Final Check:

Remaining Services:
——————


Rootkit PE386 Active, Use a Rootkit scanner !

Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\mIRC\\mirc.exe"="C:\\Program Files\\mIRC\\mirc.exe:*:Enabled:mIRC"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\WINDOWS\\system32\\smt.exe"="C:\\WINDOWS\\system32\\smt.exe:*:Enabled:enable"
"%windir%\\system32\\tcpip.exe"="%windir%\\system32\\tcpip.exe:*:Enabled:TCP and UDP Support"


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"


Remaining Files:
—————

Backups Folder: - C:\SDFix\SDFix\backups\backups.zip

Checking For Files with Hidden Attributes:

C:\WINDOWS\system32\win_w72.exe
C:\NTBOOTDD.SYS

Finished


AWF….

Find AWF report by noahdfear ©2006


bak folders found
~~~~~~~~~~~


Directory of C:\PROGRA~1\MESSEN~1\BAK

08/04/2004 02:06 AM 1,667,584 msmsgs.exe
1 File(s) 1,667,584 bytes

Directory of C:\WINDOWS\SYSTEM32\BAK

04/03/2007 09:24 AM 72,831 adirka.exe
04/03/2007 09:25 AM 7,295 adirss.exe
04/05/2007 07:43 PM 24,076 lsasss.exe
07/09/2001 11:50 AM 155,648 NeroCheck.exe
4 File(s) 259,850 bytes

Directory of C:\PROGRA~1\ALWILS~1\AVAST4\BAK

01/15/2007 12:28 PM 108,160 ashDisp.exe
1 File(s) 108,160 bytes

Directory of C:\PROGRA~1\GRISOFT\AVGANT~1.5\BAK

10/07/2006 08:20 AM 6,266,880 avgas.exe
1 File(s) 6,266,880 bytes

Directory of C:\PROGRA~1\NETROPA\MULTIM~1\BAK

11/29/2000 01:10 AM 135,168 MMKeybd.exe
1 File(s) 135,168 bytes

Directory of C:\PROGRA~1\YAHOO!\MESSEN~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\ZONELA~1\ZONEAL~1\BAK

07/18/2005 12:21 AM 980,752 zlclient.exe
1 File(s) 980,752 bytes

Directory of C:\PROGRA~1\COMMON~1\AHEAD\LIB\BAK

01/12/2006 04:40 PM 155,648 NeroCheck.exe
12/16/2005 01:57 PM 94,208 NMBgMonitor.exe
2 File(s) 249,856 bytes

Directory of C:\PROGRA~1\JAVA\JRE15~1.0_1\BIN\BAK

12/15/2006 04:23 AM 75,520 jusched.exe
1 File(s) 75,520 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

1667584 Aug 4 2004 "C:\Program Files\Messenger\bak\msmsgs.exe"
72831 Apr 3 2007 "C:\WINDOWS\system32\bak\adirka.exe"
7295 Apr 3 2007 "C:\WINDOWS\system32\bak\adirss.exe"
24076 Apr 5 2007 "C:\WINDOWS\system32\lsasss.exe"
24076 Apr 5 2007 "C:\WINDOWS\system32\bak\lsasss.exe"
155648 Jul 9 2001 "C:\WINDOWS\system32\bak\NeroCheck.exe"
24076 Apr 5 2007 "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
155648 Jan 12 2006 "C:\Program Files\Common Files\Ahead\Lib\bak\NeroCheck.exe"
108160 Jan 15 2007 "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
108160 Jan 15 2007 "C:\Program Files\Alwil Software\Avast4\bak\ashDisp.exe"
6266880 Oct 7 2006 "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\bak\avgas.exe"
24076 Apr 5 2007 "C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe"
135168 Nov 29 2000 "C:\Program Files\Netropa\Multimedia Keyboard\bak\MMKeybd.exe"
980752 Jul 18 2005 "C:\Program Files\Zone Labs\ZoneAlarm\bak\zlclient.exe"
155648 Jul 9 2001 "C:\WINDOWS\system32\bak\NeroCheck.exe"
24076 Apr 5 2007 "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
155648 Jan 12 2006 "C:\Program Files\Common Files\Ahead\Lib\bak\NeroCheck.exe"
94208 Dec 16 2005 "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe1174713820"
94208 Dec 16 2005 "C:\Program Files\Common Files\Ahead\Lib\bak\NMBgMonitor.exe"
24076 Apr 5 2007 "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
75520 Dec 15 2006 "C:\Program Files\Java\jre1.5.0_11\bin\bak\jusched.exe"


end of report
Download Rustbfix from one of these locations:
http://www.uploads.ejvindh.net/rustbfix.exe
http://uploads.ejvindh.andymanchesta.com/Rustbfix.exe
…and save it to your desktop.

Double click on rustbfix.exe to run the tool. If a Rustock.b-infection is found, you will shortly hereafter be asked to reboot the computer. The reboot will probably take quite a while, and perhaps 2 reboots will be needed. But this will happen automatically. After the reboot 2 logfiles will open (%root%\avenger.txt & %root%\rustbfix\pelog.txt). Post the content of these logfiles along with a new HijackThis log.
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\efwsmfdu

*******************

Script file located at: \??\C:\Program Files\ppsynslb.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Driver PE386 unloaded successfully.
Program C:\Rustbfix\2run.bat successfully set up to run once on reboot.

Completed script processing.

*******************

Finished! Terminate.





Logfile of HijackThis v1.99.1
Scan saved at 12:10:09 PM, on 4/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\WINDOWS\system32\v7.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\clcl3.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\Program Files\Netropa\Multimedia Keyboard\bak\MMKeybd.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\chad1\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7EADEE2A-49EE-4A7F-AA95-3463611DD56D} - C:\WINDOWS\system32\ddaby.dll (file missing)
O2 - BHO: BHO - {9BB5B49C-0D59-418d-A6A5-F6373B8FEF64} - C:\Program Files\BHO Plugin\plugin1.dll
O2 - BHO: (no name) - {9dba956d-17cf-4be2-9aae-c2355b98e95c} - C:\WINDOWS\system32\kbdext.dll (file missing)
O2 - BHO: (no name) - {B9697716-61E6-4FBC-89FD-EAC504D9EFE3} - C:\WINDOWS\system32\wvusstu.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [VaCtrls] v7
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\system32\rpcc.exe
O4 - HKLM\..\Run: [winctl] winctl.exe /install
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\pmlihe.dll",setvm
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [clcl3] C:\WINDOWS\system32\clcl3.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O21 - SSODL: DCOM Server 20509 - {2C1CD3D7-86AC-4068-93BC-A02304B20509} - C:\WINDOWS\system32\ukmr.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Hi,

*Uninstall the item in bold if found:

BHO Plugin


*An optional that I would recommend be uninstalled.

Azureus
This program is very likely the reason your system is infested with malware. Even when a program like this is not infected itself, it will still bring malware into your system because more than half of all files available for download from peer-to-peer networks have been deliberately infected with some form of malware. I recommend that you remove this program from your system.

*Click Start > Control Panel > Add or Remove Programs and uninstall the items I listed in bold if found.

*Reboot
___________________

*Please download DelDomains by WinHelp2002 and save it to your desktop:
  • Right-click on DelDomains.inf, and choose Install.
  • You may not see any noticeable changes or prompts; this is normal.
  • Then, please restart your computer, and post a new HijackThis log.
  • You will have to re-immunize with SpywareBlaster, IE-SPYAD, and/or Spybot - Search & Destroy after doing this.
*Please download ResetProtocolDefaults by WinHelp2002 and save it to your desktop:
  • Locate ResetProtocolDefaults.reg which should be on your desktop.
  • Right-click and select: Merge.
  • OK the prompt.
*Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

Do not use it et.


*Download ATF Cleaner by Atribune

Do not use it yet.
___________________

*Open HijackThis > choose Scan Only > Place a checkmark in the boxes beside these entries in bold.

O2 - BHO: (no name) - {7EADEE2A-49EE-4A7F-AA95-3463611DD56D} - C:\WINDOWS\system32\ddaby.dll (file missing)
O2 - BHO: BHO - {9BB5B49C-0D59-418d-A6A5-F6373B8FEF64} - C:\Program Files\BHO Plugin\plugin1.dll
O2 - BHO: (no name) - {9dba956d-17cf-4be2-9aae-c2355b98e95c} - C:\WINDOWS\system32\kbdext.dll (file missing)
O2 - BHO: (no name) - {B9697716-61E6-4FBC-89FD-EAC504D9EFE3} - C:\WINDOWS\system32\wvusstu.dll (file missing)
O4 - HKLM\..\Run: [VaCtrls] v7
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\system32\rpcc.exe
O4 - HKLM\..\Run: [winctl] winctl.exe /install
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\pmlihe.dll",setvm
O4 - HKLM\..\Run: [clcl3] C:\WINDOWS\system32\clcl3.exe
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O21 - SSODL: DCOM Server 20509 - {2C1CD3D7-86AC-4068-93BC-A02304B20509} - C:\WINDOWS\system32\ukmr.dll (file missing)


Close your browsers and all open windows except for HijackThis, then click "Fix checked". Exit HijackThis.
_____________________

You may want to print these instructions here or save them in notepad since you'll work offline.

Reboot into Safe Mode.

To enter Safe Mode..

Click Start > Turn Off Computer > Restart > Tap F8 key just before Windows starts to load, > This will bring up a Menu > Use your keyboard to scroll to Safe Mode> Hit enter.


*Configure your machine to view hidden files:

Windows XP
  • Click Start.
  • Open My Computer..
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the "Hidden files and folders" heading select Show hidden files and folders.
  • Uncheck the Hide Protected Operating System Files Option.
  • Click Yes to confirm.
  • Click OK.
*Using Windows Explorer, find and delete these files:

C:\WINDOWS\system32\lsasss.exe<< There is a legit file called lsass.exe in the same folder, please be very careful in deleting that file.
C:\WINDOWS\system32\rpcc.exe
C:\WINDOWS\pmlihe.dll
C:\WINDOWS\system32\clcl3.exe
c:\windows\system32\ldcore.dll
c:\windows\system32\v7.exe
C:\WINDOWS\system32\smt.exe

*Delete the following folder:

C:\Program Files\BHO Plugin

*Delete the following folerd iyou uninstalled Azureus:

C:\Program Files\Azureus

*Click Start > Search > Click "All Files and Folders".
Under "Advanced Options", make sure the following are checked:
  • Search System Folders.
  • Search Hidden Files And Folders.
  • Search Subfolders.
Then into the search box, copy and paste the following (one at a time):

winctl.exe

Then, click Search after you copy and paste each of those. After that, delete all instances of those files.

Empty your recycle bin.
__________________

*Open notepad.
Copy and paste the text inside the Code Box below into Notepad
Choose File > Save As and under "Save as type", choose "All Files".
Type fix.reg in the File name and save it to your desktop.

REGEDIT4

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\smt.exe"=-



Make sure there are NO blank lines before REGEDIT4
Make sure there IS one blank line at the end of the file.

Close notepad. Make sure that all windows are closed.

Find the fix.reg file on your desktop.
Double click it.
It will then ask if you want the file merged to your registry.
Answer Yes.

*Open notepad.
Copy and paste the text inside the Code Box below into Notepad
Choose File > Save As and under "Save as type", choose "All Files".
Type restore.bat in the File name and save it to your desktop.

if exist "C:\Program Files\Messenger\msmsgs.exe" del /q "C:\Program Files\Messenger\msmsgs.exe"
copy /y "C:\Program Files\Messenger\bak\msmsgs.exe" "C:\Program Files\Messenger"

if exist "C:\WINDOWS\system32\NeroCheck.exe" del /q "C:\WINDOWS\system32\NeroCheck.exe"
copy /y "C:\WINDOWS\system32\bak\NeroCheck.exe" "C:\WINDOWS\system32"

if exist "C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe" del /q "C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe"
copy /y "C:\Program Files\Netropa\Multimedia Keyboard\bak\MMKeybd.exe" "C:\Program Files\Netropa\Multimedia Keyboard"

if exist "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" del /q "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
copy /y "C:\Program Files\Zone Labs\ZoneAlarm\bak\zlclient.exe" "C:\Program Files\Zone Labs\ZoneAlarm"

if exist "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" del /q "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe"
copy /y "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\bak\avgas.exe" "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5"

if exist "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" del /q "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
copy /y "C:\Program Files\Common Files\Ahead\Lib\bak\NeroCheck.exe" "C:\Program Files\Common Files\Ahead\Lib"

if exist "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" del /q "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
copy /y "C:\Program Files\Java\jre1.5.0_11\bin\bak\jusched.exe" "C:\Program Files\Java\jre1.5.0_11\bin"

Double click restore.bat then please run FindAWF again to make sure nothing is left.
_______________________

*Important: Make sure all your browsers are closed before running ATF Cleaner..
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose:Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click
  • No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE:If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

*Cureit Scan
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, Click Options > Change settings
  • Choose the "Scan"-tab, remove the mark at "Heuristic analysis".
  • Back at the main window, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found:
    [external image: Posted Image]
    If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    [external image: Posted Image]
    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply
*I would like you to scan a few files for me.

Please go HERE. Click browse then, navigate to this file:

C:\WINDOWS\system32\win_w72.exe

Then click submit.

Please post the results to your next reply.

If Jotti is too busy, you can go HERE and do the same as above.

On your next reply, please include a fresh HijackThis log, Cureit log, awf.txt, results of the jotti scan and a description on how is your machine running.
Logfile of HijackThis v1.99.1
Scan saved at 7:27:12 PM, on 4/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\chad1\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [winctl] winctl.exe /install
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe



Curit

Update.exe;C:\Program Files\Common Files\{8876635D-096C-1033-1102-040326030001};Trojan.DownLoader.19850;Deleted.;
Update.exe;C:\Program Files\Common Files\{8876635D-096D-1033-1102-040326030001};Trojan.DownLoader.19850;Deleted.;
Process.exe;C:\SDFix\SDFix\apps;Tool.Prockill;;
A0019243.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP30;Trojan.Packed.75;Deleted.;
A0019244.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP30;Trojan.Packed.75;Deleted.;
A0019245.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP30;Trojan.Packed.75;Deleted.;
A0020247.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP30;Trojan.Packed.75;Deleted.;
A0022273.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP30;Trojan.Proxy.1727;Deleted.;
A0022284.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP30;Trojan.Packed.75;Deleted.;
A0022312.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP30;Trojan.Proxy.1727;Deleted.;
A0023309.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP30;Trojan.Proxy.1727;Deleted.;
A0023327.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP30;Trojan.Proxy.1727;Deleted.;
A0023346.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP30;Trojan.Proxy.1727;Deleted.;
A0024344.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP30;Trojan.Proxy.1727;Deleted.;
A0025346.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP31;Trojan.Proxy.1727;Deleted.;
A0025359.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP31;Trojan.Proxy.1727;Deleted.;
A0026360.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP32;Trojan.Proxy.1727;Deleted.;
A0027360.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP32;Trojan.Proxy.1727;Deleted.;
A0028360.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP32;Trojan.Proxy.1727;Deleted.;
A0028388.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP32;Trojan.Proxy.1727;Deleted.;
A0028428.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP32;Tool.Prockill;;
A0028470.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP32;Trojan.DownLoader.10588;Deleted.;
A0028471.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP32;Trojan.DownLoader.19701;Deleted.;
A0028472.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP32;Trojan.DownLoader.19701;Deleted.;
A0028473.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP32;Trojan.Virtumod;Deleted.;
A0028474.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP32;Trojan.DownLoader.19701;Deleted.;
A0028476.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP32;Trojan.MulDrop.5862;Deleted.;
A0028477.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP32;Trojan.Click.1888;Deleted.;
A0028478.sys;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP32;BackDoor.Groan;Deleted.;
A0028479.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP32;Trojan.DownLoader.14310;Deleted.;
A0028480.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP32;Trojan.Packed.75;Deleted.;
A0028488.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP32;Trojan.Proxy.1727;Deleted.;
A0028522.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Virtumod;Deleted.;
A0028531.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Virtumod;Deleted.;
A0028537.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Proxy.1727;Deleted.;
A0028553.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.75;Deleted.;
A0028554.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.75;Deleted.;
A0028558.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.75;Deleted.;
A0028568.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Probably BACKDOOR.Trojan;;
A0028576.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.75;Deleted.;
A0028585.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.75;Deleted.;
A0028587.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.75;Deleted.;
A0028609.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Probably BACKDOOR.Trojan;;
A0028611.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028612.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.DownLoader.19433;Deleted.;
A0028613.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.DownLoader.19433;Deleted.;
A0028614.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028615.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028616.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.DownLoader.19433;Deleted.;
A0028617.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.DownLoader.19433;Deleted.;
A0028618.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028619.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028620.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028621.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.DownLoader.19433;Deleted.;
A0028622.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.DownLoader.19433;Deleted.;
A0028623.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.DownLoader.19433;Deleted.;
A0028624.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028625.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028626.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028627.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.DownLoader.19433;Deleted.;
A0028628.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028629.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028630.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028631.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028632.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028633.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028634.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.DownLoader.19433;Deleted.;
A0028635.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028636.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.DownLoader.19433;Deleted.;
A0028637.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028638.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.DownLoader.19433;Deleted.;
A0028639.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028640.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028641.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.DownLoader.19433;Deleted.;
A0028642.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028643.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028644.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028645.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.49;Deleted.;
A0028671.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Proxy.1727;Deleted.;
A0028692.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Proxy.1727;Deleted.;
A0028710.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Proxy.1727;Deleted.;
A0028720.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Proxy.1727;Deleted.;
A0029723.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Proxy.1727;Deleted.;
A0029750.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Proxy.1727;Deleted.;
A0029762.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Proxy.1727;Deleted.;
A0029770.dll;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Adware.NewDotNet;;
A0029783.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Packed.75;Deleted.;
A0029784.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.Proxy.1727;Deleted.;
A0029789.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.DownLoader.19850;Deleted.;
A0029790.exe;C:\System Volume Information\_restore{EA372515-CBAD-4C88-8FD4-199CE8FC42A0}\RP33;Trojan.DownLoader.19850;Deleted.;
ddaby.dll.bad;C:\VundoFix Backups;Trojan.Virtumod;Deleted.;
wvusstu.dll.bad;C:\VundoFix Backups;Trojan.Virtumod;Deleted.;
duo.exe;C:\WINDOWS;Trojan.Packed.75;Deleted.;
pep.exe;C:\WINDOWS;Trojan.Packed.75;Deleted.;
duo.exe;C:\WINDOWS\system32;Trojan.Packed.75;Deleted.;
process.exe;C:\WINDOWS\system32;Tool.Prockill;Incurable.Moved.;
vtstu.exe;C:\WINDOWS\system32;Trojan.Packed.49;Deleted.;
winctl.dll;C:\WINDOWS\system32;Trojan.Proxy.1727;Deleted.;
win_w72.exe;C:\WINDOWS\system32;Trojan.DownLoader.14391;Deleted.;
adirka.exe;C:\WINDOWS\system32\bak;Trojan.Packed.75;Deleted.;
adirss.exe;C:\WINDOWS\system32\bak;Trojan.Packed.75;Deleted.;
patch.exe;D:\Programs\Cucusoft AVI MPEG to DVD VCD SVCD MPEG Converter Pro.v5.12.WinALL-DVT\Cucusoft.AVI.MPEG.to.DVD.VCD.SVCD.MPEG.Conver;Tool.DVTPatch;Incurable.Moved.;
A0000109.exe;D:\System Volume Information\_restore{DE8ADB46-4327-4391-A715-E4599FDE6492}\RP3;Tool.DVTPatch;Incurable.Moved.;


AWF

Find AWF report by noahdfear ©2006


bak folders found
~~~~~~~~~~~


Directory of C:\PROGRA~1\MESSEN~1\BAK

08/04/2004 02:06 AM 1,667,584 msmsgs.exe
1 File(s) 1,667,584 bytes

Directory of C:\WINDOWS\SYSTEM32\BAK

04/03/2007 09:24 AM 72,831 adirka.exe
04/03/2007 09:25 AM 7,295 adirss.exe
04/05/2007 07:43 PM 24,076 lsasss.exe
07/09/2001 11:50 AM 155,648 NeroCheck.exe
4 File(s) 259,850 bytes

Directory of C:\PROGRA~1\ALWILS~1\AVAST4\BAK

01/15/2007 12:28 PM 108,160 ashDisp.exe
1 File(s) 108,160 bytes

Directory of C:\PROGRA~1\GRISOFT\AVGANT~1.5\BAK

10/07/2006 08:20 AM 6,266,880 avgas.exe
1 File(s) 6,266,880 bytes

Directory of C:\PROGRA~1\NETROPA\MULTIM~1\BAK

11/29/2000 01:10 AM 135,168 MMKeybd.exe
1 File(s) 135,168 bytes

Directory of C:\PROGRA~1\YAHOO!\MESSEN~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\ZONELA~1\ZONEAL~1\BAK

07/18/2005 12:21 AM 980,752 zlclient.exe
1 File(s) 980,752 bytes

Directory of C:\PROGRA~1\COMMON~1\AHEAD\LIB\BAK

01/12/2006 04:40 PM 155,648 NeroCheck.exe
12/16/2005 01:57 PM 94,208 NMBgMonitor.exe
2 File(s) 249,856 bytes

Directory of C:\PROGRA~1\JAVA\JRE15~1.0_1\BIN\BAK

12/15/2006 04:23 AM 75,520 jusched.exe
1 File(s) 75,520 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

1667584 Aug 4 2004 "C:\Program Files\Messenger\msmsgs.exe"
1667584 Aug 4 2004 "C:\Program Files\Messenger\bak\msmsgs.exe"
72831 Apr 3 2007 "C:\WINDOWS\system32\bak\adirka.exe"
7295 Apr 3 2007 "C:\WINDOWS\system32\bak\adirss.exe"
24076 Apr 5 2007 "C:\WINDOWS\system32\bak\lsasss.exe"
155648 Jul 9 2001 "C:\WINDOWS\system32\NeroCheck.exe"
155648 Jul 9 2001 "C:\WINDOWS\system32\bak\NeroCheck.exe"
155648 Jan 12 2006 "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
155648 Jan 12 2006 "C:\Program Files\Common Files\Ahead\Lib\bak\NeroCheck.exe"
108160 Jan 15 2007 "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
108160 Jan 15 2007 "C:\Program Files\Alwil Software\Avast4\bak\ashDisp.exe"
6266880 Oct 7 2006 "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe"
6266880 Oct 7 2006 "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\bak\avgas.exe"
135168 Nov 29 2000 "C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe"
135168 Nov 29 2000 "C:\Program Files\Netropa\Multimedia Keyboard\bak\MMKeybd.exe"
980752 Jul 18 2005 "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
980752 Jul 18 2005 "C:\Program Files\Zone Labs\ZoneAlarm\bak\zlclient.exe"
155648 Jul 9 2001 "C:\WINDOWS\system32\NeroCheck.exe"
155648 Jul 9 2001 "C:\WINDOWS\system32\bak\NeroCheck.exe"
155648 Jan 12 2006 "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
155648 Jan 12 2006 "C:\Program Files\Common Files\Ahead\Lib\bak\NeroCheck.exe"
94208 Dec 16 2005 "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe1174713820"
94208 Dec 16 2005 "C:\Program Files\Common Files\Ahead\Lib\bak\NMBgMonitor.exe"
75520 Dec 15 2006 "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
75520 Dec 15 2006 "C:\Program Files\Java\jre1.5.0_11\bin\bak\jusched.exe"


end of report


i couldnt find that one file to look for on jotti. but im still getting popups and the pc is running slow

thanx for all your help so far :D i really appreciate it.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI