This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Dropper.Agent.GIT Warnings, now errors on startup - HJ

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

While browsing the internet this afternoon, I started getting bombarded by AVG Resident Shield warnings about 'Trojan Horse Dropper.Agent.GIT' in various locations on C:. I ran an Ad-Aware Scan that came up with some cookies (removed) and a Spybot S&D that Came up with several items that were cleaned. One of which (unfortunately I cant remember what it was) had a description that stated that my machine needed to be disconnected from the internet and rebooted after removal of this particular piece of malicious software.

Once rebooted I received an error about windows\system32\vtutq.exe not being found and a seprate error popup about permissions related to the same file.

Also AVG is no longer in the system tray. If I look at processes running in the task manager I do see some AVG Processes running but it does not show up in the system tray any longer and I am unable to launch the control center.

I am able to view the AVG event history log and I continue to receive warnings about dropper.agent.GIT although these warnings are no longer spawning a popup.

Thanks in advance for any help!

Matt

HJT Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:35:04 AM, on 1/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.doginhispen.com
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://bin.mcafee.com/molbin/shared/mcinsc…84/mcinsctl.cab
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - https://10.0.0.2/Remote/msrdp.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.com/molbin/shared/mcgdmg…,21/mcgdmgr.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

–
End of file - 4385 bytes
Hi mdr and welcome to the forums.

My name is Dave. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can sometimes take a while to research so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

I believe that while HJT is not showing too much you are quite infected, with both Vundo and AWF I suspect.

Please download ComboFix by sUBs from HERE or HERE
  • You must download it to and run it from your Desktop
  • Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log
  • Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hi Dave,

To disable AVG I had to repair the application prior to running combofix. I was able to successfully repair the program and run ComboFix. Here are the logs (HJT to follow):

ComboFix 08-01-04.1 - Matt 2008-01-05 15:59:18.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.665 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\SYSTEM32\qtutv.ini
C:\WINDOWS\SYSTEM32\qtutv.ini2
C:\WINDOWS\system32\z1

.
((((((((((((((((((((((((( Files Created from 2007-12-06 to 2008-01-06 )))))))))))))))))))))))))))))))
.

2008-01-05 15:58 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-05 12:34 . 2007-10-10 15:55 6,065,664 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
2008-01-05 12:34 . 2007-06-30 19:31 2,455,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dat
2008-01-05 12:34 . 2007-06-30 19:36 991,232 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll.mui
2008-01-05 12:34 . 2007-10-10 15:55 459,264 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll
2008-01-05 12:34 . 2007-10-10 15:55 383,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll
2008-01-05 12:34 . 2007-10-10 15:55 267,776 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll
2008-01-05 12:34 . 2007-10-10 15:55 63,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\icardie.dll
2008-01-05 12:34 . 2007-10-10 15:55 52,224 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll
2008-01-05 12:34 . 2007-10-10 02:59 13,824 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
2008-01-05 12:26 . 2007-08-13 18:54 33,792 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\custsat.dll
2008-01-05 09:27 . 2008-01-05 13:54 d——– C:\Documents and Settings\Administrator\Application Data\AVG7
2008-01-05 09:24 . 2004-09-29 18:58 d——– C:\Documents and Settings\Administrator\Application Data\Sonic
2008-01-05 09:24 . 2004-09-29 18:59 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2008-01-05 09:24 . 2004-09-29 19:03 d–h—– C:\Documents and Settings\Administrator\Application Data\Gtek
2007-12-31 08:23 . 2007-12-31 10:11 d——– C:\WINDOWS\SYSTEM32\pp1
2007-12-31 08:23 . 2007-12-31 10:11 d——– C:\WINDOWS\SYSTEM32\mr9
2007-12-31 08:23 . 2007-12-31 10:10 d——– C:\WINDOWS\SYSTEM32\cc9
2007-12-31 08:23 . 2008-01-04 13:21 d——– C:\WINDOWS\SYSTEM32\ardCo01
2007-12-31 08:23 . 2007-12-31 10:10 d——– C:\WINDOWS\SYSTEM32\aj2
2007-12-31 08:23 . 2007-12-31 08:23 d——– C:\Temp\cEeer12

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-05 23:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2008-01-05 17:26 ——— d—–w C:\Program Files\QuickTime
2008-01-05 17:26 ——— d—–w C:\Program Files\Dell Support
2008-01-05 17:07 ——— d—–w C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-05 03:38 ——— d—–w C:\Documents and Settings\Justine\Application Data\AVG7
2008-01-05 02:06 ——— d—–w C:\Program Files\iTunes
2008-01-04 23:00 ——— d—–w C:\Program Files\Mozilla Thunderbird
2007-12-30 23:57 ——— d—–w C:\Documents and Settings\Matt\Application Data\AVG7
2007-12-15 19:13 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-21 01:02 ——— d—–w C:\Program Files\iPod
2007-11-16 01:22 ——— d—–w C:\Documents and Settings\Matt\Application Data\JungleDisk
2007-11-16 01:14 ——— d—–w C:\Program Files\JungleDisk
2007-11-15 05:59 102,664 —-a-w C:\WINDOWS\system32\drivers\tmcomm.sys
2007-11-15 04:52 ——— d—–w C:\Program Files\Lavasoft
2007-11-15 04:52 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-15 04:50 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-15 04:38 ——— d—–w C:\Program Files\Trend Micro
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2005-05-23 18:47 848 –sha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—-a-w 185,896 2006-11-07 03:54:07 C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe

—-a-w 110,592 2003-08-19 06:01:00 C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe

—-a-w 421,888 2007-09-20 17:29:32 C:\Program Files\Grisoft\AVG7\bak\avgcc.exe
—-a-w 579,072 2008-01-05 23:48:43 C:\Program Files\Grisoft\AVG7\avgcc.exe

—-a-w 221,184 2003-09-04 01:12:44 C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe

—-a-w 267,064 2007-09-26 22:42:04 C:\Program Files\iTunes\bak\iTunesHelper.exe

—-a-w 32,881 2003-11-19 22:48:14 C:\Program Files\Java\j2re1.4.2_03\bin\bak\jusched.exe

—-a-w 286,720 2007-06-29 14:24:52 C:\Program Files\QuickTime\bak\qttask.exe

—-a-w 94,208 2003-10-10 19:23:48 C:\WINDOWS\bak\MXOALDR.EXE

—-a-w 77,824 2005-09-20 17:32:24 C:\WINDOWS\SYSTEM32\bak\hkcmd.exe

—-a-w 114,688 2005-09-20 17:36:20 C:\WINDOWS\SYSTEM32\bak\igfxpers.exe

—-a-w 94,208 2005-09-20 17:35:40 C:\WINDOWS\SYSTEM32\bak\igfxtray.exe

—-a-w 122,933 2004-03-15 06:04:00 C:\WINDOWS\SYSTEM32\dla\bak\tfswctrl.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A66976ED-0EED-48CD-B946-BB9A10758063}]
C:\WINDOWS\system32\vtutq.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E1759A31-E627-4758-9562-6899DF36C9C2}]
C:\WINDOWS\system32\urqoomj.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-05 15:48 579072]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-24 09:27 219136]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-01-12 16:09:28]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 12:05:56]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{E1759A31-E627-4758-9562-6899DF36C9C2}"= C:\WINDOWS\system32\urqoomj.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2007-02-22 16:17 9216 C:\WINDOWS\SYSTEM32\avgwlntf.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqoomj]
urqoomj.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
2003-12-22 08:38 241664 –a—— C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-02-16 22:11 49152 –a—— C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2004-04-11 17:15 290816 ——— C:\Program Files\Dell\Media Experience\PCMService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot

S3 StMp3Rec;Player Recovery Device Control Driver;C:\WINDOWS\system32\Drivers\StMp3Rec.sys [2004-08-02 14:02]
S3 WUSB54GPV4SRV;Linksys Home Wireless-G USB Adaptor Driver;C:\WINDOWS\system32\DRIVERS\rt2500usb.sys [2005-10-17 18:50]

.
Contents of the 'Scheduled Tasks' folder
"2008-01-02 00:07:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2004-10-07 01:07:52 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
- C:\WINDOWS\System32\OOBE\OOBEBALN.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-05 16:06:12
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-05 16:11:23 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-06 00:11:20
.
2008-01-05 20:36:04 — E O F —
Fresh HJT Log, after running ComboFix for the first time:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:17:15 PM, on 1/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {A66976ED-0EED-48CD-B946-BB9A10758063} - C:\WINDOWS\system32\vtutq.dll (file missing)
O2 - BHO: (no name) - {E1759A31-E627-4758-9562-6899DF36C9C2} - C:\WINDOWS\system32\urqoomj.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.doginhispen.com
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://bin.mcafee.com/molbin/shared/mcinsc…84/mcinsctl.cab
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - https://10.0.0.2/Remote/msrdp.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.com/molbin/shared/mcgdmg…,21/mcgdmgr.cab
O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
O20 - Winlogon Notify: urqoomj - urqoomj.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

–
End of file - 5818 bytes
The AWF infection did get your AVG, and some other items. We'll start to deal with that after running this fix and hopefully getting rid of Vundo trojan.
AWF replaces legitimate .exe files with infected files and puts the legit files in bak folders.

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\system32\vtutq.dll
C:\WINDOWS\system32\urqoomj.dll

Folder::
C:\WINDOWS\SYSTEM32\pp1
C:\WINDOWS\SYSTEM32\mr9
C:\WINDOWS\SYSTEM32\cc9
C:\WINDOWS\SYSTEM32\ardCo01
C:\WINDOWS\SYSTEM32\aj2
C:\Temp

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A66976ED-0EED-48CD-B946-BB9A10758063}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E1759A31-E627-4758-9562-6899DF36C9C2}]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{E1759A31-E627-4758-9562-6899DF36C9C2}"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqoomj]


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

————————————————–

Download FindAWF:

Save the file to the Desktop
Double-click the FindAWF icon.

If a Security Alert shows, allow the program to run.
As instructed, press any key to continue.
Use the following option: Press 1 then Enter to scan for bak folders
The scan may take a while, please be patient.

When done, a text file, Find AWF report is produced that we need to look at.
Please post it in your reply.
Hi Dave,

I successfully ran the ComboFix script, although when it was creating the log, I received this error in a popup:

Windows - No Disk
Exception Processing Message C0000013 Parameters 75b6bf9c 4 75b6bf9c 75b6bf9c

The options were Continue, Try Again, or Cancel. I clicked cancel, the popup went away and ComboFix finished running. Here is the log (HJT Log to follow):

ComboFix 08-01-04.1 - Matt 2008-01-05 17:43:44.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.658 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Matt\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\urqoomj.dll
C:\WINDOWS\system32\vtutq.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Temp
C:\Temp\01 Ch-Check It Out.mp3
C:\Temp\02 Killing Spree.mp3
C:\Temp\02 Right Right Now Now.mp3
C:\Temp\02 Track 02.mp3
C:\Temp\02 Track 2.mp3
C:\Temp\03 Breath (feat. Nelly Furtado).mp3
C:\Temp\03 DRY AND REAVY VOCAL.mp3
C:\Temp\03 Full Contact.mp3
C:\Temp\03 Track 03.mp3
C:\Temp\03 Track 3.mp3
C:\Temp\04 Take It Back.mp3
C:\Temp\04 Track 04.mp3
C:\Temp\04 Track 4.mp3
C:\Temp\05 get by (rmx).mp3
C:\Temp\05 Track 05.mp3
C:\Temp\05 Track 5.mp3
C:\Temp\06 Bad Dreams.mp3
C:\Temp\06 Track 06.mp3
C:\Temp\06 Triple Trouble.mp3
C:\Temp\07 Camouflage.mp3
C:\Temp\07 Hey HONK You.mp3
C:\Temp\07 Track 07.mp3
C:\Temp\08 Oh Word_.mp3
C:\Temp\08 Track 08.mp3
C:\Temp\08 Track 8.mp3
C:\Temp\09 Deep End.mp3
C:\Temp\09 That's It That's All.mp3
C:\Temp\09 Track 09.mp3
C:\Temp\09 Track 9.mp3
C:\Temp\10 All Lifestyles.mp3
C:\Temp\10 Anthrax Island.mp3
C:\Temp\10 Deep End.mp3
C:\Temp\10 hey ya.mp3
C:\Temp\10 Track 10.mp3
C:\Temp\11 Snake Bite.mp3
C:\Temp\11 Track 11.mp3
C:\Temp\12 Total Package.mp3
C:\Temp\12 Track 12.mp3
C:\Temp\13 Track 13.mp3
C:\Temp\14 The Brouhaha.mp3
C:\Temp\14 Track 14.mp3
C:\Temp\15 Burns And Scars.mp3
C:\Temp\16 Dark Riders.mp3
C:\Temp\16 Track 16.mp3
C:\Temp\17 Fuel Injected.mp3
C:\Temp\18 High Road.mp3
C:\Temp\18 Track 18.mp3
C:\Temp\19 Bring It Home.mp3
C:\Temp\AOInstall\AO_Beginners_Guide.txt
C:\Temp\AOInstall\autorun.inf
C:\Temp\AOInstall\CopyFiles
C:\Temp\AOInstall\data1.cab
C:\Temp\AOInstall\data1.hdr
C:\Temp\AOInstall\data10.cab
C:\Temp\AOInstall\data11.cab
C:\Temp\AOInstall\data12.cab
C:\Temp\AOInstall\data13.cab
C:\Temp\AOInstall\data14.cab
C:\Temp\AOInstall\data15.cab
C:\Temp\AOInstall\data16.cab
C:\Temp\AOInstall\data17.cab
C:\Temp\AOInstall\data18.cab
C:\Temp\AOInstall\data19.cab
C:\Temp\AOInstall\data2.cab
C:\Temp\AOInstall\data20.cab
C:\Temp\AOInstall\data21.cab
C:\Temp\AOInstall\data22.cab
C:\Temp\AOInstall\data23.cab
C:\Temp\AOInstall\data24.cab
C:\Temp\AOInstall\data25.cab
C:\Temp\AOInstall\data26.cab
C:\Temp\AOInstall\data27.cab
C:\Temp\AOInstall\data28.cab
C:\Temp\AOInstall\data29.cab
C:\Temp\AOInstall\data3.cab
C:\Temp\AOInstall\data30.cab
C:\Temp\AOInstall\data31.cab
C:\Temp\AOInstall\data32.cab
C:\Temp\AOInstall\data33.cab
C:\Temp\AOInstall\data34.cab
C:\Temp\AOInstall\data35.cab
C:\Temp\AOInstall\data36.cab
C:\Temp\AOInstall\data37.cab
C:\Temp\AOInstall\data38.cab
C:\Temp\AOInstall\data39.cab
C:\Temp\AOInstall\data4.cab
C:\Temp\AOInstall\data40.cab
C:\Temp\AOInstall\data41.cab
C:\Temp\AOInstall\data42.cab
C:\Temp\AOInstall\data43.cab
C:\Temp\AOInstall\data44.cab
C:\Temp\AOInstall\data45.cab
C:\Temp\AOInstall\data46.cab
C:\Temp\AOInstall\data47.cab
C:\Temp\AOInstall\data48.cab
C:\Temp\AOInstall\data49.cab
C:\Temp\AOInstall\data5.cab
C:\Temp\AOInstall\data50.cab
C:\Temp\AOInstall\data51.cab
C:\Temp\AOInstall\data52.cab
C:\Temp\AOInstall\data53.cab
C:\Temp\AOInstall\data54.cab
C:\Temp\AOInstall\data55.cab
C:\Temp\AOInstall\data56.cab
C:\Temp\AOInstall\data57.cab
C:\Temp\AOInstall\data58.cab
C:\Temp\AOInstall\data59.cab
C:\Temp\AOInstall\data6.cab
C:\Temp\AOInstall\data60.cab
C:\Temp\AOInstall\data61.cab
C:\Temp\AOInstall\data62.cab
C:\Temp\AOInstall\data63.cab
C:\Temp\AOInstall\data64.cab
C:\Temp\AOInstall\data65.cab
C:\Temp\AOInstall\data7.cab
C:\Temp\AOInstall\data8.cab
C:\Temp\AOInstall\data9.cab
C:\Temp\AOInstall\ikernel.ex_
C:\Temp\AOInstall\Install.exe
C:\Temp\AOInstall\layout.bin
C:\Temp\AOInstall\readme.txt
C:\Temp\AOInstall\Setup.ex_
C:\Temp\AOInstall\Setup.ini
C:\Temp\AOInstall\setup.inx
C:\Temp\Bhangra.mp3
C:\Temp\cEeer12\skAt.log
C:\Temp\I Get High.mp3
C:\Temp\Left Field.mp3
C:\Temp\pnet\http_cache\_0000_1
C:\Temp\pnet\http_cache\_0000_2
C:\Temp\pnet\http_cache\CacheStats.pkl
C:\Temp\pnet\http_cache\headers\_0000_1
C:\Temp\pnet\http_cache\headers\_0000_2
C:\Temp\pnet\http_cache\headers\CacheStats.pkl
C:\Temp\Roots Manuva- Motion 5000 (Groove Armada Remix).mp3
C:\Temp\WZ1
C:\WINDOWS\SYSTEM32\aj2
C:\WINDOWS\SYSTEM32\ardCo01
C:\WINDOWS\SYSTEM32\cc9
C:\WINDOWS\SYSTEM32\mr9
C:\WINDOWS\SYSTEM32\pp1

.
((((((((((((((((((((((((( Files Created from 2007-12-06 to 2008-01-06 )))))))))))))))))))))))))))))))
.

2008-01-05 15:58 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-05 12:34 . 2007-10-10 15:55 6,065,664 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
2008-01-05 12:34 . 2007-06-30 19:31 2,455,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dat
2008-01-05 12:34 . 2007-06-30 19:36 991,232 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll.mui
2008-01-05 12:34 . 2007-10-10 15:55 459,264 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll
2008-01-05 12:34 . 2007-10-10 15:55 383,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll
2008-01-05 12:34 . 2007-10-10 15:55 267,776 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll
2008-01-05 12:34 . 2007-10-10 15:55 63,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\icardie.dll
2008-01-05 12:34 . 2007-10-10 15:55 52,224 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll
2008-01-05 12:34 . 2007-10-10 02:59 13,824 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
2008-01-05 12:26 . 2007-08-13 18:54 33,792 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\custsat.dll
2008-01-05 09:27 . 2008-01-05 13:54 d——– C:\Documents and Settings\Administrator\Application Data\AVG7
2008-01-05 09:24 . 2004-09-29 18:58 d——– C:\Documents and Settings\Administrator\Application Data\Sonic
2008-01-05 09:24 . 2004-09-29 18:59 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2008-01-05 09:24 . 2004-09-29 19:03 d–h—– C:\Documents and Settings\Administrator\Application Data\Gtek

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-06 00:25 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-01-05 23:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2008-01-05 17:26 ——— d—–w C:\Program Files\QuickTime
2008-01-05 17:26 ——— d—–w C:\Program Files\Dell Support
2008-01-05 17:07 ——— d—–w C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-05 03:38 ——— d—–w C:\Documents and Settings\Justine\Application Data\AVG7
2008-01-05 02:06 ——— d—–w C:\Program Files\iTunes
2007-12-30 23:57 ——— d—–w C:\Documents and Settings\Matt\Application Data\AVG7
2007-12-15 19:13 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-21 01:02 ——— d—–w C:\Program Files\iPod
2007-11-16 01:22 ——— d—–w C:\Documents and Settings\Matt\Application Data\JungleDisk
2007-11-16 01:14 ——— d—–w C:\Program Files\JungleDisk
2007-11-15 05:59 102,664 —-a-w C:\WINDOWS\system32\drivers\tmcomm.sys
2007-11-15 04:52 ——— d—–w C:\Program Files\Lavasoft
2007-11-15 04:52 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-15 04:50 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-15 04:38 ——— d—–w C:\Program Files\Trend Micro
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-31 13:12 3,590,656 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\SYSTEM32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\quartz.dll
2007-10-28 01:40 222,720 —-a-w C:\WINDOWS\SYSTEM32\wmasf.dll
2007-10-28 01:40 222,720 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
2007-10-11 06:13 474,112 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shlwapi.dll
2007-10-11 06:13 151,040 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\cdfview.dll
2007-10-11 06:13 1,494,528 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shdocvw.dll
2007-10-11 06:13 1,054,208 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\danim.dll
2007-10-11 06:13 1,023,488 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\browseui.dll
2007-10-10 23:56 824,832 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\wininet.dll
2007-10-10 23:56 232,960 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\webcheck.dll
2007-10-10 23:56 1,159,680 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\urlmon.dll
2007-10-10 23:55 671,232 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\mstime.dll
2007-10-10 23:55 478,208 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmled.dll
2007-10-10 23:55 44,544 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\iernonce.dll
2007-10-10 23:55 384,512 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\iedkcs32.dll
2007-10-10 23:55 27,648 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\jsproxy.dll
2007-10-10 23:55 230,400 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieaksie.dll
2007-10-10 23:55 214,528 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtrans.dll
2007-10-10 23:55 193,024 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\msrating.dll
2007-10-10 23:55 153,088 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakeng.dll
2007-10-10 23:55 132,608 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\extmgr.dll
2007-10-10 23:55 124,928 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\advpack.dll
2007-10-10 23:55 105,984 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\url.dll
2007-10-10 23:55 102,400 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\occache.dll
2007-10-10 10:59 70,656 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe
2007-10-10 10:59 625,152 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
2007-10-10 05:46 161,792 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakui.dll
2005-05-23 18:47 848 –sha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—-a-w 185,896 2006-11-07 03:54:07 C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe

—-a-w 110,592 2003-08-19 06:01:00 C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe

—-a-w 421,888 2007-09-20 17:29:32 C:\Program Files\Grisoft\AVG7\bak\avgcc.exe
—-a-w 579,072 2008-01-05 23:48:43 C:\Program Files\Grisoft\AVG7\avgcc.exe

—-a-w 221,184 2003-09-04 01:12:44 C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe

—-a-w 267,064 2007-09-26 22:42:04 C:\Program Files\iTunes\bak\iTunesHelper.exe

—-a-w 32,881 2003-11-19 22:48:14 C:\Program Files\Java\j2re1.4.2_03\bin\bak\jusched.exe

—-a-w 286,720 2007-06-29 14:24:52 C:\Program Files\QuickTime\bak\qttask.exe

—-a-w 94,208 2003-10-10 19:23:48 C:\WINDOWS\bak\MXOALDR.EXE

—-a-w 77,824 2005-09-20 17:32:24 C:\WINDOWS\SYSTEM32\bak\hkcmd.exe

—-a-w 114,688 2005-09-20 17:36:20 C:\WINDOWS\SYSTEM32\bak\igfxpers.exe

—-a-w 94,208 2005-09-20 17:35:40 C:\WINDOWS\SYSTEM32\bak\igfxtray.exe

—-a-w 122,933 2004-03-15 06:04:00 C:\WINDOWS\SYSTEM32\dla\bak\tfswctrl.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-05 15:48 579072]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-24 09:27 219136]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-01-12 16:09:28]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 12:05:56]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2007-02-22 16:17 9216 C:\WINDOWS\SYSTEM32\avgwlntf.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
2003-12-22 08:38 241664 –a—— C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-02-16 22:11 49152 –a—— C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2004-04-11 17:15 290816 ——— C:\Program Files\Dell\Media Experience\PCMService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot

S3 StMp3Rec;Player Recovery Device Control Driver;C:\WINDOWS\system32\Drivers\StMp3Rec.sys [2004-08-02 14:02]
S3 WUSB54GPV4SRV;Linksys Home Wireless-G USB Adaptor Driver;C:\WINDOWS\system32\DRIVERS\rt2500usb.sys [2005-10-17 18:50]

.
Contents of the 'Scheduled Tasks' folder
"2008-01-02 00:07:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2004-10-07 01:07:52 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
- C:\WINDOWS\System32\OOBE\OOBEBALN.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-05 17:45:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-05 17:50:27
ComboFix-quarantined-files.txt 2008-01-06 01:50:25
ComboFix2.txt 2008-01-06 00:11:23
.
2008-01-05 20:36:04 — E O F —
I forgot to mention above that as before, AVG was disabled while running this round of ComboFix. Here is the fresh HJT Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:57:52 PM, on 1/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.doginhispen.com
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://bin.mcafee.com/molbin/shared/mcinsc…84/mcinsctl.cab
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - https://10.0.0.2/Remote/msrdp.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.com/molbin/shared/mcgdmg…,21/mcgdmgr.cab
O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

–
End of file - 5463 bytes
It looks like the FindAWF.exe link in your previous post isnt working (can not find server at noahdfear.org). I was able to locate FindAWF.exe at this location: noahdfear.geekstogo.com/FindAWF.exe. Is it ok to run after downloading from this particular site? Thanks! Matt
Here is the AWF Log: Find AWF report by noahdfear ©2006 Version 1.40 The current date is: Sat 01/05/2008 The current time is: 18:24:22.76 bak folders found ~~~~~~~~~~~ Directory of C:\WINDOWS\BAK 10/10/2003 11:23 AM 94,208 MXOALDR.EXE 1 File(s) 94,208 bytes Directory of C:\PROGRA~1\ITUNES\BAK 09/26/2007 02:42 PM 267,064 iTunesHelper.exe 1 File(s) 267,064 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 06/29/2007 06:24 AM 286,720 qttask.exe 1 File(s) 286,720 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 09/20/2005 09:32 AM 77,824 hkcmd.exe 09/20/2005 09:36 AM 114,688 igfxpers.exe 09/20/2005 09:35 AM 94,208 igfxtray.exe 3 File(s) 286,720 bytes Directory of C:\PROGRA~1\GRISOFT\AVG7\BAK 09/20/2007 09:29 AM 421,888 avgcc.exe 1 File(s) 421,888 bytes Directory of C:\PROGRA~1\INTEL\MODEME~1\BAK 09/03/2003 05:12 PM 221,184 IntelMEM.exe 1 File(s) 221,184 bytes Directory of C:\WINDOWS\SYSTEM32\DLA\BAK 03/14/2004 10:04 PM 122,933 tfswctrl.exe 1 File(s) 122,933 bytes Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK 11/06/2006 07:54 PM 185,896 realsched.exe 1 File(s) 185,896 bytes Directory of C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\BAK 08/18/2003 10:01 PM 110,592 sgtray.exe 1 File(s) 110,592 bytes Directory of C:\PROGRA~1\JAVA\J2RE14~1.2_0\BIN\BAK 11/19/2003 02:48 PM 32,881 jusched.exe 1 File(s) 32,881 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 94208 Oct 10 2003 "C:\WINDOWS\bak\MXOALDR.EXE" 267064 Sep 26 2007 "C:\Program Files\iTunes\bak\iTunesHelper.exe" 102400 Nov 20 2007 "C:\WINDOWS\Installer\{4F5CE18C-D97D-48FF-A510-A0D90C918294}\iTunesIco.exe" 116008 Nov 20 2007 "C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.5.0.20\iTunesSetupAdmin.exe" 286720 Jun 29 2007 "C:\Program Files\QuickTime\bak\qttask.exe" 118784 Feb 10 2004 "C:\DRIVERS\VIDEO\HKCMD.EXE" 77824 Sep 20 2005 "C:\WINDOWS\SYSTEM32\bak\hkcmd.exe" 126976 Jan 23 2005 "C:\WINDOWS\SYSTEM32\ReinstallBackups\0000\DriverFiles\hkcmd.exe" 114688 Sep 20 2005 "C:\WINDOWS\SYSTEM32\bak\igfxpers.exe" 155648 Feb 10 2004 "C:\DRIVERS\VIDEO\IGFXTRAY.EXE" 94208 Sep 20 2005 "C:\WINDOWS\SYSTEM32\bak\igfxtray.exe" 155648 Jan 23 2005 "C:\WINDOWS\SYSTEM32\ReinstallBackups\0000\DriverFiles\igfxtray.exe" 579072 Jan 5 2008 "C:\Program Files\Grisoft\AVG7\avgcc.exe" 421888 Sep 20 2007 "C:\Program Files\Grisoft\AVG7\bak\avgcc.exe" 221184 Sep 3 2003 "C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe" 122933 Mar 14 2004 "C:\Program Files\Sonic\DLA\install\tfswctrl.exe" 122933 Mar 14 2004 "C:\WINDOWS\SYSTEM32\dla\bak\tfswctrl.exe" 185896 Nov 6 2006 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe" 110592 Aug 18 2003 "C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe" 32881 Nov 19 2003 "C:\Program Files\Java\j2re1.4.2_03\bin\bak\jusched.exe" end of report
Please double-click the FindAWF icon once again.

If a Security Alert shows, allow the program to run.
As instructed, press any key to continue.
Use the following option: Press 2 then Enter to restore files from bak folders

A text file opens called: files.txt
Copy and paste the following list of files from in the code box to be restored:
C:\WINDOWS\bak\MXOALDR.EXE"
"C:\Program Files\iTunes\bak\iTunesHelper.exe"
"C:\Program Files\QuickTime\bak\qttask.exe"
"C:\WINDOWS\SYSTEM32\bak\hkcmd.exe"
"C:\WINDOWS\SYSTEM32\bak\igfxpers.exe"
"C:\WINDOWS\SYSTEM32\bak\igfxtray.exe"
"C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe"
"C:\WINDOWS\SYSTEM32\dla\bak\tfswctrl.exe"
"C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
"C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe"
"C:\Program Files\Java\j2re1.4.2_03\bin\bak\jusched.exe"
Next, close and click Yes to save the changes.

Once files.txt is saved, FindAWF does the following:
-It attempts to terminate the process represented by each filename on the list, if running
-Deletes the rogue file from the parent folder, if present
-Copies the original file to the parent folder

When done with the above, it automatically runs a new scan and opens a new log.
Please provide the new FindAWF log in your reply.
I followed the instructions and it appeared as though AWF did it's thing- it did not, however, fire a new scan. Two MS-DOS Icons (Named Locate and something else I think) popped up on my desktop. I manually ran another scan (using option 1) and got the following log (after the scan ran, the MS-DOS icons disappeared): Find AWF report by noahdfear ©2006 Version 1.40 The current date is: Sat 01/05/2008 The current time is: 18:53:10.34 bak folders found ~~~~~~~~~~~ Directory of C:\WINDOWS\BAK 10/10/2003 11:23 AM 94,208 MXOALDR.EXE 1 File(s) 94,208 bytes Directory of C:\PROGRA~1\ITUNES\BAK 09/26/2007 02:42 PM 267,064 iTunesHelper.exe 1 File(s) 267,064 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 06/29/2007 06:24 AM 286,720 qttask.exe 1 File(s) 286,720 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 09/20/2005 09:32 AM 77,824 hkcmd.exe 09/20/2005 09:36 AM 114,688 igfxpers.exe 09/20/2005 09:35 AM 94,208 igfxtray.exe 3 File(s) 286,720 bytes Directory of C:\PROGRA~1\GRISOFT\AVG7\BAK 09/20/2007 09:29 AM 421,888 avgcc.exe 1 File(s) 421,888 bytes Directory of C:\PROGRA~1\INTEL\MODEME~1\BAK 09/03/2003 05:12 PM 221,184 IntelMEM.exe 1 File(s) 221,184 bytes Directory of C:\WINDOWS\SYSTEM32\DLA\BAK 03/14/2004 10:04 PM 122,933 tfswctrl.exe 1 File(s) 122,933 bytes Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK 11/06/2006 07:54 PM 185,896 realsched.exe 1 File(s) 185,896 bytes Directory of C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\BAK 08/18/2003 10:01 PM 110,592 sgtray.exe 1 File(s) 110,592 bytes Directory of C:\PROGRA~1\JAVA\J2RE14~1.2_0\BIN\BAK 11/19/2003 02:48 PM 32,881 jusched.exe 1 File(s) 32,881 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 94208 Oct 10 2003 "C:\WINDOWS\bak\MXOALDR.EXE" 267064 Sep 26 2007 "C:\Program Files\iTunes\bak\iTunesHelper.exe" 102400 Nov 20 2007 "C:\WINDOWS\Installer\{4F5CE18C-D97D-48FF-A510-A0D90C918294}\iTunesIco.exe" 116008 Nov 20 2007 "C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.5.0.20\iTunesSetupAdmin.exe" 286720 Jun 29 2007 "C:\Program Files\QuickTime\bak\qttask.exe" 118784 Feb 10 2004 "C:\DRIVERS\VIDEO\HKCMD.EXE" 77824 Sep 20 2005 "C:\WINDOWS\SYSTEM32\bak\hkcmd.exe" 126976 Jan 23 2005 "C:\WINDOWS\SYSTEM32\ReinstallBackups\0000\DriverFiles\hkcmd.exe" 114688 Sep 20 2005 "C:\WINDOWS\SYSTEM32\bak\igfxpers.exe" 155648 Feb 10 2004 "C:\DRIVERS\VIDEO\IGFXTRAY.EXE" 94208 Sep 20 2005 "C:\WINDOWS\SYSTEM32\bak\igfxtray.exe" 155648 Jan 23 2005 "C:\WINDOWS\SYSTEM32\ReinstallBackups\0000\DriverFiles\igfxtray.exe" 579072 Jan 5 2008 "C:\Program Files\Grisoft\AVG7\avgcc.exe" 421888 Sep 20 2007 "C:\Program Files\Grisoft\AVG7\bak\avgcc.exe" 221184 Sep 3 2003 "C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe" 122933 Mar 14 2004 "C:\Program Files\Sonic\DLA\install\tfswctrl.exe" 122933 Mar 14 2004 "C:\WINDOWS\SYSTEM32\dla\bak\tfswctrl.exe" 185896 Nov 6 2006 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe" 110592 Aug 18 2003 "C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe" 32881 Nov 19 2003 "C:\Program Files\Java\j2re1.4.2_03\bin\bak\jusched.exe" end of report
Hmm? Let's move ahead a bit. Wondering if Combofix did something. The tool is constantly updated and the developer may have automated the AWF fix. Kaspersky will show if still present, and others.

Using Internet Explorer, click on Kaspersky Online Scanner * Click 'Accept' in the window that pops up.
* You will be prompted to install an ActiveX component from Kaspersky, Click on the information bar and select Install ActiveX Control if so. This may happen more than once. That is OK. You also may get a warning from your Windows Firewall. You can tell it to unblock.
* The program will launch and then start to download the latest definition files.
* Once the scanner is installed and the definitions downloaded, click 'Next'.
* Now click on 'Scan Settings'
* In the scan settings make sure that the following are selected:
o Scan using the following Anti-Virus database: 'Extended' (If available, otherwise 'Standard')
o Scan Options: 'Scan Archives' and 'Scan Mail Bases'
* Click 'OK'
* Now under 'Select a target to scan' select 'My Computer'
* The scan will take a while, so be patient and let it run. Once the scan is complete, it will display whether your system has been infected.
* Now click on the 'Save Report As…' button:
* Make sure it says Save as a text file - change it if not
* Save the file to your desktop.
Please post the Kaspersky report and a new HijackThis log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI