This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Infected Work Pc

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Trying to fix a pc at work. Tried to clean it with several online programs. Here is the Hijackthis file:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:10, on 2007-08-04
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\msdtc.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\aswServ.exe
C:\WINNT\system32\crypserv.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\system32\tcpsvcs.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\ismserv.exe
C:\WINNT\System32\llssrv.exe
C:\PROGRA~1\MICROS~3\MSSQL\binn\sqlservr.exe
C:\WINNT\system32\ntfrs.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\locator.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\dns.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\Ebrsgqhd\yvxjptov.exe
C:\PROGRA~1\ALWILS~1\Avast4\aswDisp.exe
C:\WINNT\system32\regscan.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Simac0\bin\Annunc8.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Administrator.ACSERVER\Desktop\HiJackThis.exe
C:\WINNT\System32\WBEM\WinMgmt.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {2B105645-86F5-402F-9400-469133A881CC} - C:\Program Files\Accessories\hoke4.dll (file missing)
O2 - BHO: (no name) - {3AA15550-DE7E-7515-21E5-007B746C9458} - C:\Program Files\Rotllxwo\twrmqjkb.dll
O2 - BHO: (no name) - {4AABF6E4-4753-1FD9-7804-49B6783AF2ED} - C:\WINNT\system32\wvwqigoa.dll (file missing)
O2 - BHO: (no name) - {4D4059D6-564B-47BA-AC0B-F8E26432D337} - C:\Program Files\Accessories\hoke83122.dll (file missing)
O2 - BHO: (no name) - {53B5F2B1-94DD-43E5-8187-EB4E31F00701} - C:\WINNT\system32\l3acdb.dll (file missing)
O2 - BHO: (no name) - {641D1E8C-A933-F9EC-4967-FF8DCB5184B9} - C:\WINNT\system32\erjliw.dll (file missing)
O2 - BHO: (no name) - {66194385-F030-FCE6-4F67-FF8DCB5187B5} - C:\WINNT\system32\zfuccbvx.dll (file missing)
O2 - BHO: WebAssist - {85589B5D-D53D-4237-A677-46B82EA275F3} - C:\WINNT\WebAssist.dll (file missing)
O2 - BHO: (no name) - {9300ECA0-6CC2-46BA-9712-FDFC731DC0D5} - C:\Program Files\Accessories\hoke1.dll (file missing)
O2 - BHO: (no name) - {BE8C226F-4A1F-4687-843D-A85F1AF6D6A6} - C:\WINNT\system32\ddabb.dll (file missing)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [PRONoMgrWired] c:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [svhost] "C:\WINNT\svhost.exe"
O4 - HKLM\..\Run: [tarnefiA] C:\WINNT\tarnefiA.exe
O4 - HKLM\..\Run: [g4356cbvy63] C:\WINNT\g4356cbvy63
O4 - HKLM\..\Run: [clcl14] C:\WINNT\system32\clcl14.exe
O4 - HKLM\..\Run: [ktynknyx] rundll32.exe "C:\Program Files\ktynknyx\krorcbef.dll",Init
O4 - HKLM\..\Run: [yvxjptov] C:\Program Files\Ebrsgqhd\yvxjptov.exe
O4 - HKLM\..\Run: [csrss] C:\WINNT\csrss.exe
O4 - HKLM\..\Run: [svchost] C:\WINNT\svchost.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\aswDisp.exe
O4 - HKCU\..\Run: [Regscan] C:\WINNT\system32\regscan.exe
O4 - HKCU\..\Run: [Scld] "C:\PROGRA~1\WNSXS~1\ntvdm.exe" -vt yazb
O4 - HKUS\S-1-5-21-386374210-2625489697-3336257794-1122\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'SIMRUN')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {76D68CA1-DD9D-41C4-B2CC-AA9C9A5CF220} - http://www.junkscanner.com/jsetup.exe
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://www.winantivirus.com/download/2007/…d=pp_2127650243
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…085/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = isecure.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{B42C27C6-44CC-4C20-9555-3CE0D58F13F2}: Domain = Raclocal.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{C153D196-043D-40BF-8466-6238F1F17B18}: NameServer = 10.119.8.108,10.119.16.219,10.119.24.31
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = isecure.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = isecure.local
O20 - Winlogon Notify: ddabb - C:\WINNT\system32\ddabb.dll (file missing)
O20 - Winlogon Notify: fccyywx - fccyywx.dll (file missing)
O20 - Winlogon Notify: winpsa32 - winpsa32.dll (file missing)
O22 - SharedTaskScheduler: za - {53B5F2B1-94DD-43E5-8187-EB4E31F00701} - C:\WINNT\system32\l3acdb.dll (file missing)
O23 - Service: Access Control End User Manager (ACEUM) - Unknown owner - C:\PROGRA~1\Simac0\bin\aceum.exe
O23 - Service: Access Control Historical Log (ACHLOG) - Unknown owner - C:\PROGRA~1\Simac0\bin\achls.exe
O23 - Service: Access Control Schedule Task Manager (ACSTS) - Unknown owner - C:\PROGRA~1\Simac0\bin\acsts.exe
O23 - Service: Access Control Application Watchdog (ACWD) - Unknown owner - C:\PROGRA~1\Simac0\bin\watchdog.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswWebSv.exe
O23 - Service: Altiris Carbon Copy (CarbonCopy32) - Altiris - C:\WINNT\system32\ccsrvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINNT\SYSTEM32\crypserv.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Access Control ISC 4120 Hardware Manager (ITCHM_L1) - Unknown owner - C:\PROGRA~1\Simac0\bin\itchm.exe
O23 - Service: Access Control ISC TCP Hardware Manager (ITCHM_R1) - Unknown owner - C:\PROGRA~1\Simac0\bin\ritchm.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - c:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Access Control Point Update (PUS) - Unknown owner - C:\PROGRA~1\Simac0\bin\acc_pus.exe
O24 - Desktop Component 0: (no name) - http://tbn0.google.com/images?q=tbn:02NbHO…E_chieftain.jpg

–
End of file - 8218 bytes
Hi medicman151 and welcome to the forums.

First, where has this PC been? :blink: I feel dirty just reviewing the HJT log. With that said, here goes:

One or more of the identified infections is a backdoor trojan and you also have a keylogger which can record every keystroke that is made on this computer.

These types of infections allow hackers to remotely control your computer, steal critical system information and download and execute files without your knowledge.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the Trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever be trusted again. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall

However, if you do not have the resources to reinstall your computer and would like me to attempt to clean it, I will be happy to do so.

2 NOTES:
1. Considering that fact that you said this is a work computer is there an IT staff or person there to deal with issues like these? If so I would consult them before doing anything.
2. This is a seriously infected machine (one of the worst I've ever seen). If you do decide to try and clean it there is no way I can guarantee that something will not go wrong. You should back up any documents, pictures, or critical data before doing anything. That is if the PC is even in a useable state.
Thanks for the reply. This PC runs our eletronic gate software. There is no critical data kept on this machine. I would like some help to try to get this pc cleaned. Some of the staff here like to surf the net and go places they shouldn't. I am trying to keep our whole department out of hot water over this. Any help would be appreciated.
Hi medicman151,

Well I'm always up for a good challenge…and we got one here.

This may take several posts and scans that may take some time to review so…
Please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

STEP 1:

Please download
VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click Yes
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from Click the Scan for Vundo button when VundoFix appears at reboot.


STEP 2:

Download ComboFix from Here or Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
Ok the Vundofix didn't find anything. I think I used that program the other day. Below is the Combofix log and the HiJackthis log.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:44, on 2007-08-05
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\msdtc.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\aswServ.exe
C:\WINNT\system32\crypserv.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\system32\tcpsvcs.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\ismserv.exe
C:\WINNT\System32\llssrv.exe
C:\PROGRA~1\MICROS~3\MSSQL\binn\sqlservr.exe
C:\WINNT\system32\ntfrs.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\locator.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\dns.exe
C:\WINNT\system32\Ati2evxx.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\Ebrsgqhd\yvxjptov.exe
C:\PROGRA~1\ALWILS~1\Avast4\aswDisp.exe
C:\WINNT\system32\regscan.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Simac0\bin\ACSTS_EX.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\explorer.exe
C:\Documents and Settings\Administrator.ACSERVER\Desktop\1\HiJackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {2B105645-86F5-402F-9400-469133A881CC} - (no file)
O2 - BHO: (no name) - {3AA15550-DE7E-7515-21E5-007B746C9458} - C:\Program Files\Rotllxwo\twrmqjkb.dll
O2 - BHO: (no name) - {4AABF6E4-4753-1FD9-7804-49B6783AF2ED} - (no file)
O2 - BHO: (no name) - {4D4059D6-564B-47BA-AC0B-F8E26432D337} - (no file)
O2 - BHO: (no name) - {53B5F2B1-94DD-43E5-8187-EB4E31F00701} - (no file)
O2 - BHO: (no name) - {641D1E8C-A933-F9EC-4967-FF8DCB5184B9} - (no file)
O2 - BHO: (no name) - {66194385-F030-FCE6-4F67-FF8DCB5187B5} - (no file)
O2 - BHO: WebAssist - {85589B5D-D53D-4237-A677-46B82EA275F3} - (no file)
O2 - BHO: (no name) - {9300ECA0-6CC2-46BA-9712-FDFC731DC0D5} - (no file)
O2 - BHO: (no name) - {BE8C226F-4A1F-4687-843D-A85F1AF6D6A6} - (no file)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ktynknyx] rundll32.exe "C:\Program Files\ktynknyx\krorcbef.dll",Init
O4 - HKLM\..\Run: [yvxjptov] C:\Program Files\Ebrsgqhd\yvxjptov.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\aswDisp.exe
O4 - HKCU\..\Run: [Regscan] C:\WINNT\system32\regscan.exe
O4 - HKUS\S-1-5-21-386374210-2625489697-3336257794-1122\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'SIMRUN')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {76D68CA1-DD9D-41C4-B2CC-AA9C9A5CF220} - http://www.junkscanner.com/jsetup.exe
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://www.winantivirus.com/download/2007/…d=pp_2127650243
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…085/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = isecure.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{B42C27C6-44CC-4C20-9555-3CE0D58F13F2}: Domain = Raclocal.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{C153D196-043D-40BF-8466-6238F1F17B18}: NameServer = 10.119.8.108,10.119.16.219,10.119.24.31
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = isecure.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = isecure.local
O20 - Winlogon Notify: ddabb - C:\WINNT\system32\ddabb.dll (file missing)
O20 - Winlogon Notify: fccyywx - fccyywx.dll (file missing)
O20 - Winlogon Notify: winpsa32 - winpsa32.dll (file missing)
O22 - SharedTaskScheduler: za - {53B5F2B1-94DD-43E5-8187-EB4E31F00701} - (no file)
O23 - Service: Access Control End User Manager (ACEUM) - Unknown owner - C:\PROGRA~1\Simac0\bin\aceum.exe
O23 - Service: Access Control Historical Log (ACHLOG) - Unknown owner - C:\PROGRA~1\Simac0\bin\achls.exe
O23 - Service: Access Control Schedule Task Manager (ACSTS) - Unknown owner - C:\PROGRA~1\Simac0\bin\acsts.exe
O23 - Service: Access Control Application Watchdog (ACWD) - Unknown owner - C:\PROGRA~1\Simac0\bin\watchdog.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswWebSv.exe
O23 - Service: Altiris Carbon Copy (CarbonCopy32) - Altiris - C:\WINNT\system32\ccsrvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINNT\SYSTEM32\crypserv.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Access Control ISC 4120 Hardware Manager (ITCHM_L1) - Unknown owner - C:\PROGRA~1\Simac0\bin\itchm.exe
O23 - Service: Access Control ISC TCP Hardware Manager (ITCHM_R1) - Unknown owner - C:\PROGRA~1\Simac0\bin\ritchm.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - c:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Access Control Point Update (PUS) - Unknown owner - C:\PROGRA~1\Simac0\bin\acc_pus.exe
O24 - Desktop Component 0: (no name) - http://tbn0.google.com/images?q=tbn:02NbHO…E_chieftain.jpg

–
End of file - 7298 bytes


ComboFix 07-08-04.3 - "administrator" 2007-08-05 23:42:12.4 [GMT -4:00] - NTFS
Microsoft Windows 2000 Server 5.0.2195.4.1252.1.1033.18.True


((((((((((((((((((((((((( Files Created from 2007-07-06 to 2007-08-06 )))))))))))))))))))))))))))))))


2007-08-05 23:42 16,384 –a—-t- C:\WINNT\system32\Perflib_Perfdata_158.dat
2007-08-04 15:40 16,384 –a—-t- C:\WINNT\system32\Perflib_Perfdata_47c.dat
2007-08-04 15:40 16,384 –a—-t- C:\WINNT\system32\Perflib_Perfdata_3c4.dat
2007-08-04 10:48 51,200 –a—— C:\WINNT\nircmd.exe
2007-08-04 10:21 d——– C:\Program Files\Enigma Software Group
2007-08-04 10:02 d——– C:\Program Files\CCleaner
2007-08-04 09:03 d——– C:\VundoFix Backups
2007-08-04 07:23 95,872 –a—— C:\WINNT\system32\AvastSSw.scr
2007-08-04 07:23 94,552 –a—— C:\WINNT\system32\drivers\aswmon2.sys
2007-08-04 07:23 85,952 –a—— C:\WINNT\system32\drivers\aswmon.sys
2007-08-04 07:23 744,576 –a—— C:\WINNT\system32\aswBoot.exe
2007-08-04 07:23 43,176 –a—— C:\WINNT\system32\drivers\aswTdi.sys
2007-08-04 07:23 26,888 –a—— C:\WINNT\system32\drivers\aavmker4.sys
2007-08-04 07:23 23,416 –a—— C:\WINNT\system32\drivers\aswRdr.sys
2007-08-04 07:23 1,060,864 –a—— C:\WINNT\system32\MFC71.dll
2007-08-04 07:23 d——– C:\Program Files\Alwil Software
2007-08-01 19:34 10,580 –a—— C:\WINNT\system32\k.dat
2007-07-31 05:44 d——– C:\WINNT\system32\hseawjkw
2007-07-31 05:44 d——– C:\Program Files\SecCenter
2007-07-31 05:44 d——– C:\Program Files\Rotllxwo
2007-07-31 05:44 d——– C:\Program Files\ktynknyx
2007-07-31 05:44 d——– C:\Program Files\Ebrsgqhd
2007-07-30 03:26 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip
2007-07-30 02:52 d——– C:\WINNT\system32\Kaspersky Lab
2007-07-30 02:52 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-07-30 02:44 d——– C:\KAV
2007-07-30 02:02 28,672 –a—— C:\WINNT\system32\drivers\CO_Mon.sys
2007-07-30 01:57 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
2007-07-30 01:56 d–h-c— C:\WINNT\$MSI30UninstallMSI30-KB884016$
2007-07-30 01:05 d——– C:\WINNT\BDOSCAN8
2007-07-30 00:52 d——– C:\WINNT\McAfee.com
2007-07-29 23:20 d——– C:\Program Files\ISM
2007-07-29 09:46 499,712 –a—— C:\WINNT\system32\msvcp71.dll
2007-07-29 09:46 348,160 –a—— C:\WINNT\system32\msvcr71.dll
2007-07-28 23:39 70,312 –a—— C:\Program Files\codec_setup.exe
2007-07-28 23:00 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-28 22:52 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-07-27 02:11 d——– C:\Temp


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

07-07-30 00:49 ——— d——– C:\Program Files\QuickTime
07-07-29 00:04 ——— d-a—— C:\Program Files\Accessories
07-06-25 09:54 53248 –a—— C:\WINNT\uni_eh44.exe
07-06-25 09:53 53248 –a—— C:\WINNT\uninst1014.exe
05-04-26 22:43 271 –ah—– C:\Program Files\desktop.ini
05-04-26 22:43 21952 –ah—– C:\Program Files\folder.htt


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2B105645-86F5-402F-9400-469133A881CC}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3AA15550-DE7E-7515-21E5-007B746C9458}]
07-07-31 05:44 106496 –a—— C:\Program Files\Rotllxwo\twrmqjkb.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4AABF6E4-4753-1FD9-7804-49B6783AF2ED}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4D4059D6-564B-47BA-AC0B-F8E26432D337}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53B5F2B1-94DD-43E5-8187-EB4E31F00701}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{641D1E8C-A933-F9EC-4967-FF8DCB5184B9}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66194385-F030-FCE6-4F67-FF8DCB5187B5}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{85589B5D-D53D-4237-A677-46B82EA275F3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9300ECA0-6CC2-46BA-9712-FDFC731DC0D5}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BE8C226F-4A1F-4687-843D-A85F1AF6D6A6}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [06-07-04 05:01 ]
"ktynknyx"="C:\Program Files\ktynknyx\krorcbef.dll" [07-07-31 05:44 ]
"yvxjptov"="C:\Program Files\Ebrsgqhd\yvxjptov.exe" [07-07-31 05:44 ]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\aswDisp.exe" [07-05-16 07:55 ]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Regscan"="C:\WINNT\system32\regscan.exe" [79-12-31 20:00 ]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ShowSuperHidden"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddabb]
C:\WINNT\system32\ddabb.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccyywx]
fccyywx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winpsa32]
winpsa32.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Notification Packages"= FPNWCLNT RASSFM KDCSVC scecli

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, pwdssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"

R0 DfsDriver;DfsDriver;C:\WINNT\system32\drivers\Dfs.sys
R0 mraid2k;mraid2k;C:\WINNT\system32\drivers\mraid2k.sys
R0 Symmpi;Symmpi;C:\WINNT\system32\DRIVERS\symmpi.sys
R1 CCDevice;CCDevice;C:\WINNT\system32\drivers\CCDevice.sys
R1 NetworkX;NetworkX;C:\WINNT\system32\ckldrv.sys
R2 ACEUM;Access Control End User Manager;C:\PROGRA~1\Simac0\bin\aceum.exe
R2 ACHLOG;Access Control Historical Log;C:\PROGRA~1\Simac0\bin\achls.exe
R2 ACSTS;Access Control Schedule Task Manager;C:\PROGRA~1\Simac0\bin\acsts.exe
R2 ACWD;Access Control Application Watchdog;C:\PROGRA~1\Simac0\bin\watchdog.exe
R2 aswMon;avast! Standard Shield Support;C:\WINNT\system32\drivers\aswMon.sys
R2 Dfs;Distributed File System;C:\WINNT\system32\Dfssvc.exe
R2 DHCPServer;DHCP Server;C:\WINNT\system32\tcpsvcs.exe
R2 DNS;DNS Server;C:\WINNT\System32\dns.exe
R2 IsmServ;Intersite Messaging;C:\WINNT\System32\ismserv.exe
R2 ITCHM_L1;Access Control ISC 4120 Hardware Manager;C:\PROGRA~1\Simac0\bin\itchm.exe
R2 ITCHM_R1;Access Control ISC TCP Hardware Manager;C:\PROGRA~1\Simac0\bin\ritchm.exe
R2 kdc;Kerberos Key Distribution Center;C:\WINNT\System32\lsass.exe
R2 NtFrs;File Replication Service;C:\WINNT\system32\ntfrs.exe
R2 PUS;Access Control Point Update;C:\PROGRA~1\Simac0\bin\acc_pus.exe
R2 Simplex;Simplex;C:\WINNT\system32\DRIVERS\simplex.sys
R2 TrkSvr;Distributed Link Tracking Server;C:\WINNT\system32\services.exe
R3 pvdatw2k;pvdatw2k;C:\WINNT\system32\DRIVERS\pvdatw2k.sys
R3 usbhub20;USB Hub Support;C:\WINNT\system32\DRIVERS\usbhub20.sys
S3 CO_Mon;CO_Mon;\??\C:\WINNT\system32\Drivers\CO_Mon.sys
S3 TDASYNC;TDASYNC;C:\WINNT\system32\drivers\TDASYNC.sys
S3 TDIPX;TDIPX;C:\WINNT\system32\drivers\TDIPX.sys
S3 TDNETB;TDNETB;C:\WINNT\system32\drivers\TDNETB.sys
S3 TDSPX;TDSPX;C:\WINNT\system32\drivers\TDSPX.sys
S4 4120HM_L1;Access Control 4120 Net Hardware Manager;C:\PROGRA~1\Simac0\bin\4120HM.exe
S4 ACPM;Access Control Print Manager;C:\PROGRA~1\Simac0\bin\acpm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
tapisrv Tapisrv


Contents of the 'Scheduled Tasks' folder
2007-08-05 09:00:00 C:\WINNT\Tasks\At10.job - C:\WINNT\system321hJA5Xt.exe
2007-08-05 10:00:00 C:\WINNT\Tasks\At11.job - C:\WINNT\system321hJA5Xt.exe
2007-08-05 07:00:00 C:\WINNT\Tasks\At113.job
2007-08-04 19:40:39 C:\WINNT\Tasks\At114.job
2007-08-04 19:40:39 C:\WINNT\Tasks\At115.job
2007-08-04 19:40:39 C:\WINNT\Tasks\At116.job
2007-08-05 11:00:00 C:\WINNT\Tasks\At12.job - C:\WINNT\system321hJA5Xt.exe
2007-08-05 12:00:00 C:\WINNT\Tasks\At13.job
2007-08-05 13:00:00 C:\WINNT\Tasks\At14.job - C:\WINNT\system321hJA5Xt.exe
2007-08-05 14:00:00 C:\WINNT\Tasks\At15.job
2007-08-05 15:00:00 C:\WINNT\Tasks\At16.job
2007-08-05 16:00:00 C:\WINNT\Tasks\At17.job - C:\WINNT\system321hJA5Xt.exe
2007-08-05 17:00:00 C:\WINNT\Tasks\At18.job - C:\WINNT\system321hJA5Xt.exe
2007-08-05 18:00:00 C:\WINNT\Tasks\At19.job - C:\WINNT\system321hJA5Xt.exe
2007-08-05 19:00:00 C:\WINNT\Tasks\At20.job - C:\WINNT\system321hJA5Xt.exe
2007-08-05 20:00:00 C:\WINNT\Tasks\At21.job - C:\WINNT\system321hJA5Xt.exe
2007-08-05 21:00:00 C:\WINNT\Tasks\At22.job - C:\WINNT\system321hJA5Xt.exe
2007-08-05 22:00:00 C:\WINNT\Tasks\At23.job - C:\WINNT\system321hJA5Xt.exe
2007-08-05 23:00:00 C:\WINNT\Tasks\At24.job - C:\WINNT\system321hJA5Xt.exe
2007-08-06 00:00:00 C:\WINNT\Tasks\At25.job - C:\WINNT\system321hJA5Xt.exe
2007-08-06 01:00:00 C:\WINNT\Tasks\At26.job - C:\WINNT\system321hJA5Xt.exe
2007-08-06 02:00:00 C:\WINNT\Tasks\At27.job
2007-08-06 03:00:00 C:\WINNT\Tasks\At28.job - C:\WINNT\system321hJA5Xt.exe
2007-08-05 04:00:00 C:\WINNT\Tasks\At5.job - C:\WINNT\system321hJA5Xt.exe
2007-08-05 05:00:00 C:\WINNT\Tasks\At6.job
2007-08-05 06:00:00 C:\WINNT\Tasks\At7.job - C:\WINNT\system321hJA5Xt.exe
2007-08-05 07:00:00 C:\WINNT\Tasks\At8.job - C:\WINNT\system321hJA5Xt.exe
2007-08-05 08:00:00 C:\WINNT\Tasks\At9.job - C:\WINNT\system321hJA5Xt.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-05 23:42:50
Windows 5.0.2195 Service Pack 4 NTFS

scanning hidden processes …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-05 23:43:29
C:\ComboFix-quarantined-files.txt … 07-08-05 23:43
C:\ComboFix2.txt … 07-08-04 11:06
C:\ComboFix3.txt … 07-08-04 11:03

— E O F —
Hi medicman,

It may not look like it yet but Combofix really cleaned up a lot of stuff. On to the next couple of scans before we do any work with HJT.

You will likely need more than one post to reply with the logs to keep them from getting cut off, that is fine. You can do one for each if you like.


STEP 1:

Please download SDFix and save it to your Desktop.

You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Double click on SDFix.exe. It should automatically extract a folder called SDFix to your system drive (usually C:\). Please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
  • Open the SDFix folder and double click on RunThis.bat to start the script.
  • Type Y and press Enter to begin the script.
  • It will start cleaning your PC and then prompt you to press any key to Reboot.
  • Press any key to restart the PC.
  • Your system will take longer than normal to restart as the fixtool will be removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished.
  • Press any key to end the script and to load your desktop icons.
  • A text file should automatically open, so please copy the contents and post them here.

STEP 2:

Using Internet Explorer, click on Kaspersky Online Scanner * You will be prompted to install an ActiveX component from Kaspersky, Click 'Yes'.
* The program will launch and then start to download the latest definition files.
* Once the scanner is installed and the definitions downloaded, click 'Next'.
* Now click on 'Scan Settings'
* In the scan settings make sure that the following are selected:
o Scan using the following Anti-Virus database: 'Extended' (If available, otherwise 'Standard')
o Scan Options: 'Scan Archives' and 'Scan Mail Bases'
* Click 'OK'
* Now under 'Select a target to scan' select 'My Computer'
* The scan will take a while, so be patient and let it run. Once the scan is complete, it will display whether your system has been infected.
* Now click on the 'Save as Text' button:
* Save the file to your desktop.
Please post the Kaspersky report.


STEP 3:

Use ATF Cleaner to remove temp files,
cookies, cache, ect…

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


STEP 4:

Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.

http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file.
Make sure that AVG Anti-Spyware is closed before installing the update.

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon,
    some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
Once in Safe Mode:

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot back into Normal Mode

——————————————-

So, I need:SDFix log
Kaspersky report
AVG log
New HJT log
One quick question.
"STEP 3:

Use ATF Cleaner to remove temp files,
cookies, cache, ect…
Please download ATF Cleaner by Atribune.

This program is for XP and Windows 2000 only >> WILL THIS WORK ON WINDOWS 2000 SERVER?

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button."
SDFix: Version 1.96 Run by [removed] on Tue 08-07-2007 at 19:54 Microsoft Windows 2000 [Version 5.00.2195] Running From: C:\SDFix Safe Mode: Checking Services: Restoring Windows Registry Values Restoring Windows Default Hosts File Rebooting… Normal Mode: Checking Files: Trojan Files Found: C:\system.exe - Deleted C:\WINNT\system32\form.txt - Deleted C:\WINNT\system32\regscan.exe - Deleted C:\WINNT\tcb.pmw - Deleted Removing Temp Files… ADS Check: C:\WINNT No streams found. C:\WINNT\system32 No streams found. C:\WINNT\system32\svchost.exe No streams found. C:\WINNT\system32\ntoskrnl.exe No streams found. Final Check: Remaining Services: —————— Remaining Files: ————— Backups Folder: - C:\SDFix\backups\backups.zip Files with Hidden Attributes: C:\WINNT\system32\config\default.tmp.LOG C:\WINNT\system32\config\SAM.tmp.LOG C:\WINNT\system32\config\SECURITY.tmp.LOG C:\WINNT\system32\config\software.tmp.LOG C:\WINNT\system32\config\system.tmp.LOG Finished
KASPERSKY ONLINE SCANNER REPORT 2007-08-07 20:34 Operating System: Microsoft Windows 2000 Server, Service Pack 4 (Build 2195) Kaspersky Online Scanner version: 5.0.93.0 Kaspersky Anti-Virus database last update: 8/08/2007 Kaspersky Anti-Virus database records: 376954 Scan Settings Scan using the following antivirus database extended Scan Archives true Scan Mail Bases true Scan Target My Computer A:\ C:\ D:\ E:\ Scan Statistics Total number of scanned objects 19041 Number of viruses found 10 Number of infected objects 15 Number of suspicious objects 8 Duration of the scan process 00:14:25 Infected Object Name Virus Name Last Action C:\Documents and Settings\Administrator.ACSERVER\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Administrator.ACSERVER\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Administrator.ACSERVER\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Administrator.ACSERVER\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Administrator.ACSERVER\Local Settings\History\History.IE5\MSHist012007080720070808\index.dat Object is locked skipped C:\Documents and Settings\Administrator.ACSERVER\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Administrator.ACSERVER\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Administrator.ACSERVER\NTUSER.DAT.LOG Object is locked skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PurityScan.zip/offun.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PurityScan.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde1.zip/retadpu1000106.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde1.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentqt.zip/retadpu77.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentqt.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip/Yazzle1549OinUninstaller.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\SIMRUN.ISECURE.000\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\SIMRUN.ISECURE.000\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\SIMRUN.ISECURE.000\NTUSER.DAT Object is locked skipped C:\Documents and Settings\SIMRUN.ISECURE.000\NTUSER.DAT.LOG Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped C:\Program Files\codec_setup.exe/stream/data0006 Infected: Trojan-Downloader.Win32.Zlob.bxn skipped C:\Program Files\codec_setup.exe/stream Infected: Trojan-Downloader.Win32.Zlob.bxn skipped C:\Program Files\codec_setup.exe NSIS: infected - 2 skipped C:\Program Files\Microsoft SQL Server\MSSQL\Data\master.mdf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL\Data\mastlog.ldf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL\Data\model.mdf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL\Data\modellog.ldf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL\Data\msdbdata.mdf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL\Data\msdblog.ldf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL\Data\northwnd.ldf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL\Data\northwnd.mdf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL\Data\NT3400.mdf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL\Data\NT3400AUDIT.mdf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL\Data\NT3400AUDIT_log.LDF Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL\Data\NT3400TEMP.mdf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL\Data\NT3400TEMP_log.LDF Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL\Data\NT3400_log.LDF Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL\Data\pubs.mdf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL\Data\pubs_log.ldf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL\Data\tempdb.mdf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL\Data\templog.ldf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL\LOG\ERRORLOG Object is locked skipped C:\QooBox\Quarantine\C\Program Files\Outerinfo\OiUninstaller.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped C:\QooBox\Quarantine\C\Program Files\Outerinfo\OiUninstaller.exe.vir/data0003 Infected: not-a-virus:AdWare.Win32.PurityScan.bu skipped C:\QooBox\Quarantine\C\Program Files\Outerinfo\OiUninstaller.exe.vir NSIS: infected - 2 skipped C:\QooBox\Quarantine\C\Program Files\poolsv\YazzleBundle-1549.exe.vir/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped C:\QooBox\Quarantine\C\Program Files\poolsv\YazzleBundle-1549.exe.vir NSIS: infected - 1 skipped C:\QooBox\Quarantine\C\WINNT\b122.exe.vir Infected: not-a-virus:AdWare.Win32.Rond.c skipped C:\QooBox\Quarantine\C\WINNT\system32\clcl14.exe.vir Infected: Trojan.Win32.Agent.atr skipped C:\WINNT\Debug\ipsecpa.log Object is locked skipped C:\WINNT\Debug\Netlogon.log Object is locked skipped C:\WINNT\Debug\NtFrs_0005.log Object is locked skipped C:\WINNT\Debug\oakley.log Object is locked skipped C:\WINNT\Debug\PASSWD.LOG Object is locked skipped C:\WINNT\FPSFF17T.0XE Infected: Trojan-Downloader.Win32.Small.eyq skipped C:\WINNT\NETLOGON.CHG Object is locked skipped C:\WINNT\ntds\edb.log Object is locked skipped C:\WINNT\ntds\ntds.dit Object is locked skipped C:\WINNT\ntds\temp.edb Object is locked skipped C:\WINNT\ntfrs\jet\log\edb.log Object is locked skipped C:\WINNT\ntfrs\jet\ntfrs.jdb Object is locked skipped C:\WINNT\ntfrs\jet\temp\tmp.edb Object is locked skipped C:\WINNT\SchedLgU.Txt Object is locked skipped C:\WINNT\system32\config\Antivirus.Evt Object is locked skipped C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped C:\WINNT\system32\config\default Object is locked skipped C:\WINNT\system32\config\default.LOG Object is locked skipped C:\WINNT\system32\config\DnsEvent.Evt Object is locked skipped C:\WINNT\system32\config\NTDS.Evt Object is locked skipped C:\WINNT\system32\config\NtFrs.Evt Object is locked skipped C:\WINNT\system32\config\SAM Object is locked skipped C:\WINNT\system32\config\SAM.LOG Object is locked skipped C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped C:\WINNT\system32\config\SECURITY Object is locked skipped C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped C:\WINNT\system32\config\software Object is locked skipped C:\WINNT\system32\config\software.LOG Object is locked skipped C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped C:\WINNT\system32\config\system Object is locked skipped C:\WINNT\system32\config\SYSTEM.ALT Object is locked skipped C:\WINNT\system32\dhcp\dhcp.mdb Object is locked skipped C:\WINNT\system32\dhcp\DhcpSrvLog.Tue Object is locked skipped C:\WINNT\system32\dhcp\j50.log Object is locked skipped C:\WINNT\system32\dhcp\tmp.edb Object is locked skipped C:\WINNT\system32\dns\dns.log Object is locked skipped C:\WINNT\system32\DTCLog\MSDTC.LOG Object is locked skipped C:\WINNT\system32\hseawjkw\hseawjkw1.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped C:\WINNT\system32\hseawjkw\hseawjkw3.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped C:\WINNT\system32\l3acdb.dll.bak Infected: not-a-virus:AdWare.Win32.BHO.cw skipped C:\WINNT\system32\Perflib_Perfdata_3c4.dat Object is locked skipped C:\WINNT\system32\Perflib_Perfdata_498.dat Object is locked skipped C:\WINNT\WTLNFQ.0XE Infected: Trojan-Downloader.Win32.Small.eyq skipped Scan process completed.
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 20:51 08-07-2007

+ Scan result:



C:\WINNT\system32\hseawjkw\hseawjkw1.exe -> Adware.UltimateDefender : Cleaned with backup (quarantined).
C:\WINNT\system32\hseawjkw\hseawjkw3.exe -> Adware.UltimateDefender : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINNT\system32\clcl14.exe.vir -> Trojan.Agent.atr : Cleaned with backup (quarantined).


::Report end

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:23, on 08-07-2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\msdtc.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\aswServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINNT\system32\crypserv.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\system32\tcpsvcs.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\ismserv.exe
C:\WINNT\System32\llssrv.exe
C:\PROGRA~1\MICROS~3\MSSQL\binn\sqlservr.exe
C:\WINNT\system32\ntfrs.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\locator.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\dns.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\Ebrsgqhd\yvxjptov.exe
C:\PROGRA~1\ALWILS~1\Avast4\aswDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Documents and Settings\Administrator.ACSERVER\Desktop\1\HiJackThis.exe
C:\WINNT\System32\WBEM\WinMgmt.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {2B105645-86F5-402F-9400-469133A881CC} - (no file)
O2 - BHO: (no name) - {3AA15550-DE7E-7515-21E5-007B746C9458} - C:\Program Files\Rotllxwo\twrmqjkb.dll
O2 - BHO: (no name) - {4AABF6E4-4753-1FD9-7804-49B6783AF2ED} - (no file)
O2 - BHO: (no name) - {4D4059D6-564B-47BA-AC0B-F8E26432D337} - (no file)
O2 - BHO: (no name) - {53B5F2B1-94DD-43E5-8187-EB4E31F00701} - (no file)
O2 - BHO: (no name) - {641D1E8C-A933-F9EC-4967-FF8DCB5184B9} - (no file)
O2 - BHO: (no name) - {66194385-F030-FCE6-4F67-FF8DCB5187B5} - (no file)
O2 - BHO: WebAssist - {85589B5D-D53D-4237-A677-46B82EA275F3} - (no file)
O2 - BHO: (no name) - {9300ECA0-6CC2-46BA-9712-FDFC731DC0D5} - (no file)
O2 - BHO: (no name) - {BE8C226F-4A1F-4687-843D-A85F1AF6D6A6} - (no file)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ktynknyx] rundll32.exe "C:\Program Files\ktynknyx\krorcbef.dll",Init
O4 - HKLM\..\Run: [yvxjptov] C:\Program Files\Ebrsgqhd\yvxjptov.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\aswDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKUS\S-1-5-21-386374210-2625489697-3336257794-1122\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'SIMRUN')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {76D68CA1-DD9D-41C4-B2CC-AA9C9A5CF220} - http://www.junkscanner.com/jsetup.exe
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://www.winantivirus.com/download/2007/…d=pp_2127650243
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…085/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = isecure.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{B42C27C6-44CC-4C20-9555-3CE0D58F13F2}: Domain = Raclocal.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{C153D196-043D-40BF-8466-6238F1F17B18}: NameServer = 10.119.8.108,10.119.16.219,10.119.24.31
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = isecure.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = isecure.local
O20 - Winlogon Notify: ddabb - C:\WINNT\system32\ddabb.dll (file missing)
O20 - Winlogon Notify: fccyywx - fccyywx.dll (file missing)
O20 - Winlogon Notify: winpsa32 - winpsa32.dll (file missing)
O22 - SharedTaskScheduler: za - {53B5F2B1-94DD-43E5-8187-EB4E31F00701} - (no file)
O23 - Service: Access Control End User Manager (ACEUM) - Unknown owner - C:\PROGRA~1\Simac0\bin\aceum.exe
O23 - Service: Access Control Historical Log (ACHLOG) - Unknown owner - C:\PROGRA~1\Simac0\bin\achls.exe
O23 - Service: Access Control Schedule Task Manager (ACSTS) - Unknown owner - C:\PROGRA~1\Simac0\bin\acsts.exe
O23 - Service: Access Control Application Watchdog (ACWD) - Unknown owner - C:\PROGRA~1\Simac0\bin\watchdog.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Altiris Carbon Copy (CarbonCopy32) - Altiris - C:\WINNT\system32\ccsrvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINNT\SYSTEM32\crypserv.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Access Control ISC 4120 Hardware Manager (ITCHM_L1) - Unknown owner - C:\PROGRA~1\Simac0\bin\itchm.exe
O23 - Service: Access Control ISC TCP Hardware Manager (ITCHM_R1) - Unknown owner - C:\PROGRA~1\Simac0\bin\ritchm.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - c:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Access Control Point Update (PUS) - Unknown owner - C:\PROGRA~1\Simac0\bin\acc_pus.exe
O24 - Desktop Component 0: (no name) - http://tbn0.google.com/images?q=tbn:02NbHO…E_chieftain.jpg

–
End of file - 7409 bytes
Hi medicman,

Not sure if Smitfraud is still present but there is evidence of it in your Kaspersky log. So let's just run this to make sure. After this we should be able to go in and finish up with the manual HJT fixes and file/folder deletions.

Please download SmitfraudFix (by S!Ri) to your Desktop.

Double-click SmitfraudFix.exe
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

**If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (usually C:), and launch from there.


Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc…processutil.htm
SmitFraudFix v2.210 Scan done at 19:11:35.90, Thu 08-09-2007 Run from C:\Documents and Settings\Administrator.ACSERVER\Desktop\1\SmitfraudFix OS: Microsoft Windows 2000 [Version 5.00.2195] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\Ati2evxx.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\WINNT\system32\msdtc.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\aswServ.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINNT\system32\crypserv.exe C:\WINNT\system32\Dfssvc.exe C:\WINNT\system32\tcpsvcs.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\ismserv.exe C:\WINNT\System32\llssrv.exe C:\PROGRA~1\MICROS~3\MSSQL\binn\sqlservr.exe C:\WINNT\system32\ntfrs.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\locator.exe C:\WINNT\system32\MSTask.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\dns.exe C:\WINNT\system32\Ati2evxx.exe C:\WINNT\Explorer.EXE C:\WINNT\System32\svchost.exe C:\Program Files\QuickTime\qttask.exe C:\WINNT\system32\rundll32.exe C:\Program Files\Ebrsgqhd\yvxjptov.exe C:\PROGRA~1\ALWILS~1\Avast4\aswDisp.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\internet explorer\iexplore.exe C:\PROGRA~1\Simac0\bin\ACSTS_EX.exe C:\WINNT\system32\cmd.exe C:\WINNT\System32\WBEM\WinMgmt.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT C:\WINNT\Tasks\At?.job FOUND ! C:\WINNT\Tasks\At??.job FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator.ACSERVER »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator.ACSERVER\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADMINI~1.ACS\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components] "Source"="http://tbn0.google.com/images?q=tbn:02NbHOXyFI56AM:http://pueblo.coravue.net/images/HOUSE%2520FIRE_chieftain.jpg" "SubscribedURL"="http://tbn0.google.com/images?q=tbn:02NbHOXyFI56AM:http://pueblo.coravue.net/images/HOUSE%2520FIRE_chieftain.jpg" "FriendlyName"="" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{53B5F2B1-94DD-43E5-8187-EB4E31F00701}"="za" »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: Intel® PRO/1000 MT Network Connection DNS Server Search Order: 10.119.8.108 DNS Server Search Order: 10.119.16.219 DNS Server Search Order: 10.119.24.31 HKLM\SYSTEM\CCS\Services\Tcpip\..\{C153D196-043D-40BF-8466-6238F1F17B18}: NameServer=10.119.8.108,10.119.16.219,10.119.24.31 HKLM\SYSTEM\CS1\Services\Tcpip\..\{C153D196-043D-40BF-8466-6238F1F17B18}: NameServer=10.119.8.108,10.119.16.219,10.119.24.31 HKLM\SYSTEM\CS2\Services\Tcpip\..\{C153D196-043D-40BF-8466-6238F1F17B18}: NameServer=10.119.8.108,10.119.16.219,10.119.24.31 »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
Yes, Smitfraud present too…boy this thing had a real cornucopia of malware on it (don't get to use that word often enough!). :rofl:

Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

[external image: Posted Image]

The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________

Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #3 - Delete Trusted zone by typing 3 and press Enter
Answer Yes to the question "Restore Trusted Zone ?" by typing
Y and hit Enter.

Note, if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.
______________________________

Please post:
1. c:\rapport.txt
2. A new HijackThis log
I get an error message "Cannot import cleanup.reg: Error accessing the registry" Here is the rapport log: SmitFraudFix v2.210 Scan done at 0:45:50.75, Fri 08-10-2007 Run from C:\Documents and Settings\Administrator.ACSERVER\Desktop\1\SmitfraudFix OS: Microsoft Windows 2000 [Version 5.00.2195] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{53B5F2B1-94DD-43E5-8187-EB4E31F00701}"="za" »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» hosts 127.0.0.1 localhost »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\WINNT\Tasks\At?.job Deleted C:\WINNT\Tasks\At??.job Deleted »»»»»»»»»»»»»»»»»»»»»»»» DNS HKLM\SYSTEM\CCS\Services\Tcpip\..\{C153D196-043D-40BF-8466-6238F1F17B18}: NameServer=10.119.8.108,10.119.16.219,10.119.24.31 HKLM\SYSTEM\CS1\Services\Tcpip\..\{C153D196-043D-40BF-8466-6238F1F17B18}: NameServer=10.119.8.108,10.119.16.219,10.119.24.31 HKLM\SYSTEM\CS2\Services\Tcpip\..\{C153D196-043D-40BF-8466-6238F1F17B18}: NameServer=10.119.8.108,10.119.16.219,10.119.24.31 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{53B5F2B1-94DD-43E5-8187-EB4E31F00701}"="za" »»»»»»»»»»»»»»»»»»»»»»»» End

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI