This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Caught A Nasty?

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello

My PC is having one of its 'turns' and puts me through hoops at the moment to get booted up.

Any chance of someone looking over my HJT log to see if I've caught a nasty before I take a hammer to it?

Thanking you

Nelclaret.


Logfile of HijackThis v1.99.1
Scan saved at 16:21:05, on 20/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\PC\Desktop\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/webhp?sourceid=nav…nt&ie=UTF-8
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by16fd.bay16.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1155856671045
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B03020B5-3D30-4346-ABCD-BA345DE6024F}: NameServer = 195.92.195.90 195.92.195.91
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Hi nelclaret,

Your HijackThis log looks fine, that doesn't however guarantee that your machine is clean. Could you confirm exactly what symptoms you are experiencing - do you get any errors on boot or is it just slow? Have you had any malware detections from your protection software, or any other reason to suspect infection?

Post a StartupList log:

Open HijackThis, select Open the Misc Tools section
Next to the Generate StartupList log button, place a checkmark in the box labelled list also minor sections (full)
Then press the Generate StartupList log button and say Yes to the prompt
Save the StartupList log to your deskop and include a copy in your next response.
Now press Back and Scan and then Save log to create and save a new HijackThis log.

Once complete, please post the startuplist log and another HijackThis log.
Hi Ho Silver! (sorry - couldn't resist it!)

Thanks for your response.

The problem looks something like this:

On booting up and getting into Windows the cursor freezes usually within a minute or so. then I have to reboot, Often Windows will not then load properly - Black screen or the monitor slips on to standby or hangs on the window screen or bleep-bleep -bleep etc. I am jabbing reset or the power switch. The next time I get onto my desktop I dash to do a system restore to a setting where I had done an SFC scan and the thing usually works from there. Takes about 15 minutes to get in, all told.

Not the end of the world but annoying all the same.

START UP LOG AS REQUESTED

StartupList report, 21/07/2007, 10:38:16
StartupList version: 1.52.2
Started from : C:\Documents and Settings\PC\Desktop\HJT\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
* Showing rarely important sections
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\PC\Desktop\HJT\HijackThis.exe

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

AVG7_CC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP

————————————————–

Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)

[<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
StubPath = C:\WINDOWS\system32\ieudinit.exe

[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

[>{26923b43-4d38-484f-9b9e-de460746276c}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE

[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

[{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll

[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = %SystemRoot%\system32\ie4uinit.exe

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=none
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–

Checking for EXPLORER.EXE instances:

C:\WINDOWS\Explorer.exe: PRESENT!

C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
C:\WINDOWS\Fonts\Explorer.exe: not present

————————————————–

Checking for superhidden extensions:

.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden

————————————————–

Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll - {02478D38-C3F9-4EFB-9B51-7695ECA05670}
(no name) - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
(no name) - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll - {9030D464-4C02-4ABF-8ECC-5164760863C6}
(no name) - c:\program files\google\googletoolbar4.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
(no name) - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}

————————————————–

Enumerating Download Program Files:

[QuickTime Object]
InProcServer32 = C:\Program Files\QuickTime\QTPlugin.ocx
CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab

[PCPitstop Utility]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\PCPitstop.dll
CODEBASE = http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\macromed\Director\SwDir.dll
CODEBASE = http://fpdownload.macromedia.com/get/shock…director/sw.cab

[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:\WINDOWS\system32\LegitCheckControl.DLL
CODEBASE = http://download.microsoft.com/download/9/b…heckControl.cab

[Minesweeper Flags Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\minesweeper.dll
CODEBASE = http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab

[MSN Photo Upload Tool]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll
CODEBASE = http://by16fd.bay16.hotmail.msn.com/resources/MsnPUpld.cab

[MUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\muweb.dll
CODEBASE = http://update.microsoft.com/microsoftupdat…b?1155856671045

[MessengerStatsClient Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\messengerstatsclient.dll
CODEBASE = http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab

[MsnMessengerSetupDownloadControl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.ocx
CODEBASE = http://messenger.msn.com/download/MsnMesse…pDownloader.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx
CODEBASE = http://fpdownload.macromedia.com/get/flash…ent/swflash.cab

————————————————–

Enumerating Windows NT/2000/XP services

Ad-Aware 2007 Service: "C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe" (autostart)
Alerter: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
AVG7 Alert Manager Server: C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (autostart)
AVG7 Update Service: C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (autostart)
AVG E-mail Scanner: C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe (autostart)
AVG Network Redirector: \SystemRoot\System32\Drivers\avgtdi.sys (autostart)
Background Intelligent Transfer Service: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Computer Browser: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
DigitalCam Pro Video Camera Device: System32\Drivers\Ca536av.sys (autostart)
Cryptographic Services: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
DCOM Server Process Launcher: %SystemRoot%\system32\svchost -k DcomLaunch (autostart)
DHCP Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
DNS Client: %SystemRoot%\system32\svchost.exe -k NetworkService (autostart)
Error Reporting Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Event Log: %SystemRoot%\system32\services.exe (autostart)
Help and Support: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Server: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Workstation: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
LexBce Server: C:\WINDOWS\system32\LEXBCES.EXE (autostart)
LicCtrl Service: C:\WINDOWS\runservice.exe (autostart)
TCP/IP NetBIOS Helper: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
Machine Debug Manager: "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" (autostart)
NVIDIA Display Driver Service: %SystemRoot%\system32\nvsvc32.exe (autostart)
Panda anti-virus driver: \SystemRoot\System32\Drivers\pavdrv51.sys (autostart)
Panda Process Protection Driver: \??\C:\WINDOWS\system32\DRIVERS\PavProc.sys (autostart)
Plug and Play: %SystemRoot%\system32\services.exe (autostart)
IPSEC Services: %SystemRoot%\system32\lsass.exe (autostart)
Protected Storage: %SystemRoot%\system32\lsass.exe (autostart)
Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart)
Task Scheduler: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Secdrv: system32\DRIVERS\secdrv.sys (autostart)
Secondary Logon: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
System Event Notification: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Windows Firewall/Internet Connection Sharing (ICS): %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Shell Hardware Detection: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Print Spooler: %SystemRoot%\system32\spoolsv.exe (autostart)
System Restore Service: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
STEC3: \??\C:\WINDOWS\system32\STEC3.sys (autostart)
Windows Image Acquisition (WIA): %SystemRoot%\system32\svchost.exe -k imgsvc (autostart)
Themes: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Distributed Link Tracking Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Windows User Mode Driver Framework: C:\WINDOWS\system32\wdfmgr.exe (autostart)
Windows Time: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
WebClient: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
SyGate for NT, wg3n: \SystemRoot\SYSTEM32\Drivers\wg3n.sys (autostart)
Windows Management Instrumentation: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Security Center: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Automatic Updates: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
XZDGJZDC: \??\C:\WINDOWS\system32\xzdgjzdc.fvf (autostart)


————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll

————————————————–
End of report, 11,976 bytes
Report generated in 0.300 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only


HJT LIST AS REQUESTED


Logfile of HijackThis v1.99.1
Scan saved at 10:41:44, on 21/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\PC\Desktop\HJT\HijackThis.exe
C:\WINDOWS\system32\notepad.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/webhp?sourceid=nav…nt&ie=UTF-8
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo
O1 - Hosts file is located at: C:\WINDOWS\System32\drivers\etc\hosts
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by16fd.bay16.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1155856671045
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B03020B5-3D30-4346-ABCD-BA345DE6024F}: NameServer = 195.92.195.90 195.92.195.91
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


BTW I use the Code Stuff Starter and only AVG is scheduled to run on start up (from earlier Tom Coyote advice)


Regards


Nelclaret
Hi nelclaret,

The symptoms you describe could be caused by malware or any number of other things including hardware. I'll have a look for malware and if there isn't any present I'll advise you on getting further assistance.

Please note down or save a report of what programs you have disabled using the Codestuff startup manager so I can check them for malware.

Do you have Panda antivirus software installed on your machine?

Please upload a file for scanning:
Open http://virusscan.jotti.org/
Copy/paste this file and path into the white box at the top:

C:\WINDOWS\system32\xzdgjzdc.fvf

Press Submit - this will submit the file for testing.
Please copy and paste the results in your next response.

Please download F-Secure Blacklight
  • Click I ACCEPT and download the graphical user interface version to your Desktop
  • Double click the file to run it, choose I accept the agreement then press Scan
  • It will create the fsbl-xxxxxxx.log on your desktop.
  • The log will have a list of all items found.
  • Do not choose to rename any yet! I want to see the log first because legitimate items can also be present.
  • Exit Blacklight and post the contents of the log in your next reply.
Once complete, please post the Codestuff Startup disabled programs information, the Jotti results, the Blacklight log and a new HijackThis log.
Hello Silver

Apologies for the delay in getting back to you and thank you for your post.


1 Panda is installed but is disabled. I tried to remove it after 12 months and ran in to all sorts of problems. In short, I couldn't remove it but it has been disabled via Codestuff starter. For this reason (I presume) the jotti did not work.

2 Blacklight.

I downloaded and scanned but it did not produce a log for me to post. However, I can confirm that no hidden items were found.

3 Can you clarify what info you need from the Codestuff Starter? Is it just the title (eg TK Bell) or the full address? I'm a bit confused here. If it is any help the ONLY programs active on startup are the AVG virus programs (2) - again as per earlier TC advice.

4 Latest HJT log herewith:

Logfile of HijackThis v1.99.1
Scan saved at 22:41:11, on 24/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\PC\Desktop\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/webhp?sourceid=nav…nt&ie=UTF-8
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by16fd.bay16.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1155856671045
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B03020B5-3D30-4346-ABCD-BA345DE6024F}: NameServer = 195.92.195.91 195.92.195.90
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


Aplogies for my ineptitude.


Nelclaret
Hi nelclaret,

Regarding Panda, having two antivirus programs installed can cause system problems including slowing down the system and crashes. Did the symptoms you are experiencing now start occurring anywhere near the time of changing antivirus programs? In any case, while it appears that you have disabled the program there still is a driver service starting with Windows which could cause some problems so it's important that you remove the program. What happened when you try to uninstall it normally?

Re Jotti - what happened when you try to upload that file?
Please try this:
Next press Start->Run, copy/paste the following command into the box and press OK:

cmd /c copy C:\WINDOWS\system32\xzdgjzdc.fvf "%userprofile%\desktop\suspect.file"

Hopefully, a file called suspect.file will appear on your Desktop, please upload this to Jotti and post the results.

Re Codestuff Starter - all the information would be great but if you can't produce a report and have to type it manually, what I'd like is the filename (in the case of TK Bell, the filename is probably tkbell.exe). I understand they are all disabled and not running, however I need to see them to check if any are malware-related or can give me an insight into what might be the cause of the problems.

Please also do a scan with Dr Web:
Download Dr.WEB CureIt to your desktop from here:
ftp://ftp.drweb.com/pub/drweb/cureit/cureit.exe
  • Double-click cureit.exe to start the program.
  • Press Start and then OK to start the Express scan
  • The Express scan takes just a few moments to finish, if something is found, click Yes to cure it
  • Once the short scan has finished, Click Options->Change settings
  • Choose the Scan tab and remove the check mark from Heuristic analysis
  • Choose the Actions tab and next to Infected objects select Move, then press OK to close the settings box.
  • Select all hard drives to be scanned by clicking on them - choose all drives - a red dot confirms they will be scanned
  • Click the green arrow on the right to start the scan
  • Click Yes to all if it asks if you want to move a file
  • Click File-> Save report list and save the report to your desktop
  • Close Dr.Web Cureit and reboot your computer (this is important as files may be moved/deleted during reboot)
Once complete, please post the Panda info, the Jotti results, the Codestuff Starter details, the Dr Web report and a new HijackThis log.
Silver

I think jotti is down at the moment (for the last couple of days this end)

From memory, when I tried to upload that original file it returned something like "0 bytes uploaded. May be blocked by malware" (plus something else I cannot remember).

Regarding Panda:

(To the best of my memory)

I wanted to remove Panda after the 12 month expiry. Tried via normal delete program facility. System came up with all kinds of messages about a missing file that I had to click through half-a-dozen times on startup. Getting feed up of this and having sought advice on this forum and elsewhere I (randomly) removed some of the Panda components from the program files to see what this would do. The annoying messages stopped!

I have the removed components saved in a separate file so I could put them back if necessary.

Relatively recently I was advised how to disable Panda (Code Stuff Starter) by TC forum.

If I try to remove Panda via the Install/Delete programs I get an error message. So panda remains on the system at the moment

Dr Web anti-virus result here:

MiniBugTransporter.dll;C:\Program Files\Common Files\Real\WeatherBug;Adware.Minibug;;
A0526193.dll;C:\System Volume Information\_restore{966A6EC0-E1B4-4CC0-8E22-6A0611030952}\RP162;Adware.NavHelper;;
A0526195.exe;C:\System Volume Information\_restore{966A6EC0-E1B4-4CC0-8E22-6A0611030952}\RP162;Adware.NavHelper;;
A0526196.exe;C:\System Volume Information\_restore{966A6EC0-E1B4-4CC0-8E22-6A0611030952}\RP162;Adware.NavHelper;;
A0526197.exe;C:\System Volume Information\_restore{966A6EC0-E1B4-4CC0-8E22-6A0611030952}\RP162;Adware.NavHelper;;
A0526198.dll;C:\System Volume Information\_restore{966A6EC0-E1B4-4CC0-8E22-6A0611030952}\RP162;Adware.NavHelper;;
STUNTB.exe;C:\temp\kwdbfm\help;Adware.NavHelper;;

Deactivated start ups (Code Stuff) here : I hope this is what you meant:

Adobe Reader Speed Launch
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

CTFMON.EXE
C:\WINDOWS\system32\CTFMON.EXE

IntelliPoint
"C:\Program Files\Microsoft IntelliPoint\point32.exe"

LimeWire On Startup
C:\Program Files\LimeWire\LimeWire.exe

NeroFilterCheck
C:\WINDOWS\system32\NeroCheck.exe

NvCplDaemon
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

NvMediaCenter
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

nwiz
nwiz.exe /install

Quick Time Task
"C:\Program Files\QuickTime\qttask.exe" –atboottime

RunNarrator
Narrator.exe

SpeedTouch USB
"C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon

SunJavaUpdateSched
"C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"

swg
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

TkBellExe
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

Type32
"C:\Program Files\Microsoft IntelliType Pro\type32.exe"


Ulead Photo Express 3.0 SE Calendar Checker
C:\Program Files\Ulead Systems\Ulead Photo Express 3.0 SE\CalCheck.exe

updateMgr
"C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1

Latest HJT log here:

Logfile of HijackThis v1.99.1
Scan saved at 12:51:14, on 26/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\Documents and Settings\PC\Desktop\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/webhp?sourceid=nav…nt&ie=UTF-8
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by16fd.bay16.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1155856671045
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B03020B5-3D30-4346-ABCD-BA345DE6024F}: NameServer = 195.92.195.90 195.92.195.91
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe



Phew!

Thanks for looking at all this for me. I'll try and do the Jotti thing when I can.

nelclaret
Hi nelclaret,

The Codestuff Starter information was great :thumbup:

Re Panda, this might be the cause of your problems however could you think back and tell me if changing antivirus programs happened around the same time as the start of the crashes or not.
Also, please try uninstalling Panda via Add/Remove Programs and tell me what error is displayed.

Re Jotti: When you followed the instructions did suspect.file appear on your Desktop? If so, please check whether it was in fact 0 bytes by right-clicking and selecting Properties to view the details of the file.

You may have a program called WeatherBug installed on your computer. It is not malware but it has been labelled so in the past and there is current debate as to it's status. I recommend you remove this program for these reasons and because there are free alternatives which are known to be clean such as Weather Pulse and Weather Watcher.

To uninstall WeatherBug:
Navigate to Start->Control Panel->Add/Remove Programs
Look down the list for Weatherbug and click Remove

You have LimeWire, a P2P file sharing program installed on your computer. This program does not come bundled with malware as some similar programs do, butP2P file sharing networks are one of the biggest sources of malware we see. Anything downloaded from them cannot be trusted to be clean, because even if the file appears to be what it claims to be, it can have malware embedded in it.
I recommend you remove it, but of course the choice is yours.
You can remove Limewire via Add/Remove Programs.

Your Java is outdated and is now a security risk
Go to Start » Control Panel » Add/Remove Programs
Search all previous installed versions of Java. (J2SE Runtime Environment…. )
(They should have this icon next to it: [external image: Posted Image])
Remove all versions of Java.
Download and install the newest version of Java Runtime Environment (JRE) (version 6 update 2), from here:
http://java.sun.com/javase/downloads/index.jsp

Next download ComboFix to your desktop
  • Double click combofix.exe and follow the prompts.
  • Note: Do not click ComboFix's window while it's running - it may cause it to stall!
  • When finished, it shall produce a log for you, please post it in your next response.
Once complete, please post the ComboFix log and a new HijackThis log. Also let me know how you got on with Jotti.
Hello Silver

Latest 'results':

PANDA

This expired circa Mar/Apr 2006. The problems SEEM to stem from when I tried to remove it - circa the end of 2006. I don't think there is an exact correlation between the current problems and Panda but I certainly think my system has been a lot more temperamental since the expiry of the program and particularly, the attempt to remove it.

My latest attempt to remove it via 'Add/Remove programs' gives: "Error extracting support files: The system cannot find the file specified". I sure would like to remove Panda to see what effect this would have. If there is a way to do it that an amoeba can follow, please let me know!

JOTTI

The attempt to upload the original file(?) you gave me returns "The file you uploaded is 0 bytes. It is very likely a firewall or a piece of malware is prohibiting you from uploading this file".

The other process gave NO suspect file.

WEATHERBUG etc

No trace in 'Add/Remove programs'

LIMEWIRE

sticking with it for the moment but I will bear this in mind.

JAVA 6.2 now downloaded and installed.

COMBO FIX LOG herewith:

"PC" - 2007-07-29 19:30:11 - ComboFix 07-07-23.6 - Service Pack 2 NTFS


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\PC\Desktop.\internet explorer.lnk
C:\Program Files\webhancer
C:\Program Files\webhancer\Programs\license.txt
C:\Program Files\webhancer\Programs\readme.txt


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\nm


((((((((((((((((((((((((( Files Created from 2007-06-28 to 2007-07-29 )))))))))))))))))))))))))))))))


2007-07-29 19:13 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-29 13:18 d——– C:\Program Files\Eidos Interactive
2007-07-25 11:25 d–hs—- C:\found.000
2007-07-25 10:00 d——– C:\DOCUME~1\PC\DoctorWeb
2007-07-24 21:58 6,975,488 –a—— C:\DOCUME~1\PC\ntuser.dat
2007-07-24 21:00 d——– C:\temp\kwdbfm
2007-07-24 21:00 d——– C:\temp
2007-07-24 21:00 d——– C:\Program Files\NavExcel Search Toolbar
2007-07-24 21:00 d——– C:\Program Files\NavExcel


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-29 12:18:46 ——– d—–w C:\Program Files\RegScrubXP
2007-07-27 18:12:18 ——– d—–w C:\Program Files\cam2pc
2007-07-18 11:11:20 38,567 —-a-w C:\WINDOWS\system32\pcpbios.exe
2007-06-23 14:13:53 ——– d—–w C:\Program Files\LimeWire
2007-06-23 14:13:08 ——– d—–w C:\Program Files\Combat Mission 3 Afrika Korps
2007-06-20 11:29:52 ——– d—–w C:\Program Files\Lavasoft
2007-06-20 11:29:11 ——– d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-06-20 10:15:44 ——– d—–w C:\DOCUME~1\PC\APPLIC~1\Lavasoft
2007-06-05 10:06:19 ——– d—–w C:\Program Files\PC Connectivity Solution
2007-06-05 10:05:46 ——– d—–w C:\Program Files\Windows Media Connect 2
2007-06-05 09:44:34 0 —-a-w C:\WINDOWS\system32\drivers\SET1.tmp
2007-06-04 14:18:48 9,344 —-a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 14:17:02 8,320 —-a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 14:14:56 6,272 —-a-w C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-05-30 11:21:40 ——– d—–w C:\DOCUME~1\PC\APPLIC~1\PC Suite
2007-05-17 14:57:46 0 -c–a-w C:\WINDOWS\nsreg.dat
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2005-03-27 21:01:34 0 -c–a-w C:\DOCUME~1\PC\APPLIC~1\wklnhst.dat
2006-11-22 17:40:07 2,169 –sha-w C:\WINDOWS\system32\mmf(10)(2).sys
2006-11-29 08:57:54 2,169 –sha-w C:\WINDOWS\system32\mmf(10)(3).sys
2006-11-22 21:52:03 2,169 –sha-w C:\WINDOWS\system32\mmf(11)(2).sys
2006-11-30 13:42:22 2,169 –sha-w C:\WINDOWS\system32\mmf(11)(3).sys
2006-11-22 23:10:14 2,169 –sha-w C:\WINDOWS\system32\mmf(12)(2).sys
2006-11-21 12:29:24 2,169 –sha-w C:\WINDOWS\system32\mmf(12)(3).sys
2006-11-23 08:26:34 2,169 –sha-w C:\WINDOWS\system32\mmf(13)(2).sys
2006-11-21 17:11:02 2,169 –sha-w C:\WINDOWS\system32\mmf(13)(3).sys
2006-11-23 11:15:57 2,169 –sha-w C:\WINDOWS\system32\mmf(14)(2).sys
2006-11-21 21:46:58 2,169 –sha-w C:\WINDOWS\system32\mmf(14)(3).sys
2006-11-23 15:13:57 2,169 –sha-w C:\WINDOWS\system32\mmf(15)(2).sys
2006-11-22 00:25:48 2,169 –sha-w C:\WINDOWS\system32\mmf(15)(3).sys
2006-11-23 23:01:14 2,169 –sha-w C:\WINDOWS\system32\mmf(16)(2).sys
2006-11-22 01:00:46 2,169 –sha-w C:\WINDOWS\system32\mmf(16)(3).sys
2006-11-24 10:48:09 2,169 –sha-w C:\WINDOWS\system32\mmf(17)(2).sys
2006-11-22 08:51:04 2,169 –sha-w C:\WINDOWS\system32\mmf(17)(3).sys
2006-11-24 11:38:58 2,169 –sha-w C:\WINDOWS\system32\mmf(18)(2).sys
2006-11-22 11:45:09 2,169 –sha-w C:\WINDOWS\system32\mmf(18)(3).sys
2006-11-24 15:01:18 2,169 –sha-w C:\WINDOWS\system32\mmf(19)(2).sys
2006-11-22 17:40:07 2,169 –sha-w C:\WINDOWS\system32\mmf(19)(3).sys
2006-11-11 14:12:52 2,169 –sha-w C:\WINDOWS\system32\mmf(2).sys
2006-11-24 16:40:08 2,169 –sha-w C:\WINDOWS\system32\mmf(20)(2).sys
2006-11-22 21:52:03 2,169 –sha-w C:\WINDOWS\system32\mmf(20)(3).sys
2006-11-24 18:25:55 2,169 –sha-w C:\WINDOWS\system32\mmf(21)(2).sys
2006-11-22 23:10:14 2,169 –sha-w C:\WINDOWS\system32\mmf(21)(3).sys
2006-11-24 20:06:11 2,169 –sha-w C:\WINDOWS\system32\mmf(22)(2).sys
2006-11-23 08:26:34 2,169 –sha-w C:\WINDOWS\system32\mmf(22)(3).sys
2006-11-24 21:42:09 2,169 –sha-w C:\WINDOWS\system32\mmf(23)(2).sys
2006-11-23 11:15:57 2,169 –sha-w C:\WINDOWS\system32\mmf(23)(3).sys
2006-11-25 03:50:31 2,169 –sha-w C:\WINDOWS\system32\mmf(24)(2).sys
2006-11-23 15:13:57 2,169 –sha-w C:\WINDOWS\system32\mmf(24)(3).sys
2006-11-25 04:08:24 2,169 –sha-w C:\WINDOWS\system32\mmf(25)(2).sys
2006-11-23 23:01:14 2,169 –sha-w C:\WINDOWS\system32\mmf(25)(3).sys
2006-11-25 09:04:22 2,169 –sha-w C:\WINDOWS\system32\mmf(26)(2).sys
2006-11-24 10:48:09 2,169 –sha-w C:\WINDOWS\system32\mmf(26)(3).sys
2006-11-25 11:17:39 2,169 –sha-w C:\WINDOWS\system32\mmf(27)(2).sys
2006-11-24 11:38:58 2,169 –sha-w C:\WINDOWS\system32\mmf(27)(3).sys
2006-11-25 23:34:04 2,169 –sha-w C:\WINDOWS\system32\mmf(28)(2).sys
2006-11-24 15:01:18 2,169 –sha-w C:\WINDOWS\system32\mmf(28)(3).sys
2006-11-30 19:17:08 2,169 –sha-w C:\WINDOWS\system32\mmf(3)(2).sys
2006-11-30 22:11:43 2,169 –sha-w C:\WINDOWS\system32\mmf(3)(3).sys
2006-11-29 16:16:30 2,169 –sha-w C:\WINDOWS\system32\mmf(3)(4).sys
2006-11-30 12:10:55 2,169 –sha-w C:\WINDOWS\system32\mmf(4)(2).sys
2006-11-30 17:39:12 2,169 –sha-w C:\WINDOWS\system32\mmf(4)(3).sys
2006-11-21 17:11:02 2,169 –sha-w C:\WINDOWS\system32\mmf(4)(4).sys
2006-11-30 11:05:40 2,169 –sha-w C:\WINDOWS\system32\mmf(4)(5).sys
2006-11-29 18:34:49 2,169 –sha-w C:\WINDOWS\system32\mmf(4)(6).sys
2006-11-28 16:29:08 2,169 –sha-w C:\WINDOWS\system32\mmf(4)(7).sys
2006-11-30 12:06:30 2,169 –sha-w C:\WINDOWS\system32\mmf(5)(2).sys
2006-11-30 15:40:27 2,169 –sha-w C:\WINDOWS\system32\mmf(5)(3).sys
2006-11-29 18:08:43 2,169 –sha-w C:\WINDOWS\system32\mmf(5)(4).sys
2006-11-29 18:08:43 2,169 –sha-w C:\WINDOWS\system32\mmf(5)(5).sys
2006-11-21 21:46:58 2,169 –sha-w C:\WINDOWS\system32\mmf(5)(6).sys
2006-11-22 00:25:48 2,169 –sha-w C:\WINDOWS\system32\mmf(54)(2).sys
2006-11-20 22:19:51 2,169 –sha-w C:\WINDOWS\system32\mmf(6)(2).sys
2006-11-30 14:41:06 2,169 –sha-w C:\WINDOWS\system32\mmf(6)(3).sys
2006-11-29 17:24:32 2,169 –sha-w C:\WINDOWS\system32\mmf(6)(4).sys
2006-11-29 17:24:32 2,169 –sha-w C:\WINDOWS\system32\mmf(6)(5).sys
2006-11-29 07:59:17 2,169 –sha-w C:\WINDOWS\system32\mmf(6)(6).sys
2006-11-21 12:29:24 2,169 –sha-w C:\WINDOWS\system32\mmf(7)(2).sys
2006-11-22 01:00:46 2,169 –sha-w C:\WINDOWS\system32\mmf(7)(3).sys
2006-11-29 16:16:30 2,169 –sha-w C:\WINDOWS\system32\mmf(7)(4).sys
2006-11-27 22:09:33 2,169 –sha-w C:\WINDOWS\system32\mmf(7)(5).sys
2006-11-22 08:51:04 2,169 –sha-w C:\WINDOWS\system32\mmf(8)(2).sys
2006-11-29 12:47:51 2,169 –sha-w C:\WINDOWS\system32\mmf(8)(3).sys
2006-11-29 12:47:51 2,169 –sha-w C:\WINDOWS\system32\mmf(8)(4).sys
2006-11-22 11:45:09 2,169 –sha-w C:\WINDOWS\system32\mmf(9)(2).sys
2006-11-29 09:51:02 2,169 –sha-w C:\WINDOWS\system32\mmf(9)(3).sys
2006-11-29 09:51:02 2,169 –sha-w C:\WINDOWS\system32\mmf(9)(4).sys
2006-12-01 12:41:01 2,169 –sha-w C:\WINDOWS\system32\mmf.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-04-22 09:04]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-11-27 17:13]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-03 10:41]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=3 (0x3)

R0 prohlp02;StarForce Protection Helper Driver v2;C:\WINDOWS\system32\drivers\prohlp02.sys
R0 prosync1;StarForce Protection Synchronization Driver v1;C:\WINDOWS\system32\drivers\prosync1.sys
R0 sfhlp01;StarForce Protection Helper Driver;C:\WINDOWS\system32\drivers\sfhlp01.sys
R0 Teefer;Teefer for NT;C:\WINDOWS\system32\Drivers\Teefer.sys
R1 prodrv06;StarForce Protection Environment Driver v6;C:\WINDOWS\system32\drivers\prodrv06.sys
R1 ShldDrv;Panda File Shield Driver;C:\WINDOWS\system32\drivers\ShldDrv.sys
R1 wpsdrvnt;wpsdrvnt;\??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys
R2 PAVDRV;Panda anti-virus driver;C:\WINDOWS\system32\Drivers\pavdrv51.sys
R2 PavProc;Panda Process Protection Driver;\??\C:\WINDOWS\system32\DRIVERS\PavProc.sys
R2 STEC3;STEC3;\??\C:\WINDOWS\system32\STEC3.sys
R2 wg3n;SyGate for NT, wg3n;C:\WINDOWS\system32\Drivers\wg3n.sys
R3 alcan5wn;SpeedTouch USB ADSL PPP Networking Driver (NDISWAN);C:\WINDOWS\system32\DRIVERS\alcan5wn.sys
R3 alcaudsl;SpeedTouch ADSL Modem ATM Transport;C:\WINDOWS\system32\DRIVERS\alcaudsl.sys
R3 GT680x;GrandTechICNameNT;C:\WINDOWS\system32\Drivers\gt680x.sys
R3 Intels51;Intel® 536EP Modem;C:\WINDOWS\system32\DRIVERS\Intels51.sys
R3 viafilter;VIA USB Filter;C:\WINDOWS\system32\Drivers\viausb1.sys
S2 Ca536av;DigitalCam Pro Video Camera Device;C:\WINDOWS\system32\Drivers\Ca536av.sys
S2 LicCtrlService;LicCtrl Service;C:\WINDOWS\runservice.exe
S2 XZDGJZDC;XZDGJZDC;\??\C:\WINDOWS\system32\xzdgjzdc.fvf
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\fetnd5.sys
S3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5b.sys
S3 NTSIM;NTSIM;\??\C:\WINDOWS\system32\ntsim.sys
S3 Point32;Microsoft IntelliPoint Filter Driver;C:\WINDOWS\system32\DRIVERS\point32.sys
S3 StillCam;Still Serial Digital Camera Driver;C:\WINDOWS\system32\DRIVERS\serscan.sys
S4 PASSRV;Panda Antispam Service;C:\Program Files\Panda Software\Panda Platinum Internet Security\passrv.exe
S4 PAVFIRES;Panda Firewall Service;C:\Program Files\Panda Software\Panda Platinum Internet Security\Firewall\PavFires.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Usnsvc usnsvc


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-29 19:34:57
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-29 19:37:14 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-29 19:36

— E O F —


LATEST HJT LOG herewith:

Logfile of HijackThis v1.99.1
Scan saved at 19:40:13, on 29/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Thomson\SpeedTouch USB\stdialup.exe
C:\Documents and Settings\PC\Desktop\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/webhp?sourceid=nav…nt&ie=UTF-8
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by16fd.bay16.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1155856671045
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe



THANKS!

Nelclaret

:scratch:
Hi nelclaret,

I think Panda is likely to be part or all of your problems, and I'm conferring with my colleagues on the best way to rid you of it. I'll be back to you as quickly as possible on that but in the meantime please do this:

Press Start->Run, copy/paste the following command into the box and press OK:

cmd /c dir /a /s c:\xzdgjzdc.fvf >> "%userprofile%\desktop\look.txt"

A file called look.txt should appear on your Desktop, please post the contents of this file.
Hi,

I addition to the previous step, please do the following:

Download the Panda removal tool to your Desktop from here:
http://www.pandasoftware.co.uk/hotfix/UNINSTALLER.EXE

Please disconnect from the internet and close all other windows and as this will require a reboot.

Double-click UNINSTALLER.EXE to start the program, follow the prompts and allow your computer to be rebooted immediately after it has finished running. If it doesn't reboot automatically, then do it manually.

Once complete, please post the look.txt output from my previous post, and a new HijackThis log. Also, let me know if the Panda removal tool gave any output.
Hi Silver

Instructions followed.

1 Looks like Panda has gone - not now showing in ADD/REMOVE list and folder empty in programs! I feel irrationally excited - thanks! There was an output given which gave a message about being unable to unzip something (?) Unfortunately, thinking the uninstall had failed, I clicked x thinking to retry and the system went into reboot without me making a note. However, as I said it does look as though Panda has gone (unless you tell me different!).

2 Output from 'look'

Volume in drive C has no label.
Volume Serial Number is 005D-8E93

3 HJT log

Logfile of HijackThis v1.99.1
Scan saved at 10:12:53, on 30/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\PC\Desktop\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/webhp?sourceid=nav…nt&ie=UTF-8
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by16fd.bay16.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1155856671045
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B03020B5-3D30-4346-ABCD-BA345DE6024F}: NameServer = 195.92.195.91 195.92.195.90
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


Regards

Nelclaret
Hi nelclaret,

I'm not sure whether the uninstaller worked or not, but the ComboFix output will tell us:
  • Check that combofix.exe is on your Desktop
  • Then open Notepad: press Start->Run, type notepad and click OK
  • Copy/paste the contents of the below code box into Notepad:
    Driver::
    XZDGJZDC
  • Save this as CFScript.txt and change the Save as type to All Files and save it to your Desktop.

    [external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
Note: Do not click ComboFix's window while it's running - it may cause it to stall!

Once complete, please post the new ComboFix log and another HijackThis log. Also let me know how your computer is running.
Hi silver

Combo Fix log as requested

ComboFix 07-07-30.2 - "PC" 2007-07-31 9:43:54.1 [GMT 1:00] - NTFS
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.True
Command switches used :: C:\Documents and Settings\PC\Desktop\CFScript.txt
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_XZDGJZDC
——-\XZDGJZDC


((((((((((((((((((((((((( Files Created from 2007-06-28 to 2007-07-31 )))))))))))))))))))))))))))))))


2007-07-30 09:56 d——– C:\SMCLpav
2007-07-29 19:13 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-29 13:18 d——– C:\Program Files\Eidos Interactive
2007-07-25 11:25 d–hs—- C:\found.000
2007-07-25 10:00 d——– C:\DOCUME~1\PC\DoctorWeb
2007-07-24 21:58 6,975,488 –a—— C:\DOCUME~1\PC\ntuser.dat
2007-07-24 21:00 d——– C:\temp\kwdbfm
2007-07-24 21:00 d——– C:\temp
2007-07-24 21:00 d——– C:\Program Files\NavExcel Search Toolbar
2007-07-24 21:00 d——– C:\Program Files\NavExcel
2007-06-20 12:29 d——– C:\Program Files\Lavasoft
2007-06-20 12:29 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-06-20 12:29 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-06-06 21:27 208,896 –a—— C:\WINDOWS\system32\nvudisp.exe
2007-06-06 21:27 d——– C:\WINDOWS\nview
2007-06-06 21:26 208,896 –a—— C:\WINDOWS\system32\NVUNINST.EXE
2007-06-06 20:13 d——– C:\Program Files\Combat Mission 3 Afrika Korps
2007-06-04 15:18 9,344 –a—— C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 15:17 8,320 –a—— C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 15:14 6,272 –a—— C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-06-01 17:13 d——– C:\Program Files\Windows Media Connect 2
2007-06-01 17:11 d——– C:\WINDOWS\system32\drivers\UMDF


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-31 01:33 ——— d——– C:\Program Files\RegScrubXP
2007-07-30 09:59 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-07-30 09:57 ——— d——– C:\Program Files\Common Files\Panda Software
2007-07-27 19:12 ——— d——– C:\Program Files\cam2pc
2007-07-18 12:11 38567 –a—— C:\WINDOWS\system32\pcpbios.exe
2007-06-23 15:13 ——— d——– C:\Program Files\LimeWire
2007-06-20 11:15 ——— d——– C:\DOCUME~1\PC\APPLIC~1\Lavasoft
2007-06-05 11:06 ——— d——– C:\Program Files\PC Connectivity Solution
2007-06-05 10:44 0 –a—— C:\WINDOWS\system32\drivers\SET1.tmp
2007-05-30 12:21 ——— d——– C:\DOCUME~1\PC\APPLIC~1\PC Suite
2007-05-17 15:57 0 –a–c— C:\WINDOWS\nsreg.dat
2007-05-16 16:12 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2005-03-27 22:01 0 –a–c— C:\DOCUME~1\PC\APPLIC~1\wklnhst.dat
2006-11-22 17:40:07 2,169 –sha-w C:\WINDOWS\system32\mmf(10)(2).sys
2006-11-29 08:57:54 2,169 –sha-w C:\WINDOWS\system32\mmf(10)(3).sys
2006-11-22 21:52:03 2,169 –sha-w C:\WINDOWS\system32\mmf(11)(2).sys
2006-11-30 13:42:22 2,169 –sha-w C:\WINDOWS\system32\mmf(11)(3).sys
2006-11-22 23:10:14 2,169 –sha-w C:\WINDOWS\system32\mmf(12)(2).sys
2006-11-21 12:29:24 2,169 –sha-w C:\WINDOWS\system32\mmf(12)(3).sys
2006-11-23 08:26:34 2,169 –sha-w C:\WINDOWS\system32\mmf(13)(2).sys
2006-11-21 17:11:02 2,169 –sha-w C:\WINDOWS\system32\mmf(13)(3).sys
2006-11-23 11:15:57 2,169 –sha-w C:\WINDOWS\system32\mmf(14)(2).sys
2006-11-21 21:46:58 2,169 –sha-w C:\WINDOWS\system32\mmf(14)(3).sys
2006-11-23 15:13:57 2,169 –sha-w C:\WINDOWS\system32\mmf(15)(2).sys
2006-11-22 00:25:48 2,169 –sha-w C:\WINDOWS\system32\mmf(15)(3).sys
2006-11-23 23:01:14 2,169 –sha-w C:\WINDOWS\system32\mmf(16)(2).sys
2006-11-22 01:00:46 2,169 –sha-w C:\WINDOWS\system32\mmf(16)(3).sys
2006-11-24 10:48:09 2,169 –sha-w C:\WINDOWS\system32\mmf(17)(2).sys
2006-11-22 08:51:04 2,169 –sha-w C:\WINDOWS\system32\mmf(17)(3).sys
2006-11-24 11:38:58 2,169 –sha-w C:\WINDOWS\system32\mmf(18)(2).sys
2006-11-22 11:45:09 2,169 –sha-w C:\WINDOWS\system32\mmf(18)(3).sys
2006-11-24 15:01:18 2,169 –sha-w C:\WINDOWS\system32\mmf(19)(2).sys
2006-11-22 17:40:07 2,169 –sha-w C:\WINDOWS\system32\mmf(19)(3).sys
2006-11-11 14:12:52 2,169 –sha-w C:\WINDOWS\system32\mmf(2).sys
2006-11-24 16:40:08 2,169 –sha-w C:\WINDOWS\system32\mmf(20)(2).sys
2006-11-22 21:52:03 2,169 –sha-w C:\WINDOWS\system32\mmf(20)(3).sys
2006-11-24 18:25:55 2,169 –sha-w C:\WINDOWS\system32\mmf(21)(2).sys
2006-11-22 23:10:14 2,169 –sha-w C:\WINDOWS\system32\mmf(21)(3).sys
2006-11-24 20:06:11 2,169 –sha-w C:\WINDOWS\system32\mmf(22)(2).sys
2006-11-23 08:26:34 2,169 –sha-w C:\WINDOWS\system32\mmf(22)(3).sys
2006-11-24 21:42:09 2,169 –sha-w C:\WINDOWS\system32\mmf(23)(2).sys
2006-11-23 11:15:57 2,169 –sha-w C:\WINDOWS\system32\mmf(23)(3).sys
2006-11-25 03:50:31 2,169 –sha-w C:\WINDOWS\system32\mmf(24)(2).sys
2006-11-23 15:13:57 2,169 –sha-w C:\WINDOWS\system32\mmf(24)(3).sys
2006-11-25 04:08:24 2,169 –sha-w C:\WINDOWS\system32\mmf(25)(2).sys
2006-11-23 23:01:14 2,169 –sha-w C:\WINDOWS\system32\mmf(25)(3).sys
2006-11-25 09:04:22 2,169 –sha-w C:\WINDOWS\system32\mmf(26)(2).sys
2006-11-24 10:48:09 2,169 –sha-w C:\WINDOWS\system32\mmf(26)(3).sys
2006-11-25 11:17:39 2,169 –sha-w C:\WINDOWS\system32\mmf(27)(2).sys
2006-11-24 11:38:58 2,169 –sha-w C:\WINDOWS\system32\mmf(27)(3).sys
2006-11-25 23:34:04 2,169 –sha-w C:\WINDOWS\system32\mmf(28)(2).sys
2006-11-24 15:01:18 2,169 –sha-w C:\WINDOWS\system32\mmf(28)(3).sys
2006-11-30 19:17:08 2,169 –sha-w C:\WINDOWS\system32\mmf(3)(2).sys
2006-11-30 22:11:43 2,169 –sha-w C:\WINDOWS\system32\mmf(3)(3).sys
2006-11-29 16:16:30 2,169 –sha-w C:\WINDOWS\system32\mmf(3)(4).sys
2006-11-30 12:10:55 2,169 –sha-w C:\WINDOWS\system32\mmf(4)(2).sys
2006-11-30 17:39:12 2,169 –sha-w C:\WINDOWS\system32\mmf(4)(3).sys
2006-11-21 17:11:02 2,169 –sha-w C:\WINDOWS\system32\mmf(4)(4).sys
2006-11-30 11:05:40 2,169 –sha-w C:\WINDOWS\system32\mmf(4)(5).sys
2006-11-29 18:34:49 2,169 –sha-w C:\WINDOWS\system32\mmf(4)(6).sys
2006-11-28 16:29:08 2,169 –sha-w C:\WINDOWS\system32\mmf(4)(7).sys
2006-11-30 12:06:30 2,169 –sha-w C:\WINDOWS\system32\mmf(5)(2).sys
2006-11-30 15:40:27 2,169 –sha-w C:\WINDOWS\system32\mmf(5)(3).sys
2006-11-29 18:08:43 2,169 –sha-w C:\WINDOWS\system32\mmf(5)(4).sys
2006-11-29 18:08:43 2,169 –sha-w C:\WINDOWS\system32\mmf(5)(5).sys
2006-11-21 21:46:58 2,169 –sha-w C:\WINDOWS\system32\mmf(5)(6).sys
2006-11-22 00:25:48 2,169 –sha-w C:\WINDOWS\system32\mmf(54)(2).sys
2006-11-20 22:19:51 2,169 –sha-w C:\WINDOWS\system32\mmf(6)(2).sys
2006-11-30 14:41:06 2,169 –sha-w C:\WINDOWS\system32\mmf(6)(3).sys
2006-11-29 17:24:32 2,169 –sha-w C:\WINDOWS\system32\mmf(6)(4).sys
2006-11-29 17:24:32 2,169 –sha-w C:\WINDOWS\system32\mmf(6)(5).sys
2006-11-29 07:59:17 2,169 –sha-w C:\WINDOWS\system32\mmf(6)(6).sys
2006-11-21 12:29:24 2,169 –sha-w C:\WINDOWS\system32\mmf(7)(2).sys
2006-11-22 01:00:46 2,169 –sha-w C:\WINDOWS\system32\mmf(7)(3).sys
2006-11-29 16:16:30 2,169 –sha-w C:\WINDOWS\system32\mmf(7)(4).sys
2006-11-27 22:09:33 2,169 –sha-w C:\WINDOWS\system32\mmf(7)(5).sys
2006-11-22 08:51:04 2,169 –sha-w C:\WINDOWS\system32\mmf(8)(2).sys
2006-11-29 12:47:51 2,169 –sha-w C:\WINDOWS\system32\mmf(8)(3).sys
2006-11-29 12:47:51 2,169 –sha-w C:\WINDOWS\system32\mmf(8)(4).sys
2006-11-22 11:45:09 2,169 –sha-w C:\WINDOWS\system32\mmf(9)(2).sys
2006-11-29 09:51:02 2,169 –sha-w C:\WINDOWS\system32\mmf(9)(3).sys
2006-11-29 09:51:02 2,169 –sha-w C:\WINDOWS\system32\mmf(9)(4).sys
2006-12-01 12:41:01 2,169 –sha-w C:\WINDOWS\system32\mmf.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-04-22 09:04]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=3 (0x3)

R0 prohlp02;StarForce Protection Helper Driver v2;C:\WINDOWS\system32\drivers\prohlp02.sys
R0 prosync1;StarForce Protection Synchronization Driver v1;C:\WINDOWS\system32\drivers\prosync1.sys
R0 sfhlp01;StarForce Protection Helper Driver;C:\WINDOWS\system32\drivers\sfhlp01.sys
R1 prodrv06;StarForce Protection Environment Driver v6;C:\WINDOWS\system32\drivers\prodrv06.sys
R2 STEC3;STEC3;\??\C:\WINDOWS\system32\STEC3.sys
R3 alcan5wn;SpeedTouch USB ADSL PPP Networking Driver (NDISWAN);C:\WINDOWS\system32\DRIVERS\alcan5wn.sys
R3 alcaudsl;SpeedTouch ADSL Modem ATM Transport;C:\WINDOWS\system32\DRIVERS\alcaudsl.sys
R3 Intels51;Intel® 536EP Modem;C:\WINDOWS\system32\DRIVERS\Intels51.sys
R3 viafilter;VIA USB Filter;C:\WINDOWS\system32\Drivers\viausb1.sys
S2 Ca536av;DigitalCam Pro Video Camera Device;C:\WINDOWS\system32\Drivers\Ca536av.sys
S2 LicCtrlService;LicCtrl Service;C:\WINDOWS\runservice.exe
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\fetnd5.sys
S3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5b.sys
S3 GT680x;GrandTechICNameNT;C:\WINDOWS\system32\Drivers\gt680x.sys
S3 NTSIM;NTSIM;\??\C:\WINDOWS\system32\ntsim.sys
S3 Point32;Microsoft IntelliPoint Filter Driver;C:\WINDOWS\system32\DRIVERS\point32.sys
S3 StillCam;Still Serial Digital Camera Driver;C:\WINDOWS\system32\DRIVERS\serscan.sys

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Usnsvc usnsvc


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-31 09:49:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-31 9:51:52 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-31 09:51
C:\ComboFix2.txt … 2007-07-29 19:37

HJT log


Logfile of HijackThis v1.99.1
Scan saved at 09:53:56, on 31/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\PC\Desktop\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/webhp?sourceid=nav…nt&ie=UTF-8
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by16fd.bay16.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1155856671045
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B03020B5-3D30-4346-ABCD-BA345DE6024F}: NameServer = 195.92.195.90 195.92.195.91
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe



Regrettably, still no change to problems on start up (as per first post on thread).

Regards

Nelclaret
Hi nelclaret,

The good news is that it looks like Panda's gone, and that your machine is clean of malware. The bad news is that your problems aren't yet resolved !!!

Some things to try:

Remove unused or un-necessary programs:
Please open Start->Control Panel->Add/Remove Programs
Look down the list for unnecessary, unused or unwanted programs and remove them

Use MSConfig to temporarily disable startup programs:
Press Start->Run, type msconfig and press OK
Select the Startup tab and uncheck any non-essential programs - this will disable them from running on boot
Note: I strongly recommend you only make changes to the Startup tab and leave the other tabs alone

Check Device Manager for problems:
Right-click My Computer and select Manage
Select Device Manager from the left pane, and look for question marks which indicate a device problem
If you find a question mark, look for the device causing the issue and post the details.

Update your video driver by downloading the latest version from the manufacturer's website

Remove Starforce copy protection drivers:
The Starforce copy protection drivers have been linked with system instability, however, they may be required in order for you to use protected software. If you wish to remove them, you can download the removal tool from here:
http://onlinesecurity-on.com/downloads/sfdrvrem.zip
Download the zip file, extract sfdrvrem.exe to your Desktop and double-click it to run the program

Let me know how you get on :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI