This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Baseline

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My internet service has been suspended several times in the past two months for sending bulk spam e-mail.

Have updated windows and antivirus programs but have been hit again.

We have 5 user accounts. The system is most entertainment oriented (online games, myspace, youtube, funny videos) and creating videos (my kids do that I wouldn't know how). I don't remember what I used to do anymore, I stay up all night cleaning the system and studying the registry tryng to make sense of it all.

I'm glad my Internet service has been proactive in stopping illegal actions. I'm not so glad that I could get deported to Guantanamo (?).

I've managed to delete everthing but the rootkits and the viruses.

Some start up registries that would otherwise have shown up have been disabled through either S&D or directly by me through administrator tools, but this HJT log has the Ignore products restored. You may notice alot of network services are absent, that was my previous effort to prevent remote activation (we do not use).

Here is my tattered start up log as a baseline. PS there are more problems such as antivirus programs not working properly. :

Logfile of HijackThis v1.99.1
Scan saved at 3:08:53 AM, on 7/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\ehkxnv.exe
C:\WINDOWS\Resources\mdm.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PestPatrolCL.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\Mine\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\WINDOWS\system32\msiexec.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENWW/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Documents and Settings\Deanna 2.CUDDLES\My Documents\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [adcrdv] C:\WINDOWS\system32\adcrdv.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ajhxtyqgtze] C:\WINDOWS\system32\ajhxtyqgtze.exe
O4 - HKLM\..\Run: [akepgexz] C:\WINDOWS\system32\akepgexz.exe
O4 - HKLM\..\Run: [atkeuaqtglto] C:\WINDOWS\system32\atkeuaqtglto.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [bivwwr] C:\WINDOWS\system32\bivwwr.exe
O4 - HKLM\..\Run: [ccdhqihdat] C:\WINDOWS\system32\ccdhqihdat.exe
O4 - HKLM\..\Run: [cypmqzqzwat] C:\WINDOWS\system32\cypmqzqzwat.exe
O4 - HKLM\..\Run: [czogma] C:\WINDOWS\system32\czogma.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [dfdzx] C:\WINDOWS\system32\dfdzx.exe
O4 - HKLM\..\Run: [dkbhapwkch] C:\WINDOWS\system32\dkbhapwkch.exe
O4 - HKLM\..\Run: [dlgwpfkdd] C:\WINDOWS\system32\dlgwpfkdd.exe
O4 - HKLM\..\Run: [ehkxnv] C:\WINDOWS\system32\ehkxnv.exe
O4 - HKLM\..\Run: [euhmkni] C:\WINDOWS\system32\euhmkni.exe
O4 - HKLM\..\Run: [evibzsb] C:\WINDOWS\system32\evibzsb.exe
O4 - HKLM\..\Run: [fapqunidij] C:\WINDOWS\system32\fapqunidij.exe
O4 - HKLM\..\Run: [ffkjkgk] C:\WINDOWS\system32\ffkjkgk.exe
O4 - HKLM\..\Run: [fole] C:\WINDOWS\system32\fole.exe
O4 - HKLM\..\Run: [fyhmkqdk] C:\WINDOWS\system32\fyhmkqdk.exe
O4 - HKLM\..\Run: [fyzogzmhqxpq] C:\WINDOWS\system32\fyzogzmhqxpq.exe
O4 - HKLM\..\Run: [gd] C:\WINDOWS\system32\gd.exe
O4 - HKLM\..\Run: [ggo] C:\WINDOWS\system32\ggo.exe
O4 - HKLM\..\Run: [gprdm] C:\WINDOWS\system32\gprdm.exe
O4 - HKLM\..\Run: [grkqmmidmav] C:\WINDOWS\system32\grkqmmidmav.exe
O4 - HKLM\..\Run: [gxqfz] C:\WINDOWS\system32\gxqfz.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [howfviiwvd] C:\WINDOWS\system32\howfviiwvd.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [hrr] C:\WINDOWS\system32\hrr.exe
O4 - HKLM\..\Run: [hvsbquk] C:\WINDOWS\system32\hvsbquk.exe
O4 - HKLM\..\Run: [hymjnwhnieoh] C:\WINDOWS\system32\hymjnwhnieoh.exe
O4 - HKLM\..\Run: [ict] C:\WINDOWS\system32\ict.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [ik] C:\WINDOWS\system32\ik.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [joarnpz] C:\WINDOWS\system32\joarnpz.exe
O4 - HKLM\..\Run: [jzrgy] C:\WINDOWS\system32\jzrgy.exe
O4 - HKLM\..\Run: [kbmoadnmz] C:\WINDOWS\system32\kbmoadnmz.exe
O4 - HKLM\..\Run: [klnkoqpb] C:\WINDOWS\system32\klnkoqpb.exe
O4 - HKLM\..\Run: [ksmgwp] C:\WINDOWS\system32\ksmgwp.exe
O4 - HKLM\..\Run: [kzhdssu] C:\WINDOWS\system32\kzhdssu.exe
O4 - HKLM\..\Run: [lgmsy] C:\WINDOWS\system32\lgmsy.exe
O4 - HKLM\..\Run: [lpitgrltjvqy] C:\WINDOWS\system32\lpitgrltjvqy.exe
O4 - HKLM\..\Run: [lwrwbxlflw] C:\WINDOWS\system32\lwrwbxlflw.exe
O4 - HKLM\..\Run: [lycgbhhkg] C:\WINDOWS\system32\lycgbhhkg.exe
O4 - HKLM\..\Run: [m] C:\WINDOWS\system32\m.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [muijk] C:\WINDOWS\system32\muijk.exe
O4 - HKLM\..\Run: [n] C:\WINDOWS\system32\n.exe
O4 - HKLM\..\Run: [nagjhzgkucq] C:\WINDOWS\system32\nagjhzgkucq.exe
O4 - HKLM\..\Run: [nvi] C:\WINDOWS\system32\nvi.exe
O4 - HKLM\..\Run: [ofvsuimbk] C:\WINDOWS\system32\ofvsuimbk.exe
O4 - HKLM\..\Run: [ogvjbomutmgu] C:\WINDOWS\system32\ogvjbomutmgu.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PestPatrolCL] C:\PROGRA~1\PESTPA~1\PestPatrolCL.exe c:\
O4 - HKLM\..\Run: [pg] C:\WINDOWS\system32\pg.exe
O4 - HKLM\..\Run: [pof] C:\WINDOWS\system32\pof.exe
O4 - HKLM\..\Run: [pqvfejequbr] C:\WINDOWS\system32\pqvfejequbr.exe
O4 - HKLM\..\Run: [prnpqx] C:\WINDOWS\system32\prnpqx.exe
O4 - HKLM\..\Run: [pvvpadwy] C:\WINDOWS\system32\pvvpadwy.exe
O4 - HKLM\..\Run: [qlcsz] C:\WINDOWS\system32\qlcsz.exe
O4 - HKLM\..\Run: [qvicwnxpcu] C:\WINDOWS\system32\qvicwnxpcu.exe
O4 - HKLM\..\Run: [rab] C:\WINDOWS\system32\rab.exe
O4 - HKLM\..\Run: [rtbkm] C:\WINDOWS\system32\rtbkm.exe
O4 - HKLM\..\Run: [rtmiqwwt] C:\WINDOWS\system32\rtmiqwwt.exe
O4 - HKLM\..\Run: [rxgqdxuoqr] C:\WINDOWS\system32\rxgqdxuoqr.exe
O4 - HKLM\..\Run: [sqmtmzlwz] C:\WINDOWS\system32\sqmtmzlwz.exe
O4 - HKLM\..\Run: [srcsqsf] C:\WINDOWS\system32\srcsqsf.exe
O4 - HKLM\..\Run: [uc] C:\WINDOWS\system32\uc.exe
O4 - HKLM\..\Run: [uoyqpabd] C:\WINDOWS\system32\uoyqpabd.exe
O4 - HKLM\..\Run: [urzyysdasfh] C:\WINDOWS\system32\urzyysdasfh.exe
O4 - HKLM\..\Run: [uumhy] C:\WINDOWS\system32\uumhy.exe
O4 - HKLM\..\Run: [vc] C:\WINDOWS\system32\vc.exe
O4 - HKLM\..\Run: [vf] C:\WINDOWS\system32\vf.exe
O4 - HKLM\..\Run: [vlfompskx] C:\WINDOWS\system32\vlfompskx.exe
O4 - HKLM\..\Run: [vvc] C:\WINDOWS\system32\vvc.exe
O4 - HKLM\..\Run: [vya] C:\WINDOWS\system32\vya.exe
O4 - HKLM\..\Run: [vysmpvzmpihd] C:\WINDOWS\system32\vysmpvzmpihd.exe
O4 - HKLM\..\Run: [w] C:\WINDOWS\system32\w.exe
O4 - HKLM\..\Run: [wbs] C:\WINDOWS\system32\wbs.exe
O4 - HKLM\..\Run: [wf] C:\WINDOWS\system32\wf.exe
O4 - HKLM\..\Run: [xbi] C:\WINDOWS\system32\xbi.exe
O4 - HKLM\..\Run: [xd] C:\WINDOWS\system32\xd.exe
O4 - HKLM\..\Run: [xtvymox] C:\WINDOWS\system32\xtvymox.exe
O4 - HKLM\..\Run: [xx] C:\WINDOWS\system32\xx.exe
O4 - HKLM\..\Run: [ybk] C:\WINDOWS\system32\ybk.exe
O4 - HKLM\..\Run: [ybtvjuz] C:\WINDOWS\system32\ybtvjuz.exe
O4 - HKLM\..\Run: [yi] C:\WINDOWS\system32\yi.exe
O4 - HKLM\..\Run: [yrc] C:\WINDOWS\system32\yrc.exe
O4 - HKLM\..\Run: [zdpq] C:\WINDOWS\system32\zdpq.exe
O4 - HKLM\..\Run: [csziqestx] C:\WINDOWS\system32\csziqestx.exe
O4 - HKLM\..\Run: [pb] C:\WINDOWS\system32\pb.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunServices: [ehkxnv] C:\WINDOWS\system32\ehkxnv.exe
O4 - HKLM\..\RunServices: [csziqestx] C:\WINDOWS\system32\csziqestx.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [HijackThis startup scan] C:\DOCUME~1\Mine\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe /startupscan
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase8300.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://msnuk.oberon-media.com//online2/MSN…mjolauncher.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Print Spooler Service (et9o22aa3xlsike) - Unknown owner - C:\WINDOWS\system32\ehkxnv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Machine Debug Manager (MCH_Debug) - Unknown owner - C:\WINDOWS\Resources\mdm.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
_________________________________
Welcome to the Forums.

The fixes we will use are specific to your problems and should only be used for this issue on this machine.

PLease follow my instructions in the order given!!

Please only use this topic to reply to. Do not start another thread.
If any other issues arise let me know.
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear. So lets do this to the end!
Please if you decide to seek help at another forum let us know. There is a shortage of helpers and tying 2 of us up is a waste of time.
If you have any questions about any advice given here please STOP and ask!


WHEW! What a mess. Please keep the kids from downloading anything untill we clean this up.


_______________________________________
THIS IS IMPORTANT!!
You are running HJT directly from A temporary diectory.
Create a folder called HJT either in C: or My documents or some place convienient and place the
hijackthis.exe in there.
This will ensure we have back ups made and it doesn't get deleted .






___________________________________
Please disable SpybotSD TeaTimer, as it may hinder the removal of the infection. You can enable it after you're clean.
To disable SpybotSD TeaTimer:
Open Spybot and click on Mode and check Advanced Mode
Check yes to next window.
Click on Tools in bottom left hand corner.
Click on System Startup icon.
Uncheck Teatimer box.
Click Allow Change box.




______________________________
HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked






R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)

O4 - HKLM\..\Run: [adcrdv] C:\WINDOWS\system32\adcrdv.exe
O4 - HKLM\..\Run: [ajhxtyqgtze] C:\WINDOWS\system32\ajhxtyqgtze.exe
O4 - HKLM\..\Run: [akepgexz] C:\WINDOWS\system32\akepgexz.exe
O4 - HKLM\..\Run: [atkeuaqtglto] C:\WINDOWS\system32\atkeuaqtglto.exe
O4 - HKLM\..\Run: [bivwwr] C:\WINDOWS\system32\bivwwr.exe
O4 - HKLM\..\Run: [ccdhqihdat] C:\WINDOWS\system32\ccdhqihdat.exe
O4 - HKLM\..\Run: [cypmqzqzwat] C:\WINDOWS\system32\cypmqzqzwat.exe
O4 - HKLM\..\Run: [czogma] C:\WINDOWS\system32\czogma.exe
O4 - HKLM\..\Run: [dfdzx] C:\WINDOWS\system32\dfdzx.exe
O4 - HKLM\..\Run: [dkbhapwkch] C:\WINDOWS\system32\dkbhapwkch.exe
O4 - HKLM\..\Run: [dlgwpfkdd] C:\WINDOWS\system32\dlgwpfkdd.exe
O4 - HKLM\..\Run: [ehkxnv] C:\WINDOWS\system32\ehkxnv.exe
O4 - HKLM\..\Run: [euhmkni] C:\WINDOWS\system32\euhmkni.exe
O4 - HKLM\..\Run: [evibzsb] C:\WINDOWS\system32\evibzsb.exe
O4 - HKLM\..\Run: [fapqunidij] C:\WINDOWS\system32\fapqunidij.exe
O4 - HKLM\..\Run: [ffkjkgk] C:\WINDOWS\system32\ffkjkgk.exe
O4 - HKLM\..\Run: [fole] C:\WINDOWS\system32\fole.exe
O4 - HKLM\..\Run: [fyhmkqdk] C:\WINDOWS\system32\fyhmkqdk.exe
O4 - HKLM\..\Run: [fyzogzmhqxpq] C:\WINDOWS\system32\fyzogzmhqxpq.exe
O4 - HKLM\..\Run: [gd] C:\WINDOWS\system32\gd.exe
O4 - HKLM\..\Run: [ggo] C:\WINDOWS\system32\ggo.exe
O4 - HKLM\..\Run: [gprdm] C:\WINDOWS\system32\gprdm.exe
O4 - HKLM\..\Run: [grkqmmidmav] C:\WINDOWS\system32\grkqmmidmav.exe
O4 - HKLM\..\Run: [gxqfz] C:\WINDOWS\system32\gxqfz.exe
O4 - HKLM\..\Run: [howfviiwvd] C:\WINDOWS\system32\howfviiwvd.exe
O4 - HKLM\..\Run: [hrr] C:\WINDOWS\system32\hrr.exe
O4 - HKLM\..\Run: [hvsbquk] C:\WINDOWS\system32\hvsbquk.exe
O4 - HKLM\..\Run: [hymjnwhnieoh] C:\WINDOWS\system32\hymjnwhnieoh.exe
O4 - HKLM\..\Run: [ict] C:\WINDOWS\system32\ict.exe
O4 - HKLM\..\Run: [ik] C:\WINDOWS\system32\ik.exe
O4 - HKLM\..\Run: [joarnpz] C:\WINDOWS\system32\joarnpz.exe
O4 - HKLM\..\Run: [jzrgy] C:\WINDOWS\system32\jzrgy.exe
O4 - HKLM\..\Run: [kbmoadnmz] C:\WINDOWS\system32\kbmoadnmz.exe
O4 - HKLM\..\Run: [klnkoqpb] C:\WINDOWS\system32\klnkoqpb.exe
O4 - HKLM\..\Run: [ksmgwp] C:\WINDOWS\system32\ksmgwp.exe
O4 - HKLM\..\Run: [kzhdssu] C:\WINDOWS\system32\kzhdssu.exe
O4 - HKLM\..\Run: [lgmsy] C:\WINDOWS\system32\lgmsy.exe
O4 - HKLM\..\Run: [lpitgrltjvqy] C:\WINDOWS\system32\lpitgrltjvqy.exe
O4 - HKLM\..\Run: [lwrwbxlflw] C:\WINDOWS\system32\lwrwbxlflw.exe
O4 - HKLM\..\Run: [lycgbhhkg] C:\WINDOWS\system32\lycgbhhkg.exe
O4 - HKLM\..\Run: [m] C:\WINDOWS\system32\m.exe
O4 - HKLM\..\Run: [muijk] C:\WINDOWS\system32\muijk.exe
O4 - HKLM\..\Run: [n] C:\WINDOWS\system32\n.exe
O4 - HKLM\..\Run: [nagjhzgkucq] C:\WINDOWS\system32\nagjhzgkucq.exe
O4 - HKLM\..\Run: [nvi] C:\WINDOWS\system32\nvi.exe
O4 - HKLM\..\Run: [ofvsuimbk] C:\WINDOWS\system32\ofvsuimbk.exe
O4 - HKLM\..\Run: [ogvjbomutmgu] C:\WINDOWS\system32\ogvjbomutmgu.exe
O4 - HKLM\..\Run: [pg] C:\WINDOWS\system32\pg.exe
O4 - HKLM\..\Run: [pof] C:\WINDOWS\system32\pof.exe
O4 - HKLM\..\Run: [pqvfejequbr] C:\WINDOWS\system32\pqvfejequbr.exe
O4 - HKLM\..\Run: [prnpqx] C:\WINDOWS\system32\prnpqx.exe
O4 - HKLM\..\Run: [pvvpadwy] C:\WINDOWS\system32\pvvpadwy.exe
O4 - HKLM\..\Run: [qlcsz] C:\WINDOWS\system32\qlcsz.exe
O4 - HKLM\..\Run: [qvicwnxpcu] C:\WINDOWS\system32\qvicwnxpcu.exe
O4 - HKLM\..\Run: [rab] C:\WINDOWS\system32\rab.exe
O4 - HKLM\..\Run: [rtbkm] C:\WINDOWS\system32\rtbkm.exe
O4 - HKLM\..\Run: [rtmiqwwt] C:\WINDOWS\system32\rtmiqwwt.exe
O4 - HKLM\..\Run: [rxgqdxuoqr] C:\WINDOWS\system32\rxgqdxuoqr.exe
O4 - HKLM\..\Run: [sqmtmzlwz] C:\WINDOWS\system32\sqmtmzlwz.exe
O4 - HKLM\..\Run: [srcsqsf] C:\WINDOWS\system32\srcsqsf.exe
O4 - HKLM\..\Run: [uc] C:\WINDOWS\system32\uc.exe
O4 - HKLM\..\Run: [uoyqpabd] C:\WINDOWS\system32\uoyqpabd.exe
O4 - HKLM\..\Run: [urzyysdasfh] C:\WINDOWS\system32\urzyysdasfh.exe
O4 - HKLM\..\Run: [uumhy] C:\WINDOWS\system32\uumhy.exe
O4 - HKLM\..\Run: [vc] C:\WINDOWS\system32\vc.exe
O4 - HKLM\..\Run: [vf] C:\WINDOWS\system32\vf.exe
O4 - HKLM\..\Run: [vlfompskx] C:\WINDOWS\system32\vlfompskx.exe
O4 - HKLM\..\Run: [vvc] C:\WINDOWS\system32\vvc.exe
O4 - HKLM\..\Run: [vya] C:\WINDOWS\system32\vya.exe
O4 - HKLM\..\Run: [vysmpvzmpihd] C:\WINDOWS\system32\vysmpvzmpihd.exe
O4 - HKLM\..\Run: [w] C:\WINDOWS\system32\w.exe
O4 - HKLM\..\Run: [wbs] C:\WINDOWS\system32\wbs.exe
O4 - HKLM\..\Run: [wf] C:\WINDOWS\system32\wf.exe
O4 - HKLM\..\Run: [xbi] C:\WINDOWS\system32\xbi.exe
O4 - HKLM\..\Run: [xd] C:\WINDOWS\system32\xd.exe
O4 - HKLM\..\Run: [xtvymox] C:\WINDOWS\system32\xtvymox.exe
O4 - HKLM\..\Run: [xx] C:\WINDOWS\system32\xx.exe
O4 - HKLM\..\Run: [ybk] C:\WINDOWS\system32\ybk.exe
O4 - HKLM\..\Run: [ybtvjuz] C:\WINDOWS\system32\ybtvjuz.exe
O4 - HKLM\..\Run: [yi] C:\WINDOWS\system32\yi.exe
O4 - HKLM\..\Run: [yrc] C:\WINDOWS\system32\yrc.exe
O4 - HKLM\..\Run: [zdpq] C:\WINDOWS\system32\zdpq.exe
O4 - HKLM\..\Run: [csziqestx] C:\WINDOWS\system32\csziqestx.exe
O4 - HKLM\..\Run: [pb] C:\WINDOWS\system32\pb.exe
O4 - HKLM\..\RunServices: [ehkxnv] C:\WINDOWS\system32\ehkxnv.exe
O4 - HKLM\..\RunServices: [csziqestx] C:\WINDOWS\system32\csziqestx.exe






Please download the OTMoveIt by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\adcrdv.exe
    C:\WINDOWS\system32\ajhxtyqgtze.exe
    C:\WINDOWS\system32\akepgexz.exe
    C:\WINDOWS\system32\atkeuaqtglto.exe
    C:\WINDOWS\system32\bivwwr.exe
    C:\WINDOWS\system32\ccdhqihdat.exe
    C:\WINDOWS\system32\cypmqzqzwat.exe
    C:\WINDOWS\system32\czogma.exe
    C:\WINDOWS\system32\dfdzx.exe
    C:\WINDOWS\system32\dkbhapwkch.exe
    C:\WINDOWS\system32\dlgwpfkdd.exe
    C:\WINDOWS\system32\ehkxnv.exe
    C:\WINDOWS\system32\euhmkni.exe
    C:\WINDOWS\system32\evibzsb.exe
    C:\WINDOWS\system32\fapqunidij.exe
    C:\WINDOWS\system32\ffkjkgk.exe
    C:\WINDOWS\system32\fole.exe
    C:\WINDOWS\system32\fyhmkqdk.exe
    C:\WINDOWS\system32\fyzogzmhqxpq.exe
    C:\WINDOWS\system32\gd.exe
    C:\WINDOWS\system32\ggo.exe
    C:\WINDOWS\system32\gprdm.exe
    C:\WINDOWS\system32\grkqmmidmav.exe
    C:\WINDOWS\system32\gxqfz.exe
    C:\WINDOWS\system32\howfviiwvd.exe
    C:\WINDOWS\system32\hrr.exe
    C:\WINDOWS\system32\hvsbquk.exe
    C:\WINDOWS\system32\hymjnwhnieoh.exe
    C:\WINDOWS\system32\ict.exe
    C:\WINDOWS\system32\ik.exe
    C:\WINDOWS\system32\joarnpz.exe
    C:\WINDOWS\system32\jzrgy.exe
    C:\WINDOWS\system32\kbmoadnmz.exe
    C:\WINDOWS\system32\klnkoqpb.exe
    C:\WINDOWS\system32\ksmgwp.exe
    C:\WINDOWS\system32\kzhdssu.exe
    C:\WINDOWS\system32\lgmsy.exe
    C:\WINDOWS\system32\lpitgrltjvqy.exe
    C:\WINDOWS\system32\lwrwbxlflw.exe
    C:\WINDOWS\system32\lycgbhhkg.exe
    C:\WINDOWS\system32\m.exe
    C:\WINDOWS\system32\muijk.exe
    C:\WINDOWS\system32\n.exe
    C:\WINDOWS\system32\nagjhzgkucq.exe
    C:\WINDOWS\system32\nvi.exe
    C:\WINDOWS\system32\ofvsuimbk.exe
    C:\WINDOWS\system32\ogvjbomutmgu.exe
    C:\WINDOWS\system32\pg.exe
    C:\WINDOWS\system32\pof.exe
    C:\WINDOWS\system32\pqvfejequbr.exe
    C:\WINDOWS\system32\prnpqx.exe
    C:\WINDOWS\system32\pvvpadwy.exe
    C:\WINDOWS\system32\qlcsz.exe
    C:\WINDOWS\system32\qvicwnxpcu.exe
    C:\WINDOWS\system32\rab.exe
    C:\WINDOWS\system32\rtbkm.exe
    C:\WINDOWS\system32\rtmiqwwt.exe
    C:\WINDOWS\system32\rxgqdxuoqr.exe
    C:\WINDOWS\system32\sqmtmzlwz.exe
    C:\WINDOWS\system32\srcsqsf.exe
    C:\WINDOWS\system32\uc.exe
    C:\WINDOWS\system32\uoyqpabd.exe
    C:\WINDOWS\system32\urzyysdasfh.exe
    C:\WINDOWS\system32\uumhy.exe
    C:\WINDOWS\system32\vc.exe
    C:\WINDOWS\system32\vf.exe
    C:\WINDOWS\system32\vlfompskx.exe
    C:\WINDOWS\system32\vvc.exe
    C:\WINDOWS\system32\vya.exe
    C:\WINDOWS\system32\vysmpvzmpihd.exe
    C:\WINDOWS\system32\w.exe
    C:\WINDOWS\system32\wbs.exe
    C:\WINDOWS\system32\wf.exe
    C:\WINDOWS\system32\xbi.exe
    C:\WINDOWS\system32\xd.exe
    C:\WINDOWS\system32\xtvymox.exe
    C:\WINDOWS\system32\xx.exe
    C:\WINDOWS\system32\ybk.exe
    C:\WINDOWS\system32\ybtvjuz.exe
    C:\WINDOWS\system32\yi.exe
    C:\WINDOWS\system32\yrc.exe
    C:\WINDOWS\system32\zdpq.exe
    C:\WINDOWS\system32\csziqestx.exe
    C:\WINDOWS\system32\pb.exe
    C:\WINDOWS\system32\ehkxnv.exe
    C:\WINDOWS\system32\csziqestx.exe


  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply.
*If a file or folder cannot be moved immediately, you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine, choose Yes.
  • Close OTMoveIt
**If a reboot was necessary or you needed to Exit before posting the log, you will find a copy of the log at the root of the drive where OTMoveIt is installed, usually at :
C:\\_OTMoveIt\\MovedFiles\\********_******.log
(where "********_******" is the "date_time")


_____________________________________________________



_____________________________
Submit a file to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath, copy and paste these filepaths: 1 at a time.


C:\WINDOWS\Resources\mdm.exe

C:\WINDOWS\system32\ehkxnv.exe



Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html



______________________________

Download and install CCleaner from here


If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.
  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".


    Now run the program and click on Run Cleaner
    ( Do not use the Issues block to clean anything with this program. It is for experts only and it is risky).
AVG Anti-Spyware:
________________________________________
Download the trial version of AVG Anti-Spyware from here and install it. When the program has been installed, and you click the Finish button, AVG Anti-Spyware will open. Do not run a scan yet.

If the program does not automatically update itself during installation, or you are unsure whether it has done so, please do the following:
  • Click the Update icon at the top and under Manual Update click the Start update button.
  • The program will either update or inform you that no update was available.
  • It is essential that you get the update - keep trying until successful. (Note: If you have problems getting the update, you can download an installer for the full database from here (save it on your desktop). Once you have downloaded the installer, make sure that AVG Anti-Spyware is closed and then double-click on avgas-signatures-full-current.exe to install the database).



    Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
  • Open up AVG anti Malware
Please set up the program as follows:
  • Click the Shield icon at the top and under Resident shield is… click active. This should now change to inactive.
  • Click the Update icon and untick the automatic update option.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
  • Under How to act? - make sure that Quarantine is selected.
  • Under How to scan? - All checkboxes should be ticked.
  • Under Possibly unwanted software - All checkboxes should be ticked.
  • Under Reports - Select Do not automatically generate reports.
  • Under What to scan? - Select Scan every file.
Close all open windows.
  • Click on Scanner on the toolbar.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan your computer.
  • When the scan has finished, follow the instructions below:
    • Make sure that Set all elements to: shows Quarantine
    • Important: Click on the Apply all Actions button (*** This must done before saving the report ***)
    • When the program has finished, it will display the message All actions have been applied.
    • Then click the Save Scan Report button.
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Tray Icon and select Exit.
_______________________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from OTMOVEIT
  • The report from AVG Anti-Malware.
  • The reort from Jotti's/Virus total
Thank you for replying so quickly! And God Bless You!

I suspected all those… things? They have no origin details and the look like they were typed by my cat. What are these, Java script calls? I have some of those disabled from running by S&D. Should I re-enable them and move them too? (a,e,r,l,s…)

I wasn't able to act on the running process, C:\WINDOWS\sytem32\ehkxnv.exe, with HJT. These are apparently only shown in the saved text. Task manager shows it is running. I have Xoftspy and RegCure. Reg Cure might not tag it but I will try it (it will take a long time to search through all of RegCure's results). RC will make backups.

I stopped my progress after the Jotti scan in lieu of the hiccup with the second file. I won't investigate the file myself unless you tell me to. I thought it best to check with you before proceeding.

The Jotti scan was a real treat though! Could these be the rootkits? Is it possible to tell if my system is being remotely operated or running a program? Should I have my (IP?) address changed later on?

Oh! I kept a detailed log of all the changes I've made on this sytem since I started dicing it June 22, 2007. Firewall settings, IE settings, Service changes in administator tools, programs removed, Updates made, and so forth. So I could put everything back the way it was if need be. One of my main objects was to disable remote and network services.

OTMoveIt Results

C:\WINDOWS\system32\adcrdv.exe moved successfully.
C:\WINDOWS\system32\ajhxtyqgtze.exe moved successfully.
C:\WINDOWS\system32\akepgexz.exe moved successfully.
C:\WINDOWS\system32\atkeuaqtglto.exe moved successfully.
C:\WINDOWS\system32\bivwwr.exe moved successfully.
C:\WINDOWS\system32\ccdhqihdat.exe moved successfully.
C:\WINDOWS\system32\cypmqzqzwat.exe moved successfully.
C:\WINDOWS\system32\czogma.exe moved successfully.
C:\WINDOWS\system32\dfdzx.exe moved successfully.
C:\WINDOWS\system32\dkbhapwkch.exe moved successfully.
C:\WINDOWS\system32\dlgwpfkdd.exe moved successfully.
C:\WINDOWS\system32\ehkxnv.exe moved successfully.
C:\WINDOWS\system32\euhmkni.exe moved successfully.
C:\WINDOWS\system32\evibzsb.exe moved successfully.
C:\WINDOWS\system32\fapqunidij.exe moved successfully.
C:\WINDOWS\system32\ffkjkgk.exe moved successfully.
C:\WINDOWS\system32\fole.exe moved successfully.
C:\WINDOWS\system32\fyhmkqdk.exe moved successfully.
C:\WINDOWS\system32\fyzogzmhqxpq.exe moved successfully.
C:\WINDOWS\system32\gd.exe moved successfully.
C:\WINDOWS\system32\ggo.exe moved successfully.
C:\WINDOWS\system32\gprdm.exe moved successfully.
C:\WINDOWS\system32\grkqmmidmav.exe moved successfully.
C:\WINDOWS\system32\gxqfz.exe moved successfully.
C:\WINDOWS\system32\howfviiwvd.exe moved successfully.
C:\WINDOWS\system32\hrr.exe moved successfully.
C:\WINDOWS\system32\hvsbquk.exe moved successfully.
C:\WINDOWS\system32\hymjnwhnieoh.exe moved successfully.
C:\WINDOWS\system32\ict.exe moved successfully.
C:\WINDOWS\system32\ik.exe moved successfully.
C:\WINDOWS\system32\joarnpz.exe moved successfully.
C:\WINDOWS\system32\jzrgy.exe moved successfully.
C:\WINDOWS\system32\kbmoadnmz.exe moved successfully.
C:\WINDOWS\system32\klnkoqpb.exe moved successfully.
C:\WINDOWS\system32\ksmgwp.exe moved successfully.
C:\WINDOWS\system32\kzhdssu.exe moved successfully.
C:\WINDOWS\system32\lgmsy.exe moved successfully.
C:\WINDOWS\system32\lpitgrltjvqy.exe moved successfully.
C:\WINDOWS\system32\lwrwbxlflw.exe moved successfully.
C:\WINDOWS\system32\lycgbhhkg.exe moved successfully.
C:\WINDOWS\system32\m.exe moved successfully.
C:\WINDOWS\system32\muijk.exe moved successfully.
C:\WINDOWS\system32\n.exe moved successfully.
C:\WINDOWS\system32\nagjhzgkucq.exe moved successfully.
C:\WINDOWS\system32\nvi.exe moved successfully.
C:\WINDOWS\system32\ofvsuimbk.exe moved successfully.
C:\WINDOWS\system32\ogvjbomutmgu.exe moved successfully.
C:\WINDOWS\system32\pg.exe moved successfully.
C:\WINDOWS\system32\pof.exe moved successfully.
C:\WINDOWS\system32\pqvfejequbr.exe moved successfully.
C:\WINDOWS\system32\prnpqx.exe moved successfully.
C:\WINDOWS\system32\pvvpadwy.exe moved successfully.
C:\WINDOWS\system32\qlcsz.exe moved successfully.
C:\WINDOWS\system32\qvicwnxpcu.exe moved successfully.
C:\WINDOWS\system32\rab.exe moved successfully.
C:\WINDOWS\system32\rtbkm.exe moved successfully.
C:\WINDOWS\system32\rtmiqwwt.exe moved successfully.
C:\WINDOWS\system32\rxgqdxuoqr.exe moved successfully.
C:\WINDOWS\system32\sqmtmzlwz.exe moved successfully.
C:\WINDOWS\system32\srcsqsf.exe moved successfully.
C:\WINDOWS\system32\uc.exe moved successfully.
C:\WINDOWS\system32\uoyqpabd.exe moved successfully.
C:\WINDOWS\system32\urzyysdasfh.exe moved successfully.
C:\WINDOWS\system32\uumhy.exe moved successfully.
C:\WINDOWS\system32\vc.exe moved successfully.
C:\WINDOWS\system32\vf.exe moved successfully.
C:\WINDOWS\system32\vlfompskx.exe moved successfully.
C:\WINDOWS\system32\vvc.exe moved successfully.
C:\WINDOWS\system32\vya.exe moved successfully.
C:\WINDOWS\system32\vysmpvzmpihd.exe moved successfully.
C:\WINDOWS\system32\w.exe moved successfully.
C:\WINDOWS\system32\wbs.exe moved successfully.
C:\WINDOWS\system32\wf.exe moved successfully.
C:\WINDOWS\system32\xbi.exe moved successfully.
C:\WINDOWS\system32\xd.exe moved successfully.
C:\WINDOWS\system32\xtvymox.exe moved successfully.
C:\WINDOWS\system32\xx.exe moved successfully.
C:\WINDOWS\system32\ybk.exe moved successfully.
C:\WINDOWS\system32\ybtvjuz.exe moved successfully.
C:\WINDOWS\system32\yi.exe moved successfully.
C:\WINDOWS\system32\yrc.exe moved successfully.
C:\WINDOWS\system32\zdpq.exe moved successfully.
C:\WINDOWS\system32\csziqestx.exe moved successfully.
C:\WINDOWS\system32\pb.exe moved successfully.
File/Folder C:\WINDOWS\system32\ehkxnv.exe not found.
File/Folder C:\WINDOWS\system32\csziqestx.exe not found.

Created on 07/21/2007 04:12:26



Scan Results from Jotti

C:\WINDOWS\Resources\mdm.exe

Scan taken on 21 Jul 2007 08:33:21 (GMT)
A-Squared Found nothing
AntiVir Found HEUR/Crypted
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found Backdoor.Sdbot.AAD
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found W32/Backdoor.BERU
F-Secure Anti-Virus Found Backdoor.Win32.SdBot.aad
Fortinet Found W32/SDBot.AAD!tr.bdr
Kaspersky Anti-Virus Found Backdoor.Win32.SdBot.aad
NOD32 Found nothing
Norman Virus Control Found W32/Hupigon.gen76
Panda Antivirus Found W32/Sdbot.JEE.worm
Rising Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing


C:\WINDOWS\system32\ehkxnv.exe

The file you uploaded is 0 bytes. It is very likely a firewall or a piece of malware is prohibiting you from uploading this file


(This is the message Jotti gave me on the second file. Is it Okay to go ahead with the rest of your instructions?)
Logfile of HijackThis v1.99.1
Scan saved at 1:39:56 AM, on 7/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\Resources\mdm.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PestPatrolCL.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Mine\Desktop\HijackThis.exe
C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENWW/SAOS01?FORM=TOOLBR
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Documents and Settings\Deanna 2.CUDDLES\My Documents\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PestPatrolCL] C:\PROGRA~1\PESTPA~1\PestPatrolCL.exe c:\
O4 - HKLM\..\Run: [muijk] C:\WINDOWS\system32\muijk.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Documents and Settings\Mine\Desktop\HijackThis.exe /startupscan
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase8300.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://msnuk.oberon-media.com//online2/MSN…mjolauncher.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Print Spooler Service (et9o22aa3xlsike) - Unknown owner - C:\WINDOWS\system32\ehkxnv.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Machine Debug Manager (MCH_Debug) - Unknown owner - C:\WINDOWS\Resources\mdm.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
OK. Sorry I got pulled away for most of the weekend.



C:\WINDOWS\Resources\mdm.exe



c:/resources/mdm.exe Seems to be reported as a backdoor trojan. Not a good thing.

At thyis point I am going to give you may speech for backdoor/remote trojans. Just let me know if you would like to continue.



It looks like you have been infected by a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

Its very possible that anything could have been installed on your computer by the remote attacker, including opening other backdoors and installing rootkits. While we can attempt to clean what we see in your logs, we can't guarantee that your computer will be completely in the clear since we have no way of knowing that has been done to the computer. Your computer could be completely compromised at this moment. It may be prudent to backup your information, reformat, and reinstall.

More information on Remote Access Trojans can be found
here

I suggest you do the following immediately:
  • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passords and transaction information.
If, however, you decide that the computer is not used for any sensitive work, or if you do not wish to reformat at this time, I can help you clean your computer to the best of my abilities.

Should you have any questions, please feel free to ask.

Please let me know what you decide to do in your next post.

Should you decide to clean this machine start by doing the following.


______________________________________
  • Please double-click OTMoveIt.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\Resources\mdm.exe
    C:\WINDOWS\system32\ehkxnv.exe


  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply.
*If a file or folder cannot be moved immediately, you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine, choose Yes.
  • Close OTMoveIt
**If a reboot was necessary or you needed to Exit before posting the log, you will find a copy of the log at the root of the drive where OTMoveIt is installed, usually at :
C:\_OTMoveIt\MovedFiles\********_******.log
(where "********_******" is the "date_time")




______________________________
Stop and Disable 2 Services



Go to Start " Run " type: Services.msc " OK.
Scroll down and find this service: et9o22aa3xlsike
Double-click on it.
Under the General tab, click the Stop button.
Then as start up type click disable.

Please do the exact same for

MCH_Debug


____________________________



Download SDFix and save it to your Desktop.

Double click SDFix.exe and choose Install to extract it to its own folder on the Desktop. Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
  • In Safe Mode, right click the SDFix.zip folder and choose Extract All,
  • Open the extracted folder and double click RunThis.bat to start the script.
  • Type Y to begin the script.
  • It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • Your system will take longer that normal to restart as the fixtool will be running and removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
  • Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt back onto the forum with a new HijackThis log
____________________________



_________________________________
Please do an online scan with Kaspersky Online Scanner
Click on Kaspersky Online Scanner
You will be promted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings
In the scan settings make sure that the following are selected:
Scan using the following Anti-Virus database:

Extended (If available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK

Now under select a target to scan select My Computer


Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.



The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.

Now click on the Save as Text button:

Save the file to your desktop.

Copy and paste that information in your next post.


In your next reply I would like to see:
  • A new HJT log
  • The report from Kasperskys
  • The report from OT MOVE IT
  • The report from S&D FIX

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI