This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Need Help With "perfc000.dat"

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Sorry to jump in on ur forums without an intro but I really need an expert opinnion. I read thru a few other posts about this trojan and followed the recommendations for deletion. Well it's gone, it stops popping up AVG warnings, and I can't locate it in the system32 file anymore, but HJT still picks it up in a scan. (system32 file has a few other files with similar names ie; perfc009.dat…. not sure if that's supposed to be there or not)

The method I used for removal was the "delete upon reboot" option in HJT. I'm hoping someone can look at my log and give me any more tips about what I should do from here. I don't think this poor crappy laptop can take much more abuse! I just took this thing over from my husband and so there is no telling what all might be wrong with it, so if you see anything else that needs to go please feel free to mention it :D

Thanks in advance.
~Malice

Logfile of HijackThis v1.99.1
Scan saved at 9:19:22 AM, on 5/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Compaq\Hotkey Software\hkss.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Belkin\Cardbus F5D701F\Wireless Utility\Belkinwcui.exe
C:\WINDOWS\system32\atievxx.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: 0 - {2647E45A-815F-440F-F5A9-4CEDB43F51E6} - C:\Program Files\ComPlus Applications\lawume.dll (file missing)
O2 - BHO: ofb1 - {3E1500AC-87A5-416b-A211-82E848649DA9} - C:\PROGRA~1\Ofb11\Ofb11.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: IE Redirector - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\WINDOWS\system32\dnsersnd.dll (file missing)
O4 - HKLM\..\Run: [hkss] C:\Program Files\Compaq\Hotkey Software\hkss.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [{63-37-79-9C-ZN}] c:\windows\system32\vdsreg.exe SKY001
O4 - HKLM\..\Run: [SDTray] C:\Program Files\Spyware Doctor\SDTrayApp.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Belkin Wireless G Notebook Card Client Utility.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1155942058189
O20 - AppInit_DLLs: C:\WINDOWS\system32\perfc000.dat
O20 - Winlogon Notify: A3dxq - C:\WINDOWS\system32\a3dxx.dll
O20 - Winlogon Notify: rpcc1 - C:\WINDOWS\system32\rpcc1.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: DCOM Server 60787 - {2C1CD3D7-86AC-4068-93BC-A02304B60787} - (no file)
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
Hello!
I go by FencerGirl. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.

Please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Finally, please reply to this thread. Do not start a new topic.

It may take me a while to reply to you as all of my fixes are being checked by experts to ensure that you are getting a good fix. And remember, like you I have a real life, so I may not be at my computer when you are!

FencerGirl
Thanks so much FencerGirl! No worries, I am no rush. I appreciate your time and assistance, and promise to follow your instructions. ~Malice
Hi malice,
You did indeed have a trojan or two and there's still more to clean. Please follow the steps outlined below.

Step 1: Disable Spyware Doctor.
Some anti-malware programs can interfere with the removal of malware.
For now, disable PC Tools Spyware Doctor.
  • Open Spyware Doctor
  • Click on the 'Settings' button on the left hand panel
  • Then click on the 'Startup Settings' under 'Pick a Category'
  • Uncheck the box on the right that says 'Run at Windows Startup'
Step 2: Clean with HijackThis.
Scan with HijackThis and check the following if present.

O2 - BHO: 0 - {2647E45A-815F-440F-F5A9-4CEDB43F51E6} - C:\Program Files\ComPlus Applications\lawume.dll (file missing)
O2 - BHO: ofb1 - {3E1500AC-87A5-416b-A211-82E848649DA9} - C:\PROGRA~1\Ofb11\Ofb11.dll (file missing)
O2 - BHO: IE Redirector - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\WINDOWS\system32\dnsersnd.dll (file missing)
O4 - HKLM\..\Run: [{63-37-79-9C-ZN}] c:\windows\system32\vdsreg.exe SKY001
O20 - AppInit_DLLs: C:\WINDOWS\system32\perfc000.dat
O20 - Winlogon Notify: A3dxq - C:\WINDOWS\system32\a3dxx.dll
O20 - Winlogon Notify: rpcc1 - C:\WINDOWS\system32\rpcc1.dll
O21 - SSODL: DCOM Server 60787 - {2C1CD3D7-86AC-4068-93BC-A02304B60787} - (no file)

CLOSE ALL OTHER WINDOWS and select "Fixed Checked".

Step 3: Take out the trash.
Now, browse to the following folders and files and delete them if present.

c:\windows\system32\vdsreg.exe
C:\WINDOWS\system32\perfc000.dat
C:\WINDOWS\system32\a3dxx.dll
C:\WINDOWS\system32\rpcc1.dll

Step 4: Check your computer with Kaspersky.
Please do an online scan withKaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky,
Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise
    Standard)

    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been
    infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
After you've completed the above steps, please post back with your Kaspersky log along with a new HijackThis log.
Thanks,
FencerGirl
Hey FencerGirl, Thanks again for trying to help out! I ran into an issue though, and wanted to know if I should still proceed with your instructions as stated. I disabled Spydoctor, and then ran the hjt scan and "fixed" all that you said to fix. After the fix, these 2 files still remained: O20 - Winlogon Notify: A3dxq - C:\WINDOWS\system32\a3dxx.dll O20 - Winlogon Notify: rpcc1 - C:\WINDOWS\system32\rpcc1.dll I went on to delete the files you listed and the same 2 files would not delete: C:\WINDOWS\system32\a3dxx.dll C:\WINDOWS\system32\rpcc1.dll The error message stated they were in use by another person/program, etc. though nothing else was visibly running. I tried deleting them in safe mode and still had no luck. Should I proceed with the Kapersky scan? Or do you want me to try something else to get rid of these files first? Thanks in advance! ~Malice
Hi Malice,
Let's see if we can't get rid of those two files.
Download and Run ComboFix
  • Download this file from either of the two below listed places :

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    http://www.techsupportforum.com/sectools/ComboFix.exe
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

When you're done with ComboFix, post back with its log and a new HijackThis log.
Thanks,
Fencergirl
Heya FencerGirl,

Looks to me like that may have helped with those files. Here is the combofix log, followed by the latest hjt log.

Thanks so much.
~Malice



"Administrator" - 2007-05-09 16:20:45 Service Pack 2
ComboFix 07-05.09.V - Running from: "C:\Documents and Settings\Administrator\Desktop\"


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\9_exception.nls
C:\WINDOWS\system32\qvx5gamet2.exe
C:\DOCUME~1\ADMINI~1\APPLIC~1\Install.dat
C:\WINDOWS\system32\tiso.dll
C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft\60787.dat
C:\WINDOWS\system32\msdrives\BIT3E.tmp
C:\WINDOWS\system32\ksys.sys
C:\WINDOWS\system32\winsub.xml
C:\WINDOWS\g32.txt
C:\WINDOWS\s32.txt
C:\WINDOWS\ws386.ini
C:\Documents and Settings\All Users.\documents\settings
C:\WINDOWS\system32\msdrives
C:\WINDOWS\system32\a3dxx.dll
C:\WINDOWS\system32\rpcc1.dll

Infected copy of C:\WINDOWS\system32\winlogon.exe was found & disinfected
Restored copy from - "C:\WINDOWS\system32\dllcache\winlogon.exe"



((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_DRIVER
——-\LEGACY_DRIVERPP
——-\LEGACY_EXAMPLE
——-\LEGACY_LDRSVC
——-\LEGACY_NDNET1
——-\LEGACY_RUNTIME
——-\Driver
——-\driverpp
——-\EXAMPLE
——-\ldrsvc
——-\NDnet1
——-\Runtime


((((((((((((((((((((((((((((((( Files Created from 2007-04-09 to 2007-05-09 ))))))))))))))))))))))))))))))))))


2007-05-07 22:35 43,584 –a—— C:\WINDOWS\system32\drivers\avipbb.sys
2007-05-07 22:35 28,352 –a—— C:\WINDOWS\system32\drivers\ssmdrv.sys
2007-05-07 22:35 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\AntiVir PersonalEdition Classic
2007-05-06 21:19 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-05-06 20:21 83,536 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-05-06 20:21 59,984 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-05-06 20:21 52,304 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-05-06 20:21 39,248 –a—— C:\WINDOWS\system32\drivers\ikfileflt.sys
2007-05-06 20:21 26,064 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-05-06 20:21 d——– C:\Program Files\Spyware Doctor
2007-05-06 20:21 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\PC Tools
2007-05-06 20:20 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-05-06 20:09 552,960 –a—— C:\DOCUME~1\ADMINI~1\ucmoreiex.exe
2007-05-06 20:09 d——– C:\Program Files\Dealio
2007-05-06 20:08 337,781 –a—— C:\DOCUME~1\ADMINI~1\zippy2.exe
2007-05-06 20:08 135,168 –a—— C:\WINDOWS\system32\rkupginstaller.exe
2007-05-06 20:08 d——– C:\WINDOWS\system32\smpi1
2007-05-06 20:08 d——– C:\Temp\tn3
2007-05-06 20:08 d——– C:\Temp\17O7
2007-05-06 20:08 d——– C:\Temp
2007-05-06 20:08 d——– C:\Program Files\Ofb11
2007-05-02 20:45 d——– C:\Program Files\mIRC


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-05-07 03:49:48 82,944 —-a-w C:\WINDOWS\system32\ws2_32.dll
2007-04-06 03:11:12 ——– d—–w C:\DOCUME~1\ADMINI~1\APPLIC~1\U3
2007-03-30 23:05:41 ——– d—–w C:\Program Files\BearShare Applications
2007-03-29 16:10:30 ——– d—–w C:\Program Files\Google
2007-03-26 03:15:20 21,035 —-a-w C:\WINDOWS\system32\drivers\AegisP.sys
2007-03-26 03:14:26 ——– d—–w C:\Program Files\Belkin
2007-03-26 03:14:23 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-03-26 03:14:13 ——– d—–w C:\Program Files\Common Files\InstallShield
2007-03-26 02:58:20 ——– d—–w C:\Program Files\Network Stumbler
2007-03-07 02:39:22 8 —-a-w C:\DOCUME~1\ADMINI~1\APPLIC~1\usb.dat.bin
2007-02-10 10:03:21 268,704 —-a-w C:\WINDOWS\OfB11_Setup.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
"{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}"="C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll"
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"="C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"hkss"="C:\\Program Files\\Compaq\\Hotkey Software\\hkss.exe"
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""
"Lexmark X83 Button Monitor"="C:\\PROGRA~1\\LEXMAR~1\\ACMonitor_X83.exe"
"Lexmark X83 Button Manager"="C:\\PROGRA~1\\LEXMAR~1\\AcBtnMgr_X83.exe"
"PrinTray"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\printray.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_01\\bin\\jusched.exe\""
"avgnt"="\"C:\\Program Files\\AntiVir PersonalEdition Classic\\avgnt.exe\" /min"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages msv1_0\
Security Packages kerberosmsv1_0schannelwdigest\
Notification Packages scecli\

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdauxservice
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdcoreservice




[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter HTTPFilter\
LocalService AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV\
NetworkService DnsCache\
DcomLaunch DcomLaunchTermService\
rpcss RpcSs\
imgsvc StiSvc\
termsvcs TermService\

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost


[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E]
Shell\AutoRun\command E:\LaunchU3.exe

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b7c6f220-2f11-11db-a2d2-00d05938cd6f}]
Shell\AutoRun\command E:\LaunchU3.exe

********************************************************************

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-09 16:26:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


********************************************************************

Completion time: 2007-05-09 16:26:24 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-05-09 16:26







Logfile of HijackThis v1.99.1
Scan saved at 4:31:04 PM, on 5/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\atievxx.exe
C:\Program Files\Compaq\Hotkey Software\hkss.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Belkin\Cardbus F5D701F\Wireless Utility\Belkinwcui.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [hkss] C:\Program Files\Compaq\Hotkey Software\hkss.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Belkin Wireless G Notebook Card Client Utility.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1155942058189
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
Hi Malice,
ComboFix got a lot of stuff, but there is still more to do.

Did you install the UCMore and Dealio Toolbars? If so, you should know that they are regarded as spyware. I recommend that you remove them.

You are running a P2P filesharing programme.
  • Many of these programmes come with unwanted components bundled with them.
  • If you wish to find out whether the one you're using does click here.

Please note: Even if you are using a "safe" P2P programme, it is only the programme that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.


My recommendation is you uninstall it. At the very least, please refrain from filesharing while we're cleaning your computer.

Let's start cleaning

Step 1: Remove known spyware.
Some parasites can be easily and effectively removed from the Add/Remove Programs applet in the Windows Control Panel.
Please go to Start >> Control Panel >> Add/Remove Programs and remove UCMore and Dealio if present.

Step 2: Download AVG Anti-Spyware.
Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update AVG Anti-Spyware.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.

Step 3: Get into Safe Mode.
It is easier to remove many malware applications while in Safe Mode.

You can do this by restarting your computer, then contiunally tapping F8 until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter.

You'll want to print out these instructions because you will not have internet access while in Safe Mode.

Step 4: Show it all!
Be sure that Windows is set to show hidden and system files and folders.
In My Computer, click Tools >> Folder Options >> View, set Hidden files and folder to "Show," and uncheck Hide protected operating system files.

Step 5: Delete the bad files.
Now, browse to the following folders and files and delete them if present.

C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\ucmoreiex.exe
C:\Program Files\Dealio <= This Whole Folder!
C:\WINDOWS\system32\rkupginstaller.exe
C:\WINDOWS\system32\smpi1<= This Whole Folder!
C:\Temp\tn3<= This Whole Folder!
C:\Temp\17O7<= This Whole Folder!
C:\Program Files\Ofb11<= This Whole Folder!
C:\WINDOWS\OfB11_Setup.exe


Step 6: Run AVG Anti-Spyware.
Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.

    Reboot into normal mode.
After you've completed all of the above steps, please post back with your AVG Anti-Spyware log, a new HijackThis log and let me know if there were any files you couldn't delete.
Thanks,
FencerGirl
Hello hello again!

Ok first let me say that I do not use a p2p program. When I took over this laptop from my husband bearshare was the first thing I deleted. I know better, (and so does my husband who is an MCSE+Security, why he insists on using it I have no clue! There ARE safer ways to get porn lol).
So it wasnt installed this whole time. As for the toolbars, I have never heard of them, and there is nothing in the add/remove progs that shouldnt be there. With that said I have completed all of your instructions. Everything deleted properly, and here is the AVG log followed by a new hjt log.

Just outta curiosty, since you said to quarantine everything as apposed to deleting, is there anything I should do now with the quarantined files?

Again I thank you sooo much for your help and your time! Just tell me what to do next :)

~Malice


AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 3:01:29 PM 5/10/2007

+ Scan result:



C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP31\A0006479.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006534.exe -> Adware.Relevant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP31\A0006476.exe -> Adware.SpySheriff : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-3512545250-82862768-2583177834-500\Dc1.exe/IUCMORE.DLL -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-3512545250-82862768-2583177834-500\Dc1.exe/UCMTSAIE.DLL -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-3512545250-82862768-2583177834-500\Dc1.exe/empty_00000001 -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006557.exe -> Adware.ZQuest : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006549.dll -> Backdoor.Agent.adr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP30\A0005468.exe -> Backdoor.Agent.aju : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006538.exe -> Backdoor.Agent.aju : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006539.exe -> Backdoor.Agent.aju : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP30\A0006448.sys -> Backdoor.Bulknet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP31\A0006505.sys -> Backdoor.Bulknet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP30\A0005457.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP30\A0005464.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006526.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006537.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006555.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006556.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006530.exe -> Downloader.Agent.bnn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP30\A0005456.exe -> Downloader.Tibs.ku : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP30\A0005458.exe -> Downloader.Tibs.ku : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP30\A0005460.exe -> Downloader.Tibs.ku : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP30\A0006462.exe -> Downloader.Tibs.ku : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006532.exe -> Downloader.Tibs.ku : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006540.exe -> Downloader.Tibs.ku : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006542.exe -> Downloader.Tibs.ku : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006545.exe -> Downloader.Tibs.ku : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006547.exe -> Downloader.Tibs.ku : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006550.exe -> Downloader.Tibs.ku : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006551.exe -> Downloader.Tibs.ku : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006527.exe -> Downloader.VB.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006531.exe -> Hijacker.Agent.jp : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006528.exe -> Hijacker.Small.cf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006561.dll -> Hijacker.Small.cf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP30\A0005463.sys -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP30\A0006453.sys -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006548.sys -> Proxy.Agent.ji : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\rpcc1.dll.vir -> Proxy.Dlena : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP30\A0005465.dll -> Proxy.Dlena : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006676.dll -> Proxy.Dlena : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP30\A0005455.exe -> Proxy.Xorpix.ba : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006554.exe -> Proxy.Xorpix.ba : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\a3dxx.dll.vir -> Proxy.Xorpix.m : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP30\A0006442.dll -> Proxy.Xorpix.m : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006675.dll -> Proxy.Xorpix.m : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP30\A0006447.sys -> Rootkit.Agent.el : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP31\A0006504.sys -> Rootkit.Agent.el : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006544.sys -> Rootkit.Agent.el : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\ksys.sys.vir -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP30\A0006459.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP31\A0006524.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006670.sys -> Rootkit.NtRootKit : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\administrator@aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@clickbank[2].txt -> TrackingCookie.Clickbank : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\WINDOWS\system32\config\systemprofile\Cookies\[removed][2].txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006529.exe -> Trojan.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006535.exe -> Trojan.Agent : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\zippy2.exe -> Trojan.BHO.ab : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006536.exe -> Trojan.BHO.ab : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006559.dll -> Trojan.BHO.ab : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006560.dll -> Trojan.OwlF.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP31\A0006495.dll:fork2 -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006562.dll:fork2 -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP30\A0005459.exe -> Trojan.Tibs.w : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP30\A0005461.exe -> Trojan.Tibs.w : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP30\A0006463.sys -> Trojan.Tibs.w : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP31\A0006484.exe -> Trojan.Tibs.w : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006553.exe -> Trojan.Tibs.w : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006541.exe -> Worm.Nuwar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP30\A0005454.exe -> Worm.Zhelatin.by : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{764BC083-161E-448E-A85A-12721A6A195C}\RP32\A0006552.exe -> Worm.Zhelatin.by : Cleaned with backup (quarantined).



Logfile of HijackThis v1.99.1
Scan saved at 3:05:38 PM, on 5/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Compaq\Hotkey Software\hkss.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Belkin\Cardbus F5D701F\Wireless Utility\Belkinwcui.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\atievxx.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [hkss] C:\Program Files\Compaq\Hotkey Software\hkss.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Belkin Wireless G Notebook Card Client Utility.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1155942058189
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
HAHA! 10 minutes after posting my last message, while the laptop was just sitting here idle, AV-Guard pops up saying it found the trojan horse TR/Crypt.Xpack.gen (A0006533.exe). I hadnt even touched the laptop since posting last and closing out IE! This poor thing :wacko: When that happens is it better to quarantine or delete?
Hello Malice,
Whew, AVG cleaned off a lot of stuff. But the fact that you had another Trojan show up, makes me think we're not out of the woods yet. If something like that does pop-up again, please write down the name of the infected file and its location then go ahead and quarantine it. You can always delete it later.
Thanks for the info regarding Bearshare. It looks like it is gone now, so that's good.
Let's see if there is anything else lurking on your computer.

Step 1: Download and Run SDFix.
Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
Reboot your computer

Step 2: Run Kaspersky's Online Scanner.
Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky,
Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise
    Standard)

    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been
    infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
Reboot your computer.

Please post back the results of the Kaspersky scan, the contents of the SDFix report.txt and a new HijackThis log.
Thanks!
FencerGirl

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI