This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Log Report

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:55:39 PM, on 7/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.6.14.dll
O2 - BHO: (no name) - {E26CEADA-67B0-4543-BE8B-307F00265118} - (no file)
O3 - Toolbar: (no name) - {29C5A3B6-9A8D-4FA0-B5AD-3E20F4AA5C00} - (no file)
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15030/CTSUEng.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1183088371265
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15030/CTPID.cab
O22 - SharedTaskScheduler: dustuck - {4a9e875b-d032-45e4-8294-789fe3be5b19} - C:\WINDOWS\system32\vgibz.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe

–
End of file - 4298 bytes
Hello radmghost and welcome to the TomCoyote Forums

My name is Trevuren and I will be helping you with your problem.


Please download this file - combofix.exe by sUBs
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log.
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

Regards,

Trevuren
new KJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:58:54 AM, on 7/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.6.14.dll
O2 - BHO: (no name) - {E26CEADA-67B0-4543-BE8B-307F00265118} - (no file)
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15030/CTSUEng.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1183088371265
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15030/CTPID.cab
O22 - SharedTaskScheduler: dustuck - {4a9e875b-d032-45e4-8294-789fe3be5b19} - C:\WINDOWS\system32\vgibz.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe

–
End of file - 3984 bytes



Comcfix log
"Paul" - 2007-07-18 9:49:04 - ComboFix 07-07-17.8 - Service Pack 2 NTFS


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\Paul\APPLIC~1.\macromedia\Flash Player\#SharedObjects\W64T8B4Y\www.broadcaster.com
C:\DOCUME~1\Paul\APPLIC~1.\macromedia\Flash Player\#SharedObjects\W64T8B4Y\www.broadcaster.com\played_list.sol
C:\DOCUME~1\Paul\APPLIC~1.\macromedia\Flash Player\#SharedObjects\W64T8B4Y\www.broadcaster.com\video_queue.sol
C:\DOCUME~1\Paul\APPLIC~1.\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\DOCUME~1\Paul\APPLIC~1.\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol


((((((((((((((((((((((((( Files Created from 2007-06-18 to 2007-07-18 )))))))))))))))))))))))))))))))


2007-07-18 09:48 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-17 19:45 d——– C:\Program Files\Trend Micro
2007-07-17 09:14 d-a—— C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-07-16 20:09 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-07-16 20:09 d——– C:\WINDOWS\system32\AGEIA
2007-07-16 20:09 d——– C:\Program Files\AGEIA Technologies
2007-07-15 19:06 d——– C:\Program Files\Kuma Games
2007-07-14 11:12 443,752 –a—— C:\WINDOWS\system32\d3dx10_33.dll
2007-07-14 11:12 3,495,784 –a—— C:\WINDOWS\system32\d3dx9_33.dll
2007-07-14 11:12 1,123,696 –a—— C:\WINDOWS\system32\D3DCompiler_33.dll
2007-07-13 18:31 d——– C:\Program Files\MSXML 6.0
2007-07-13 16:34 d——– C:\tmp
2007-07-13 16:31 81,920 –a—— C:\DOCUME~1\Paul\APPLIC~1\ezpinst.exe
2007-07-12 02:26 d——– C:\DOCUME~1\Paul\APPLIC~1\AdobeUM
2007-07-11 16:29 d——– C:\Program Files\Google
2007-07-10 02:19 81,768 –a—— C:\WINDOWS\system32\xinput1_3.dll
2007-07-10 02:19 62,744 –a—— C:\WINDOWS\system32\xinput1_2.dll
2007-07-10 02:19 3,426,072 –a—— C:\WINDOWS\system32\d3dx9_32.dll
2007-07-10 02:19 251,672 –a—— C:\WINDOWS\system32\xactengine2_5.dll
2007-07-10 02:19 237,848 –a—— C:\WINDOWS\system32\xactengine2_4.dll
2007-07-10 02:19 236,824 –a—— C:\WINDOWS\system32\xactengine2_3.dll
2007-07-10 02:19 2,414,360 –a—— C:\WINDOWS\system32\d3dx9_31.dll
2007-07-10 02:19 15,128 –a—— C:\WINDOWS\system32\x3daudio1_1.dll
2007-07-10 02:06 d——– C:\DOCUME~1\Paul\APPLIC~1\InstallShield
2007-07-10 02:04 d——– C:\Program Files\DAEMON Tools
2007-07-10 02:02 682,232 –a—— C:\WINDOWS\system32\drivers\sptd.sys
2007-07-09 10:43 108,144 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2007-07-09 10:43 dr-h—– C:\DOCUME~1\Paul\APPLIC~1\SecuROM
2007-07-09 07:24 d——– C:\Program Files\directx
2007-07-08 11:11 d——– C:\Program Files\MagicDVDCopier
2007-07-07 00:11 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\vsosdk
2007-07-07 00:10 87,608 –a—— C:\DOCUME~1\Paul\APPLIC~1\inst.exe
2007-07-07 00:10 47,360 –a—— C:\DOCUME~1\Paul\APPLIC~1\pcouffin.sys
2007-07-07 00:10 d——– C:\DOCUME~1\Paul\APPLIC~1\Vso
2007-07-06 23:58 d——– C:\Program Files\MagicDVDRipper
2007-07-05 15:20 86,016 –a—— C:\WINDOWS\unvise32qt.exe
2007-07-05 15:20 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
2007-07-05 15:19 d——– C:\WINDOWS\system32\QuickTime
2007-07-05 15:19 d——– C:\Program Files\QuickTime
2007-07-05 15:15 507,904 ——— C:\WINDOWS\Silent Hunter II remove.exe
2007-07-05 15:15 44,544 -ra—— C:\WINDOWS\dsetup.dll
2007-07-05 15:15 1,772,544 -ra—— C:\WINDOWS\dsetup32.dll
2007-07-05 15:15 d——– C:\Program Files\SSI
2007-07-03 21:16 3,840 –a—— C:\WINDOWS\system32\drivers\BANTExt.sys
2007-07-03 21:16 d——– C:\Program Files\Belarc
2007-07-02 13:42 d——– C:\DVDTemp
2007-07-02 13:32 47,360 –a—— C:\WINDOWS\system32\drivers\pcouffin.sys
2007-07-02 01:56 d——– C:\My Downloads
2007-07-02 01:36 d——– C:\DOCUME~1\Paul\APPLIC~1\DivX
2007-07-02 01:35 36,624 ——— C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-07-02 01:35 2,560 ——— C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-07-02 01:35 2,432 ——— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-07-02 01:35 129,784 ——— C:\WINDOWS\system32\pxafs.dll
2007-07-02 01:35 118,520 ——— C:\WINDOWS\system32\pxinsi64.exe
2007-07-02 01:35 116,472 ——— C:\WINDOWS\system32\pxcpyi64.exe
2007-07-02 01:34 d——– C:\Program Files\DivX
2007-07-02 01:28 d——– C:\Program Files\PowerISO
2007-07-01 21:46 d——– C:\Program Files\Ventrilo
2007-07-01 21:46 d——– C:\DOCUME~1\Paul\APPLIC~1\Ventrilo
2007-07-01 18:18 205,824 –a—— C:\WINDOWS\patchw32.dll
2007-07-01 18:14 28 –a—— C:\WINDOWS\system32\copytowin.bat
2007-07-01 18:14 205,824 –a—— C:\WINDOWS\system32\pw32a.dll
2007-07-01 18:14 205,824 –a—— C:\WINDOWS\pw32a.dll
2007-07-01 05:16 63 –a—— C:\WINDOWS\system\SYSRegC.dll
2007-07-01 05:16 143,360 –a—— C:\WINDOWS\system32\GetHardDiskNo.dll
2007-07-01 05:16 1,126,400 –a—— C:\WINDOWS\system32\VchReg.dll
2007-07-01 05:16 d——– C:\Program Files\Max Registry Cleaner
2007-07-01 05:03 1,230,336 –a—— C:\botpacked.exe
2007-07-01 02:05 d——– C:\Program Files\Lavasoft
2007-07-01 02:05 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-07-01 02:05 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-06-30 19:03 114,176 –a—— C:\kav.exe
2007-06-30 17:00 d——– C:\WINDOWS\pss
2007-06-30 16:58 786,432 –ah—– C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-06-30 16:53 26,832 –a—— C:\WINDOWS\system\CTL3DV2.DLL
2007-06-30 16:02 1 –a—— C:\DOCUME~1\Paul\SI.bin
2007-06-30 14:01 2,297,552 –a—— C:\WINDOWS\system32\d3dx9_26.dll
2007-06-30 14:01 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
2007-06-30 13:59 d——– C:\Program Files\Ubisoft
2007-06-30 13:56 d–hs—- C:\RECYCLER
2007-06-30 09:16 14,032 –a—— C:\WINDOWS\system\x3daudio1_0.dll
2007-06-30 08:54 d——– C:\DOCUME~1\Paul\APPLIC~1\WinRAR
2007-06-30 03:16 d——– C:\Program Files\MSBuild
2007-06-30 03:13 d——– C:\WINDOWS\system32\XPSViewer
2007-06-30 03:12 14,048 ——— C:\WINDOWS\system32\spmsg2.dll
2007-06-30 03:12 d——– C:\Program Files\Reference Assemblies
2007-06-30 03:03 d——– C:\WINDOWS\system32\ReinstallBackups
2007-06-30 03:00 d——– C:\WINDOWS\RegisteredPackages
2007-06-30 02:04 d——– C:\WINDOWS\system32\URTTemp
2007-06-30 02:01 36,352 ——— C:\WINDOWS\system32\tsgqec.dll
2007-06-30 02:01 288,768 ——— C:\WINDOWS\system32\rhttpaa.dll
2007-06-30 02:01 116,736 ——— C:\WINDOWS\system32\aaclient.dll
2007-06-29 20:10 0 –a—— C:\WINDOWS\PowerReg.dat
2007-06-29 18:50 306,688 –a—— C:\WINDOWS\IsUninst.exe
2007-06-29 18:50 d——– C:\DOCUME~1\Paul\WINDOWS
2007-06-29 17:20 d——– C:\WINDOWS\aod
2007-06-29 17:20 d——– C:\DOCUME~1\Paul\APPLIC~1\ICQ
2007-06-29 17:19 d——– C:\Program Files\ICQ
2007-06-29 14:29 d——– C:\Program Files\CDBurnerXP Pro 3
2007-06-29 13:44 d——– C:\Downloads


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-17 14:39:43 39,932 –sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2007-07-17 14:39:43 161,024 –sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-06-30 06:51:07 359,808 —-a-w C:\WINDOWS\system32\drivers\tcpip.sys
2007-06-29 22:20:16 457 —-a-w C:\Program Files\INSTALL.LOG
2007-06-29 18:44:19 2,560 —-a-w C:\WINDOWS\system32\BitCometRes.dll
2007-06-13 19:50:17 43,152 —-a-w C:\WINDOWS\system32\drivers\ativvpxx.vp
2007-06-13 19:25:36 339,968 —-a-w C:\WINDOWS\system32\ATIDEMGX.dll
2007-06-13 19:24:32 268,288 —-a-w C:\WINDOWS\system32\ati2dvag.dll
2007-06-13 19:24:13 2,155,520 —-a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-06-13 19:23:23 307,200 —-a-w C:\WINDOWS\system32\atiiiexx.dll
2007-06-13 19:17:37 139,264 —-a-w C:\WINDOWS\system32\atipdlxx.dll
2007-06-13 19:17:26 118,784 —-a-w C:\WINDOWS\system32\Oemdspif.dll
2007-06-13 19:17:18 26,112 —-a-w C:\WINDOWS\system32\Ati2mdxx.exe
2007-06-13 19:17:12 42,496 —-a-w C:\WINDOWS\system32\ati2edxx.dll
2007-06-13 19:16:59 118,784 —-a-w C:\WINDOWS\system32\ati2evxx.dll
2007-06-13 19:15:39 483,328 —-a-w C:\WINDOWS\system32\ati2evxx.exe
2007-06-13 19:14:51 53,248 —-a-w C:\WINDOWS\system32\ATIDDC.DLL
2007-06-13 19:10:33 8,097,792 —-a-w C:\WINDOWS\system32\atioglx2.dll
2007-06-13 19:07:26 2,922,208 —-a-w C:\WINDOWS\system32\ati3duag.dll
2007-06-13 18:57:21 1,512,960 —-a-w C:\WINDOWS\system32\ativvaxx.dll
2007-06-13 18:57:04 972,072 —-a-w C:\WINDOWS\system32\ativva6x.dat
2007-06-13 18:57:04 3,107,788 —-a-w C:\WINDOWS\system32\ativvaxx.dat
2007-06-13 18:57:04 3,107,788 —-a-w C:\WINDOWS\system32\ativva5x.dat
2007-06-13 18:46:28 5,431,296 —-a-w C:\WINDOWS\system32\atioglxx.dll
2007-06-13 18:43:53 262,144 —-a-w C:\WINDOWS\system32\atikvmag.dll
2007-06-13 18:42:29 17,408 —-a-w C:\WINDOWS\system32\atitvo32.dll
2007-06-13 18:41:46 49,152 —-a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2007-06-13 18:41:06 50,176 —-a-w C:\WINDOWS\system32\atiok3x2.dll
2007-06-13 18:36:45 368,640 —-a-w C:\WINDOWS\system32\ati2cqag.dll
2007-06-04 20:18:48 9,344 —-a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 20:17:02 8,320 —-a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 20:14:56 6,272 —-a-w C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-05-31 06:45:07 524,288 —-a-w C:\WINDOWS\system32\DivXsm.exe
2007-05-31 06:44:55 823,296 —-a-w C:\WINDOWS\system32\divx_xx07.dll
2007-05-31 06:44:54 823,296 —-a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-05-31 06:44:54 802,816 —-a-w C:\WINDOWS\system32\divx_xx11.dll
2007-05-31 06:44:54 740,442 —-a-w C:\WINDOWS\system32\DivX.dll
2007-05-20 03:37:14 206,352 —-a-w C:\WINDOWS\system32\klogon.dll
2007-05-20 03:36:24 22,354 —-a-w C:\WINDOWS\system32\drivers\klop.dat
2007-05-16 00:06:58 71,208 —-a-w C:\WINDOWS\system32\PhysXLoader.dll
2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-23 00:15:29 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2007-04-23 00:15:18 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2007-04-23 00:15:18 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
2007-04-23 00:02:34 73,728 —-a-w C:\WINDOWS\system32\dpl100.dll
2007-04-23 00:02:34 196,608 —-a-w C:\WINDOWS\system32\dtu100.dll
2007-04-23 00:02:33 53,248 —-a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-04-23 00:02:31 593,920 —-a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-04-23 00:02:31 57,344 —-a-w C:\WINDOWS\system32\dpv11.dll
2007-04-23 00:02:31 344,064 —-a-w C:\WINDOWS\system32\dpus11.dll
2007-04-23 00:02:31 294,912 —-a-w C:\WINDOWS\system32\dpu11.dll
2007-04-23 00:02:31 294,912 —-a-w C:\WINDOWS\system32\dpu10.dll
2007-04-23 00:01:47 12,288 —-a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-04-23 00:01:46 124,472 —-a-w C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2003-11-03 14:17 54248 –a—— C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
2007-06-14 08:07 443968 –a—— C:\Program Files\BitComet\tools\BitCometBHO_1.1.6.14.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E26CEADA-67B0-4543-BE8B-307F00265118}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2007-05-19 22:36]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{4a9e875b-d032-45e4-8294-789fe3be5b19}"="C:\WINDOWS\system32\vgibz.dll" [2007-07-16 20:09]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Paul^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
backup=C:\WINDOWS\pss\PowerReg Scheduler.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Watch]
C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP]
"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
"C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mirabilis ICQ]
C:\PROGRA~1\ICQ\ICQNet.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P17Helper]
Rundll32 P17.dll,P17Helper

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RCSystemTray]
C:\Program Files\Max Registry Cleaner\MaxRCSystemTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\svchst]
C:\PROGRA~1\INTERN~1\svchst.exe

*Newly Created Service* - RSVP

**************************************************************************

catchme 0.3.1040 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-18 09:50:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-18 9:55:37
C:\ComboFix-quarantined-files.txt … 2007-07-18 09:51

— E O F —
Please provide a list of uninstallable programs.

To Provide a List of Installed Programs
  • Run HijackThis.
  • Click Config>>Miscellaneous Tools>>Open Uninstall Manager>>Save List
  • Save list to Desktop
  • Copy the Notepad list and Paste it into this thread.

Trevuren
Uninstall list: Ad-Aware 2007 Adobe Flash Player 9 ActiveX Adobe Reader 6.0.1 AGEIA PhysX v7.05.17 ATI Display Driver Belarc Advisor 7.2 BitComet 0.90 CDBurnerXP Pro 3 DivX Codec DivX Content Uploader DivX Converter DivX Player DivX Web Player Falcon 4.0: Allied Force Google Video Player Harry Potter and the Order of the Phoenix™ HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.0 (KB932471) Hotfix for Windows Media Format SDK (KB902344) Hotfix for Windows XP (KB896344) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) ICQ Kaspersky Anti-Virus 7.0 Kaspersky Anti-Virus 7.0 Magic DVD Copier V4.4.3 Magic DVD Ripper V5.0.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Microsoft .NET Framework 3.0 Microsoft .NET Framework 3.0 Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Visual C++ 2005 Redistributable MSXML 6.0 Parser NVIDIA Drivers PowerISO QuickTime Registry Cleaner 6.0.0.016 Security Update for Microsoft .NET Framework 2.0 (KB928365) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB917734) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933566) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Silent Hunter 4 Wolves of the Pacific Super DVD Creator 9.30 Tom Clancy's Ghost Recon Advanced Warfighter® 2 Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920342) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB925720) Update for Windows XP (KB925876) Update for Windows XP (KB927891) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Ventrilo Windows Communication Foundation Windows Imaging Component Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Media Format Runtime Windows Media Format SDK Hotfix - KB891122 Windows Presentation Foundation Windows Workflow Foundation Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 WinRAR archiver
Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Double-click smitfraudfix.exe
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc…processutil.htm


Regards,

Trevuren
SmitFraudFix v2.204 Scan done at 19:16:41.04, Wed 07/18/2007 Run from C:\Documents and Settings\Paul\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe C:\WINDOWS\explorer.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\cmd.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Paul »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Paul\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Paul\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{4a9e875b-d032-45e4-8294-789fe3be5b19}"="dustuck" [HKEY_CLASSES_ROOT\CLSID\{4a9e875b-d032-45e4-8294-789fe3be5b19}\InProcServer32] @="C:\WINDOWS\system32\vgibz.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{4a9e875b-d032-45e4-8294-789fe3be5b19}\InProcServer32] @="C:\WINDOWS\system32\vgibz.dll" »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: Realtek RTL8139 Family PCI Fast Ethernet NIC - Packet Scheduler Miniport DNS Server Search Order: 192.168.1.254 HKLM\SYSTEM\CCS\Services\Tcpip\..\{88AD51AA-9F12-44CB-B861-891EC24ECC41}: DhcpNameServer=192.168.1.254 HKLM\SYSTEM\CS1\Services\Tcpip\..\{88AD51AA-9F12-44CB-B861-891EC24ECC41}: DhcpNameServer=192.168.1.254 HKLM\SYSTEM\CS2\Services\Tcpip\..\{88AD51AA-9F12-44CB-B861-891EC24ECC41}: DhcpNameServer=192.168.1.254 HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254 HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254 HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254 »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
Please print out or copy these instructions/tutorial to Notepad as the internet will not be available to you at certain points of the removal process (while in Safe Mode). Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.


1. Download and update AVG AntiSpyware 7.5.

First download AVG AntiSpyware from HERE and save that file to your desktop.
This is a 30 day trial of the program
  • Once you have downloaded AVG AntiSpyware, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete, run AVG AntiSpyware and update the definition files.
  • On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close AVG AntiSpyware, Do Not run a scan just yet


2. Reboot your computer into Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
3. Once in Safe Mode, double-click Smitfraudfix.exe
Select option #2 - Clean by typing 2 and press Enter to delete the infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
The tool will now check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.


4. Clean out your Temporary Internet files. Proceed as follows:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.

5. Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

6. Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.

7. Launch AVG AntiSpyware by double-clicking the icon on your desktop.
  • Note: IMPORTANT: Do not open any other windows or programs while AVG AntiSpyware is scanning, it may interfere with the scanning proccess
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  • AVG AntiSpyware will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
8. Close AVG AntiSpyware and Reboot back into Normal Windows Mode

9. Run SmitfraudFix. Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #3 - Delete Trusted zone by typing 3 and press Enter
Answer YES to the question "Restore Trusted Zone?" by Typing Y and hit Enter.

Note, if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.

10. Please Post the following logs:
  • c:\rapport.txt
  • AVG AntiSpyware log
  • A new HijackThis log
Your may need several replies to post the requested logs, otherwise they might get cut off.

Regards,

Trevuren
:D Thanks for your Help after following all the steps ypu provided, except posting reports; it has cleared my problem. If ever I run into this type of situation again I will definatly look you guys up, also will recommend you to my friends. Again Thank You :D
I fixed the problem that was annoying you. There are still probably more malware on your system. If you want a clean system, I strongly encourage you to continue with the procedures and start by posting a new HijackThis log. Trevuren
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI