This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Unable To Get Malware Cleaned Up

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This computer was running Windows sp1 without firewall and with Norton definitions from 2003. It was highly infected with Trojans and Downloaders and spyware when I started working on it.

The Panda Active Scan and HJT lead me to believe that I still have traces and infections left that are causing the computer to get reinfected. I have cleaned it with AVG anti-virus and anti-spyware, spybot, spyware doctor, SuperAntispyware, Vundofix, VirtumundoBegone, Trojan Hunter, ATF Cleaner, and AVG Rootkit.

AVG, Spyware Doctor, Trojan Hunter, and SuperAntispyware are indicating that the computer is clean now.

Your help would be appreciated. Thanks!- Jcat'smom :unsure:



Panda Active Scan

Incident Status Location

Potentially unwanted tool:application/need2find Not disinfected hkey_local_machine\software\microsoft\windows\currentversion\uninstall\Need2FindBar Uninstall
Potentially unwanted tool:application/altnet Not disinfected hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache\AltnetDM
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\lz91478d.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\lz91478d.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\lz91478d.default\cookies.txt[.questionmarket.com/]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Owner\Desktop\Downloads\VirtumundoBeGone.exe
Virus:Trj/Downloader.PME Disinfected C:\Documents and Settings\Owner\Local Settings\Application Data\Wildtangent\Cdacache\17.dat
Hacktool:HackTool/KillProcWin.A Not disinfected C:\Documents and Settings\Owner\Local Settings\Application Data\Wildtangent\Cdacache\1B.dat[simple_killw.exe]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@go[1].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\nsb5.tmp
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\nsmA.tmp
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Owner\Local Settings\Temp\nsz5.tmp
Potentially unwanted tool:Application/KillApp.B Not disinfected C:\hp\bin\KillIt.exe
Potentially unwanted tool:Application/KillWind Not disinfected C:\hp\bin\KillWind.exe
Potentially unwanted tool:Application/KillApp.A Not disinfected C:\hp\bin\Terminator.exe
Adware:Adware/Henbang Not disinfected C:\Program Files\TrojanHunter 4.7\Quarantine\2zgB.dat
Potentially unwanted tool:Application/Need2Find Not disinfected C:\Program Files\TrojanHunter 4.7\Quarantine\uSKMn2.dat
Spyware:Cookie/bravenetA Not disinfected C:\WINDOWS\system32\config\systemprofile\Cookies\system@bravenet[1].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\WINDOWS\system32\config\systemprofile\Cookies\system@errorsafe[1].txt
Virus:Generic Trojan Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\HWFOEXXC\1853[1].exe



Logfile of HijackThis v1.99.1
Scan saved at 9:15:47 PM, on 8/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\GEARSEC.EXE
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus8.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus8.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus8.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O1 - Hosts: 84.252.148.113 www.affinityfcu.org
O1 - Hosts: 84.252.148.113 affinityfcu.org
O1 - Hosts: 84.252.148.113 www.azfcu.org
O1 - Hosts: 84.252.148.113 azfcu.org
O1 - Hosts: 84.252.148.113 www.zionbank.com
O1 - Hosts: 84.252.148.113 zionbank.com
O1 - Hosts: 84.252.148.113 www.suncoastfcu.org
O1 - Hosts: 84.252.148.113 suncoastfcu.org
O1 - Hosts: 84.252.148.113 www.citi.com
O1 - Hosts: 84.252.148.113 citi.com
O1 - Hosts: 84.252.148.113 tcfbank.com
O1 - Hosts: 84.252.148.113 www.tcfbank.com
O1 - Hosts: 84.252.148.113 comerica.com
O1 - Hosts: 84.252.148.113 www.comerica.com
O1 - Hosts: 84.252.148.113 www.3riversfcu.org
O1 - Hosts: 84.252.148.113 3riversfcu.org
O1 - Hosts: 84.252.148.113 www.bbt.com
O1 - Hosts: 84.252.148.113 bbt.com
O1 - Hosts: 84.252.148.113 www.cnbwax.com
O1 - Hosts: 84.252.148.113 cnbwax.com
O1 - Hosts: 84.252.148.113 www.cwbk.com
O1 - Hosts: 84.252.148.113 cwbk.com
O1 - Hosts: 84.252.148.113 www.edsefcu.org
O1 - Hosts: 84.252.148.113 edsefcu.org
O1 - Hosts: 84.252.148.113 www.gncu.org
O1 - Hosts: 84.252.148.113 gncu.org
O1 - Hosts: 84.252.148.113 www.householdbank.com
O1 - Hosts: 84.252.148.113 householdbank.com
O1 - Hosts: 84.252.148.113 www.mibank.com
O1 - Hosts: 84.252.148.113 mibank.com
O1 - Hosts: 84.252.148.113 www.myindymacbank.com
O1 - Hosts: 84.252.148.113 myindymacbank.com
O1 - Hosts: 84.252.148.113 www.nafcunet.org
O1 - Hosts: 84.252.148.113 nafcunet.org
O1 - Hosts: 84.252.148.113 www.nationalcity.com
O1 - Hosts: 84.252.148.113 nationalcity.com
O1 - Hosts: 84.252.148.113 www.cnb.com
O1 - Hosts: 84.252.148.113 cnb.com
O1 - Hosts: 84.252.148.113 www.nationwide.com
O1 - Hosts: 84.252.148.113 nationwide.com
O1 - Hosts: 84.252.148.113 www.netbank.com
O1 - Hosts: 84.252.148.113 netbank.com
O1 - Hosts: 84.252.148.113 www.netbank.com
O1 - Hosts: 84.252.148.113 netbank.com.au
O1 - Hosts: 84.252.148.113 www.netbank.com.au
O1 - Hosts: 84.252.148.113 www.postfinance.com
O1 - Hosts: 84.252.148.113 postfinance.com
O1 - Hosts: 84.252.148.113 telcomcu.com
O1 - Hosts: 84.252.148.113 www.telcomcu.com
O1 - Hosts: 84.252.148.113 www.tcuonline.org
O1 - Hosts: 84.252.148.113 tcuonline.org
O1 - Hosts: 84.252.148.113 www.uofcfcu.com
O1 - Hosts: 84.252.148.113 uofcfcu.com
O1 - Hosts: 84.252.148.113 www.warrenfcu.com
O1 - Hosts: 84.252.148.113 warrenfcu.com
O1 - Hosts: 84.252.148.113 visionsfcu.org
O1 - Hosts: 84.252.148.113 www.visionsfcu.org
O1 - Hosts: 84.252.148.113 www.tcfexpress.com
O1 - Hosts: 84.252.148.113 tcfexpress.com
O2 - BHO: (no name) - {0161C753-C283-4A23-A3E3-7064EE9187DA} - C:\Program Files\Internet Explorer\hoke.dll (file missing)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5,1,1,0.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: 0 - {471D6BAE-FB77-4627-EAA7-5F44BEC36141} - C:\Program Files\Messenger\lavupa371.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7B085521-9193-4D78-92DA-A239065849D7} - C:\WINDOWS\System32\qwodjvtq.dll (file missing)
O2 - BHO: (no name) - {84782460-B4B9-43F1-A7DD-1538F98EC324} - C:\WINDOWS\System32\qwodjvtq.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: (no name) - {BDFB988F-3D61-4726-8ED5-9F03A55776F9} - C:\Program Files\Windows Media Player\hoke.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5,1,1,0.dll
O3 - Toolbar: (no name) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [OmniPass] C:\Program Files\Softex\OmniPass\scureapp.exe
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire HomePortal Monitor\2portalmon.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\System32\lsasss.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\poker.exe
O9 - Extra button: ThunderLuck Poker - {73761F50-136E-47b4-979E-E8F37872C6B2} - C:\Program Files\ThunderluckMPP\MPPoker.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1105157635375
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7974F2B4-EA8F-4FEE-BB33-3B0462C496C9}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{D4CB7B21-11A1-4B6C-ABD6-88D593F4BB91}: NameServer = 62.217.54.69
O18 - Filter: text/html - (no CLSID) - (no file)
O20 - Winlogon Notify: !SASWinLogon - C:\My Downloads\SASWINLO.dll
O20 - Winlogon Notify: byxwtsr - byxwtsr.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: mciqsvr - mciqsvr.dll (file missing)
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O21 - SSODL: PXRVONEfGCpY - {949AA79C-3E30-0D36-CD94-B5F893E356A0} - C:\WINDOWS\System32\pdxdt.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSEC.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
_________________________________
Welcome to the Forums.

The fixes we will use are specific to your problems and should only be used for this issue on this machine.

Please only use this topic to reply to. Do not start another thread.
If any other issues arise let me know.
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear. So lets do this to the end!
Please if you decide to seek help at another forum let us know. There is a shortage of helpers and tying 2 of us up is a waste of time.
If you have any questions about any advice given here please STOP and ask!




Please download and run HostsXpert 4.0



Save it to a new folder on your desktop > open the new folder and unzip the file hoster.zip > run Hoster.exe > if your host file is marked as "read only", click the button "Make Hosts Writable" > click the "Restore Original Hosts" button > press OK to restore the original Hosts file > click OK > close The Hoster.




______________________________
HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked

Most/all of the 01 lines should be gone by now.




O1 - Hosts: 84.252.148.113 www.affinityfcu.org
O1 - Hosts: 84.252.148.113 affinityfcu.org
O1 - Hosts: 84.252.148.113 www.azfcu.org
O1 - Hosts: 84.252.148.113 azfcu.org
O1 - Hosts: 84.252.148.113 www.zionbank.com
O1 - Hosts: 84.252.148.113 zionbank.com
O1 - Hosts: 84.252.148.113 www.suncoastfcu.org
O1 - Hosts: 84.252.148.113 suncoastfcu.org
O1 - Hosts: 84.252.148.113 www.citi.com
O1 - Hosts: 84.252.148.113 citi.com
O1 - Hosts: 84.252.148.113 tcfbank.com
O1 - Hosts: 84.252.148.113 www.tcfbank.com
O1 - Hosts: 84.252.148.113 comerica.com
O1 - Hosts: 84.252.148.113 www.comerica.com
O1 - Hosts: 84.252.148.113 www.3riversfcu.org
O1 - Hosts: 84.252.148.113 3riversfcu.org
O1 - Hosts: 84.252.148.113 www.bbt.com
O1 - Hosts: 84.252.148.113 bbt.com
O1 - Hosts: 84.252.148.113 www.cnbwax.com
O1 - Hosts: 84.252.148.113 cnbwax.com
O1 - Hosts: 84.252.148.113 www.cwbk.com
O1 - Hosts: 84.252.148.113 cwbk.com
O1 - Hosts: 84.252.148.113 www.edsefcu.org
O1 - Hosts: 84.252.148.113 edsefcu.org
O1 - Hosts: 84.252.148.113 www.gncu.org
O1 - Hosts: 84.252.148.113 gncu.org
O1 - Hosts: 84.252.148.113 www.householdbank.com
O1 - Hosts: 84.252.148.113 householdbank.com
O1 - Hosts: 84.252.148.113 www.mibank.com
O1 - Hosts: 84.252.148.113 mibank.com
O1 - Hosts: 84.252.148.113 www.myindymacbank.com
O1 - Hosts: 84.252.148.113 myindymacbank.com
O1 - Hosts: 84.252.148.113 www.nafcunet.org
O1 - Hosts: 84.252.148.113 nafcunet.org
O1 - Hosts: 84.252.148.113 www.nationalcity.com
O1 - Hosts: 84.252.148.113 nationalcity.com
O1 - Hosts: 84.252.148.113 www.cnb.com
O1 - Hosts: 84.252.148.113 cnb.com
O1 - Hosts: 84.252.148.113 www.nationwide.com
O1 - Hosts: 84.252.148.113 nationwide.com
O1 - Hosts: 84.252.148.113 www.netbank.com
O1 - Hosts: 84.252.148.113 netbank.com
O1 - Hosts: 84.252.148.113 www.netbank.com
O1 - Hosts: 84.252.148.113 netbank.com.au
O1 - Hosts: 84.252.148.113 www.netbank.com.au
O1 - Hosts: 84.252.148.113 www.postfinance.com
O1 - Hosts: 84.252.148.113 postfinance.com
O1 - Hosts: 84.252.148.113 telcomcu.com
O1 - Hosts: 84.252.148.113 www.telcomcu.com
O1 - Hosts: 84.252.148.113 www.tcuonline.org
O1 - Hosts: 84.252.148.113 tcuonline.org
O1 - Hosts: 84.252.148.113 www.uofcfcu.com
O1 - Hosts: 84.252.148.113 uofcfcu.com
O1 - Hosts: 84.252.148.113 www.warrenfcu.com
O1 - Hosts: 84.252.148.113 warrenfcu.com
O1 - Hosts: 84.252.148.113 visionsfcu.org
O1 - Hosts: 84.252.148.113 www.visionsfcu.org
O1 - Hosts: 84.252.148.113 www.tcfexpress.com
O1 - Hosts: 84.252.148.113 tcfexpress.com
O2 - BHO: (no name) - {0161C753-C283-4A23-A3E3-7064EE9187DA} - C:\Program Files\Internet Explorer\hoke.dll (file missing)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5,1,1,0.dll
O2 - BHO: 0 - {471D6BAE-FB77-4627-EAA7-5F44BEC36141} - C:\Program Files\Messenger\lavupa371.dll (file missing)
O2 - BHO: (no name) - {7B085521-9193-4D78-92DA-A239065849D7} - C:\WINDOWS\System32\qwodjvtq.dll (file missing)
O2 - BHO: (no name) - {84782460-B4B9-43F1-A7DD-1538F98EC324} - C:\WINDOWS\System32\qwodjvtq.dll (file missing)
O2 - BHO: (no name) - {BDFB988F-3D61-4726-8ED5-9F03A55776F9} - C:\Program Files\Windows Media Player\hoke.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: (no name) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - (no file)



O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\System32\lsasss.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{7974F2B4-EA8F-4FEE-BB33-3B0462C496C9}: NameServer = 62.217.54.69
O17 - HKLM\System\CCS\Services\Tcpip\..\{D4CB7B21-11A1-4B6C-ABD6-88D593F4BB91}: NameServer = 62.217.54.69
O18 - Filter: text/html - (no CLSID) - (no file)
O20 - Winlogon Notify: byxwtsr - byxwtsr.dll (file missing)
O20 - Winlogon Notify: mciqsvr - mciqsvr.dll (file missing)
O21 - SSODL: PXRVONEfGCpY - {949AA79C-3E30-0D36-CD94-B5F893E356A0} - C:\WINDOWS\System32\pdxdt.dll (file missing)


If you not using this machine to play online poker anylonger Have HJT fix these lines.


O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\poker.exe
O9 - Extra button: ThunderLuck Poker - {73761F50-136E-47b4-979E-E8F37872C6B2} - C:\Program Files\ThunderluckMPP\MPPoker.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)


Please download the OTMoveIt by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\System32\lsasss.exe

  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply.
*If a file or folder cannot be moved immediately, you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine, choose Yes.
  • Close OTMoveIt
**If a reboot was necessary or you needed to Exit before posting the log, you will find a copy of the log at the root of the drive where OTMoveIt is installed, usually at :
C:\\_OTMoveIt\\MovedFiles\\********_******.log
(where "********_******" is the "date_time")




______________________________

Download and install CCleaner from here


If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.
  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".


    Now run the program and click on Run Cleaner
    ( Do not use the Issues block to clean anything with this program. It is for experts only and it is risky)


    _________________________________
    Please do an online scan with Kaspersky Online Scanner
    Click on Kaspersky Online Scanner
    You will be promted to install an ActiveX component from Kaspersky, Click Yes.
    The program will launch and then start to download the latest definition files.
    Once the scanner is installed and the definitions downloaded, click Next.
    Now click on Scan Settings
    In the scan settings make sure that the following are selected:
    Scan using the following Anti-Virus database:

    Extended (If available otherwise Standard)
    Scan Options:
    Scan Archives
    Scan Mail Bases
    Click OK

    Now under select a target to scan select My Computer


    Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.



    The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.

    Now click on the Save as Text button:

    Save the file to your desktop.

    Copy and paste that information in your next post.


    _____________________________
    Open HJT this time click on Mics. tools /open uninstall manager.
    Click on save list
    Save it some place you can find it.
    Post the contents of that list in your next reply.


    ___________________________________



    In your next reply I would like to see:

    • A new HJT log
    • The report from OTMOVEIT
    • The report from Kasperskys
    • The report from HJT uninstall list.
Thank you for your help with this issue. I have followed the steps requested. I am including the information you requested. B)



KASPERSKY ONLINE SCANNER REPORT
Monday, August 06, 2007 2:44:11 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 6/08/2007
Kaspersky Anti-Virus database records: 373426


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\
E:\

Scan Statistics
Total number of scanned objects 86522
Number of viruses found 13
Number of infected objects 19
Number of suspicious objects 5
Duration of the scan process 01:41:51

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\avg7\AVG7QT.DAT Infected: Trojan.Win32.Qhost.go skipped

C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\History\History.IE5\MSHist012007080620070807\index.dat Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Temp\Perflib_Perfdata_1428.dat Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Temp\tmp7.tmp.exe Infected: Trojan.Win32.Agent.agv skipped

C:\Documents and Settings\Owner\Local Settings\Temp\~DF880C.tmp Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Temp\~DF883D.tmp Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Owner\My Documents\ezcardsbdayfree.exe/WISE0038.BIN Infected: not-a-virus:AdTool.Win32.WhenU.a skipped

C:\Documents and Settings\Owner\My Documents\ezcardsbdayfree.exe/WISE0039.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped

C:\Documents and Settings\Owner\My Documents\ezcardsbdayfree.exe/WISE0040.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped

C:\Documents and Settings\Owner\My Documents\ezcardsbdayfree.exe/WISE0041.BIN/data.rar/whAgent.exe Infected: not-a-virus:AdWare.Win32.WebHancer.351 skipped

C:\Documents and Settings\Owner\My Documents\ezcardsbdayfree.exe/WISE0041.BIN/data.rar/whInstaller.exe Infected: not-a-virus:AdWare.Win32.WebHancer.381 skipped

C:\Documents and Settings\Owner\My Documents\ezcardsbdayfree.exe/WISE0041.BIN/data.rar/whSurvey.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped

C:\Documents and Settings\Owner\My Documents\ezcardsbdayfree.exe/WISE0041.BIN/data.rar/webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer.370 skipped

C:\Documents and Settings\Owner\My Documents\ezcardsbdayfree.exe/WISE0041.BIN/data.rar/whiehlpr.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped

C:\Documents and Settings\Owner\My Documents\ezcardsbdayfree.exe/WISE0041.BIN/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer skipped

C:\Documents and Settings\Owner\My Documents\ezcardsbdayfree.exe/WISE0041.BIN Infected: not-a-virus:AdWare.Win32.WebHancer skipped

C:\Documents and Settings\Owner\My Documents\ezcardsbdayfree.exe/WISE0042.BIN Infected: not-a-virus:AdWare.Win32.Relevant.a skipped

C:\Documents and Settings\Owner\My Documents\ezcardsbdayfree.exe WiseSFX: infected - 11 skipped

C:\Documents and Settings\Owner\My Documents\ezcardsbdayfree.exe WiseSFX Dropper: infected - 11 skipped

C:\Documents and Settings\Owner\ntuser.dat Object is locked skipped

C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped

C:\hp\bin\KillWind.exe Infected: not-a-virus:RiskTool.Win32.PsKill.p skipped

C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\Log\CHANNEL.LOG Object is locked skipped

C:\Program Files\Intuit\QuickBooks Pro\Components\DownloadQB13\Patch\.update\.QBLock.lck Object is locked skipped

C:\Program Files\TrojanHunter 4.7\Quarantine\2zgB.dat Infected: not-a-virus:AdWare.Win32.BHO.v skipped

C:\Program Files\TrojanHunter 4.7\Quarantine\uSKMn2.dat Infected: not-a-virus:AdWare.Win32.MySearch.e skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\WINDOWS\1853.exe Suspicious: Packed.Win32.Morphine.a skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\iihgda.dll Infected: Trojan.Win32.Agent.agv skipped

C:\WINDOWS\installer.exe Suspicious: Packed.Win32.Morphine.a skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\LKHHAT9O\1853[1].exe Suspicious: Packed.Win32.Morphine.a skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\update.html Suspicious: Packed.Win32.Morphine.a skipped

C:\WINDOWS\update2.html Suspicious: Packed.Win32.Morphine.a skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped


Scan of D was done separately due to time constraints and was clean.




Logfile of HijackThis v1.99.1
Scan saved at 9:56:27 AM, on 8/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\GEARSEC.EXE
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus8.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus8.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus8.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5,1,1,0.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [OmniPass] C:\Program Files\Softex\OmniPass\scureapp.exe
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire HomePortal Monitor\2portalmon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1105157635375
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Filter: text/html - (no CLSID) - (no file)
O20 - Winlogon Notify: !SASWinLogon - C:\My Downloads\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSEC.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe



MoveIt log

Item C:\WINDOWS\System32\lsass.exe is whitelisted and cannot be moved.

Created on 08/05/2007 20:17:02




HJT Uninstall List
101 Law Forms
Ad-Aware 2007
Adobe Flash Player 9 ActiveX
ArcSoft Camera Suite
AVG 7.5
AVG Anti-Rootkit Free
AVG Anti-Spyware 7.5
BellSouth FastAccess DSL Help Center
Blackhawk Striker from Compaq (remove only)
Blasterball 2 from Compaq (remove only)
BlasterBall Wild from Compaq (remove only)
Canon Camera Window for ZoomBrowser EX
Canon i860
Canon PhotoRecord
Canon PIXMA iP4000R
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities Easy-PhotoPrint
Canon Utilities PhotoStitch 3.1
Canon Utilities ZoomBrowser EX
CareBears
CCleaner (remove only)
Cinderella's Dollhouse
Compaq Connections
Dark Orbit from Compaq (remove only)
Disney`s Lilo and Stitch Pinball from Compaq (remove only)
Excavation from Compaq (remove only)
Final Draft 5
GemMaster 3 from Compaq (remove only)
Google Earth
Google Toolbar for Internet Explorer
Hijackthis 1.99.1
HijackThis 1.99.1
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
hp deskjet 3420 series (Remove only)
HP Deskjet printer preloaded drivers
Instant Support
Intel® Extreme Graphics Driver
IntelliMover Data Transfer Demo
InterVideo WinDVD Player
iTunes
Java 2 Runtime Environment, SE v1.4.1
Java Web Start
JumpStart Advanced Kindergarten
JumpStart Parent Resource Center v1.0
JumpStart Preschool v2.0
Kaspersky Online Scanner
Lets Ride Corral Club
Macromedia Shockwave Player
Men In Black II CROSSFIRE from Compaq (remove only)
Microsoft .NET Framework (English)
Microsoft .NET Framework (English) v1.0.3705
Microsoft .NET Framework 1.1
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2003
Microsoft Money 2003 System Pack
Microsoft National Language Support Downlevel APIs
Microsoft Office Standard Edition 2003
Microsoft Windows Journal Viewer
Microsoft Works 7.0
Millie and Bailey Kindergarten
Monsters Jr
Mozilla Firefox (2.0.0.5)
MSN
MSXML 4.0 SP2 (KB927978)
My Fantasy Wedding
NVIDIA Windows 2000/XP Display Drivers
OmniPass
Panda ActiveScan
PC-Doctor for Windows
Princess Fashion Boutique
PS2
Python 2.2 combined Win32 extensions
Python 2.2.1
QuickBooks Pro Edition 2004
Quicken 2005
QuickTime
Reader Rabbit 1st Grade® Capers on Cloud Nine!™
Reader Rabbit Kindergarten
Reader Rabbit® I Can Read! With Phonics
RealOne Player
RecordNow
RingMaster from Compaq (remove only)
S3Display
S3Gamma2
S3Info2
S3Overlay
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Shockwave
Simple Installer - Multilanguage Version
Snowboard Extreme from Compaq (remove only)
Sonic Update Manager
Space Rocks from Compaq (remove only)
Spybot - Search & Destroy 1.4
Spyware Doctor 5.0
Strawberry Shortcake - Amazing Cookie Party
SUPERAntiSpyware Free Edition
ThunderLuck Poker
TrojanHunter 4.7
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB936357)
Virtual Warfare from Compaq (remove only)
WeatherBug
Weblink
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Player 9 Hotfix [See KB885492 for more information]
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WordPerfect Office 2002 Trial
WordPerfect Office 2002 Trial
Yahoo! Companion
______________________________
HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked

O18 - Filter: text/html - (no CLSID) - (no file)


______________________________

Download and install CCleaner from here


If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.
  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".


    Now run the program and click on Run Cleaner
    ( Do not use the Issues block to clean anything with this program. It is for experts only and it is risky).


  • Please double-click OTMoveIt.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    Please be sure and use copy and paste . As your last log looks as if there was a typo from what I asked to be removed. Good thing OTMOVEIT has a white list. That was a good file you typed in.


    C:\Documents and Settings\Owner\Local Settings\Temp\tmp7.tmp.exe
    C:\Documents and Settings\Owner\My Documents\ezcardsbdayfree.exe
    C:\WINDOWS\1853.exe
    C:\WINDOWS\iihgda.dll
    C:\WINDOWS\installer.exe
    C:\WINDOWS\update.html
    C:\WINDOWS\update2.html
    C:\WINDOWS\System32\lsasss.exe


  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply.
*If a file or folder cannot be moved immediately, you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine, choose Yes.
  • Close OTMoveIt
**If a reboot was necessary or you needed to Exit before posting the log, you will find a copy of the log at the root of the drive where OTMoveIt is installed, usually at :
C:\_OTMoveIt\MovedFiles\********_******.log
(where "********_******" is the "date_time")



_______________________________________________________


Navigate to and delete the contents of this folder. DO NOT DELETE THE FOLDER ITSELF.

C:\Program Files\TrojanHunter 4.7\Quarantine once inside this folder<< CLICK EDIT /SELECT ALL/DELETE

________________________________________________


1. Download Combo fix from one of these locations.
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall




In your next reply I would like to see:
  • A new HJT log
  • The report from OTMOVEIT
  • The report from Combo fix
Bob4- Thank you for your continuing help. I was bogged down on another computer. Before I use OTMOVEIT again, please review the files you have asked me to select. You have included lsasss.exe again and I want to make sure there aren't any typos on the other files. —————————————– Please double-click OTMoveIt.exe to run it. Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy): Please be sure and use copy and paste . As your last log looks as if there was a typo from what I asked to be removed. Good thing OTMOVEIT has a white list. That was a good file you typed in. C:\Documents and Settings\Owner\Local Settings\Temp\tmp7.tmp.exe C:\Documents and Settings\Owner\My Documents\ezcardsbdayfree.exe C:\WINDOWS\1853.exe C:\WINDOWS\iihgda.dll C:\WINDOWS\installer.exe C:\WINDOWS\update.html C:\WINDOWS\update2.html C:\WINDOWS\System32\lsasss.exe Thanks!- Jcatsmom :wavey:
No typos there. Run it ! lsasss.exe is a bad file. And that is what I typed before. While using my instructions please use copy and paste to avoid typing errors. :thumbup:
Thanks, Bob4! Here are my new reports:


Logfile of HijackThis v1.99.1
Scan saved at 7:02:25 PM, on 8/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus8.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus8.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5,1,1,0.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [OmniPass] C:\Program Files\Softex\OmniPass\scureapp.exe
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire HomePortal Monitor\2portalmon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1105157635375
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - Winlogon Notify: !SASWinLogon - C:\My Downloads\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSEC.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe



ComboFix 07-08-09.3 - "Owner" 2007-08-10 18:34:37.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.90 [GMT -5:00]


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\as.txt
C:\DOCUME~1\Owner\APPLIC~1\install.dat
C:\Documents and Settings\All Users.\documents\settings
C:\Program Files\Common Files\{349AA~1
C:\Program Files\Common Files\{349AA~1\Bar888.dll.lzma
C:\Program Files\Common Files\{949AA~1
C:\temp\tn3
C:\WINDOWS\stat
C:\WINDOWS\system32\bund1
C:\WINDOWS\system32\bund1\temp.txt
C:\WINDOWS\system32\msdrives
C:\WINDOWS\system32\msdrives\BIT15.tmp
C:\WINDOWS\system32\satmat.exe
C:\WINDOWS\system32\updatetc.exe
C:\WINDOWS\update.exe
C:\WINDOWS\winhp32.exe
D:\Autorun.inf


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_ASC3550U
——-\LEGACY_EXAMPLE


((((((((((((((((((((((((( Files Created from 2007-07-10 to 2007-08-10 )))))))))))))))))))))))))))))))


2007-08-10 18:33 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-05 20:46 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-08-05 20:46 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-08-05 20:24 d——– C:\Program Files\CCleaner
2007-08-02 10:08 d——– C:\Program Files\Lavasoft
2007-08-02 10:08 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-08-01 10:21 d——– C:\WINDOWS\system32\ActiveScan
2007-08-01 09:59 33,792 –a–c— C:\WINDOWS\system32\dllcache\custsat.dll
2007-08-01 09:59 d——– C:\WINDOWS\network diagnostic
2007-08-01 09:39 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-08-01 09:31 d——– C:\DOCUME~1\Owner\APPLIC~1\Talkback
2007-07-31 15:54 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-07-31 15:53 d——– C:\DOCUME~1\Owner\APPLIC~1\SUPERAntiSpyware.com
2007-07-31 15:52 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-07-31 14:55 d——– C:\VundoFix Backups
2007-07-28 15:28 23,040 —–c— C:\WINDOWS\system32\dllcache\fltmc.exe
2007-07-28 15:28 16,896 —–c— C:\WINDOWS\system32\dllcache\fltlib.dll
2007-07-28 15:28 128,896 —–c— C:\WINDOWS\system32\dllcache\fltmgr.sys
2007-07-28 15:28 d——– C:\Program Files\MSXML 4.0
2007-07-28 14:06 d——– C:\WINDOWS\Prefetch
2007-07-28 00:23 d——– C:\WINDOWS\provisioning
2007-07-28 00:23 d——– C:\WINDOWS\peernet
2007-07-28 00:18 d——– C:\WINDOWS\ServicePackFiles
2007-07-28 00:08 d——– C:\WINDOWS\EHome
2007-07-27 23:40 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2007-07-27 23:16 4,569 ——— C:\WINDOWS\system32\secupd.dat
2007-07-27 23:16 11,776 ——— C:\WINDOWS\system32\spnpinst.exe
2007-07-27 21:04 1,082,368 –a—— C:\WINDOWS\system32\esent.dll
2007-07-27 16:52 d——– C:\WINDOWS\system32\PreInstall
2007-07-27 16:30 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Motive
2007-07-27 15:38 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-23 21:39 83,024 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-07-23 21:39 57,424 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-07-23 21:39 53,840 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-07-23 21:39 39,376 –a—— C:\WINDOWS\system32\drivers\ikfileflt.sys
2007-07-23 21:39 29,264 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-07-23 21:39 d——– C:\Program Files\Spyware Doctor
2007-07-23 21:39 d——– C:\DOCUME~1\Owner\APPLIC~1\PC Tools
2007-07-23 21:38 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-07-23 20:15 d——– C:\DOCUME~1\Owner\APPLIC~1\TrojanHunter
2007-07-23 19:16 d——– C:\Program Files\TrojanHunter 4.7
2007-07-23 12:15 3,968 –a—— C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-07-23 08:49 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-07-22 19:36 1,048,576 –a—— C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-07-22 19:36 d—s—- C:\DOCUME~1\ADMINI~1\UserData
2007-07-22 19:36 d——– C:\DOCUME~1\ADMINI~1\WINDOWS
2007-07-22 19:36 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
2007-07-22 19:36 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Sonic
2007-07-22 19:36 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\SampleView
2007-07-22 19:36 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Real
2007-07-22 19:36 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\InterTrust
2007-07-22 19:36 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\interMute


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-02 21:09 ——— d——– C:\Program Files\PartyGaming
2007-08-01 11:42 ——— d——– C:\Program Files\Google
2007-07-28 15:34 ——— d——– C:\Program Files\Messenger
2007-07-28 00:23 ——— d——– C:\Program Files\Movie Maker
2007-07-28 00:18 ——— d——– C:\Program Files\Windows NT
2007-07-27 20:39 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\interMute
2007-07-23 11:56 ——— d——– C:\Program Files\MSN Messenger
2007-07-01 00:08 0 –a—— C:\WINDOWS\Sloopy7.exe
2007-07-01 00:04 ——— d——– C:\Program Files\QuickTime
2007-07-01 00:00 89230 -rahs—- C:\WINDOWS\system32\conmjmbe.exe
2007-06-14 05:37 948302 –ahs—- C:\WINDOWS\system32\phlluwtl.ini2
2007-06-12 20:28 ——— d——– C:\Program Files\iTunes
2007-06-12 20:28 ——— d——– C:\Program Files\2Wire HomePortal Monitor
2007-05-16 10:12 86528 —–c— C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 10:12 85504 —–c— C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 10:12 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-05-16 10:12 683520 —–c— C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 10:12 510976 —–c— C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 10:12 1314816 —–c— C:\WINDOWS\system32\dllcache\msoe.dll
2004-10-19 16:38 11052037 –a–c— C:\DOCUME~1\Owner\APPLIC~1\HCSetup2.0_IW.5.1.exe
2004-09-16 15:28 21739 –a–c— C:\Program Files\uninstal.log
2004-01-26 15:38 13927 -r—c— C:\Program Files\ReadMe.txt
2003-11-04 20:48:29 0 -csha-w C:\WINDOWS\SMINST\HPCD.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PS2"="C:\WINDOWS\system32\ps2.exe" []
"QuickFinder Scheduler"="C:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE" []
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe" []
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" []
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" []
"OmniPass"="C:\Program Files\Softex\OmniPass\scureapp.exe" []
"2wSysTray"="C:\Program Files\2Wire HomePortal Monitor\2portalmon.exe" []
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" []
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" []
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-07-22 20:11]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIEW"="nview.dll,nViewLoadHook" []
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" []
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2005-04-04 13:09:49]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{8BFA0939-92D5-4762-B188-2F45AE6D445B}"= C:\WINDOWS\System32\dsbshell32.dll [ ]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\My Downloads\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\My Downloads\SASWINLO.dll 2007-02-27 11:39 282624 C:\My Downloads\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
C:\Program Files\Softex\OmniPass\opxpgina.dll 2003-02-21 05:50 40960 C:\Program Files\Softex\OmniPass\OPXPGina.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk
backup=C:\WINDOWS\pss\Compaq Connections.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^spamsubtract.lnk]
path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\spamsubtract.lnk
backup=C:\WINDOWS\pss\spamsubtract.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCNT]
C:\PROGRA~1\AWS\WEATHE~1\BCNT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"c:\Program Files\Common Files\Symantec Shared\ccApp.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccRegVfy]
"c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\System32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
c:\windows\system\hpsysdrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\System32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
C:\HP\KBD\KBD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KYE_UDSI]
"C:\Program Files\USB Storage RW\udsi.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NAV CfgWiz]
c:\PROGRA~1\NORTON~1\Cfgwiz.exe /R

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /installquiet /keeploaded /nodetect

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
C:\WINDOWS\system32\ps2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
C:\WINDOWS\SMINST\RECGUARD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WT GameChannel]
C:\Program Files\WildTangent\Apps\GameChannel.exe

R0 fasttx2k;fasttx2k;C:\WINDOWS\system32\DRIVERS\fasttx2k.sys
R1 SASDIFSV;SASDIFSV;\??\C:\My Downloads\SASDIFSV.SYS
R1 SASKUTIL;SASKUTIL;\??\C:\My Downloads\SASKUTIL.sys
R3 ltmodem5;LT Modem Driver;C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys
R3 MxlW2k;MxlW2k;C:\WINDOWS\system32\drivers\MxlW2k.sys
R3 Ps2;PS2;C:\WINDOWS\system32\DRIVERS\PS2.sys
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver;C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys
S3 2WIREPCP;2Wire USB;C:\WINDOWS\system32\DRIVERS\2WirePCP.sys
S3 IKFileFlt;File Filter Driver;C:\WINDOWS\system32\drivers\ikfileflt.sys
S3 IKFileSec;File Security Driver;C:\WINDOWS\system32\drivers\ikfilesec.sys
S3 IkSysFlt;System Filter Driver;C:\WINDOWS\system32\drivers\iksysflt.sys
S3 IKSysSec;System Security Driver;C:\WINDOWS\system32\drivers\iksyssec.sys
S3 SASENUM;SASENUM;\??\C:\My Downloads\SASENUM.SYS


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2683403a-403b-11dc-ab93-00402b631b27}]
AutoRun\command- F:\setupSNK.exe


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-10 18:46:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:00000031

scanning hidden files …

**************************************************************************

Completion time: 2007-08-10 18:52:43 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-10 18:51

— E O F —


Moveit log

File/Folder C:\Documents and Settings\Owner\Local Settings\Temp\tmp7.tmp.exe not found.
C:\Documents and Settings\Owner\My Documents\ezcardsbdayfree.exe moved successfully.
C:\WINDOWS\1853.exe moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\iihgda.dll
C:\WINDOWS\iihgda.dll NOT unregistered.
C:\WINDOWS\iihgda.dll moved successfully.
C:\WINDOWS\installer.exe moved successfully.
C:\WINDOWS\update.html moved successfully.
C:\WINDOWS\update2.html moved successfully.
File/Folder C:\WINDOWS\System32\lsasss.exe not found.

Created on 08/10/2007 18:24:38


Thank you for your continued help. :weee:
Jcatsmom
_____________________________
Submit 3 files to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath, copy and paste these filepaths: 1 at a time.


C:\WINDOWS\System32\dsbshell32.dll

C:\WINDOWS\system32\phlluwtl.ini2

C:\WINDOWS\System32\dsbshell32.dll



Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html


_____________________________________


You need to update SunJava for security reasons.
Updating Java:
Download the latest version of
Java Runtime Environment (JRE) 6u2
  • Scroll down to where it says "Java Runtime Environment (JRE) 6u2… allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name. It should have the [external image: Posted Image] icon next to it.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u2-windows-i586-p.exe to install the newest version.
__________________________________


In your next reply I would like to see:
  • A new HJT log
  • The report from Jotti/ virus total on all 3 of those files.
  • Let me know how things seem to be running.
Bob4- Here are my latest reports. The computer has actually run quite well since I removed the first major load of viruses and spyware. I have wanted to get the remaining infections cleaned up so it won't rapidly get reinfected. Thank you for your help. :) Jcatsmom



Logfile of HijackThis v1.99.1
Scan saved at 12:34:07 PM, on 8/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\GEARSEC.EXE
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus8.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus8.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5,1,1,0.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [OmniPass] C:\Program Files\Softex\OmniPass\scureapp.exe
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire HomePortal Monitor\2portalmon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1105157635375
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - Winlogon Notify: !SASWinLogon - C:\My Downloads\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSEC.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe



Jotti Scan

Please note, you actually gave me 2 files to scan, not 3.

C:\WINDOWS\System32\dsbshell32.dll
The file you uploaded is 0 bytes. It is very likely a firewall or a piece of malware is prohibiting you from uploading this file

C:\WINDOWS\system32\phlluwtl.ini2
phlluwtl.ini2 Status: OK

ComboFix 07-08-09.3
- "Owner" 2007-08-10 18:34:37.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.90 [GMT -5:00]


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\as.txt
C:\DOCUME~1\Owner\APPLIC~1\install.dat
C:\Documents and Settings\All Users.\documents\settings
C:\Program Files\Common Files\{349AA~1
C:\Program Files\Common Files\{349AA~1\Bar888.dll.lzma
C:\Program Files\Common Files\{949AA~1
C:\temp\tn3
C:\WINDOWS\stat
C:\WINDOWS\system32\bund1
C:\WINDOWS\system32\bund1\temp.txt
C:\WINDOWS\system32\msdrives
C:\WINDOWS\system32\msdrives\BIT15.tmp
C:\WINDOWS\system32\satmat.exe
C:\WINDOWS\system32\updatetc.exe
C:\WINDOWS\update.exe
C:\WINDOWS\winhp32.exe
D:\Autorun.inf


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_ASC3550U
——-\LEGACY_EXAMPLE


((((((((((((((((((((((((( Files Created from 2007-07-10 to 2007-08-10 )))))))))))))))))))))))))))))))


2007-08-10 18:33 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-05 20:46 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-08-05 20:46 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-08-05 20:24 d——– C:\Program Files\CCleaner
2007-08-02 10:08 d——– C:\Program Files\Lavasoft
2007-08-02 10:08 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-08-01 10:21 d——– C:\WINDOWS\system32\ActiveScan
2007-08-01 09:59 33,792 –a–c— C:\WINDOWS\system32\dllcache\custsat.dll
2007-08-01 09:59 d——– C:\WINDOWS\network diagnostic
2007-08-01 09:39 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-08-01 09:31 d——– C:\DOCUME~1\Owner\APPLIC~1\Talkback
2007-07-31 15:54 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-07-31 15:53 d——– C:\DOCUME~1\Owner\APPLIC~1\SUPERAntiSpyware.com
2007-07-31 15:52 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-07-31 14:55 d——– C:\VundoFix Backups
2007-07-28 15:28 23,040 —–c— C:\WINDOWS\system32\dllcache\fltmc.exe
2007-07-28 15:28 16,896 —–c— C:\WINDOWS\system32\dllcache\fltlib.dll
2007-07-28 15:28 128,896 —–c— C:\WINDOWS\system32\dllcache\fltmgr.sys
2007-07-28 15:28 d——– C:\Program Files\MSXML 4.0
2007-07-28 14:06 d——– C:\WINDOWS\Prefetch
2007-07-28 00:23 d——– C:\WINDOWS\provisioning
2007-07-28 00:23 d——– C:\WINDOWS\peernet
2007-07-28 00:18 d——– C:\WINDOWS\ServicePackFiles
2007-07-28 00:08 d——– C:\WINDOWS\EHome
2007-07-27 23:40 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2007-07-27 23:16 4,569 ——— C:\WINDOWS\system32\secupd.dat
2007-07-27 23:16 11,776 ——— C:\WINDOWS\system32\spnpinst.exe
2007-07-27 21:04 1,082,368 –a—— C:\WINDOWS\system32\esent.dll
2007-07-27 16:52 d——– C:\WINDOWS\system32\PreInstall
2007-07-27 16:30 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Motive
2007-07-27 15:38 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-23 21:39 83,024 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-07-23 21:39 57,424 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-07-23 21:39 53,840 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-07-23 21:39 39,376 –a—— C:\WINDOWS\system32\drivers\ikfileflt.sys
2007-07-23 21:39 29,264 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-07-23 21:39 d——– C:\Program Files\Spyware Doctor
2007-07-23 21:39 d——– C:\DOCUME~1\Owner\APPLIC~1\PC Tools
2007-07-23 21:38 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-07-23 20:15 d——– C:\DOCUME~1\Owner\APPLIC~1\TrojanHunter
2007-07-23 19:16 d——– C:\Program Files\TrojanHunter 4.7
2007-07-23 12:15 3,968 –a—— C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-07-23 08:49 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-07-22 19:36 1,048,576 –a—— C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-07-22 19:36 d—s—- C:\DOCUME~1\ADMINI~1\UserData
2007-07-22 19:36 d——– C:\DOCUME~1\ADMINI~1\WINDOWS
2007-07-22 19:36 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
2007-07-22 19:36 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Sonic
2007-07-22 19:36 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\SampleView
2007-07-22 19:36 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Real
2007-07-22 19:36 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\InterTrust
2007-07-22 19:36 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\interMute


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-02 21:09 ——— d——– C:\Program Files\PartyGaming
2007-08-01 11:42 ——— d——– C:\Program Files\Google
2007-07-28 15:34 ——— d——– C:\Program Files\Messenger
2007-07-28 00:23 ——— d——– C:\Program Files\Movie Maker
2007-07-28 00:18 ——— d——– C:\Program Files\Windows NT
2007-07-27 20:39 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\interMute
2007-07-23 11:56 ——— d——– C:\Program Files\MSN Messenger
2007-07-01 00:08 0 –a—— C:\WINDOWS\Sloopy7.exe
2007-07-01 00:04 ——— d——– C:\Program Files\QuickTime
2007-07-01 00:00 89230 -rahs—- C:\WINDOWS\system32\conmjmbe.exe
2007-06-14 05:37 948302 –ahs—- C:\WINDOWS\system32\phlluwtl.ini2
2007-06-12 20:28 ——— d——– C:\Program Files\iTunes
2007-06-12 20:28 ——— d——– C:\Program Files\2Wire HomePortal Monitor
2007-05-16 10:12 86528 —–c— C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 10:12 85504 —–c— C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 10:12 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-05-16 10:12 683520 —–c— C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 10:12 510976 —–c— C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 10:12 1314816 —–c— C:\WINDOWS\system32\dllcache\msoe.dll
2004-10-19 16:38 11052037 –a–c— C:\DOCUME~1\Owner\APPLIC~1\HCSetup2.0_IW.5.1.exe
2004-09-16 15:28 21739 –a–c— C:\Program Files\uninstal.log
2004-01-26 15:38 13927 -r—c— C:\Program Files\ReadMe.txt
2003-11-04 20:48:29 0 -csha-w C:\WINDOWS\SMINST\HPCD.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PS2"="C:\WINDOWS\system32\ps2.exe" []
"QuickFinder Scheduler"="C:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE" []
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe" []
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" []
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" []
"OmniPass"="C:\Program Files\Softex\OmniPass\scureapp.exe" []
"2wSysTray"="C:\Program Files\2Wire HomePortal Monitor\2portalmon.exe" []
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" []
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" []
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-07-22 20:11]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIEW"="nview.dll,nViewLoadHook" []
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" []
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2005-04-04 13:09:49]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{8BFA0939-92D5-4762-B188-2F45AE6D445B}"= C:\WINDOWS\System32\dsbshell32.dll [ ]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\My Downloads\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\My Downloads\SASWINLO.dll 2007-02-27 11:39 282624 C:\My Downloads\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
C:\Program Files\Softex\OmniPass\opxpgina.dll 2003-02-21 05:50 40960 C:\Program Files\Softex\OmniPass\OPXPGina.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk
backup=C:\WINDOWS\pss\Compaq Connections.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^spamsubtract.lnk]
path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\spamsubtract.lnk
backup=C:\WINDOWS\pss\spamsubtract.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCNT]
C:\PROGRA~1\AWS\WEATHE~1\BCNT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"c:\Program Files\Common Files\Symantec Shared\ccApp.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccRegVfy]
"c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\System32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
c:\windows\system\hpsysdrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\System32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
C:\HP\KBD\KBD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KYE_UDSI]
"C:\Program Files\USB Storage RW\udsi.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NAV CfgWiz]
c:\PROGRA~1\NORTON~1\Cfgwiz.exe /R

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /installquiet /keeploaded /nodetect

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
C:\WINDOWS\system32\ps2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
C:\WINDOWS\SMINST\RECGUARD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WT GameChannel]
C:\Program Files\WildTangent\Apps\GameChannel.exe

R0 fasttx2k;fasttx2k;C:\WINDOWS\system32\DRIVERS\fasttx2k.sys
R1 SASDIFSV;SASDIFSV;\??\C:\My Downloads\SASDIFSV.SYS
R1 SASKUTIL;SASKUTIL;\??\C:\My Downloads\SASKUTIL.sys
R3 ltmodem5;LT Modem Driver;C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys
R3 MxlW2k;MxlW2k;C:\WINDOWS\system32\drivers\MxlW2k.sys
R3 Ps2;PS2;C:\WINDOWS\system32\DRIVERS\PS2.sys
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver;C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys
S3 2WIREPCP;2Wire USB;C:\WINDOWS\system32\DRIVERS\2WirePCP.sys
S3 IKFileFlt;File Filter Driver;C:\WINDOWS\system32\drivers\ikfileflt.sys
S3 IKFileSec;File Security Driver;C:\WINDOWS\system32\drivers\ikfilesec.sys
S3 IkSysFlt;System Filter Driver;C:\WINDOWS\system32\drivers\iksysflt.sys
S3 IKSysSec;System Security Driver;C:\WINDOWS\system32\drivers\iksyssec.sys
S3 SASENUM;SASENUM;\??\C:\My Downloads\SASENUM.SYS


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2683403a-403b-11dc-ab93-00402b631b27}]
AutoRun\command- F:\setupSNK.exe


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-10 18:46:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:00000031

scanning hidden files …

**************************************************************************

Completion time: 2007-08-10 18:52:43 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-10 18:51

— E O F —
  • Please double-click OTMoveIt.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\System32\dsbshell32.dll


  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply.
*If a file or folder cannot be moved immediately, you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine, choose Yes.
  • Close OTMoveIt
**If a reboot was necessary or you needed to Exit before posting the log, you will find a copy of the log at the root of the drive where OTMoveIt is installed, usually at :
C:\_OTMoveIt\MovedFiles\********_******.log
(where "********_******" is the "date_time")


_______________________________________


Let me know that went OK!!!

_________________________________



Great news ! [external image: Posted Image]

Your log now appears to be clean.

Lets do a few things to tidy up.
Please do these in the order I suggest!


___________________________________
If we have set your computer to see all files and folders we must reprotect them.

UNDO SHOW ALL FILES
click on the My Computer icon.
Select the Tools menu and click Folder Options.
After the new window appears select the View tab.
Deselect in the checkbox labeled Display the contents of system folders.
Deselect the checkbox labeled Show hidden files and folders.
Select the checkmark from the checkbox labeled Hide file extensions for known file types.
Replace the checkmark from the checkbox labeled Hide protected operating system files.
Press the Apply button and then the OK .
Now many important files are safe.


___________________________________
Download and install CCleaner from here.
If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.


Now open the program and click on Run Cleaner
( Do not use the Issues block to clean anything with this program. It is for experts only and it is risky).

You may opt out of cleaning cookies. If you clean them alls you will have to do is retype names and passwords for places you visit on the net 1 time.
If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla
I clean all my cookies out from time to time. It's not that big a deal if you remember passwords.


___________________________________
Please create a 'clean' System Restore Point:
The reason for doing this is in case you need system restore you don't put back all we just took out.
Right click My Computer
Then Propeties then system restore
Place a check mark by turn off system restore
Click APPLY
Windows will give you a warning click yes
REBOOT

Now go right back to the same place and unchecksystem restore
Click APPLYand OK




A few things to help with possible threats

These are optional . But will help protect you further.
___________________________________

SpywareBlaster

Install SpywareBlaster

SpywareBlaster will add a large list of programs and sites to your Internet Explorer settings that will protect you from accidentally running or downloading known malicious programs.
After the installation, click Download Latest Protection Updates. When it finishes, click Enable All Protection.


______________________________
SiteHound

http://www.firetrust.com/firetrustsitehound.html

This tool bar will help protect you from.

Over 4,000 fake bank and credit sites.
Tens of thousands of pornographic
and adult sites.
The never ending fake phishing sites.
Malicious sites, which can infect you
with spyware and adware if you visit
them.
Sites to download software which
may infect your computer with
spyware, a virus or adware


___________________________________
Download and keep this updated and run weekly if you don't already have it.

spybot seach & destroy
Tutorial




___________________________________
Download and Install a HOSTS File
A Hosts file is a plain text file which prevents your computer from connecting to malware and spyware sites by redirecting the connection request to 127.0.0.1, which is your local address. If you use a proxy server, or if you are on AOL, be sure to read the special instructions.
You can download the MVPS Hosts File and see a HOSTS file tutorial here :
This website also contains useful tips, and links to other resources and utilities.


___________________________________
Make your Internet Explorer more secure
1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click on the Security tab
3. Click the Internet icon so it becomes highlighted.
4. Click on Default Level and click Ok
5. Click on the Custom Level button.

Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialise and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.

6. Next press the Apply button and then the OK to exit the Internet Properties page.

  • Be certain windows stays updated here




___________________________________
Please take the time to tell us what you would like to be done about the people who are behind all the problems you have had. We can only get something done about this if the people that we help, like you, are prepared to complain. We have a dedicated forum for collecting these complaints Malware Complaints, you do not have to be registered to post.. just find your country room and register your complaint.
The infections you had was Sasser.E Worm


Safe and Happy Surfing. :)
Bob4- The file is still being resistant to removal :rant2: : File/Folder C:\WINDOWS\System32\dsbshell32.dll not found. Created on 08/12/2007 16:32:04 I appreciate your information on security steps and will proceed with them when you feel that we have resolved the above file. Thanks! Jcatsmom
Bob4- I'm glad that you mentioned System Restore. I've actually had it turned off for quite a while because I didn't want traces of malware hiding in there and wanted to cut down on how many files needed searching. Time to turn it back on. Thanks! Jcatsmom
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a valid link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used.
If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php
Reopened per users request.


click start/run and copy this in exactly.

regedit /e desktop\runkey.txt "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

This will place a notepad file on your desktop called runkey.txt.
Open that and copy the contenets in your next reply for me.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI