This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Unknown Spyware Problem

34 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, i got major spyware problem. I cannot access my local disks by double clicking. On the context menus of my local drives (C,D,E,F,) are also options 'Auto' and 'Autoplay'.
[external image: Posted Image]

I found some help on the net how to remove those, but nothing helped. I tried to erase autorun.inf and pegefile.pif, but they always return again and again.
[external image: Posted Image]
i also tried to remove MountPoints2 folder from Registry, but it also returns. I am helpless.

And my internet connection pops up to connect to these site:
www.832822.cn
www.plince.net
www.sms591.com
data.alexa.com
[external image: Posted Image]

I feel i got heavily infected. I hope that someone will help me save me this problem. I did read some help here, but i don't understand russian. russian help



here is also Hijack log:
Logfile of HijackThis v1.99.1
Scan saved at 15:10:05, on 25.7.2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\anvshell.exe
C:\WINDOWS\System32\SiSAudUt.exe
C:\WINDOWS\System32\Linksts.exe
C:\Program Files\OnLine Brojac v.7.0\onlinebrojac.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Programi\Problem!!\hijack\HijackThis\HijackThis.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [anvshell] anvshell.exe
O4 - HKLM\..\Run: [SiS7012Utility] C:\WINDOWS\System32\SiSAudUt.exe -wdm
O4 - HKLM\..\Run: [ISDN Monitor] Linksts.exe W 1024
O4 - HKLM\..\Run: [OnLineBrojac] C:\Program Files\OnLine Brojac v.7.0\onlinebrojac.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O17 - HKLM\System\CCS\Services\Tcpip\..\{BCF72CEB-777E-4C8C-A322-EDBA6F75E89E}: NameServer = 161.53.114.135 161.53.114.145
O20 - AppInit_DLLs: dhbpri.dll
O23 - Service: ASUS Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe


help is appreciated. thanks
Hi! Welcome to the Tom Coyote forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.


Rename HijackThis
There is probably an infection which is hiding part of the HijackThis log because it's called hijackthis.exe.
Please rename hijackthis.exe to hello.exe

Now scan again and post a new log, please.
thank u for taking interest to help me. i really appreciate it.

Here's my uninstall list:
ACDSee 9 Photo Manager
Adobe Flash Player 9 ActiveX
AIM 6
ASUS Display Drivers
CCleaner (remove only)
HijackThis 2.0.2
Hotfix for Windows XP (KB915865)
Java 2 Runtime Environment, SE v1.4.1_02
Java Web Start
LimeWire PRO 4.12.14
Microsoft DirectX Transform optional components
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
OnLine Brojač v.7.0
PCI Audio Applications
SiS Audio Driver
Sophos Anti-Virus version 4.09.0
Spybot - Search & Destroy 1.4
Viewpoint Media Player
Winamp (remove only)
Windows Internet Explorer 7
Windows XP Service Pack 2
Yahoo! Messenger

And new HijackThis scan log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 0:22:11, on 28.7.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\anvshell.exe
C:\WINDOWS\System32\SiSAudUt.exe
C:\WINDOWS\system32\Linksts.exe
C:\Program Files\OnLine Brojac v.7.0\onlinebrojac.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\WINDOWS\system\internat.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\Hello.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.net.hr/
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [anvshell] anvshell.exe
O4 - HKLM\..\Run: [SiS7012Utility] C:\WINDOWS\System32\SiSAudUt.exe -wdm
O4 - HKLM\..\Run: [ISDN Monitor] Linksts.exe W 1024
O4 - HKLM\..\Run: [OnLineBrojac] C:\Program Files\OnLine Brojac v.7.0\onlinebrojac.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ztsa] C:\DOCUME~1\TONI~1.TB-\LOCALS~1\Temp\ztso.exe
O4 - HKLM\..\Run: [rxsa] C:\DOCUME~1\TONI~1.TB-\LOCALS~1\Temp\rxso.exe
O4 - HKLM\..\Run: [wlsa] C:\DOCUME~1\TONI~1.TB-\LOCALS~1\Temp\wlso.exe
O4 - HKLM\..\Run: [wgsa] C:\DOCUME~1\TONI~1.TB-\LOCALS~1\Temp\wgso.exe
O4 - HKLM\..\Run: [TIMHost] C:\WINDOWS\TIMHost.exe
O4 - HKLM\..\Run: [tlsa] C:\DOCUME~1\TONI~1.TB-\LOCALS~1\Temp\tlso.exe
O4 - HKLM\..\Run: [wdsa] C:\DOCUME~1\TONI~1.TB-\LOCALS~1\Temp\wdso.exe
O4 - HKLM\..\Run: [zxsa] C:\DOCUME~1\TONI~1.TB-\LOCALS~1\Temp\zxso.exe
O4 - HKLM\..\Run: [qjsa] C:\DOCUME~1\TONI~1.TB-\LOCALS~1\Temp\qjso.exe
O4 - HKLM\..\Run: [WinDCP32] C:\WINDOWS\WinDCP32.exe
O4 - HKLM\..\Run: [KVP] C:\WINDOWS\system32\drivers\svchost.exe
O4 - HKLM\..\Run: [wosa] C:\DOCUME~1\TONI~1.TB-\LOCALS~1\Temp\woso.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKLM\..\Policies\Explorer\Run: [twin] C:\WINDOWS\system32\ctfnom.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_02\bin\npjpi141_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_02\bin\npjpi141_02.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{BCF72CEB-777E-4C8C-A322-EDBA6F75E89E}: NameServer = 161.53.114.135 161.53.114.145
O20 - AppInit_DLLs: dhbpri.dll
O23 - Service: ASUS Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

–
End of file - 3381 bytes


now i got much more files… interesting
Hi Tonib

You are currently using an unpatched version of Microsoft XP. It is CRITICAL that you update to Service Pack 1a
Please visit this link:
Microsoft Service Pack 1a

and install Service Pack 1a. If you run into troubles, please post them here.

IMPORTANT: DO NOT update to Service pack 2. Doing so before your computer is clean can cause Windows to become unstable.
We will update to SP2 when you are clean.



Please post back with a HJT log and your computer running with Service pack 1a, or with any problems you are having updating.
Hello tonib

Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.

Double-click ATF Cleaner.exe to open it.

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache

*The other boxes are optional*
Then click the Empty Selected button.

Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt in your next reply.
Download and Run ComboFix
  • Download this file from below:

    Here
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
SDFix: Version 1.94 Run by [removed] on sub 28.07.2007 at 01:01 Microsoft Windows XP [Version 5.1.2600] Running From: C:\SDFix\SDFix Safe Mode: Checking Services: Restoring Windows Registry Values Restoring Windows Default Hosts File Rebooting… Normal Mode: Checking Files: Trojan Files Found: C:\WINDOWS\system32\drivers\svchost.exe - Deleted Removing Temp Files… ADS Check: C:\WINDOWS No streams found. C:\WINDOWS\system32 No streams found. C:\WINDOWS\system32\svchost.exe No streams found. C:\WINDOWS\system32\ntoskrnl.exe No streams found. Final Check: Remaining Services: —————— Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire" "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader" "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger" "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" Remaining Files: ————— Backups Folder: - C:\SDFix\SDFix\backups\backups.zip Files with Hidden Attributes: C:\Documents and Settings\Toni\Local Settings\Temp\jh.dll C:\Documents and Settings\Toni\Local Settings\Temp\vvif4fx2.dll C:\Program Files\Internet Explorer\PLUGINS\NewTemp.dll C:\Program Files\MSN Messenger\1033\dwintl.dll C:\Program Files\OnLine Brojac v.7.0\_Setup.dll C:\WINDOWS\system32\zxepri.dll C:\Documents and Settings\Administrator\Local Settings\Temp\RavMonD.exe C:\Documents and Settings\Administrator\Local Settings\Temp\RAVWM.EXE C:\Program Files\OnLine Brojac v.7.0\Setup.exe C:\WINDOWS\system\internat.exe C:\WINDOWS\system32\ctfnom.exe C:\PegeFile.pif C:\Program Files\Internet Explorer\IEXPLORE.Sys C:\Program Files\Internet Explorer\IEXPLORE32.Sys C:\Program Files\Internet Explorer\PLUGINS\SysWin64.Sys C:\Documents and Settings\Administrator\Desktop\efst.hr\Engleski\Portfolio\~WRL2844.tmp C:\Documents and Settings\Administrator\Local Settings\Temp\Off115.tmp C:\Documents and Settings\Administrator\My Documents\~WRL0002.tmp C:\Documents and Settings\Administrator\My Documents\~WRL0004.tmp C:\Documents and Settings\Administrator\My Documents\~WRL0005.tmp C:\Documents and Settings\Administrator\My Documents\~WRL0046.tmp C:\Documents and Settings\Administrator\My Documents\~WRL0063.tmp C:\Documents and Settings\Administrator\My Documents\~WRL1672.tmp C:\Documents and Settings\Administrator\My Documents\~WRL3314.tmp C:\Documents and Settings\Administrator\My Documents\l.e.k.t.i.r.e\~WRL1310.tmp C:\Documents and Settings\Administrator\My Documents\LEKTIRE M.Z.T. i K\~WRL2193.tmp C:\Documents and Settings\Administrator\My Documents\matura\~WRL0004.tmp C:\Documents and Settings\Administrator\My Documents\matura\~WRL2196.tmp C:\Documents and Settings\Toni\Local Settings\Temp\BIT75.tmp C:\Program Files\Common Files\Microsoft Shared\MSInfo\NewInfo.tmp C:\Program Files\InterActual\InterActual Player\iti237.tmp Finished
ComboFix 07-07-27.6 - "Toni" 2007-07-28 1:19:55.1 [GMT 2:00] - NTFS
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.True


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\Common Files\Microsoft Shared\MSInfo\system.2dt
C:\Program Files\iMeshBar
C:\Program Files\iMeshBar\bar\1.bin\IMESHBAR.DLL
C:\Program Files\iMeshBar\bar\Cache13B5893
C:\Program Files\iMeshBar\bar\Cache13B7C09
C:\Program Files\iMeshBar\bar\Cache13B7EB9.bin
C:\Program Files\iMeshBar\bar\Cache13B87A2.bmp
C:\Program Files\iMeshBar\bar\Cache13BB1DF.bmp
C:\Program Files\iMeshBar\bar\Cache\files.ini
C:\Program Files\iMeshBar\bar\History\search
C:\Program Files\iMeshBar\bar\Settings\prevcfg.htm
C:\Program Files\Internet Explorer\IEXPLORE.jmp
C:\Program Files\internet explorer\iexplore.win
C:\Program Files\Internet Explorer\IEXPLORE32.jmp
C:\Program Files\Internet Explorer\PLUGINS\System64.Jmp
C:\Program Files\Internet Explorer\PLUGINS\SysWin64.Jmp
C:\Program Files\internet explorer\plugins\syswin64.sys
C:\WINDOWS\msccrt.exe
C:\WINDOWS\msimms32.exe
C:\WINDOWS\system\1.exe
C:\WINDOWS\system\2.exe
C:\WINDOWS\system\5.exe
C:\WINDOWS\system\6.exe
C:\WINDOWS\system\7.exe
C:\WINDOWS\system\system32.vxd
C:\WINDOWS\system32\CC4D2100.EXE
C:\WINDOWS\system32\ctfnom.exe
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\moyu103.dll
C:\WINDOWS\system32\msccrt.dll
C:\WINDOWS\system32\msdebug.dll
C:\WINDOWS\system32\Msf3sf.sys
C:\WINDOWS\system32\msimms32.dll
C:\WINDOWS\system32\mydata.exe
C:\WINDOWS\system32\remotedbg.dll
C:\WINDOWS\system32\upxdnd.dll
C:\WINDOWS\system32\windhcp.ocx
C:\WINDOWS\system32\winform.dll
C:\WINDOWS\upxdnd.exe
C:\WINDOWS\winform.exe


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_CELINDRV
——-\LEGACY_MSDEBUGSVC
——-\LEGACY_NPF
——-\LEGACY_REMOTEDBG
——-\LEGACY_WINDHCPSVC
——-\MSDebugsvc
——-\NPF
——-\RemoteDbg
——-\WinDHCPsvc


((((((((((((((((((((((((( Files Created from 2007-06-27 to 2007-07-27 )))))))))))))))))))))))))))))))


2007-07-28 01:18 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-28 01:01 d——– C:\WINDOWS\ERUNT
2007-07-28 00:59 d——– C:\WINDOWS\CSC
2007-07-27 22:28 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2007-07-27 22:28 d——– C:\DOCUME~1\TONI~1.TB-\APPLIC~1\BSplayer
2007-07-27 22:21 d——– C:\DOCUME~1\TONI~1.TB-\.jpi_cache
2007-07-27 20:03 d——– C:\DOCUME~1\TONI~1.TB-\APPLIC~1\SUPERAntiSpyware.com
2007-07-27 20:03 d——– C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\SUPERAntiSpyware.com
2007-07-27 19:47 48 –a—— C:\WINDOWS\system32\zxeini.dll
2007-07-27 02:30 d——– C:\Program Files\AIM6
2007-07-27 01:52 d——– C:\DOCUME~1\TONI~1.TB-\APPLIC~1\ACD Systems
2007-07-27 01:51 d——– C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\ACD Systems
2007-07-27 01:50 10,368 –a—— C:\WINDOWS\system32\drivers\pfc.sys
2007-07-27 01:42 d——– C:\WINDOWS\Downloaded Installations
2007-07-26 19:22 10,012 –a—— C:\WINDOWS\system\16.exe
2007-07-26 19:21 9,968 –a—— C:\WINDOWS\system32\RAV008C.exe
2007-07-26 19:21 9,968 –a—— C:\WINDOWS\system\10.exe
2007-07-26 12:26 15,360 –a—— C:\WINDOWS\system32\WinDCP32.dll
2007-07-26 12:26 13,312 –a—— C:\WINDOWS\WinDCP32.exe
2007-07-26 02:55 d——– C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Yahoo!
2007-07-26 02:19 d——– C:\DOCUME~1\TONI~1.TB-\APPLIC~1\acccore
2007-07-26 02:19 d——– C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\AOL OCP
2007-07-26 02:18 d——– C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Viewpoint
2007-07-26 02:18 d——– C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\AOL
2007-07-26 02:17 d——– C:\Program Files\Common Files\AOL
2007-07-26 01:22 d——– C:\DOCUME~1\TONI~1.TB-\APPLIC~1\LimeWire
2007-07-26 01:21 d——– C:\Program Files\LimeWire
2007-07-26 00:44 d——– C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\AOL Downloads
2007-07-26 00:15 d——– C:\Program Files\AIM Toolbar
2007-07-25 23:52 d——– C:\DOCUME~1\TONI~1.TB-\Incomplete
2007-07-25 23:47 d——– C:\Program Files\Java Web Start
2007-07-25 23:47 d——– C:\DOCUME~1\TONI~1.TB-\.javaws
2007-07-25 22:51 d——– C:\Sophos SWEEP for NT
2007-07-25 22:40 d——– C:\WINDOWS\system32\appmgmt
2007-07-25 22:00 29,184 –a—— C:\WINDOWS\TIMHost.exe
2007-07-25 22:00 22,016 –a—— C:\WINDOWS\system32\TIMHost.dll
2007-07-25 21:48 16,943 —hs—- C:\PegeFile.pif
2007-07-25 21:37 d–h—– C:\WINDOWS\$hf_mig$
2007-07-25 21:35 d——– C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Windows Genuine Advantage
2007-07-25 21:00 8,192 –a—— C:\WINDOWS\system32\wshirda.dll
2007-07-25 21:00 27,136 –a—— C:\WINDOWS\system32\irmon.dll
2007-07-25 21:00 152,576 –a—— C:\WINDOWS\system32\irftp.exe
2007-07-25 20:57 d——– C:\WINDOWS\SoftwareDistribution
2007-07-25 20:45 95,424 ——— C:\WINDOWS\system32\drivers\slnthal.sys
2007-07-25 20:45 937,984 ——— C:\WINDOWS\system32\winbrand.dll
2007-07-25 20:45 9,728 ——— C:\WINDOWS\system32\comsdupd.exe
2007-07-25 20:45 896,512 ——— C:\WINDOWS\system32\wmspdmoe.dll
2007-07-25 20:45 88,064 ——— C:\WINDOWS\system32\p2pnetsh.dll
2007-07-25 20:45 870,784 ——— C:\WINDOWS\system32\ati3d1ag.dll
2007-07-25 20:45 86,016 ——— C:\WINDOWS\system32\p2pgasvc.dll
2007-07-25 20:45 86,016 ——— C:\WINDOWS\system32\mdmxsdk.dll
2007-07-25 20:45 81,408 ——— C:\WINDOWS\system32\wscsvc.dll
2007-07-25 20:45 8,192 ——— C:\WINDOWS\system32\smbinst.exe
2007-07-25 20:45 8,192 ——— C:\WINDOWS\system32\bitsprx2.dll
2007-07-25 20:45 78,464 ——— C:\WINDOWS\system32\drivers\usbvideo.sys
2007-07-25 20:45 78,336 –a—— C:\WINDOWS\system32\ieencode.dll
2007-07-25 20:45 75,776 ——— C:\WINDOWS\system32\strmfilt.dll
2007-07-25 20:45 73,832 ——— C:\WINDOWS\system32\slcoinst.dll
2007-07-25 20:45 73,796 ——— C:\WINDOWS\system32\slserv.exe
2007-07-25 20:45 73,216 ——— C:\WINDOWS\system32\drivers\atintuxx.sys
2007-07-25 20:45 71,680 ——— C:\WINDOWS\system32\blastcln.exe
2007-07-25 20:45 701,440 ——— C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-07-25 20:45 7,680 ——— C:\WINDOWS\system32\kbdsmsno.dll
2007-07-25 20:45 7,680 ——— C:\WINDOWS\system32\kbdsmsfi.dll
2007-07-25 20:45 7,168 ——— C:\WINDOWS\system32\kbdukx.dll
2007-07-25 20:45 7,168 ——— C:\WINDOWS\system32\kbdno1.dll
2007-07-25 20:45 7,168 ——— C:\WINDOWS\system32\kbdfi1.dll
2007-07-25 20:45 7,168 ——— C:\WINDOWS\system32\hccoin.dll
2007-07-25 20:45 7,168 ——— C:\WINDOWS\system32\bitsprx3.dll
2007-07-25 20:45 685,056 ——— C:\WINDOWS\system32\drivers\hsfcxts2.sys
2007-07-25 20:45 67,584 ——— C:\WINDOWS\system32\drivers\sdbus.sys
2007-07-25 20:45 63,663 ——— C:\WINDOWS\system32\drivers\ati1rvxx.sys
2007-07-25 20:45 63,488 ——— C:\WINDOWS\system32\drivers\atinxsxx.sys
2007-07-25 20:45 60,416 ——— C:\WINDOWS\system32\fwcfg.dll
2007-07-25 20:45 6,656 ——— C:\WINDOWS\system32\kbdinmal.dll
2007-07-25 20:45 6,656 ——— C:\WINDOWS\system32\kbdinben.dll
2007-07-25 20:45 6,144 ——— C:\WINDOWS\system32\kbdmlt48.dll
2007-07-25 20:45 6,144 ——— C:\WINDOWS\system32\kbdmlt47.dll
2007-07-25 20:45 6,144 ——— C:\WINDOWS\system32\kbdinbe1.dll
2007-07-25 20:45 6,016 ——— C:\WINDOWS\system32\drivers\smbali.sys
2007-07-25 20:45 59,648 ——— C:\WINDOWS\system32\drivers\rfcomm.sys
2007-07-25 20:45 57,856 ——— C:\WINDOWS\system32\drivers\atinbtxx.sys
2007-07-25 20:45 56,623 ——— C:\WINDOWS\system32\drivers\ati1btxx.sys
2007-07-25 20:45 526,848 ——— C:\WINDOWS\system32\p2psvc.dll
2007-07-25 20:45 52,224 ——— C:\WINDOWS\system32\mspmsnsv.dll
2007-07-25 20:45 52,224 ——— C:\WINDOWS\system32\drivers\atinraxx.sys
2007-07-25 20:45 516,768 ——— C:\WINDOWS\system32\ativvaxx.dll
2007-07-25 20:45 50,688 ——— C:\WINDOWS\system32\btpanui.dll
2007-07-25 20:45 50,176 ——— C:\WINDOWS\system32\xmlprovi.dll
2007-07-25 20:45 5,632 ——— C:\WINDOWS\system32\kbdmaori.dll
2007-07-25 20:45 49,152 ——— C:\WINDOWS\system32\powercfg.exe
2007-07-25 20:45 484,864 ——— C:\WINDOWS\system32\wmspdmod.dll
2007-07-25 20:45 48,640 ——— C:\WINDOWS\system32\pnrpnsp.dll
2007-07-25 20:45 46,464 ——— C:\WINDOWS\system32\drivers\gagp30kx.sys
2007-07-25 20:45 452,736 ——— C:\WINDOWS\system32\drivers\mtxparhm.sys
2007-07-25 20:45 44,928 ——— C:\WINDOWS\system32\drivers\agpcpq.sys
2007-07-25 20:45 44,672 ——— C:\WINDOWS\system32\drivers\uagp35.sys
2007-07-25 20:45 44,032 ——— C:\WINDOWS\system32\twext.dll
2007-07-25 20:45 438,784 ——— C:\WINDOWS\system32\xpob2res.dll
2007-07-25 20:45 430,592 ——— C:\WINDOWS\system32\wuapi.dll


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-27 20:02 ——— d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-07-27 01:51 ——— d——– C:\Program Files\Common Files\ACD Systems
2007-07-26 02:18 ——— d——– C:\Program Files\Viewpoint
2007-07-25 23:47 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-07-25 20:45 ——— d——– C:\Program Files\Messenger
2007-07-25 20:44 ——— d——– C:\Program Files\Movie Maker
2007-07-25 20:36 ——— d——– C:\Program Files\Windows NT
2007-07-25 09:21 ——— d——– C:\Program Files\OnLine Brojac v.7.0
2007-07-25 07:51 ——— d–h—– C:\Program Files\WindowsUpdate
2007-07-25 01:42 ——— d——– C:\Program Files\Creative
2007-07-24 15:29 ——— d——– C:\Program Files\Word Translator
2007-07-24 15:29 ——— d——– C:\Program Files\Tsunami_Filter_Pack_Mini
2007-07-24 15:29 ——— d——– C:\Program Files\Sony Ericsson
2007-07-24 15:29 ——— d——– C:\Program Files\Common Files\Autodesk Shared
2007-07-16 18:32 ——— d——– C:\Program Files\ffdshow
2007-06-18 17:47 ——— d——– C:\Program Files\Lavasoft
2007-06-18 17:42 ——— d——– C:\Program Files\DivX
2007-06-18 17:38 ——— d——– C:\Program Files\QuickTime
2007-06-18 17:34 ——— d——– C:\Program Files\Apple Software Update
2007-05-30 01:48 ——— d——– C:\Program Files\MySpace
2004-08-04 17:47:21 15,909 –sh–w C:\WINDOWS\system32\zxepri.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" []
"anvshell"="anvshell.exe" [2002-04-10 04:14 C:\WINDOWS\anvshell.exe]
"ISDN Monitor"="Linksts.exe" [2002-06-24 04:49 C:\WINDOWS\system32\linksts.exe]
"OnLineBrojac"="C:\Program Files\OnLine Brojac v.7.0\onlinebrojac.exe" [2004-11-01 13:13]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 00:56 C:\WINDOWS\system32\bthprops.cpl]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 00:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{0EA66AD2-CF26-2E23-532B-B292E22F3266}"= C:\Program Files\Internet Explorer\PLUGINS\NewTemp.dll [2007-07-28 01:12 10799]
"{713AF41A-21B1-131B-1BFC-D2A90DF4A2B7}"= C:\WINDOWS\system32\xyfpri.dll [2004-08-04 11:58 16426]
"{26368135-64FA-BC34-DA32-DCF4FD431C92}"= C:\WINDOWS\system32\qhbpri.dll [2004-08-04 22:01 15403]
"{22311A42-AC1B-158F-FD32-5674345F23A2}"= C:\WINDOWS\system32\dhbpri.dll [2004-08-04 22:01 16439]
"{425AB2F3-234A-7469-2F43-E341713ABFA4}"= C:\WINDOWS\system32\wgdpri.dll [2004-08-04 12:39 15909]
"{3562452F-FA36-BA4F-892A-FF5FBBAC5313}"= C:\WINDOWS\system32\mycpri.dll [2004-08-04 12:40 17445]
"{C5E87A05-F463-4841-B19E-DD3EC3862368}"= C:\Program Files\Internet Explorer\IEXPLORE32.Sys [2007-07-28 00:23 29832]
"{EE12D60D-AD9A-4095-B839-3BE6862679FD}"= C:\Program Files\Internet Explorer\IEXPLORE32.Dat [2007-07-28 00:23 35481]
"{A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E}"= C:\Program Files\Internet Explorer\IEXPLORE32.win [2007-07-28 00:23 28790]
"{5A65498A-7653-9801-1647-987114AB7F45}"= C:\WINDOWS\system32\zxepri.dll [2004-08-04 19:47 15909]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=xyfpri.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Launcher.exe]
Debugger=C:\WINDOWS\system\7.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\my.exe]
Debugger=C:\WINDOWS\system\2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\WoW.exe]
Debugger=C:\WINDOWS\system\7.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]

R0 isdnlink;isdnlink;C:\WINDOWS\system32\DRIVERS\linkisdn.sys
R1 ANVIOCTL;ANVIOCTL;C:\WINDOWS\system32\DRIVERS\anvioctl.sys
R1 ANVOSDNT;ASUS Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\anvosdnt.sys
R1 AVZRK;AVZ-RK Kernel Driver;\??\C:\WINDOWS\System32\Drivers\uzm3mtq5.sys
R1 SASDIFSV;SASDIFSV;\??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
R1 SASKUTIL;SASKUTIL;\??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
R2 BthServ;Bluetooth Support Service;C:\WINDOWS\system32\svchost.exe -k bthsvcs
R3 BthEnum;Bluetooth Enumerator Service;C:\WINDOWS\system32\DRIVERS\BthEnum.sys
R3 BthPan;Bluetooth Device (Personal Area Network);C:\WINDOWS\system32\DRIVERS\bthpan.sys
R3 BTHUSB;Bluetooth Radio USB Driver;C:\WINDOWS\system32\Drivers\BTHUSB.sys
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI);C:\WINDOWS\system32\DRIVERS\rfcomm.sys
R3 SiS7012;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\sis7012.sys
R3 wanlink;wanlink;C:\WINDOWS\system32\DRIVERS\wanlink.sys
S2 EFED6050;EFED6050;C:\WINDOWS\system32\CC4D2100.EXE -d
S3 BTHPORT;Bluetooth Port Driver;C:\WINDOWS\system32\Drivers\BTHport.sys
S3 SASENUM;SASENUM;\??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
Auto\command- C:\PegeFile.pif
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL PegeFile.pif

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
Auto\command- D:\PegeFile.pif
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL PegeFile.pif

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
Auto\command- E:\PegeFile.pif
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL PegeFile.pif

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
Auto\command- F:\PegeFile.pif
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL PegeFile.pif


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-28 01:24:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-28 1:26:13 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-28 01:26

— E O F —
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:29:26, on 28.7.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\anvshell.exe
C:\WINDOWS\system32\Linksts.exe
C:\Program Files\OnLine Brojac v.7.0\onlinebrojac.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\Hello.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.net.hr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [anvshell] anvshell.exe
O4 - HKLM\..\Run: [ISDN Monitor] Linksts.exe W 1024
O4 - HKLM\..\Run: [OnLineBrojac] C:\Program Files\OnLine Brojac v.7.0\onlinebrojac.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_02\bin\npjpi141_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_02\bin\npjpi141_02.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{BCF72CEB-777E-4C8C-A322-EDBA6F75E89E}: NameServer = 161.53.114.135 161.53.114.145
O20 - AppInit_DLLs: wgdpri.dll
O23 - Service: EFED6050 - Unknown owner - C:\WINDOWS\system32\CC4D2100.EXE (file missing)
O23 - Service: ASUS Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

–
End of file - 2323 bytes
sorry for doing multiply replies… and i just wanted to tell u i still got connection windows to pop up. about dozen pop ups when i enter windows. and is till got autorun.inf files on my disks, as well pegefile.pif files
Hi tonib

You have no anti-virus on your computer. It is important you install one now before we continue with your fix. Check this out for a list of free AV scanners, AVG is highly recommended.

Install one while I work on the next move. :thumbup:
Hello Tonib
  • Download Silent runners by Andrew Aronoff from here
  • Unzip/extract it to a folder on your desktop
  • Double click on Silent Runners.vbs to start Silent runners
  • If your antivirus warns you about a script, allow it to run, this script does not contain malicious code
  • You will be asked if you want skip the supplementary search, click Yes
  • Wait for Silent runners to inform you that it has finished
  • A log will be created in the same folder as Silent Runners.vbs
  • It will have a name of Startup Programs (yourusername) date-time.txt
  • Use notepad to open that file
  • Copy and paste the contents as a reply to this topic
here's the log:
"Silent Runners.vbs", revision R51, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
———————————

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
"MSMSGS" = ""C:\Program Files\Messenger\msmsgs.exe" /background" [MS]
"(Default)" = (unknown data type)

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ {++}
"twin" = "C:\WINDOWS\system32\ctfnom.exe" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"NvCplDaemon" = "RUNDLL32.EXE NvQTwk,NvCplDaemon initialize" [MS]
"anvshell" = "anvshell.exe" ["AsusTeK Computer Inc."]
"ISDN Monitor" = "Linksts.exe W 1024" ["ASUSCOM"]
"OnLineBrojac" = "C:\Program Files\OnLine Brojac v.7.0\onlinebrojac.exe" ["Ivica Kutnjak , FOI - Varaždin 2004."]
"BluetoothAuthenticationAgent" = "rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent" [MS]
"upxdnd" = "C:\WINDOWS\upxdnd.exe" [null data]
"RAV008C" = "C:\WINDOWS\system32\RAV008C.exe" [null data]
"msccrt" = "C:\WINDOWS\msccrt.exe" [null data]
"RAV009B" = "C:\WINDOWS\system32\RAV009B.exe" [null data]
"ztsa" = "C:\DOCUME~1\TONI~1.TB-\LOCALS~1\Temp\ztso.exe" [null data]
"wlsa" = "C:\DOCUME~1\TONI~1.TB-\LOCALS~1\Temp\wlso.exe" [null data]
"wgsa" = "C:\DOCUME~1\TONI~1.TB-\LOCALS~1\Temp\wgso.exe" [null data]
"TIMHost" = "C:\WINDOWS\TIMHost.exe" [null data]
"tlsa" = "C:\DOCUME~1\TONI~1.TB-\LOCALS~1\Temp\tlso.exe" [null data]
"wdsa" = "C:\DOCUME~1\TONI~1.TB-\LOCALS~1\Temp\wdso.exe" [null data]
"zxsa" = "C:\DOCUME~1\TONI~1.TB-\LOCALS~1\Temp\zxso.exe" [null data]
"qjsa" = "C:\DOCUME~1\TONI~1.TB-\LOCALS~1\Temp\qjso.exe" [null data]
"WinDCP32" = "C:\WINDOWS\WinDCP32.exe" [null data]
"KVP" = "C:\WINDOWS\system32\drivers\svchost.exe"
"AVG7_CC" = "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP" ["GRISOFT, s.r.o."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
-> {HKLM…CLSID} = "Display Panning CPL Extension"
\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> {HKLM…CLSID} = "HyperTerminal Icon Ext"
\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
"{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"
-> {HKLM…CLSID} = "Desktop Explorer"
\InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {HKLM…CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
"{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Shell Extension"
-> {HKLM…CLSID} = "AVG7 Shell Extension Class"
\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
"{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Find Extension"
-> {HKLM…CLSID} = "AVG7 Find Extension Class"
\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
<> "{0EA66AD2-CF26-2E23-532B-B292E22F3266}" = (no title provided)
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Internet Explorer\PLUGINS\NewTemp.dll" [null data]
<> "{713AF41A-21B1-131B-1BFC-D2A90DF4A2B7}" = "xyfpri.dll"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\xyfpri.dll" [null data]
<> "{26368135-64FA-BC34-DA32-DCF4FD431C92}" = "qhbpri.dll"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\qhbpri.dll" [null data]
<> "{22311A42-AC1B-158F-FD32-5674345F23A2}" = "dhbpri.dll"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\dhbpri.dll" [null data]
<> "{425AB2F3-234A-7469-2F43-E341713ABFA4}" = "wgdpri.dll"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\wgdpri.dll" [null data]
<> "{3562452F-FA36-BA4F-892A-FF5FBBAC5313}" = "mycpri.dll"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\mycpri.dll" [null data]
<> "{C5E87A05-F463-4841-B19E-DD3EC3862368}" = (no title provided)
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Internet Explorer\IEXPLORE32.Sys" [null data]
<> "{EE12D60D-AD9A-4095-B839-3BE6862679FD}" = (no title provided)
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Internet Explorer\IEXPLORE32.Dat" [null data]
<> "{A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E}" = (no title provided)
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Internet Explorer\IEXPLORE32.win" [null data]
<> "{5A65498A-7653-9801-1647-987114AB7F45}" = "zxepri.dll"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\zxepri.dll" [null data]
<> "{559AFD5B-159F-ACD8-954C-ACD545FA6585}" = "jzepri.dll"
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\jzepri.dll" [null data]
<> "{40117B96-998D-4D80-8F89-5E9DBD9F3460}" = (no title provided)
-> {HKLM…CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Internet Explorer\PLUGINS\SysWin64.Sys" [null data]

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\
"load" = (value not set)

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\
<> "AppInit_DLLs" = "wgdpri.dll" [null data]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\
<> Launcher.exe\Debugger = "C:\WINDOWS\system\7.exe" [null data]
<> my.exe\Debugger = "C:\WINDOWS\system\2.exe" [null data]
<> WoW.exe\Debugger = "C:\WINDOWS\system\7.exe" [null data]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
-> {HKLM…CLSID} = "AVG7 Shell Extension Class"
\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM…CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM…CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
-> {HKLM…CLSID} = "AVG7 Shell Extension Class"
\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM…CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {HKLM…CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]


Active Desktop and Wallpaper:
—————————–

Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\WINDOWS\web\wallpaper\Bliss.bmp"

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\WINDOWS\web\wallpaper\Bliss.bmp"


Winsock2 Service Provider DLLs:
——————————-

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000004\LibraryPath = "%SystemRoot%\system32\wshbth.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 16
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
————————————

Toolbars

HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{40D41A8B-D79B-43D7-99A7-9EE0F344C385}"
-> {HKLM…CLSID} = "AIM Search"
\InProcServer32\(Default) = "C:\Program Files\AIM Toolbar\AIMBar.dll" [file not found]

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{08B0E5C0-4FCB-11CF-AAA5-00401C608501}"


Running Services (Display Name, Service Name, Path {Service DLL}):
——————————————————————

ASUS Driver Helper Service, NVSvc, "C:\WINDOWS\System32\nvsvc32.exe" ["NVIDIA Corporation"]
AVG E-mail Scanner, AVGEMS, "C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe" ["GRISOFT, s.r.o."]
AVG7 Alert Manager Server, Avg7Alrt, "C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe" ["GRISOFT, s.r.o."]
AVG7 Update Service, Avg7UpdSvc, "C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe" ["GRISOFT, s.r.o."]
Bluetooth Support Service, BthServ, "C:\WINDOWS\system32\svchost.exe -k bthsvcs" {"C:\WINDOWS\System32\bthserv.dll" [MS]}
ERSvc, ERSvc, (null value) [file not found]


———- (launch time: 2007-07-28 15:03:58)
<>: Suspicious data at a malware launch point.

+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
DLL launch points, use the -supp parameter or answer "No" at the
first message box and "Yes" at the second message box.
———- (total run time: 60 seconds)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI