This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] think i might have a trojan part II

68 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Simon V was looking at this post but he advised to start a new topic due to inactivity so here it is!

have run ATF cleaner, SDfix, Combofix and Ccleaner as advised.

Combofix log not possible as it kept getting stuck for ages on 'deleting files/folders' page

logs + HJT logs requested as follows,

do your best guys

many thanks

Steve H.

———————————

SDFix: Version 1.118

Run by [removed] on 2007-12-20 at 21:58

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:

C:\WINDOWS\system32\9_exception.nls - Deleted




Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-20 22:04:27
Windows 5.1.2600 FAT NTAPI

scanning hidden processes …

scanning hidden services …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
——————



Authorized Application Key Export:

Remaining Files:
—————

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Sat 2 Sep 2006 214 ..SH. — "C:\AUTOEXEC.BAK"
Mon 29 Aug 2005 1,690 ..SHR — "C:\MSDOS.BAK"
Tue 30 Jan 2001 172,099 …H. — "C:\ZZ.EXE"
Thu 30 Sep 1993 1,754 …H. — "C:\CHOICE.COM"
Thu 23 Aug 2001 200,704 ..SHR — "C:\WINDOWS\SYSTEM32\igihoc.exe"
Sun 2 Dec 2007 20,810 ..SH. — "C:\WINDOWS\SYSTEM32\gzjhroqx.dllbox"
Thu 20 Dec 2007 20,810 ..SH. — "C:\WINDOWS\SYSTEM32\urlpcnpu.dllbox"
Sat 11 Aug 2007 4,348 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 11 Aug 2007 20 A..H. — "C:\Documents and Settings\h1gg1\My Documents\My Music\License Backup\drmv1lic.bak"
Sat 11 Aug 2007 4,348 …H. — "C:\Documents and Settings\h1gg1\My Documents\My Music\License Backup\drmv1key.bak"
Sat 11 Aug 2007 9,655 A.SH. — "C:\Documents and Settings\h1gg1\My Documents\My Music\License Backup\drmv2key.bak"
Mon 28 May 2001 42,496 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Templates\~WRL0002.TMP"
Tue 2 Oct 2001 78,336 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Templates\~WRL1110.TMP"
Mon 25 Mar 2002 26,624 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Templates\~WRL0626.TMP"
Tue 10 Dec 2002 26,112 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Templates\~WRL3840.tmp"
Sat 1 Nov 2003 83,456 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Templates\~WRL2901.tmp"
Sat 29 Mar 2003 59,904 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Templates\~WRL1156.tmp"
Mon 13 Oct 2003 80,896 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Templates\~WRL3550.tmp"
Tue 4 Nov 2003 86,528 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Templates\~WRL2472.tmp"
Wed 5 Nov 2003 88,064 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Templates\~WRL0261.tmp"
Sun 1 Feb 2004 107,008 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Templates\~WRL0731.tmp"
Wed 17 Jul 2002 19,456 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL3988.TMP"
Sat 21 Feb 2004 124,416 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL2561.tmp"
Sun 21 Sep 2003 80,384 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL3958.tmp"
Sat 21 Feb 2004 118,784 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL3870.tmp"
Sat 21 Feb 2004 120,320 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL0677.tmp"
Sat 21 Feb 2004 113,152 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL1901.tmp"
Sat 21 Feb 2004 114,176 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL3466.tmp"
Sat 21 Feb 2004 118,272 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL0820.tmp"
Sat 21 Feb 2004 107,520 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL2972.tmp"
Sun 22 Feb 2004 108,032 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL3131.tmp"
Sun 22 Feb 2004 107,520 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL0208.tmp"
Sun 22 Feb 2004 142,848 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL2770.tmp"
Sun 22 Feb 2004 143,872 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL3968.tmp"
Mon 15 Mar 2004 82,432 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL3754.tmp"
Mon 23 Feb 2004 123,904 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL2678.tmp"
Mon 23 Feb 2004 121,344 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL2008.tmp"
Mon 15 Mar 2004 80,384 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL1925.tmp"
Mon 15 Mar 2004 78,848 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL0715.tmp"
Mon 15 Mar 2004 79,360 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL1751.tmp"
Mon 15 Mar 2004 81,920 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL2677.tmp"
Mon 15 Mar 2004 79,872 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL1487.tmp"
Mon 15 Mar 2004 80,896 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL0052.tmp"
Mon 15 Mar 2004 78,848 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL2941.tmp"
Mon 15 Mar 2004 81,920 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL1570.tmp"
Sat 27 Mar 2004 87,552 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL1505.tmp"
Sat 27 Mar 2004 91,136 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL3950.tmp"
Sat 27 Mar 2004 93,696 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL1285.tmp"
Mon 15 Nov 2004 36,352 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL0004.tmp"
Sun 30 Jan 2005 53,760 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL0005.tmp"
Sun 30 Jan 2005 56,832 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL3746.tmp"
Sun 30 Jan 2005 56,320 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL2454.tmp"
Sun 27 Mar 2005 122,880 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL0006.tmp"
Sun 27 Mar 2005 126,976 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL3927.tmp"
Sun 27 Mar 2005 132,608 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL3657.tmp"
Sun 27 Mar 2005 151,552 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL3832.tmp"
Fri 7 Jul 2006 23,040 A..H. — "C:\Documents and Settings\h1gg1\Application Data\Microsoft\Word\~WRL0007.tmp"

Finished!

—————————————-

install.txt

Adaptec Easy CD Creator 4
ATI Display Driver
AVG Anti-Spyware 7.5
CCleaner (remove only)
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 8
Lara Croft Tomb Raider: Angel Of Darkeness
LiveReg (Symantec Corporation)
LiveUpdate 1.6 (Symantec Corporation)
Microsoft Picture It! Publishing 2001
Microsoft Word 2000 SR-1
Microsoft Works 2001 Setup Launcher
Microsoft Works 6.0
Mozilla Firefox (2.0.0.11)
Napster
Napster Burn Engine
QuickTime
RealPlayer
Sony Picture Utility
Sony USB Driver
Spybot - Search & Destroy 1.4
WebFldrs XP
Windows Media Format Runtime
Windows Media Player 10
Works Suite OS Pack
Works Synchronization
ZoneAlarm Pro

————————————————————–

HJT log

Logfile of HijackThis v1.99.1
Scan saved at 23:28, on 2007-12-20
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lycos.co.uk/
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\urlpcnpu.dll
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [07d104b4] rundll32.exe "C:\WINDOWS\System32\hexpcytu.dll",b
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f007.mail.lycos.co.uk/app/uploader/FileUploader.cab
O20 - AppInit_DLLs: C:\WINDOWS\System32\__c00965A6.dat
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\System32\ZoneLabs\vsmon.exe

———————————–
I don't see a anti-virus program running. Get this free one.

Click HERE Click the Download Now and Save, Install, Update and run a full scan.


Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment
Followed instructions as requested and log as follows.

PC seems to run slower than usual and internet explorer icon keeps appaering on desktop even though not requested.
Icon will then take you to unwanted site.

Logfile of HijackThis v1.99.1
Scan saved at 23:24, on 2007-12-23
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lycos.co.uk/
O2 - BHO: {1a3196b1-8d3f-eb89-e714-7b29b2bc94c3} - {3c49cb2b-92b7-417e-98be-f3d81b6913a1} - C:\WINDOWS\System32\qofwaxyu.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\urlpcnpu.dll
O2 - BHO: (no name) - {DA6B819D-3CA0-478C-A48E-A9553D724307} - C:\WINDOWS\System32\qopqo.dll (file missing)
O2 - BHO: (no name) - {FED51DF2-9644-4C58-9104-90244EDD6EEC} - C:\WINDOWS\system32\fccyvsp.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\urlpcnpu.dll
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [07d104b4] rundll32.exe "C:\WINDOWS\System32\yypqaycb.dll",b
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f007.mail.lycos.co.uk/app/uploader/FileUploader.cab
O20 - AppInit_DLLs: C:\WINDOWS\System32\__c00965A6.dat
O20 - Winlogon Notify: fccyvsp - fccyvsp.dll (file missing)
O20 - Winlogon Notify: gzjhroqx - gzjhroqx.dll (file missing)
O20 - Winlogon Notify: urlpcnpu - C:\WINDOWS\SYSTEM32\urlpcnpu.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\System32\bsukoein.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.

Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here to your Desktop.

**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
ComboFix 07-12-21.4 - h1gg1 2007-12-24 9:11:13.6 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.0.1252.1.1033.18.317 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\drivers\Xdh72.sys
C:\WINDOWS\system32\qomljhg.dll
.
—- Previous Run ——-
.
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\h1gg1\Application Data\1415002.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\hosts
C:\WINDOWS\start.exe
C:\WINDOWS\system32\4_exception.nls
C:\WINDOWS\system32\gzjhroqx.dllbox
C:\WINDOWS\system32\jkkhiii.dll
C:\WINDOWS\system32\khffcbb.dll
C:\WINDOWS\system32\ljhih.dll
C:\WINDOWS\system32\opnlijk.dll
C:\WINDOWS\SYSTEM32\oqpoq.ini
C:\WINDOWS\SYSTEM32\oqpoq.ini2
C:\WINDOWS\system32\urlpcnpu.dllbox

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CTL_W32
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_RUNTIME
——-\LEGACY_XDH72
——-\DomainService
——-\Xdh72


——-\Xdh72


((((((((((((((((((((((((( Files Created from 2007-11-24 to 2007-12-24 )))))))))))))))))))))))))))))))
.

2007-12-23 23:54 . 2007-12-24 08:47 4,484 –a—— C:\tcp.exe
2007-12-23 23:49 . 2007-12-24 08:47 4,484 –a—— C:\WINDOWS\SYSTEM\run.exe
2007-12-23 23:48 . 2007-12-24 08:47 48,640 –a—— C:\WINDOWS\SYSTEM\del.exe
2007-12-23 23:48 . 2007-12-24 08:47 7,628 –a—— C:\WINDOWS\SYSTEM\delnew.exe
2007-12-23 23:47 . 2007-12-23 23:47 30,720 -r-hs—- C:\WINDOWS\SYSTEM32\svshost.exe
2007-12-23 23:47 . 2007-12-24 08:47 4,592 –a—— C:\msu32.exe
2007-12-23 23:47 . 2007-12-23 23:47 68 –a—— C:\WINDOWS\SYSTEM32\i
2007-12-23 23:15 . 2007-12-23 23:59 21,760 –a—— C:\WINDOWS\Xdh72.sys
2007-12-23 17:47 . 2007-12-23 17:47 dr-h—– C:\$VAULT$.AVG
2007-12-23 17:46 . 2007-12-23 17:46 d——– C:\Documents and Settings\h1gg1\Application Data\AVG7
2007-12-23 17:40 . 2007-12-23 17:40 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-23 17:39 . 2007-12-23 17:39 d——– C:\Documents and Settings\All Users\Application Data\avg7
2007-12-23 15:22 . 2007-12-23 15:22 294 —hs—- C:\WINDOWS\SYSTEM32\bcyaqpyy.ini
2007-12-20 22:46 . 2007-12-20 22:46 d——– C:\Program Files\CCleaner
2007-12-20 21:55 . 2007-12-20 21:55 d–hs—- C:\FOUND.023
2007-12-20 21:08 . 2007-12-20 21:08 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-20 21:08 . 2007-12-20 21:08 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-20 16:47 . 2007-12-21 20:08 971,163 —hs—- C:\WINDOWS\SYSTEM32\utycpxeh.ini
2007-12-20 16:07 . 2007-12-20 16:07 d–hs—- C:\FOUND.022
2007-12-19 16:22 . 2007-12-20 16:46 970,743 —hs—- C:\WINDOWS\SYSTEM32\tlgjkyqa.ini
2007-12-16 18:56 . 2007-12-19 16:21 970,434 —hs—- C:\WINDOWS\SYSTEM32\pufnqbbl.ini
2007-12-14 22:01 . 2007-12-14 22:01 d——– C:\WINDOWS\ERUNT
2007-12-14 19:42 . 2007-12-14 19:42 d–hs—- C:\FOUND.021
2007-12-12 19:31 . 2007-12-12 19:31 d–hs—- C:\FOUND.020
2007-12-11 13:41 . 2007-12-11 13:41 d–hs—- C:\FOUND.019
2007-12-08 15:11 . 2007-12-08 15:11 d–hs—- C:\FOUND.018
2007-12-06 22:18 . 2007-12-06 22:18 d–hs—- C:\FOUND.017
2007-12-06 21:25 . 2007-12-06 21:25 d–hs—- C:\FOUND.016
2007-12-06 20:29 . 2007-12-09 19:15 831,897 —hs—- C:\WINDOWS\SYSTEM32\yinvwbbj.ini
2007-12-06 20:25 . 2007-12-19 22:40 0 –a—— C:\WINDOWS\SYSTEM32\mcrh.tmp
2007-12-06 19:36 . 2007-12-06 19:36 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-05 20:32 . 2007-12-06 19:21 807,598 —hs—- C:\WINDOWS\SYSTEM32\usjvybbd.ini
2007-12-05 10:16 . 2007-12-05 10:16 d–hs—- C:\FOUND.015
2007-12-03 13:53 . 2007-12-03 13:53 d–hs—- C:\FOUND.014
2007-12-02 17:12 . 2007-12-02 17:12 793,664 —hs—- C:\WINDOWS\SYSTEM32\hqkomvgd.ini
2007-12-02 16:51 . 2007-12-02 16:51 d–hs—- C:\FOUND.013
2007-12-01 19:01 . 2007-12-01 19:01 d–hs—- C:\FOUND.012
2007-12-01 15:08 . 2007-12-01 15:08 d——– C:\WINDOWS\sdir

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-06-01 08:08 113 —-a-w C:\Documents and Settings\h1gg1\Application Data\fusioncache.dat
2006-10-30 20:46 111,928 —-a-w C:\Documents and Settings\h1gg1\Application Data\GDIPFONTCACHEV1.DAT
2006-08-20 21:01 271 –sh–w C:\Program Files\DESKTOP.INI
2006-08-20 21:01 23,357 —h–w C:\Program Files\FOLDER.HTT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3c49cb2b-92b7-417e-98be-f3d81b6913a1}]
C:\WINDOWS\System32\qofwaxyu.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DA6B819D-3CA0-478C-A48E-A9553D724307}]
C:\WINDOWS\System32\qopqo.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2000-07-02 18:48]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-06-29 16:00]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-12-03 14:49]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" [2006-07-26 03:03]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
"07d104b4"="C:\WINDOWS\System32\yypqaycb.dll" []
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-23 17:39]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-08-23 12:00]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-23 17:40]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2000-06-29 16:15:10]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"EditLevel"= 0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"EditLevel"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccyvsp]
fccyvsp.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gzjhroqx]
gzjhroqx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urlpcnpu]
urlpcnpu.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"EnsoniqMixer"=starter.exe
"LTWinModem1"=ltmsg.exe 9
"WorksFUD"=C:\Program Files\Microsoft Works\wkfud.exe
"POINTER"=point32.exe
"Zone Labs Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

R2 qo4q6q3m4w6;qo4q6q3m4w6;"C:\WINDOWS\system32\svshost.exe" [2007-12-23 23:47]
S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;C:\WINDOWS\System32\DRIVERS\ADM8511.SYS [2001-08-17 12:11]
S3 sea1bus;Sony Ericsson Device 0A1 driver (WDM);C:\WINDOWS\System32\DRIVERS\sea1bus.sys [2006-11-20 13:47]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\^RNA]
rundll rnasetup.dll,installoptionalcomponent rna

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:WIN9X /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:WIN9X /user /install
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install
"C:\Program Files\Outlook Express\setup50.exe" /APP:WAB /CALLER:IE50 /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
C:\WINDOWS\SYSTEM32\UPDCRL.EXE -e -u C:\WINDOWS\SYSTEM\verisignpub1.crl
.
Contents of the 'Scheduled Tasks' folder
"2007-12-01 23:00:02 C:\WINDOWS\Tasks\Tune-up Application Start.job"
"2007-12-24 09:07:44 C:\WINDOWS\Tasks\PCHealth Scheduler for Data Collection.job"
- C:\WINDOWS\PCHEALTH\SUPPORT\PCHSCHD.EXE
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-24 09:16:25
Windows 5.1.2600 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-24 9:17:25 - machine was rebooted [h1gg1]






Logfile of HijackThis v1.99.1
Scan saved at 09:20:33, on 24/12/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\svshost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system\delnew.exe
C:\WINDOWS\system\delnew.exe
C:\WINDOWS\system\delnew.exe
C:\WINDOWS\system\delnew.exe
C:\WINDOWS\system\delnew.exe
C:\WINDOWS\system\delnew.exe
C:\WINDOWS\system\delnew.exe
C:\WINDOWS\system\delnew.exe
C:\WINDOWS\system\delnew.exe
C:\WINDOWS\system\delnew.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lycos.co.uk/
O2 - BHO: {1a3196b1-8d3f-eb89-e714-7b29b2bc94c3} - {3c49cb2b-92b7-417e-98be-f3d81b6913a1} - C:\WINDOWS\System32\qofwaxyu.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: (no name) - {DA6B819D-3CA0-478C-A48E-A9553D724307} - C:\WINDOWS\System32\qopqo.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [07d104b4] rundll32.exe "C:\WINDOWS\System32\yypqaycb.dll",b
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O16 - DPF: {1A26F07F-0D60-4835-91CF-1E1766A0EC56} - http://scanner2.malware-scan.com/setup/webinst.cab
O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f007.mail.lycos.co.uk/app/uploader/FileUploader.cab
O20 - Winlogon Notify: fccyvsp - fccyvsp.dll (file missing)
O20 - Winlogon Notify: gzjhroqx - gzjhroqx.dll (file missing)
O20 - Winlogon Notify: urlpcnpu - urlpcnpu.dll (file missing)
O20 - Winlogon Notify: xxywvus - C:\WINDOWS\SYSTEM32\xxywvus.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: qo4q6q3m4w6 - Unknown owner - C:\WINDOWS\system32\svshost.exe
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\tcp.exe
C:\WINDOWS\SYSTEM\run.exe
C:\WINDOWS\SYSTEM\del.exe
C:\WINDOWS\SYSTEM\delnew.exe
C:\WINDOWS\SYSTEM32\svshost.exe
C:\msu32.exe
C:\WINDOWS\SYSTEM32\i
C:\WINDOWS\Xdh72.sys
C:\WINDOWS\SYSTEM32\bcyaqpyy.ini
C:\WINDOWS\SYSTEM32\utycpxeh.ini
C:\WINDOWS\SYSTEM32\tlgjkyqa.ini
C:\WINDOWS\SYSTEM32\pufnqbbl.ini
C:\WINDOWS\SYSTEM32\yinvwbbj.ini
C:\WINDOWS\SYSTEM32\mcrh.tmp
C:\WINDOWS\SYSTEM32\usjvybbd.ini
C:\WINDOWS\SYSTEM32\hqkomvgd.ini
C:\WINDOWS\System32\qofwaxyu.dll
C:\WINDOWS\System32\qopqo.dll
C:\WINDOWS\System32\yypqaycb.dll

Folder::
C:\FOUND.022
C:\FOUND.023
C:\FOUND.021
C:\FOUND.020
C:\FOUND.019
C:\FOUND.018
C:\FOUND.017
C:\FOUND.016
C:\FOUND.015
C:\FOUND.014
C:\FOUND.013
C:\FOUND.012
C:\WINDOWS\sdir

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3c49cb2b-92b7-417e-98be-f3d81b6913a1}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DA6B819D-3CA0-478C-A48E-A9553D724307}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"07d104b4"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccyvsp]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gzjhroqx]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urlpcnpu]


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
ComboFix 07-12-21.4 - h1gg1 2007-12-28 13:52:15.9 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.0.1252.1.1033.18.295 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\h1gg1\Desktop\CFscript.txt
* Created a new restore point

FILE
C:\msu32.exe
C:\tcp.exe
C:\WINDOWS\SYSTEM\del.exe
C:\WINDOWS\SYSTEM\delnew.exe
C:\WINDOWS\SYSTEM\run.exe
C:\WINDOWS\SYSTEM32\bcyaqpyy.ini
C:\WINDOWS\SYSTEM32\hqkomvgd.ini
C:\WINDOWS\SYSTEM32\i
C:\WINDOWS\SYSTEM32\mcrh.tmp
C:\WINDOWS\SYSTEM32\pufnqbbl.ini
C:\WINDOWS\System32\qofwaxyu.dll
C:\WINDOWS\System32\qopqo.dll
C:\WINDOWS\SYSTEM32\svshost.exe
C:\WINDOWS\SYSTEM32\tlgjkyqa.ini
C:\WINDOWS\SYSTEM32\usjvybbd.ini
C:\WINDOWS\SYSTEM32\utycpxeh.ini
C:\WINDOWS\SYSTEM32\yinvwbbj.ini
C:\WINDOWS\System32\yypqaycb.dll
C:\WINDOWS\Xdh72.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\FOUND.012
C:\FOUND.012\FILE0000.CHK

.
((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-28 )))))))))))))))))))))))))))))))
.

2007-12-28 11:10 . 2007-12-28 11:10 30,720 –a—— C:\WINDOWS\SYSTEM32\eraseme_52156.exe
2007-12-27 22:02 . 2007-12-27 22:02 30,720 –a—— C:\WINDOWS\SYSTEM32\eraseme_42882.exe
2007-12-27 16:52 . 2007-12-27 16:52 0 –a—— C:\WINDOWS\SYSTEM32\eraseme_45851.exe
2007-12-26 21:30 . 2007-12-28 11:07 7,408 –a—— C:\WINDOWS\SYSTEM\dc4all.exe
2007-12-25 18:08 . 2007-12-25 18:08 d–hs—- C:\FOUND.024
2007-12-23 17:47 . 2007-12-23 17:47 dr-h—– C:\$VAULT$.AVG
2007-12-23 17:46 . 2007-12-23 17:46 d——– C:\Documents and Settings\h1gg1\Application Data\AVG7
2007-12-23 17:40 . 2007-12-23 17:40 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-23 17:39 . 2007-12-23 17:39 d——– C:\Documents and Settings\All Users\Application Data\avg7
2007-12-20 22:46 . 2007-12-20 22:46 d——– C:\Program Files\CCleaner
2007-12-20 21:08 . 2007-12-24 14:36 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-20 21:08 . 2007-12-20 21:08 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-14 22:01 . 2007-12-14 22:01 d——– C:\WINDOWS\ERUNT
2007-12-06 19:36 . 2007-12-06 19:36 d——– C:\Documents and Settings\All Users\Application Data\Grisoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-06-01 08:08 113 —-a-w C:\Documents and Settings\h1gg1\Application Data\fusioncache.dat
2006-10-30 20:46 111,928 —-a-w C:\Documents and Settings\h1gg1\Application Data\GDIPFONTCACHEV1.DAT
2006-08-20 21:01 271 –sh–w C:\Program Files\DESKTOP.INI
2006-08-20 21:01 23,357 —h–w C:\Program Files\FOLDER.HTT
2006-07-13 07:06 12,801,467 ——w C:\WINDOWS\Internet Logs\ZLCLIENT_2nd_2006_07_12_22_21_58.dmp.zip
.

((((((((((((((((((((((((((((( snapshot@2007-12-24_ 9.16.56.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-03-13 10:57:12 163,328 —-a-w C:\WINDOWS\erdnt\subs\F3M\ERDNT.EXE
- 2007-12-23 23:47:36 16,384 —-a-w C:\WINDOWS\SYSTEM32\config\systemprofile\Cookies\index.dat
+ 2007-12-28 11:10:46 16,384 —-a-w C:\WINDOWS\SYSTEM32\config\systemprofile\Cookies\index.dat
- 2007-12-23 23:47:36 32,768 —-a-w C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-12-28 11:10:46 32,768 —-a-w C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-12-24 09:16:16 32,768 —-a-w C:\WINDOWS\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-28 13:52:38 32,768 —-a-w C:\WINDOWS\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7A5565EF-A594-46E4-AF56-FE71AEAFD7D5}]
C:\WINDOWS\System32\vtuvwtu.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B0EEDC94-E177-43D2-B600-84E7AC69969B}]
C:\WINDOWS\System32\efcbxxy.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2000-07-02 18:48]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-06-29 16:00]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-12-03 14:49]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" [2006-07-26 03:03]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-23 17:39]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-08-23 12:00]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-23 17:40]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2000-06-29 16:15:10]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"EditLevel"= 0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"EditLevel"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{A74F3FC3-CC9A-4D4C-AFB5-B56F0CAA445D}"= C:\WINDOWS\System32\xxywvus.dll [ ]
"{B0EEDC94-E177-43D2-B600-84E7AC69969B}"= C:\WINDOWS\System32\efcbxxy.dll [ ]
"{7A5565EF-A594-46E4-AF56-FE71AEAFD7D5}"= C:\WINDOWS\System32\vtuvwtu.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcbxxy]
efcbxxy.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtuvwtu]
vtuvwtu.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxywvus]
xxywvus.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"EnsoniqMixer"=starter.exe
"LTWinModem1"=ltmsg.exe 9
"WorksFUD"=C:\Program Files\Microsoft Works\wkfud.exe
"POINTER"=point32.exe
"Zone Labs Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

R3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;C:\WINDOWS\System32\DRIVERS\ADM8511.SYS [2001-08-17 12:11]
S2 Security Restore Services;Security Restore Services;"C:\WINDOWS\system32\svshost.exe" []
S3 sea1bus;Sony Ericsson Device 0A1 driver (WDM);C:\WINDOWS\System32\DRIVERS\sea1bus.sys [2006-11-20 13:47]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\^RNA]
rundll rnasetup.dll,installoptionalcomponent rna

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:WIN9X /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:WIN9X /user /install
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install
"C:\Program Files\Outlook Express\setup50.exe" /APP:WAB /CALLER:IE50 /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
C:\WINDOWS\SYSTEM32\UPDCRL.EXE -e -u C:\WINDOWS\SYSTEM\verisignpub1.crl
.
Contents of the 'Scheduled Tasks' folder
"2007-12-01 23:00:02 C:\WINDOWS\Tasks\Tune-up Application Start.job"
"2007-12-28 13:43:04 C:\WINDOWS\Tasks\PCHealth Scheduler for Data Collection.job"
- C:\WINDOWS\PCHEALTH\SUPPORT\PCHSCHD.EXE
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-28 13:54:51
Windows 5.1.2600 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-28 13:55:14
C:\ComboFix2.txt … 2007-12-28 12:43
C:\ComboFix3.txt … 2007-12-24 09:17









Logfile of HijackThis v1.99.1
Scan saved at 03:38:38, on 28/12/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lycos.co.uk/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: (no name) - {7A5565EF-A594-46E4-AF56-FE71AEAFD7D5} - C:\WINDOWS\System32\vtuvwtu.dll (file missing)
O2 - BHO: (no name) - {B0EEDC94-E177-43D2-B600-84E7AC69969B} - C:\WINDOWS\System32\efcbxxy.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O16 - DPF: {1A26F07F-0D60-4835-91CF-1E1766A0EC56} - http://scanner2.malware-scan.com/setup/webinst.cab
O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f007.mail.lycos.co.uk/app/uploader/FileUploader.cab
O20 - Winlogon Notify: efcbxxy - efcbxxy.dll (file missing)
O20 - Winlogon Notify: vtuvwtu - vtuvwtu.dll (file missing)
O20 - Winlogon Notify: xxywvus - xxywvus.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Security Restore Services - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)


How pc behaves

Computer takes ages to boot up and is just not its fast self.

rundll files missing on boot up

still some pop ups for malware software

internet explorer icon appears on screen even though keep deleting it.
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\SYSTEM32\eraseme_52156.exe
C:\WINDOWS\SYSTEM32\eraseme_42882.exe
C:\WINDOWS\SYSTEM32\eraseme_45851.exe
C:\WINDOWS\SYSTEM\dc4all.exe
C:\WINDOWS\System32\vtuvwtu.dll

Folder::
C:\FOUND.024

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7A5565EF-A594-46E4-AF56-FE71AEAFD7D5}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B0EEDC94-E177-43D2-B600-84E7AC69969B}]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{A74F3FC3-CC9A-4D4C-AFB5-B56F0CAA445D}"=-
"{B0EEDC94-E177-43D2-B600-84E7AC69969B}"=-
"{7A5565EF-A594-46E4-AF56-FE71AEAFD7D5}"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcbxxy]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtuvwtu]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxywvus]


Save this as CFScript.txt


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.
As requested my friend





ComboFix 07-12-21.4 - h1gg1 2007-12-28 22:33:46.10 - FAT32x86

Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\h1gg1\Desktop\CFscript.txt

FILE
C:\WINDOWS\SYSTEM\dc4all.exe
C:\WINDOWS\SYSTEM32\eraseme_42882.exe
C:\WINDOWS\SYSTEM32\eraseme_45851.exe
C:\WINDOWS\SYSTEM32\eraseme_52156.exe
C:\WINDOWS\System32\vtuvwtu.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\FOUND.024
C:\FOUND.024\FILE0000.CHK
C:\FOUND.024\FILE0001.CHK
C:\FOUND.024\FILE0002.CHK
C:\FOUND.024\FILE0003.CHK
C:\FOUND.024\FILE0004.CHK
C:\FOUND.024\FILE0005.CHK
C:\FOUND.024\FILE0006.CHK
C:\WINDOWS\SYSTEM\dc4all.exe
C:\WINDOWS\SYSTEM32\eraseme_42882.exe
C:\WINDOWS\SYSTEM32\eraseme_45851.exe
C:\WINDOWS\SYSTEM32\eraseme_52156.exe

.
((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-28 )))))))))))))))))))))))))))))))
.

2007-12-28 21:13 . 2007-12-28 21:14 30,720 –a—— C:\WINDOWS\SYSTEM32\eraseme_42853.exe
2007-12-28 18:42 . 2007-12-28 21:04 57,856 –a—— C:\WINDOWS\SYSTEM\nadlocop.exe
2007-12-28 18:42 . 2007-12-28 21:04 48,640 –a—— C:\WINDOWS\SYSTEM\del.exe
2007-12-28 18:15 . 2007-12-28 18:15 30,720 –a—— C:\WINDOWS\SYSTEM32\setup_44362.exe
2007-12-28 18:08 . 2007-12-28 22:21 4,484 –a—— C:\tcp.exe
2007-12-28 18:07 . 2007-12-28 21:04 65,024 –a—— C:\WINDOWS\SYSTEM\lc.exe
2007-12-28 18:07 . 2007-12-28 21:04 64,512 –a—— C:\WINDOWS\SYSTEM\zm.exe
2007-12-28 18:07 . 2007-12-28 21:04 60,416 –a—— C:\WINDOWS\SYSTEM\locop.exe
2007-12-28 18:07 . 2007-12-28 21:04 7,604 –a—— C:\WINDOWS\SYSTEM\delnew.exe
2007-12-28 18:07 . 2007-12-28 21:04 5,632 –a—— C:\WINDOWS\SYSTEM\helper.exe
2007-12-28 18:07 . 2007-12-28 21:04 4,612 –a—— C:\msu32.exe
2007-12-28 18:07 . 2007-12-28 21:04 4,484 –a—— C:\WINDOWS\SYSTEM\run.exe
2007-12-28 18:06 . 2007-12-28 18:06 30,720 -r-hs—- C:\WINDOWS\SYSTEM32\svshost.exe
2007-12-28 18:06 . 2007-12-28 21:13 69 –a—— C:\WINDOWS\SYSTEM32\i
2007-12-28 17:26 . 2007-12-28 17:26 0 -ra—— C:\WINDOWS\SYSTEM32\TFTP764
2007-12-28 17:24 . 2007-12-28 17:24 d–hs—- C:\FOUND.012
2007-12-23 17:47 . 2007-12-23 17:47 dr-h—– C:\$VAULT$.AVG
2007-12-23 17:46 . 2007-12-23 17:46 d——– C:\Documents and Settings\h1gg1\Application Data\AVG7
2007-12-23 17:40 . 2007-12-23 17:40 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-23 17:39 . 2007-12-23 17:39 d——– C:\Documents and Settings\All Users\Application Data\avg7
2007-12-20 22:46 . 2007-12-20 22:46 d——– C:\Program Files\CCleaner
2007-12-20 21:08 . 2007-12-24 14:36 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-20 21:08 . 2007-12-20 21:08 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-14 22:01 . 2007-12-14 22:01 d——– C:\WINDOWS\ERUNT
2007-12-06 19:36 . 2007-12-06 19:36 d——– C:\Documents and Settings\All Users\Application Data\Grisoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-06-01 08:08 113 —-a-w C:\Documents and Settings\h1gg1\Application Data\fusioncache.dat
2006-10-30 20:46 111,928 —-a-w C:\Documents and Settings\h1gg1\Application Data\GDIPFONTCACHEV1.DAT
2006-08-20 21:01 271 –sh–w C:\Program Files\DESKTOP.INI
2006-08-20 21:01 23,357 —h–w C:\Program Files\FOLDER.HTT
2006-07-13 07:06 12,801,467 ——w C:\WINDOWS\Internet Logs\ZLCLIENT_2nd_2006_07_12_22_21_58.dmp.zip
.

((((((((((((((((((((((((((((( snapshot@2007-12-24_ 9.16.56.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-03-13 10:57:12 163,328 —-a-w C:\WINDOWS\erdnt\subs\F3M\ERDNT.EXE
- 2007-12-23 23:47:36 16,384 —-a-w C:\WINDOWS\SYSTEM32\config\systemprofile\Cookies\index.dat
+ 2007-12-28 21:14:04 16,384 —-a-w C:\WINDOWS\SYSTEM32\config\systemprofile\Cookies\index.dat
- 2007-12-23 23:47:36 32,768 —-a-w C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-12-28 21:14:04 32,768 —-a-w C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-12-23 23:47:36 32,768 —-a-w C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-28 21:14:04 32,768 —-a-w C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-12-24 09:16:16 32,768 —-a-w C:\WINDOWS\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-28 22:25:44 32,768 —-a-w C:\WINDOWS\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2000-07-02 18:48]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-06-29 16:00]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-12-03 14:49]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" [2006-07-26 03:03]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-23 17:39]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-08-23 12:00]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-23 17:40]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2000-06-29 16:15:10]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"EditLevel"= 0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"EditLevel"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"EnsoniqMixer"=starter.exe
"LTWinModem1"=ltmsg.exe 9
"WorksFUD"=C:\Program Files\Microsoft Works\wkfud.exe
"POINTER"=point32.exe
"Zone Labs Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot



[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\^RNA]
rundll rnasetup.dll,installoptionalcomponent rna

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:WIN9X /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:WIN9X /user /install
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install
"C:\Program Files\Outlook Express\setup50.exe" /APP:WAB /CALLER:IE50 /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
C:\WINDOWS\SYSTEM32\UPDCRL.EXE -e -u C:\WINDOWS\SYSTEM\verisignpub1.crl
.
Contents of the 'Scheduled Tasks' folder
"2007-12-01 23:00:02 C:\WINDOWS\Tasks\Tune-up Application Start.job"
"2007-12-28 22:23:04 C:\WINDOWS\Tasks\PCHealth Scheduler for Data Collection.job"
- C:\WINDOWS\PCHEALTH\SUPPORT\PCHSCHD.EXE
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-28 22:35:08
Windows 5.1.2600 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-28 22:35:28
C:\ComboFix3.txt … 2007-12-28 12:43
C:\ComboFix2.txt … 2007-12-28 13:55






Logfile of HijackThis v1.99.1
Scan saved at 10:41:01, on 28/12/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\svshost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lycos.co.uk/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O16 - DPF: {1A26F07F-0D60-4835-91CF-1E1766A0EC56} - http://scanner2.malware-scan.com/setup/webinst.cab
O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f007.mail.lycos.co.uk/app/uploader/FileUploader.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Security Restore Services - Unknown owner - C:\WINDOWS\system32\svshost.exe
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\SYSTEM32\eraseme_42853.exe
C:\WINDOWS\SYSTEM\nadlocop.exe
C:\WINDOWS\SYSTEM\del.exe
C:\WINDOWS\SYSTEM32\setup_44362.exe
C:\tcp.exe
C:\WINDOWS\SYSTEM\lc.exe
C:\WINDOWS\SYSTEM\zm.exe
C:\WINDOWS\SYSTEM\locop.exe
C:\WINDOWS\SYSTEM\delnew.exe
C:\WINDOWS\SYSTEM\helper.exe
C:\msu32.exe
C:\WINDOWS\SYSTEM\run.exe
C:\WINDOWS\SYSTEM32\svshost.exe
C:\WINDOWS\SYSTEM32\i
C:\WINDOWS\SYSTEM32\TFTP764
C:\FOUND.012


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
ComboFix 07-12-21.4 - h1gg1 2007-12-29 10:13:13.11 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.0.1252.1.1033.18.253 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\h1gg1\Desktop\CFscript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-29 )))))))))))))))))))))))))))))))
.

2007-12-28 22:38 . 2007-12-29 10:03 7,408 –a—— C:\WINDOWS\SYSTEM\dc4all.exe
2007-12-28 21:13 . 2007-12-28 21:14 30,720 –a—— C:\WINDOWS\SYSTEM32\eraseme_42853.exe
2007-12-28 18:42 . 2007-12-29 10:03 57,856 –a—— C:\WINDOWS\SYSTEM\nadlocop.exe
2007-12-28 18:42 . 2007-12-29 10:03 48,640 –a—— C:\WINDOWS\SYSTEM\del.exe
2007-12-28 18:15 . 2007-12-28 18:15 30,720 –a—— C:\WINDOWS\SYSTEM32\setup_44362.exe
2007-12-28 18:08 . 2007-12-29 10:08 4,484 –a—— C:\tcp.exe
2007-12-28 18:07 . 2007-12-29 10:03 65,024 –a—— C:\WINDOWS\SYSTEM\lc.exe
2007-12-28 18:07 . 2007-12-29 10:03 64,512 –a—— C:\WINDOWS\SYSTEM\zm.exe
2007-12-28 18:07 . 2007-12-29 10:03 60,416 –a—— C:\WINDOWS\SYSTEM\locop.exe
2007-12-28 18:07 . 2007-12-29 10:03 7,604 –a—— C:\WINDOWS\SYSTEM\delnew.exe
2007-12-28 18:07 . 2007-12-29 10:03 5,632 –a—— C:\WINDOWS\SYSTEM\helper.exe
2007-12-28 18:07 . 2007-12-29 10:03 4,612 –a—— C:\msu32.exe
2007-12-28 18:07 . 2007-12-29 10:03 4,484 –a—— C:\WINDOWS\SYSTEM\run.exe
2007-12-28 18:06 . 2007-12-28 18:06 30,720 -r-hs—- C:\WINDOWS\SYSTEM32\svshost.exe
2007-12-28 18:06 . 2007-12-28 21:13 69 –a—— C:\WINDOWS\SYSTEM32\i
2007-12-28 17:26 . 2007-12-28 17:26 0 -ra—— C:\WINDOWS\SYSTEM32\TFTP764
2007-12-28 17:24 . 2007-12-28 17:24 d–hs—- C:\FOUND.012
2007-12-23 17:47 . 2007-12-23 17:47 dr-h—– C:\$VAULT$.AVG
2007-12-23 17:46 . 2007-12-23 17:46 d——– C:\Documents and Settings\h1gg1\Application Data\AVG7
2007-12-23 17:40 . 2007-12-23 17:40 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-23 17:39 . 2007-12-23 17:39 d——– C:\Documents and Settings\All Users\Application Data\avg7
2007-12-20 22:46 . 2007-12-20 22:46 d——– C:\Program Files\CCleaner
2007-12-20 21:08 . 2007-12-24 14:36 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-20 21:08 . 2007-12-20 21:08 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-14 22:01 . 2007-12-14 22:01 d——– C:\WINDOWS\ERUNT
2007-12-06 19:36 . 2007-12-06 19:36 d——– C:\Documents and Settings\All Users\Application Data\Grisoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-06-01 08:08 113 —-a-w C:\Documents and Settings\h1gg1\Application Data\fusioncache.dat
2006-10-30 20:46 111,928 —-a-w C:\Documents and Settings\h1gg1\Application Data\GDIPFONTCACHEV1.DAT
2006-08-20 21:01 271 –sh–w C:\Program Files\DESKTOP.INI
2006-08-20 21:01 23,357 —h–w C:\Program Files\FOLDER.HTT
2006-07-13 07:06 12,801,467 ——w C:\WINDOWS\Internet Logs\ZLCLIENT_2nd_2006_07_12_22_21_58.dmp.zip
.

((((((((((((((((((((((((((((( snapshot@2007-12-24_ 9.16.56.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-03-13 10:57:12 163,328 —-a-w C:\WINDOWS\erdnt\subs\F3M\ERDNT.EXE
- 2007-12-23 23:47:36 16,384 —-a-w C:\WINDOWS\SYSTEM32\config\systemprofile\Cookies\index.dat
+ 2007-12-28 21:14:04 16,384 —-a-w C:\WINDOWS\SYSTEM32\config\systemprofile\Cookies\index.dat
- 2007-12-23 23:47:36 32,768 —-a-w C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-12-28 21:14:04 32,768 —-a-w C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-12-24 09:16:16 32,768 —-a-w C:\WINDOWS\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-29 10:15:38 32,768 —-a-w C:\WINDOWS\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2000-07-02 18:48]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-06-29 16:00]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-12-03 14:49]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" [2006-07-26 03:03]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-23 17:39]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-08-23 12:00]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-23 17:40]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2000-06-29 16:15:10]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"EditLevel"= 0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"EditLevel"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"EnsoniqMixer"=starter.exe
"LTWinModem1"=ltmsg.exe 9
"WorksFUD"=C:\Program Files\Microsoft Works\wkfud.exe
"POINTER"=point32.exe
"Zone Labs Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

R2 Security Restore Services;Security Restore Services;"C:\WINDOWS\system32\svshost.exe" [2007-12-28 18:06]
R3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;C:\WINDOWS\System32\DRIVERS\ADM8511.SYS [2001-08-17 12:11]
S3 sea1bus;Sony Ericsson Device 0A1 driver (WDM);C:\WINDOWS\System32\DRIVERS\sea1bus.sys [2006-11-20 13:47]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\^RNA]
rundll rnasetup.dll,installoptionalcomponent rna

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:WIN9X /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:WIN9X /user /install
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install
"C:\Program Files\Outlook Express\setup50.exe" /APP:WAB /CALLER:IE50 /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
C:\WINDOWS\SYSTEM32\UPDCRL.EXE -e -u C:\WINDOWS\SYSTEM\verisignpub1.crl
.
Contents of the 'Scheduled Tasks' folder
"2007-12-01 23:00:02 C:\WINDOWS\Tasks\Tune-up Application Start.job"
"2007-12-29 10:17:30 C:\WINDOWS\Tasks\PCHealth Scheduler for Data Collection.job"
- C:\WINDOWS\PCHEALTH\SUPPORT\PCHSCHD.EXE
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-29 10:17:07
Windows 5.1.2600 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-29 10:18:09
C:\ComboFix3.txt … 2007-12-28 13:55
C:\ComboFix2.txt … 2007-12-28 22:35



Logfile of HijackThis v1.99.1
Scan saved at 03:31:34, on 29/12/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lycos.co.uk/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O16 - DPF: {1A26F07F-0D60-4835-91CF-1E1766A0EC56} - http://scanner2.malware-scan.com/setup/webinst.cab
O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f007.mail.lycos.co.uk/app/uploader/FileUploader.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Security Restore Services - Unknown owner - C:\WINDOWS\system32\svshost.exe



How pc behaves


some avg move to vault requests for svc host and other things.

What is it that your trying to remove as when Simon V was looking at part one of this post he stated that i had a trojan that could allow anyone to see my passwords, etc for personal infomation.
Is that still the case as i am scared to do any personal banking over the internet - would that still not be wise??
Let me know what you think.
That didn't work right.
Delete any CFScript.txt files on the desktop now.
Try it again

Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\SYSTEM32\eraseme_42853.exe
C:\WINDOWS\SYSTEM\nadlocop.exe
C:\WINDOWS\SYSTEM\del.exe
C:\WINDOWS\SYSTEM32\setup_44362.exe
C:\tcp.exe
C:\WINDOWS\SYSTEM\lc.exe
C:\WINDOWS\SYSTEM\zm.exe
C:\WINDOWS\SYSTEM\locop.exe
C:\WINDOWS\SYSTEM\delnew.exe
C:\WINDOWS\SYSTEM\helper.exe
C:\msu32.exe
C:\WINDOWS\SYSTEM\run.exe
C:\WINDOWS\SYSTEM32\svshost.exe
C:\WINDOWS\SYSTEM32\i
C:\WINDOWS\SYSTEM32\TFTP764
C:\FOUND.012


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
ComboFix 07-12-21.4 - h1gg1 2007-12-29 18:56:11.13 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.0.1252.1.1033.18.304 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\h1gg1\Desktop\CFscript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-29 )))))))))))))))))))))))))))))))
.

2007-12-29 17:38 . 2007-12-29 17:38 58,820 –a—— C:\WINDOWS\SYSTEM32\scrcs.exe
2007-12-28 22:38 . 2007-12-29 18:43 7,408 –a—— C:\WINDOWS\SYSTEM\dc4all.exe
2007-12-28 21:13 . 2007-12-28 21:14 30,720 –a—— C:\WINDOWS\SYSTEM32\eraseme_42853.exe
2007-12-28 18:15 . 2007-12-28 18:15 30,720 –a—— C:\WINDOWS\SYSTEM32\setup_44362.exe
2007-12-28 18:08 . 2007-12-29 10:08 4,484 –a—— C:\tcp.exe
2007-12-28 18:07 . 2007-12-29 18:43 60,416 –a—— C:\WINDOWS\SYSTEM\locop.exe
2007-12-28 18:07 . 2007-12-29 18:43 7,604 –a—— C:\WINDOWS\SYSTEM\delnew.exe
2007-12-28 18:07 . 2007-12-29 18:43 5,632 –a—— C:\WINDOWS\SYSTEM\helper.exe
2007-12-28 18:07 . 2007-12-29 18:42 4,612 –a—— C:\msu32.exe
2007-12-28 18:07 . 2007-12-29 18:43 4,484 –a—— C:\WINDOWS\SYSTEM\run.exe
2007-12-28 18:06 . 2007-12-29 17:12 30,720 -r-hs—- C:\WINDOWS\SYSTEM32\svshost.exe
2007-12-28 18:06 . 2007-12-29 17:12 68 –a—— C:\WINDOWS\SYSTEM32\i
2007-12-28 17:26 . 2007-12-28 17:26 0 -ra—— C:\WINDOWS\SYSTEM32\TFTP764
2007-12-28 17:24 . 2007-12-28 17:24 d–hs—- C:\FOUND.012
2007-12-23 17:47 . 2007-12-23 17:47 dr-h—– C:\$VAULT$.AVG
2007-12-23 17:46 . 2007-12-23 17:46 d——– C:\Documents and Settings\h1gg1\Application Data\AVG7
2007-12-23 17:40 . 2007-12-23 17:40 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-23 17:39 . 2007-12-23 17:39 d——– C:\Documents and Settings\All Users\Application Data\avg7
2007-12-20 22:46 . 2007-12-20 22:46 d——– C:\Program Files\CCleaner
2007-12-20 21:08 . 2007-12-24 14:36 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-20 21:08 . 2007-12-20 21:08 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-14 22:01 . 2007-12-14 22:01 d——– C:\WINDOWS\ERUNT
2007-12-06 19:36 . 2007-12-06 19:36 d——– C:\Documents and Settings\All Users\Application Data\Grisoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-06-01 08:08 113 —-a-w C:\Documents and Settings\h1gg1\Application Data\fusioncache.dat
2006-10-30 20:46 111,928 —-a-w C:\Documents and Settings\h1gg1\Application Data\GDIPFONTCACHEV1.DAT
2006-08-20 21:01 271 –sh–w C:\Program Files\DESKTOP.INI
2006-08-20 21:01 23,357 —h–w C:\Program Files\FOLDER.HTT
2006-07-13 07:06 12,801,467 ——w C:\WINDOWS\Internet Logs\ZLCLIENT_2nd_2006_07_12_22_21_58.dmp.zip
.

((((((((((((((((((((((((((((( snapshot@2007-12-24_ 9.16.56.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-03-13 10:57:12 163,328 —-a-w C:\WINDOWS\erdnt\subs\F3M\ERDNT.EXE
- 2007-12-23 23:47:36 16,384 —-a-w C:\WINDOWS\SYSTEM32\config\systemprofile\Cookies\index.dat
+ 2007-12-29 17:12:52 16,384 —-a-w C:\WINDOWS\SYSTEM32\config\systemprofile\Cookies\index.dat
- 2007-12-23 23:47:36 32,768 —-a-w C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-12-29 17:12:52 32,768 —-a-w C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-12-23 23:47:36 32,768 —-a-w C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-29 17:12:52 32,768 —-a-w C:\WINDOWS\SYSTEM32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-12-24 09:16:16 32,768 —-a-w C:\WINDOWS\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-29 18:54:06 32,768 —-a-w C:\WINDOWS\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2000-07-02 18:48]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-06-29 16:00]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-12-03 14:49]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" [2006-07-26 03:03]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-23 17:39]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-08-23 12:00]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-23 17:40]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2000-06-29 16:15:10]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"EditLevel"= 0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"EditLevel"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"EnsoniqMixer"=starter.exe
"LTWinModem1"=ltmsg.exe 9
"WorksFUD"=C:\Program Files\Microsoft Works\wkfud.exe
"POINTER"=point32.exe
"Zone Labs Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

R2 g7m8v3;g7m8v3;"C:\WINDOWS\system32\svshost.exe" [2007-12-29 17:12]
R2 Security Restore Services;Security Restore Services;"C:\WINDOWS\system32\svshost.exe" [2007-12-29 17:12]
R3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;C:\WINDOWS\System32\DRIVERS\ADM8511.SYS [2001-08-17 12:11]
S3 sea1bus;Sony Ericsson Device 0A1 driver (WDM);C:\WINDOWS\System32\DRIVERS\sea1bus.sys [2006-11-20 13:47]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\^RNA]
rundll rnasetup.dll,installoptionalcomponent rna

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:WIN9X /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:WIN9X /user /install
"C:\Program Files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"C:\Program Files\Outlook Express\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install
"C:\Program Files\Outlook Express\setup50.exe" /APP:WAB /CALLER:IE50 /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
C:\WINDOWS\SYSTEM32\UPDCRL.EXE -e -u C:\WINDOWS\SYSTEM\verisignpub1.crl
.
Contents of the 'Scheduled Tasks' folder
"2007-12-01 23:00:02 C:\WINDOWS\Tasks\Tune-up Application Start.job"
"2007-12-29 18:44:24 C:\WINDOWS\Tasks\PCHealth Scheduler for Data Collection.job"
- C:\WINDOWS\PCHEALTH\SUPPORT\PCHSCHD.EXE
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-29 18:58:46
Windows 5.1.2600 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-29 18:59:19
C:\ComboFix3.txt … 2007-12-29 10:18
C:\ComboFix2.txt … 2007-12-29 17:54










Logfile of HijackThis v1.99.1
Scan saved at 07:11:01, on 29/12/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\svshost.exe
C:\WINDOWS\system32\svshost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lycos.co.uk/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O16 - DPF: {1A26F07F-0D60-4835-91CF-1E1766A0EC56} - http://scanner2.malware-scan.com/setup/webinst.cab
O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f007.mail.lycos.co.uk/app/uploader/FileUploader.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: g7m8v3 - Unknown owner - C:\WINDOWS\system32\svshost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Security Restore Services - Unknown owner - C:\WINDOWS\system32\svshost.exe


Pc seems ok but dont know if there are trojan lurking
  • Click on your START button and choose Run. Then copy/paste the entire content of the following quotebox (Including the "" marks and the Symbols) into the run box.

    "%userprofile%\desktop\ComboFix.exe" /KillAll


  • Click OK and this will start ComboFix in a special way.
  • When finished, it will produce a log. Please save that log to a Notepad File to post in your next reply along with a fresh HJT log.

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

* Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI