This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Smitfraud + More Problems!

33 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The fix report itself does not show anything but I do see a malware file among the processes. If you have previously downloaded this tool, please delete it and download it again as this version is more current.

Trevuren

Please download this file - combofix.exe by sUBs
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log.
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

Regards,

Trevuren
I hope you are well and not experiencing any difficulties carrying out my last set of instructions. If you are, do not hesitate to ask for further explanations. If however, your problem has been solved or you no longer require our assistance, please advise us accordingly and we will archive your topic.

Trevuren
My apologies for the delayed response Trevuren

Here is the combo fix log:

ComboFix 07-08-01.6 - "Ryan" 2007-08-02 21:53:51.1 [GMT -7:00] - NTFS
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.True
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\asembl~1
C:\Program Files\asembl~1\?hkntfs.exe
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
C:\Program Files\ComPlus Applications\nipy83122.dll
C:\Program Files\outerinfo
C:\Program Files\outerinfo\Terms.rtf
C:\tempc2
C:\tempc2\tmpFF.log
C:\temp\brr
C:\temp\brr\tmpZTF.log
C:\temp\tn3
C:\WINDOWS\dls0523pmw.exe
C:\WINDOWS\poolsv.exe
C:\WINDOWS\rau001978.exe
C:\WINDOWS\retadpu1000106.exe
C:\WINDOWS\retadpu572.exe
C:\WINDOWS\system32\ahenjdbc.ini
C:\WINDOWS\system32\b02FdUe
C:\WINDOWS\system32\b02FdUe\b02FdUe1065.exe
C:\WINDOWS\system32\cbdjneha.dll
C:\WINDOWS\system32\driver
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\core.sys
C:\WINDOWS\system32\dynjcler.exe
C:\WINDOWS\system32\hggdbby.dll
C:\WINDOWS\system32\hggggec.dll
C:\WINDOWS\system32\ldcore.dll
C:\WINDOWS\system32\npqss.bak1
C:\WINDOWS\system32\npqss.bak2
C:\WINDOWS\system32\npqss.ini
C:\WINDOWS\system32\qummuian.dll
C:\WINDOWS\system32\sovegvmp.dll
C:\WINDOWS\system32\ssqpn.dll
C:\WINDOWS\system32\vnesyfj.dll
C:\WINDOWS\system32\winnb58.dll
C:\WINDOWS\system32\wnsxs~1
C:\WINDOWS\system32\wnsxs~1\ati2evxx.exe
C:\WINDOWS\system32\Z1
C:\WINDOWS\system32\Z1\mwspasrt83122.exe
C:\WINDOWS\system32\Z11
C:\WINDOWS\system32\Z11\z53.exe
C:\WINDOWS\system32\Z3
C:\WINDOWS\system32\Z3\wr73.exe
C:\WINDOWS\system32\Z5
C:\WINDOWS\system32\Z5\st2.exe
C:\WINDOWS\system32\Z7
C:\WINDOWS\system32\Z9
C:\WINDOWS\system32\Z9\bw73.exe
C:\WINDOWS\TISKY009.exe
C:\WINDOWS\tk58.exe
C:\WINDOWS\wr.txt
C:\WINDOWS\ypnhpnu.exe


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_CORE
——-\LEGACY_NET_AGENT
——-\LEGACY_WINDOWS_OVERLAY_COMPONENTS
——-\core
——-\Net Agent


((((((((((((((((((((((((( Files Created from 2007-07-03 to 2007-08-03 )))))))))))))))))))))))))))))))


2007-08-02 21:53 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-02 21:52 9,769 –a—— C:\WINDOWS\fzybu0578.exe
2007-08-02 21:52 6,689 –a—— C:\WINDOWS\system32\ldcore.dll
2007-07-17 15:13 846 –a—— C:\WINDOWS\system32\tmp.reg
2007-07-17 15:13 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-07-17 15:13 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-07-17 15:13 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-07-17 15:13 d——– C:\DOCUME~1\Ryan\SmitfraudFix
2007-07-17 03:51 766,352 -r-hs—- C:\WINDOWS\ypnhpnuA.exe
2007-07-17 03:51 d——– C:\Temp
2007-07-15 19:34 d——– C:\WINDOWS\ERUNT
2007-07-15 17:31 d——– C:\info
2007-07-15 17:23 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trend Micro
2007-07-15 17:21 d——– C:\WINDOWS\TAV15.1
2007-07-15 16:02 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-07-15 15:54 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-07-15 15:54 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-07-12 16:48 d——– C:\WINDOWS\pss
2007-07-12 16:33 d——– C:\Program Files\Trend Micro
2007-07-12 16:00 d——– C:\DOCUME~1\Ryan\.housecall6.6
2007-07-12 15:52 d——– C:\WINDOWS\system32\appmgmt
2007-07-12 15:39 d——– C:\Program Files\MSXML 4.0
2007-07-11 17:05 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Drivers Headquarters
2007-07-11 17:01 176,128 –a—— C:\WINDOWS\system32\nvuide.exe
2007-07-11 17:01 101,120 –a—— C:\WINDOWS\system32\drivers\nvtcp.sys
2007-07-11 17:01 d——– C:\Program Files\Silicon Image
2007-07-11 16:59 33,280 –a—— C:\WINDOWS\system32\nvconrmins.dll
2007-07-11 16:59 33,280 –a—— C:\WINDOWS\system32\NVCOI.DLL
2007-07-11 16:59 289,792 –a—— C:\WINDOWS\system32\idecoins.dll
2007-07-11 16:40 d——– C:\Program Files\Marvell
2007-07-11 16:30 d——– C:\DOCUME~1\Ryan\APPLIC~1\VersionTracker Pro


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-18 02:48 ——— d——– C:\DOCUME~1\Ryan\APPLIC~1\uTorrent
2007-07-16 21:54 22328 –a—— C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-07-16 21:54 103736 –a—— C:\WINDOWS\system32\PnkBstrB.exe
2007-07-15 19:47 ——— d–h—– C:\Program Files\WindowsUpdate
2007-07-15 19:47 ——— d——– C:\Program Files\Online Services
2007-07-15 19:47 ——— d——– C:\Program Files\Messenger
2007-07-12 16:46 ——— d——– C:\Program Files\AIM6
2007-07-12 15:56 ——— d——– C:\Program Files\Yahoo!
2007-07-12 15:55 ——— d——– C:\Program Files\Replay Music 2
2007-07-12 15:55 ——— d——– C:\Program Files\Common Files\Scanner
2007-07-12 15:54 ——— d——– C:\Program Files\Google
2007-07-12 15:53 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-07-12 15:53 ——— d——– C:\Program Files\Electronic Arts
2007-07-12 15:52 ——— d——– C:\Program Files\Steam
2007-07-12 15:52 ——— d——– C:\Program Files\Azureus
2007-07-12 15:50 ——— d—s—- C:\Program Files\Xfire
2007-07-12 15:50 ——— d——– C:\DOCUME~1\Ryan\APPLIC~1\Xfire
2007-07-01 01:18 ——— d——– C:\DOCUME~1\Ryan\APPLIC~1\Azureus
2007-06-24 18:31 ——— d——– C:\DOCUME~1\Ryan\APPLIC~1\acccore
2007-06-23 03:18 ——— d——– C:\DOCUME~1\Ryan\APPLIC~1\Yahoo!
2007-06-22 03:10 2414 –a—— C:\WINDOWS\mozver.dat
2007-06-22 03:00 ——— d——– C:\Program Files\uTorrent
2007-06-20 16:00 ——— d——– C:\Program Files\Western Digital Technologies
2007-06-19 16:38 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2007-06-19 16:38 ——— d——– C:\DOCUME~1\Ryan\APPLIC~1\Logitech
2007-06-19 16:37 0 –ah—– C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-06-19 16:37 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2007-06-19 16:37 ——— d——– C:\Program Files\Common Files\Logitech
2007-06-19 16:36 ——— d——– C:\Program Files\Logitech
2007-06-19 16:36 ——— d——– C:\DOCUME~1\Ryan\APPLIC~1\InstallShield
2007-06-14 16:35 ——— d——– C:\Program Files\Viewpoint
2007-06-14 16:34 ——— d——– C:\Program Files\Common Files\AOL
2007-06-14 16:33 335 –a—— C:\WINDOWS\nsreg.dat
2007-06-14 16:21 ——— d——– C:\DOCUME~1\Ryan\APPLIC~1\Google
2007-06-12 19:25 63040 –a—— C:\WINDOWS\system32\PnkBstrA.exe
2007-06-12 15:17 384 –a—— C:\WINDOWS\system32\DVCStateBkp-{00000005-00000000-00000006-00001102-00000004-20021102}.dat
2007-06-12 15:17 384 –a—— C:\WINDOWS\system32\DVCState-{00000005-00000000-00000006-00001102-00000004-20021102}.dat
2007-06-12 14:41 ——— d——– C:\DOCUME~1\Ryan\APPLIC~1\DMCache
2007-06-12 14:28 ——— d——– C:\Program Files\Common Files\InstallShield
2007-05-23 22:01 737280 –a—— C:\WINDOWS\iun6002.exe
2007-05-20 19:46 108144 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2007-05-16 08:12 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-05-13 20:03 451072 –a—— C:\WINDOWS\Radeon Omega Drivers v3.8.330 Uninstall.exe
2007-05-11 20:50 98304 –a—— C:\WINDOWS\system32CmdLineExt.dll
2007-05-05 20:09 184 –a—— C:\WINDOWS\system32\e000001.dat
2007-05-05 19:25 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2007-05-04 20:50 0 -rahs—- C:\MSDOS.SYS
2007-05-04 20:50 0 -rahs—- C:\IO.SYS
2007-05-04 20:50 0 –a—— C:\CONFIG.SYS
2007-05-04 20:50 0 –a—— C:\AUTOEXEC.BAT
2007-05-04 20:48 21640 –a—— C:\WINDOWS\system32\emptyregdb.dat


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AtiPTA"="atiptaxx.exe" [2006-02-21 17:05 C:\WINDOWS\system32\atiptaxx.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 C:\WINDOWS\KHALMNPR.Exe]
"ypnhpnuA"="C:\WINDOWS\ypnhpnuA.exe" [1989-12-12 10:10]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Ralink Wireless Utility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
backup=C:\WINDOWS\pss\Ralink Wireless Utility.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ryan^Start Menu^Programs^Startup^TA_Start.lnk]
path=C:\Documents and Settings\Ryan\Start Menu\Programs\Startup\TA_Start.lnk
backup=C:\WINDOWS\pss\TA_Start.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ryan^Start Menu^Programs^Startup^Xfire.lnk]
path=C:\Documents and Settings\Ryan\Start Menu\Programs\Startup\Xfire.lnk
backup=C:\WINDOWS\pss\Xfire.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
"C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDET]
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
CTHELPER.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SBDrvDet]
C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"C:\Program Files\Steam\Steam.exe" -silent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe

R1 atitray;atitray;\??\C:\Program Files\Radeon Omega Drivers\v3.8.330\ATI Tray Tools\atitray.sys
R2 PfDetNT;PfDetNT;\??\C:\WINDOWS\system32\drivers\PfModNT.sys
R3 COMMONFX.DLL;COMMONFX.DLL;C:\WINDOWS\system32\COMMONFX.DLL
R3 CTAUDFX.DLL;CTAUDFX.DLL;C:\WINDOWS\system32\CTAUDFX.DLL
R3 CTSBLFX.DLL;CTSBLFX.DLL;C:\WINDOWS\system32\CTSBLFX.DLL
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver;C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter;C:\WINDOWS\system32\Drivers\LUsbFilt.Sys
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver;C:\WINDOWS\system32\drivers\msmpu401.sys
R3 Wdf01000;Wdf01000;C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
S0 Si3132r5;SiI-3132 SoftRaid 5 Controller;C:\WINDOWS\system32\DRIVERS\Si3132r5.sys
S0 SiFilter;SATALink driver accelerator;C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys
S3 ATIAVAIW;ATI T200 Unified AVStream service;C:\WINDOWS\system32\DRIVERS\atinavt2.sys
S3 CT20XUT.DLL;CT20XUT.DLL;C:\WINDOWS\system32\CT20XUT.DLL
S3 CTEAPSFX.DLL;CTEAPSFX.DLL;C:\WINDOWS\system32\CTEAPSFX.DLL
S3 CTEDSPFX.DLL;CTEDSPFX.DLL;C:\WINDOWS\system32\CTEDSPFX.DLL
S3 CTEDSPIO.DLL;CTEDSPIO.DLL;C:\WINDOWS\system32\CTEDSPIO.DLL
S3 CTEDSPSY.DLL;CTEDSPSY.DLL;C:\WINDOWS\system32\CTEDSPSY.DLL
S3 CTERFXFX.DLL;CTERFXFX.DLL;C:\WINDOWS\system32\CTERFXFX.DLL
S3 CTEXFIFX.DLL;CTEXFIFX.DLL;C:\WINDOWS\system32\CTEXFIFX.DLL
S3 CTHWIUT.DLL;CTHWIUT.DLL;C:\WINDOWS\system32\CTHWIUT.DLL
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0;C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
S3 hap17v2k;Creative P17V HAL Driver;C:\WINDOWS\system32\drivers\hap17v2k.sys
S3 idsvc;Windows CardSpace;"C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"
S3 MPE;BDA MPE Filter;C:\WINDOWS\system32\DRIVERS\MPE.sys
S3 TVICHW32;TVICHW32;\??\C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service;"C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe"


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-02 21:59:36
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-02 22:00:12 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-02 22:00

— E O F —



HJT:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:05:53 PM, on 8/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ypnhpnuA.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\killer.exe.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [ypnhpnuA] C:\WINDOWS\ypnhpnuA.exe
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\prxernsp.dll
O10 - Unknown file in Winsock LSP: prxerdrv.dll
O10 - Unknown file in Winsock LSP: prxerdrv.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1178338978029
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1178341677451
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

–
End of file - 2689 bytes

:thumbup:
A. I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto-updating for the Viewpoint Manager – the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.


Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware
I recommend that you remove the Viewpoint products; however, decide for yourself. To uninstall the the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):

1. Click Start, then Settings, then click Control Panel.
2. In Control Panel, double-click Add or Remove Programs.
3. In Add or Remove Programs, Remove the Viewpoint component
4. Do the same for each Viewpoint component.


B. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\fzybu0578.exe
C:\WINDOWS\system32\ldcore.dll
C:\WINDOWS\ypnhpnuA.exe
C:\WINDOWS\iun6002.exe
C:\WINDOWS\system32\d3d9caps.dat

Folder::
C:\Program Files\Viewpoint
C:\DOCUME~1\Ryan\SmitfraudFix
C:\WINDOWS\system32\appmgmt

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ypnhpnuA"=-


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
No restart needed, ComboFix:

ComboFix 07-08-01.6 - "Ryan" 2007-08-02 23:03:51.2 [GMT -7:00] - NTFS
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.True
Command switches used :: C:\Documents and Settings\Ryan\Desktop\CFScript.txt
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\Ryan\SmitfraudFix
C:\DOCUME~1\Ryan\SmitfraudFix\dumphive.exe
C:\DOCUME~1\Ryan\SmitfraudFix\GenericRenosFix.exe
C:\DOCUME~1\Ryan\SmitfraudFix\HostsChk.exe
C:\DOCUME~1\Ryan\SmitfraudFix\Process.exe
C:\DOCUME~1\Ryan\SmitfraudFix\Reboot.exe
C:\DOCUME~1\Ryan\SmitfraudFix\restart.exe
C:\DOCUME~1\Ryan\SmitfraudFix\SmitfraudFix.cmd
C:\DOCUME~1\Ryan\SmitfraudFix\SmiUpdate.exe
C:\DOCUME~1\Ryan\SmitfraudFix\SrchSTS.exe
C:\DOCUME~1\Ryan\SmitfraudFix\swreg.exe
C:\DOCUME~1\Ryan\SmitfraudFix\swsc.exe
C:\DOCUME~1\Ryan\SmitfraudFix\swxcacls.exe
C:\DOCUME~1\Ryan\SmitfraudFix\unzip.exe
C:\WINDOWS\system32\appmgmt
C:\WINDOWS\system32\ldcore.dll


((((((((((((((((((((((((( Files Created from 2007-07-03 to 2007-08-03 )))))))))))))))))))))))))))))))


2007-08-02 22:54 409,600 –a—— C:\WINDOWS\system32\wrap_oal.dll
2007-08-02 22:54 3,072 –a—— C:\WINDOWS\CTXFIRES.DLL
2007-08-02 21:53 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-02 21:52 9,769 –a—— C:\WINDOWS\fzybu0578.exe
2007-07-17 15:13 846 –a—— C:\WINDOWS\system32\tmp.reg
2007-07-17 15:13 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-07-17 15:13 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-07-17 15:13 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-07-17 03:51 766,352 -r-hs—- C:\WINDOWS\ypnhpnuA.exe
2007-07-17 03:51 d——– C:\Temp
2007-07-15 19:34 d——– C:\WINDOWS\ERUNT
2007-07-15 17:31 d——– C:\info
2007-07-15 17:23 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trend Micro
2007-07-15 17:21 d——– C:\WINDOWS\TAV15.1
2007-07-15 16:02 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-07-15 15:54 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-07-15 15:54 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-07-12 16:48 d——– C:\WINDOWS\pss
2007-07-12 16:33 d——– C:\Program Files\Trend Micro
2007-07-12 16:00 d——– C:\DOCUME~1\Ryan\.housecall6.6
2007-07-12 15:39 d——– C:\Program Files\MSXML 4.0
2007-07-11 17:05 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Drivers Headquarters
2007-07-11 17:01 176,128 –a—— C:\WINDOWS\system32\nvuide.exe
2007-07-11 17:01 101,120 –a—— C:\WINDOWS\system32\drivers\nvtcp.sys
2007-07-11 17:01 d——– C:\Program Files\Silicon Image
2007-07-11 16:59 33,280 –a—— C:\WINDOWS\system32\nvconrmins.dll
2007-07-11 16:59 33,280 –a—— C:\WINDOWS\system32\NVCOI.DLL
2007-07-11 16:59 289,792 –a—— C:\WINDOWS\system32\idecoins.dll
2007-07-11 16:40 d——– C:\Program Files\Marvell
2007-07-11 16:30 d——– C:\DOCUME~1\Ryan\APPLIC~1\VersionTracker Pro


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-02 22:54 86016 –a—— C:\WINDOWS\system32\OpenAL32.dll
2007-08-02 22:54 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-02 22:54 ——— d——– C:\Program Files\Creative
2007-08-02 22:53 ——— d——– C:\DOCUME~1\Ryan\APPLIC~1\uTorrent
2007-07-16 21:54 22328 –a—— C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-07-16 21:54 103736 –a—— C:\WINDOWS\system32\PnkBstrB.exe
2007-07-15 19:47 ——— d–h—– C:\Program Files\WindowsUpdate
2007-07-15 19:47 ——— d——– C:\Program Files\Online Services
2007-07-15 19:47 ——— d——– C:\Program Files\Messenger
2007-07-12 16:46 ——— d——– C:\Program Files\AIM6
2007-07-12 15:56 ——— d——– C:\Program Files\Yahoo!
2007-07-12 15:55 ——— d——– C:\Program Files\Replay Music 2
2007-07-12 15:55 ——— d——– C:\Program Files\Common Files\Scanner
2007-07-12 15:54 ——— d——– C:\Program Files\Google
2007-07-12 15:53 ——— d——– C:\Program Files\Electronic Arts
2007-07-12 15:52 ——— d——– C:\Program Files\Steam
2007-07-12 15:52 ——— d——– C:\Program Files\Azureus
2007-07-12 15:50 ——— d—s—- C:\Program Files\Xfire
2007-07-12 15:50 ——— d——– C:\DOCUME~1\Ryan\APPLIC~1\Xfire
2007-07-01 01:18 ——— d——– C:\DOCUME~1\Ryan\APPLIC~1\Azureus
2007-06-24 18:31 ——— d——– C:\DOCUME~1\Ryan\APPLIC~1\acccore
2007-06-23 03:18 ——— d——– C:\DOCUME~1\Ryan\APPLIC~1\Yahoo!
2007-06-22 03:10 2414 –a—— C:\WINDOWS\mozver.dat
2007-06-22 03:00 ——— d——– C:\Program Files\uTorrent
2007-06-20 16:00 ——— d——– C:\Program Files\Western Digital Technologies
2007-06-19 16:38 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2007-06-19 16:38 ——— d——– C:\DOCUME~1\Ryan\APPLIC~1\Logitech
2007-06-19 16:37 0 –ah—– C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-06-19 16:37 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2007-06-19 16:37 ——— d——– C:\Program Files\Common Files\Logitech
2007-06-19 16:36 ——— d——– C:\Program Files\Logitech
2007-06-19 16:36 ——— d——– C:\DOCUME~1\Ryan\APPLIC~1\InstallShield
2007-06-14 16:34 ——— d——– C:\Program Files\Common Files\AOL
2007-06-14 16:33 335 –a—— C:\WINDOWS\nsreg.dat
2007-06-14 16:21 ——— d——– C:\DOCUME~1\Ryan\APPLIC~1\Google
2007-06-12 19:25 63040 –a—— C:\WINDOWS\system32\PnkBstrA.exe
2007-06-12 14:41 ——— d——– C:\DOCUME~1\Ryan\APPLIC~1\DMCache
2007-06-12 14:28 ——— d——– C:\Program Files\Common Files\InstallShield
2007-05-23 22:01 737280 –a—— C:\WINDOWS\iun6002.exe
2007-05-20 19:46 108144 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2007-05-16 08:12 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-05-13 20:03 451072 –a—— C:\WINDOWS\Radeon Omega Drivers v3.8.330 Uninstall.exe
2007-05-11 20:50 98304 –a—— C:\WINDOWS\system32CmdLineExt.dll
2007-05-05 20:09 184 –a—— C:\WINDOWS\system32\e000001.dat
2007-05-05 19:25 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2007-05-04 20:50 0 -rahs—- C:\MSDOS.SYS
2007-05-04 20:50 0 -rahs—- C:\IO.SYS
2007-05-04 20:50 0 –a—— C:\CONFIG.SYS
2007-05-04 20:50 0 –a—— C:\AUTOEXEC.BAT
2007-05-04 20:48 21640 –a—— C:\WINDOWS\system32\emptyregdb.dat


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AtiPTA"="atiptaxx.exe" [2006-02-21 17:05 C:\WINDOWS\system32\atiptaxx.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 C:\WINDOWS\KHALMNPR.Exe]
"CtxfiReg"="CTXFIREG.exe" [2006-08-11 14:53 C:\WINDOWS\system32\CTXFIREG.EXE]
"CTHelper"="CTHELPER.EXE" [2006-08-11 14:56 C:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 14:56 C:\WINDOWS\system32\CTXFIHLP.EXE]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Ralink Wireless Utility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
backup=C:\WINDOWS\pss\Ralink Wireless Utility.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ryan^Start Menu^Programs^Startup^TA_Start.lnk]
path=C:\Documents and Settings\Ryan\Start Menu\Programs\Startup\TA_Start.lnk
backup=C:\WINDOWS\pss\TA_Start.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ryan^Start Menu^Programs^Startup^Xfire.lnk]
path=C:\Documents and Settings\Ryan\Start Menu\Programs\Startup\Xfire.lnk
backup=C:\WINDOWS\pss\Xfire.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
"C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDET]
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
CTHELPER.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SBDrvDet]
C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"C:\Program Files\Steam\Steam.exe" -silent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe

R1 atitray;atitray;\??\C:\Program Files\Radeon Omega Drivers\v3.8.330\ATI Tray Tools\atitray.sys
R2 PfDetNT;PfDetNT;\??\C:\WINDOWS\system32\drivers\PfModNT.sys
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver;C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter;C:\WINDOWS\system32\Drivers\LUsbFilt.Sys
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver;C:\WINDOWS\system32\drivers\msmpu401.sys
R3 Wdf01000;Wdf01000;C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
S0 Si3132r5;SiI-3132 SoftRaid 5 Controller;C:\WINDOWS\system32\DRIVERS\Si3132r5.sys
S0 SiFilter;SATALink driver accelerator;C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys
S3 ATIAVAIW;ATI T200 Unified AVStream service;C:\WINDOWS\system32\DRIVERS\atinavt2.sys
S3 COMMONFX.DLL;COMMONFX.DLL;C:\WINDOWS\system32\COMMONFX.DLL
S3 CT20XUT.DLL;CT20XUT.DLL;C:\WINDOWS\system32\CT20XUT.DLL
S3 CTAUDFX.DLL;CTAUDFX.DLL;C:\WINDOWS\system32\CTAUDFX.DLL
S3 CTEAPSFX.DLL;CTEAPSFX.DLL;C:\WINDOWS\system32\CTEAPSFX.DLL
S3 CTEDSPFX.DLL;CTEDSPFX.DLL;C:\WINDOWS\system32\CTEDSPFX.DLL
S3 CTEDSPIO.DLL;CTEDSPIO.DLL;C:\WINDOWS\system32\CTEDSPIO.DLL
S3 CTEDSPSY.DLL;CTEDSPSY.DLL;C:\WINDOWS\system32\CTEDSPSY.DLL
S3 CTERFXFX.DLL;CTERFXFX.DLL;C:\WINDOWS\system32\CTERFXFX.DLL
S3 CTEXFIFX.DLL;CTEXFIFX.DLL;C:\WINDOWS\system32\CTEXFIFX.DLL
S3 CTHWIUT.DLL;CTHWIUT.DLL;C:\WINDOWS\system32\CTHWIUT.DLL
S3 CTSBLFX.DLL;CTSBLFX.DLL;C:\WINDOWS\system32\CTSBLFX.DLL
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0;C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
S3 hap17v2k;Creative P17V HAL Driver;C:\WINDOWS\system32\drivers\hap17v2k.sys
S3 idsvc;Windows CardSpace;"C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"
S3 MPE;BDA MPE Filter;C:\WINDOWS\system32\DRIVERS\MPE.sys
S3 TVICHW32;TVICHW32;\??\C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service;"C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe"


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-02 23:05:08
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-02 23:05:33
C:\ComboFix-quarantined-files.txt … 2007-08-02 23:05
C:\ComboFix2.txt … 2007-08-02 22:00

— E O F —


HJT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:08:31 PM, on 8/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ypnhpnuA.exe
C:\WINDOWS\CTHELPER.EXE
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\killer.exe.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [CtxfiReg] CTXFIREG.exe /FAIL1
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [ypnhpnuA] C:\WINDOWS\ypnhpnuA.exe
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\prxernsp.dll
O10 - Unknown file in Winsock LSP: prxerdrv.dll
O10 - Unknown file in Winsock LSP: prxerdrv.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1178338978029
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1178341677451
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

–
End of file - 2850 bytes
:thumbup:
A. Press Control-Alt-Del to enter the Task Manager.

Click on the Processes tab and end the following processes:

C:\WINDOWS\ypnhpnuA.exe
Exit the Task Manager when finished.


B. Close all programs leaving only HijackThis running. Place a check against each of the following entries:

O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [ypnhpnuA] C:\WINDOWS\ypnhpnuA.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab


Click on Fix Checked when finished and exit HijackThis.


C. Reboot into Safe Mode: please see here if you are not sure how to do this.


Using Windows Explorer (Windows Key + E), locate the following file, and delete it:

C:\WINDOWS\ypnhpnuA.exe

Exit Explorer, and reboot as normal afterwards.


D. Please post a fresh HJT log.
Hi, I was unable to find

C:\WINDOWS\ypnhpnuA.exe

I did a search and deleted one file that had ypnhpnuA in it but it was not .exe
I can still see ypnhpnuA.exe running in task manager though. ???

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:19:23 AM, on 8/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ypnhpnuA.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Trend Micro\HijackThis\killer.exe.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [CtxfiReg] CTXFIREG.exe /FAIL2
O4 - HKLM\..\Run: [ypnhpnuA] C:\WINDOWS\ypnhpnuA.exe
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\prxernsp.dll
O10 - Unknown file in Winsock LSP: prxerdrv.dll
O10 - Unknown file in Winsock LSP: prxerdrv.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1178338978029
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1178341677451
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

–
End of file - 2638 bytes
Please do the following to show hidden files. To enable the viewing of Hidden files follow these steps: 1. Close all programs so that you are at your desktop. 2. Double-click on the My Computer icon. 3. Select the Tools menu and click Folder Options. 4. After the new window appears select the View tab. 5. Put a checkmark in the checkbox labeled Display the contents of system folders. 6. Under the Hidden files and folders section select the radio button labeled Show hidden files and folders. 7. Remove the checkmark from the checkbox labeled Hide file extensions for known file types. 8. Remove the checkmark from the checkbox labeled Hide protected operating system files. 9. Press the Apply button and then the OK button and shutdown My Computer. 10. Now your computer is configured to show all hidden files. Now attempt the procedures as outlined in my previous post. Regards, Trevuren
Great, I located and deleted the file.

Here is the HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:14:21 AM, on 8/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Electronic Arts\EA Link\Core.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Ryan\Desktop\NEED STUFF\BF2142_Update_1.25.exe
C:\Documents and Settings\Ryan\Desktop\NEED STUFF\BF2142_Update_1.25.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\killer.exe.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [ypnhpnuA] C:\WINDOWS\ypnhpnuA.exe
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EA Link\Core.exe" -silent
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\prxernsp.dll
O10 - Unknown file in Winsock LSP: prxerdrv.dll
O10 - Unknown file in Winsock LSP: prxerdrv.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1178338978029
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1178341677451
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

–
End of file - 2817 bytes


:thumbup:
1. Backup Your Registry with ERUNT
  • Please use the following link and scroll down to ERUNT and download it.
    http://aumha.org/freeware/freeware.php
  • For version with the Installer:
    Use the setup program to install ERUNT on your computer
  • For the zipped version:
    Unzip all the files into a folder of your choice.
Click Erunt.exe to backup your registry to the folder of your choice.

Note: to restore your registry, go to the folder and start ERDNT.exe


2. Launch Notepad, and copy/paste everything in the codebox below into the new document, including the word REGEDIT4. Go up to "File Save As" and click the drop-down box to change the "Save As Type" to "All Files" and save it to your desktop as fixme.reg.

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ypnhpnuA"=-


3. Locate fixme.reg on your Desktop. It should look like this [external image: Posted Image]. Double-click on it. You will receive a prompt similar to: "Do you wish to merge the information into the registry?". Answer Yes and wait for a message to appear similar to Merged Successfully.

4. Restart your computer.

5. Post a fresh HJT log.


Trevuren
Even after changing the save as drop box to All Files windows still doesn't recognize it as a registry file. I get an error message similar to "Cannot import fixme.reg. The specific file is not a registry script. You can only import binary registry files from within the registry editor.
1. Please download The Avenger by Swandog46 to your Desktop.
  • Click on Avenger.zip to open the file
  • Extract avenger.exe to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Files to delete:
C:\WINDOWS\ypnhpnuA.exe

Registry keys to delete:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|ypnhpnuA

Programs to launch on Reboot:
C:\Program Files\Trend Micro\HijackThis\killer.exe.exe

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, start The Avenger program by clicking on its icon on your desktop.
  • Under "Script file to execute" choose "Input Script Manually".
  • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
  • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
  • Click Done
  • Now click on the Green Light to begin execution of the script
  • Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log by using Add/Reply

Regards,

Trevuren
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\ojrvmthi

*******************

Script file located at: \??\C:\Documents and Settings\wdjtrpha.txt
Script file opened successfully.

Script file read successfully
Backups direct

File C:\WINDOWS\ypnhpnuA.exe not found!
Deletion of file C:\WINDOWS\ypnhpnuA.exe failed!

Could not process line:
C:\WINDOWS\ypnhpnuA.exe
Status: 0xc0000034



Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|ypnhpnuA not found!
Deletion of registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|ypnhpnuA failed!
Status: 0xc0000034

Program C:\Program Files\Trend Micro\HijackThis\killer.exe.exe successfully set up to run once on reboot.

Completed script processing.

*******************

Finished! Terminate.

HJT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:14:03 AM, on 8/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Electronic Arts\EA Link\Core.exe
C:\WINDOWS\system32\notepad.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\uTorrent\utorrent.exe
C:\Program Files\Trend Micro\HijackThis\killer.exe.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [ypnhpnuA] C:\WINDOWS\ypnhpnuA.exe
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EA Link\Core.exe" -silent
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\prxernsp.dll
O10 - Unknown file in Winsock LSP: prxerdrv.dll
O10 - Unknown file in Winsock LSP: prxerdrv.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1178338978029
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1178341677451
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

–
End of file - 2742 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI