This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojans, Popups

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
My PC had a trojans detected by avast, put in chest. Then l started receiving popup stating my computer is infected. recommend special spyware tools. This popup has a yellow triangle w/explanation point in it. Along with Internet speed Monitor.and QDRModule11 wanting access.
Ran avast, Adware, Spybot, removed threats. Yellow triange still in taskbar . Downloaded SuperAntispyware.Found Trojan.Vundo/varient,and Trojan.Winfixer, Trojan. unclassified/Fakealert. Internet Speed monitor disappeared.
Downloaded and ran VundoFix.(nothing found)
Now weird thing are happening Pc allows all cookies, my search page wants to change, and can no longer connect to outlook explorer. Yellow triange still in taskbar
Ran SmitfraudFix on 1/8 . Log is below after reading on the forum decided to run HJT and ask for help. Please


SmitFraudFix v2.274

Scan done at 21:11:43.40, Tue 01/08/2008
Run from C:\Documents and Settings\Owner\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» IEDFix

IEDFix.exe by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{247F9EAB-0971-4CFC-AB7B-CAF49B3E1E7D}: DhcpNameServer=10.0.0.3
HKLM\SYSTEM\CCS\Services\Tcpip\..\{AE96172A-A3B1-4562-ACC9-454AF8CF4445}: DhcpNameServer=10.0.0.3
HKLM\SYSTEM\CS1\Services\Tcpip\..\{247F9EAB-0971-4CFC-AB7B-CAF49B3E1E7D}: DhcpNameServer=10.0.0.3
HKLM\SYSTEM\CS1\Services\Tcpip\..\{AE96172A-A3B1-4562-ACC9-454AF8CF4445}: DhcpNameServer=10.0.0.3
HKLM\SYSTEM\CS2\Services\Tcpip\..\{247F9EAB-0971-4CFC-AB7B-CAF49B3E1E7D}: DhcpNameServer=10.0.0.3
HKLM\SYSTEM\CS2\Services\Tcpip\..\{AE96172A-A3B1-4562-ACC9-454AF8CF4445}: DhcpNameServer=10.0.0.3
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=10.0.0.3
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=10.0.0.3
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=10.0.0.3


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"DefaultDomainName"="GATEWAY_SYSTEM"
"System"=""
"AltDefaultDomainName"="GATEWAY_SYSTEM"


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End
VundoFix V6.7.7

Checking Java version…

Sun Java not detected
Scan started at 9:25:09 AM 1/11/2008

Listing files found while scanning….

No infected files were found.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:05:16 PM, on 1/11/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Documents and Settings\Owner\Application Data\jtnhrtydtphz.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://r.office.microsoft.com/r/rlidOfficeUpdate?clid=1033
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [SansaDispatch] C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe
O4 - HKLM\..\Run: [843c3fa7] rundll32.exe "C:\WINDOWS\System32\csmwqskl.dll",b
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Microsft Windows Adapter 5.1.3013] C:\Documents and Settings\Owner\Application Data\deox.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 4940 bytes
Hello and Welcome to the forum.

Any reason you haven't updated windows to SP2?

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.

Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here to your Desktop.

**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Thank you so much for your time.
I did as you said and here are the logs
Combofix and HJT

ComboFix 08-01-11.3 - Owner 2008-01-11 21:47:52.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.0.1252.1.1033.18.50 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\jlnmp.ini
C:\WINDOWS\system32\jlnmp.ini2
C:\WINDOWS\system32\lksqwmsc.ini

.
((((((((((((((((((((((((( Files Created from 2007-12-12 to 2008-01-12 )))))))))))))))))))))))))))))))
.

2008-01-11 21:45 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-11 13:03 . 2008-01-06 11:17 19,456 –a—— C:\Documents and Settings\Owner\Application Data\deox.exe
2008-01-11 11:48 . 2008-01-11 11:48 d——– C:\Program Files\Trend Micro
2008-01-11 09:25 . 2008-01-11 09:25 d——– C:\VundoFix Backups
2008-01-09 06:42 . 2008-01-06 11:17 19,456 –a—— C:\Documents and Settings\Owner\Application Data\jtnhrtydtphz.exe
2008-01-08 22:32 . 2008-01-08 22:32 d——– C:\Documents and Settings\Owner\Application Data\Grisoft
2008-01-08 22:32 . 2008-01-08 22:32 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-08 22:32 . 2007-05-30 06:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-08 21:23 . 2008-01-06 11:17 19,456 –a—— C:\Documents and Settings\Owner\Application Data\vuyvfzznaf.exe
2008-01-07 17:59 . 2008-01-06 11:17 19,456 –a—— C:\Documents and Settings\Owner\Application Data\hdrobeoros.exe
2008-01-06 17:12 . 2008-01-06 17:12 d——– C:\Program Files\Lavasoft
2008-01-06 17:12 . 2008-01-06 17:12 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-06 15:49 . 2008-01-06 11:17 19,456 –a—— C:\Documents and Settings\Owner\Application Data\brgks.exe
2008-01-06 11:17 . 2008-01-06 11:17 19,456 –a—— C:\Documents and Settings\Owner\Application Data\hzmycp.exe
2008-01-03 08:14 . 2008-01-03 08:14 552 –a—— C:\WINDOWS\system32\d3d8caps.dat
2008-01-01 17:02 . 2008-01-01 17:02 19,456 –a—— C:\Documents and Settings\Owner\Application Data\whxrvtyaz .exe
2008-01-01 16:57 . 2008-01-01 16:57 19,456 –a—— C:\Documents and Settings\Owner\Application Data\ezvffleczn .exe
2008-01-01 16:46 . 2008-01-08 21:11 2,580 –a—— C:\WINDOWS\system32\tmp.reg
2008-01-01 16:26 . 2008-01-01 16:26 19,456 –a—— C:\Documents and Settings\Owner\Application Data\jmiafczfvn .exe
2008-01-01 14:47 . 2008-01-01 14:47 19,456 –a—— C:\Documents and Settings\Owner\Application Data\fjidhoadt .exe
2008-01-01 14:18 . 2008-01-01 14:18 19,456 –a—— C:\Documents and Settings\Owner\Application Data\pdtubkw .exe
2008-01-01 13:05 . 2008-01-01 13:05 19,456 –a—— C:\Documents and Settings\Owner\Application Data\grshyk .exe
2008-01-01 12:57 . 2008-01-01 12:57 19,456 –a—— C:\Documents and Settings\Owner\Application Data\wxcaiykyc .exe
2008-01-01 11:24 . 2008-01-01 11:24 d–h—– C:\WINDOWS\PIF
2008-01-01 11:24 . 2008-01-01 11:24 2,855 –a—— C:\SMARTDRV.PIF
2007-12-31 23:09 . 2007-12-31 23:09 19,456 –a—— C:\Documents and Settings\Owner\Application Data\wmwpgqk .exe
2007-12-31 20:45 . 2007-12-31 20:45 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-31 20:44 . 2008-01-08 22:37 d——– C:\Program Files\SUPERAntiSpyware
2007-12-31 20:44 . 2007-12-31 20:44 d——– C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2007-12-31 20:42 . 2008-01-06 17:11 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-12-31 08:27 . 2007-12-31 08:26 19,456 –a—— C:\Documents and Settings\Owner\Application Data\wwer.exe
2007-12-31 07:40 . 2008-01-08 21:23 101,615 –a—— C:\WINDOWS\GWMDMMSG .exe
2007-12-30 23:06 . 2007-12-30 23:06 19,456 –a—— C:\Documents and Settings\Owner\Application Data\sngwvidjdikg.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-09 04:25 ——— d—–w C:\Program Files\QuickTime
2008-01-01 19:03 ——— d—–w C:\Program Files\SIFXINST
2007-12-14 15:41 1,931,480 —-a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2007-12-04 14:56 93,264 —-a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 —-a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 —-a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 —-a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 —-a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 —-a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 —-a-w C:\WINDOWS\system32\AvastSS.scr
2007-11-21 20:52 ——— d—–w C:\Program Files\Millennium Gamepak Gold
2007-11-21 20:47 286,720 —-a-w C:\WINDOWS\iun506.exe
2007-11-21 16:15 ——— d—–w C:\Documents and Settings\Owner\Application Data\QQ Games Plugin
2007-11-21 16:14 ——— d—–w C:\Program Files\AIM6
2007-11-21 16:13 ——— d—–w C:\Program Files\Tencent
2007-11-21 16:12 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-11-21 16:11 ——— d—–w C:\Program Files\Viewpoint
2007-11-21 16:11 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-21 16:10 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
.
—-a-w			19,456 2008-01-01 22:57:26  C:\Documents and Settings\Owner\Application Data\ezvffleczn .exe
—-a-w			19,456 2008-01-01 20:47:37  C:\Documents and Settings\Owner\Application Data\fjidhoadt .exe
—-a-w			19,456 2008-01-01 19:05:48  C:\Documents and Settings\Owner\Application Data\grshyk .exe
—-a-w			19,456 2008-01-01 22:26:12  C:\Documents and Settings\Owner\Application Data\jmiafczfvn .exe
—-a-w			19,456 2008-01-01 20:18:15  C:\Documents and Settings\Owner\Application Data\pdtubkw .exe
—-a-w			19,456 2008-01-01 23:02:26  C:\Documents and Settings\Owner\Application Data\whxrvtyaz .exe
—-a-w			19,456 2008-01-01 05:09:18  C:\Documents and Settings\Owner\Application Data\wmwpgqk .exe
—-a-w			19,456 2008-01-01 18:57:28  C:\Documents and Settings\Owner\Application Data\wxcaiykyc .exe
—-a-w			39,792 2008-01-09 03:23:19  C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
—-a-w			79,224 2008-01-06 17:17:01  C:\Program Files\Alwil Software\Avast4\ashDisp .exe
—-a-w			49,152 2008-01-09 03:23:17  C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
—-a-w		   241,664 2008-01-09 03:23:19  C:\Program Files\HP\hpcoretech\hpcmpmgr .exe
—-a-w		 1,077,277 2008-01-09 03:23:30  C:\Program Files\Messenger\msmsgs .exe
—-a-w		   155,648 2008-01-06 17:17:05  C:\Program Files\QuickTime\qttask		   .exe
—-a-w			55,368 2008-01-09 03:23:20  C:\Program Files\SanDisk\Sansa Updater\SansaDispatch .exe
—-a-w		 1,318,912 2008-01-09 03:23:32  C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware .exe
—-a-w		   919,016 2008-01-09 03:23:27  C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe
—-a-w		   101,615 2008-01-09 03:23:17  C:\WINDOWS\GWMDMMSG .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="" []
"Microsft Windows Adapter 5.1.3013"="C:\Documents and Settings\Owner\Application Data\deox.exe" [2008-01-06 11:17 19456]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" []
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 07:00 79224]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [2008-01-06 11:17 155648]
"SansaDispatch"="C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe" [ ]
"843c3fa7"="C:\WINDOWS\System32\csmwqskl.dll" [ ]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 03:25 6731312]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 21:31:38]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 22:06:36]
Install Pending Files.LNK - C:\Program Files\SIFXINST\SIFXINST.EXE [2007-08-25 14:45:27]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

R3 iadusb;Zoom USB Network Adapter;C:\WINDOWS\System32\DRIVERS\glauiad.sys [2004-07-02 14:20]
S3 iscFlash;iscFlash;C:\WINDOWS\SYSTEM32\DRIVERS\iscflash.sys []

*Newly Created Service* - PROCEXP90
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-11 21:53:24
Windows 5.1.2600 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-11 21:56:21
ComboFix-quarantined-files.txt 2008-01-12 03:56:14
.
2007-12-13 13:34:02 — E O F —



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:26:49 PM, on 1/11/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Documents and Settings\Owner\Application Data\jtnhrtydtphz.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://r.office.microsoft.com/r/rlidOfficeUpdate?clid=1033
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [SansaDispatch] C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe
O4 - HKLM\..\Run: [843c3fa7] rundll32.exe "C:\WINDOWS\System32\csmwqskl.dll",b
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Microsft Windows Adapter 5.1.3013] C:\Documents and Settings\Owner\Application Data\deox.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 4979 bytes
You have a few infection which infects legitimate files, it can be a bit of a pain


1. Download RenV.exe by sUBs to your desktop
2. Double click on it to run it
It will search your system drive looking for any modified .exe file and will produce a log for you.
3. Please copy and paste this report to your reply
this explain the missing shortcuts on the desktop. The yellow triangle is now gone.
Here is the RenV log.


Ran on Sat 01/12/2008 -  8:20:07.98

—-a-w			19,456 2008-01-01 22:57:26  C:\Documents and Settings\Owner\Application Data\ezvffleczn .exe
—-a-w			19,456 2008-01-01 20:47:37  C:\Documents and Settings\Owner\Application Data\fjidhoadt .exe
—-a-w			19,456 2008-01-01 19:05:48  C:\Documents and Settings\Owner\Application Data\grshyk .exe
—-a-w			19,456 2008-01-01 22:26:12  C:\Documents and Settings\Owner\Application Data\jmiafczfvn .exe
—-a-w			19,456 2008-01-01 20:18:15  C:\Documents and Settings\Owner\Application Data\pdtubkw .exe
—-a-w			19,456 2008-01-01 23:02:26  C:\Documents and Settings\Owner\Application Data\whxrvtyaz .exe
—-a-w			19,456 2008-01-01 05:09:18  C:\Documents and Settings\Owner\Application Data\wmwpgqk .exe
—-a-w			19,456 2008-01-01 18:57:28  C:\Documents and Settings\Owner\Application Data\wxcaiykyc .exe
—-a-w			39,792 2008-01-09 03:23:19  C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
—-a-w			79,224 2008-01-06 17:17:01  C:\Program Files\Alwil Software\Avast4\ashDisp .exe
—-a-w			49,152 2008-01-09 03:23:17  C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
—-a-w		   241,664 2008-01-09 03:23:19  C:\Program Files\HP\hpcoretech\hpcmpmgr .exe
—-a-w		 1,077,277 2008-01-09 03:23:30  C:\Program Files\Messenger\msmsgs .exe
—-a-w		   155,648 2008-01-06 17:17:05  C:\Program Files\QuickTime\qttask		   .exe
—-a-w			55,368 2008-01-09 03:23:20  C:\Program Files\SanDisk\Sansa Updater\SansaDispatch .exe
—-a-w		 1,318,912 2008-01-09 03:23:32  C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware .exe
—-a-w		   919,016 2008-01-09 03:23:27  C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe
—-a-w		   101,615 2008-01-09 03:23:17  C:\WINDOWS\GWMDMMSG .exe

 Entries:			   18  (18)
 Directories:			0  Files:			18
 Bytes:		  4,193,316  Blocks:		8,193
Now please run a new combofix scan :thumbup:

  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Thanks for taking time out of your Sat.
Here are the logs.


ComboFix 08-01-11.3 - Owner 2008-01-12 8:53:04.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.0.1252.1.1033.18.74 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-12-12 to 2008-01-12 )))))))))))))))))))))))))))))))
.

2008-01-12 08:13 . 2008-01-12 08:13 118 –a—— C:\WINDOWS\system32\MRT.INI
2008-01-11 21:45 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-11 11:48 . 2008-01-11 11:48 d——– C:\Program Files\Trend Micro
2008-01-11 09:25 . 2008-01-11 09:25 d——– C:\VundoFix Backups
2008-01-08 22:32 . 2008-01-08 22:32 d——– C:\Documents and Settings\Owner\Application Data\Grisoft
2008-01-08 22:32 . 2008-01-08 22:32 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-08 22:32 . 2007-05-30 06:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-08 21:23 . 2008-01-06 11:17 19,456 –a—— C:\Documents and Settings\Owner\Application Data\vuyvfzznaf.exe
2008-01-07 17:59 . 2008-01-06 11:17 19,456 –a—— C:\Documents and Settings\Owner\Application Data\hdrobeoros.exe
2008-01-06 17:12 . 2008-01-06 17:12 d——– C:\Program Files\Lavasoft
2008-01-06 17:12 . 2008-01-06 17:12 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-06 15:49 . 2008-01-06 11:17 19,456 –a—— C:\Documents and Settings\Owner\Application Data\brgks.exe
2008-01-06 11:17 . 2008-01-06 11:17 19,456 –a—— C:\Documents and Settings\Owner\Application Data\hzmycp.exe
2008-01-03 08:14 . 2008-01-03 08:14 552 –a—— C:\WINDOWS\system32\d3d8caps.dat
2008-01-01 17:02 . 2008-01-01 17:02 19,456 –a—— C:\Documents and Settings\Owner\Application Data\whxrvtyaz .exe
2008-01-01 16:57 . 2008-01-01 16:57 19,456 –a—— C:\Documents and Settings\Owner\Application Data\ezvffleczn .exe
2008-01-01 16:46 . 2008-01-08 21:11 2,580 –a—— C:\WINDOWS\system32\tmp.reg
2008-01-01 16:26 . 2008-01-01 16:26 19,456 –a—— C:\Documents and Settings\Owner\Application Data\jmiafczfvn .exe
2008-01-01 14:47 . 2008-01-01 14:47 19,456 –a—— C:\Documents and Settings\Owner\Application Data\fjidhoadt .exe
2008-01-01 14:18 . 2008-01-01 14:18 19,456 –a—— C:\Documents and Settings\Owner\Application Data\pdtubkw .exe
2008-01-01 13:05 . 2008-01-01 13:05 19,456 –a—— C:\Documents and Settings\Owner\Application Data\grshyk .exe
2008-01-01 12:57 . 2008-01-01 12:57 19,456 –a—— C:\Documents and Settings\Owner\Application Data\wxcaiykyc .exe
2008-01-01 11:24 . 2008-01-01 11:24 d–h—– C:\WINDOWS\PIF
2008-01-01 11:24 . 2008-01-01 11:24 2,855 –a—— C:\SMARTDRV.PIF
2007-12-31 23:09 . 2007-12-31 23:09 19,456 –a—— C:\Documents and Settings\Owner\Application Data\wmwpgqk .exe
2007-12-31 20:45 . 2007-12-31 20:45 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-31 20:44 . 2008-01-08 22:37 d——– C:\Program Files\SUPERAntiSpyware
2007-12-31 20:44 . 2007-12-31 20:44 d——– C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2007-12-31 20:42 . 2008-01-06 17:11 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-12-31 08:27 . 2007-12-31 08:26 19,456 –a—— C:\Documents and Settings\Owner\Application Data\wwer.exe
2007-12-31 07:40 . 2008-01-08 21:23 101,615 –a—— C:\WINDOWS\GWMDMMSG .exe
2007-12-30 23:06 . 2007-12-30 23:06 19,456 –a—— C:\Documents and Settings\Owner\Application Data\sngwvidjdikg.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-09 04:25 ——— d—–w C:\Program Files\QuickTime
2008-01-01 19:03 ——— d—–w C:\Program Files\SIFXINST
2007-12-14 15:41 1,931,480 —-a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2007-12-04 14:56 93,264 —-a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 —-a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 —-a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 —-a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 —-a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 —-a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 —-a-w C:\WINDOWS\system32\AvastSS.scr
2007-11-21 20:52 ——— d—–w C:\Program Files\Millennium Gamepak Gold
2007-11-21 20:47 286,720 —-a-w C:\WINDOWS\iun506.exe
2007-11-21 16:15 ——— d—–w C:\Documents and Settings\Owner\Application Data\QQ Games Plugin
2007-11-21 16:14 ——— d—–w C:\Program Files\AIM6
2007-11-21 16:13 ——— d—–w C:\Program Files\Tencent
2007-11-21 16:12 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-11-21 16:11 ——— d—–w C:\Program Files\Viewpoint
2007-11-21 16:11 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-21 16:10 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
.
—-a-w			19,456 2008-01-01 22:57:26  C:\Documents and Settings\Owner\Application Data\ezvffleczn .exe
—-a-w			19,456 2008-01-01 20:47:37  C:\Documents and Settings\Owner\Application Data\fjidhoadt .exe
—-a-w			19,456 2008-01-01 19:05:48  C:\Documents and Settings\Owner\Application Data\grshyk .exe
—-a-w			19,456 2008-01-01 22:26:12  C:\Documents and Settings\Owner\Application Data\jmiafczfvn .exe
—-a-w			19,456 2008-01-01 20:18:15  C:\Documents and Settings\Owner\Application Data\pdtubkw .exe
—-a-w			19,456 2008-01-01 23:02:26  C:\Documents and Settings\Owner\Application Data\whxrvtyaz .exe
—-a-w			19,456 2008-01-01 05:09:18  C:\Documents and Settings\Owner\Application Data\wmwpgqk .exe
—-a-w			19,456 2008-01-01 18:57:28  C:\Documents and Settings\Owner\Application Data\wxcaiykyc .exe
—-a-w			39,792 2008-01-09 03:23:19  C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
—-a-w			79,224 2008-01-06 17:17:01  C:\Program Files\Alwil Software\Avast4\ashDisp .exe
—-a-w			49,152 2008-01-09 03:23:17  C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
—-a-w		   241,664 2008-01-09 03:23:19  C:\Program Files\HP\hpcoretech\hpcmpmgr .exe
—-a-w		 1,077,277 2008-01-09 03:23:30  C:\Program Files\Messenger\msmsgs .exe
—-a-w		   155,648 2008-01-06 17:17:05  C:\Program Files\QuickTime\qttask		   .exe
—-a-w			55,368 2008-01-09 03:23:20  C:\Program Files\SanDisk\Sansa Updater\SansaDispatch .exe
—-a-w		 1,318,912 2008-01-09 03:23:32  C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware .exe
—-a-w		   919,016 2008-01-09 03:23:27  C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe
—-a-w		   101,615 2008-01-09 03:23:17  C:\WINDOWS\GWMDMMSG .exe


((((((((((((((((((((((((((((( snapshot@2008-01-11_21.55.46.34 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-08-30 13:14:12 16,384 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-01-12 14:12:41 16,384 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-08-30 13:14:12 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-01-12 14:12:41 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-01-12 14:13:33 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-12-02 21:00:06 18,684,536 —-a-w C:\WINDOWS\system32\MRT.exe
+ 2008-01-02 18:21:36 17,642,616 —-a-w C:\WINDOWS\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="" []
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" []
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 07:00 79224]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [2008-01-06 11:17 155648]
"SansaDispatch"="C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe" [ ]
"843c3fa7"="C:\WINDOWS\System32\csmwqskl.dll" [ ]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 03:25 6731312]
"MRT"="C:\WINDOWS\System32\MRT.exe" [2008-01-02 12:21 17642616]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 21:31:38]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 22:06:36]
Install Pending Files.LNK - C:\Program Files\SIFXINST\SIFXINST.EXE [2007-08-25 14:45:27]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

R3 iadusb;Zoom USB Network Adapter;C:\WINDOWS\System32\DRIVERS\glauiad.sys [2004-07-02 14:20]
S3 iscFlash;iscFlash;C:\WINDOWS\SYSTEM32\DRIVERS\iscflash.sys []

*Newly Created Service* - PROCEXP90
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-12 08:55:37
Windows 5.1.2600 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-12 8:56:56
ComboFix-quarantined-files.txt 2008-01-12 14:56:42
ComboFix2.txt 2008-01-12 03:56:22
.
2008-01-12 14:13:36 — E O F —


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:59:03 AM, on 1/12/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://r.office.microsoft.com/r/rlidOfficeUpdate?clid=1033
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [SansaDispatch] C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe
O4 - HKLM\..\Run: [843c3fa7] rundll32.exe "C:\WINDOWS\System32\csmwqskl.dll",b
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MRT] "C:\WINDOWS\System32\MRT.exe" /R
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 4807 bytes
Open notepad and copy/paste the text in the Codebox below into it:

[b]File::[/b]
C:\Documents and Settings\Owner\Application Data\vuyvfzznaf.exe
C:\Documents and Settings\Owner\Application Data\hdrobeoros.exe
C:\Documents and Settings\Owner\Application Data\brgks.exe
C:\Documents and Settings\Owner\Application Data\hzmycp.exe
C:\Documents and Settings\Owner\Application Data\whxrvtyaz .exe
C:\Documents and Settings\Owner\Application Data\ezvffleczn .exe
C:\Documents and Settings\Owner\Application Data\jmiafczfvn .exe
C:\Documents and Settings\Owner\Application Data\fjidhoadt .exe
C:\Documents and Settings\Owner\Application Data\pdtubkw .exe
C:\Documents and Settings\Owner\Application Data\grshyk .exe
C:\Documents and Settings\Owner\Application Data\wxcaiykyc .exe
C:\Documents and Settings\Owner\Application Data\wmwpgqk .exe
C:\Documents and Settings\Owner\Application Data\wwer.exe
C:\Documents and Settings\Owner\Application Data\sngwvidjdikg.exe
C:\WINDOWS\System32\csmwqskl.dll

[b]Folder::[/b]
C:\VundoFix Backups
C:\Program Files\Viewpoint
C:\Documents and Settings\All Users\Application Data\Viewpoint

[b]Registry::[/b]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"843c3fa7"=-


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
The computer seems to be running alot better, faster and no popups. Any sign of infections? How can so many get in when I run Avast and Zone alarm and scan spybot weekly. I will have to reload zone alarm it seemed to have dissapeared a few days ago.

ComboFix 08-01-11.3 - Owner 2008-01-12 9:51:18.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.0.1252.1.1033.18.79 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-12-12 to 2008-01-12 )))))))))))))))))))))))))))))))
.

2008-01-12 08:13 . 2008-01-12 08:13 118 –a—— C:\WINDOWS\system32\MRT.INI
2008-01-11 21:45 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-11 11:48 . 2008-01-11 11:48 d——– C:\Program Files\Trend Micro
2008-01-11 09:25 . 2008-01-11 09:25 d——– C:\VundoFix Backups
2008-01-08 22:32 . 2008-01-08 22:32 d——– C:\Documents and Settings\Owner\Application Data\Grisoft
2008-01-08 22:32 . 2008-01-08 22:32 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-08 22:32 . 2007-05-30 06:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-08 21:23 . 2008-01-06 11:17 19,456 –a—— C:\Documents and Settings\Owner\Application Data\vuyvfzznaf.exe
2008-01-07 17:59 . 2008-01-06 11:17 19,456 –a—— C:\Documents and Settings\Owner\Application Data\hdrobeoros.exe
2008-01-06 17:12 . 2008-01-06 17:12 d——– C:\Program Files\Lavasoft
2008-01-06 17:12 . 2008-01-06 17:12 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-06 15:49 . 2008-01-06 11:17 19,456 –a—— C:\Documents and Settings\Owner\Application Data\brgks.exe
2008-01-06 11:17 . 2008-01-06 11:17 19,456 –a—— C:\Documents and Settings\Owner\Application Data\hzmycp.exe
2008-01-03 08:14 . 2008-01-03 08:14 552 –a—— C:\WINDOWS\system32\d3d8caps.dat
2008-01-01 17:02 . 2008-01-01 17:02 19,456 –a—— C:\Documents and Settings\Owner\Application Data\whxrvtyaz .exe
2008-01-01 16:57 . 2008-01-01 16:57 19,456 –a—— C:\Documents and Settings\Owner\Application Data\ezvffleczn .exe
2008-01-01 16:46 . 2008-01-08 21:11 2,580 –a—— C:\WINDOWS\system32\tmp.reg
2008-01-01 16:26 . 2008-01-01 16:26 19,456 –a—— C:\Documents and Settings\Owner\Application Data\jmiafczfvn .exe
2008-01-01 14:47 . 2008-01-01 14:47 19,456 –a—— C:\Documents and Settings\Owner\Application Data\fjidhoadt .exe
2008-01-01 14:18 . 2008-01-01 14:18 19,456 –a—— C:\Documents and Settings\Owner\Application Data\pdtubkw .exe
2008-01-01 13:05 . 2008-01-01 13:05 19,456 –a—— C:\Documents and Settings\Owner\Application Data\grshyk .exe
2008-01-01 12:57 . 2008-01-01 12:57 19,456 –a—— C:\Documents and Settings\Owner\Application Data\wxcaiykyc .exe
2008-01-01 11:24 . 2008-01-01 11:24 d–h—– C:\WINDOWS\PIF
2008-01-01 11:24 . 2008-01-01 11:24 2,855 –a—— C:\SMARTDRV.PIF
2007-12-31 23:09 . 2007-12-31 23:09 19,456 –a—— C:\Documents and Settings\Owner\Application Data\wmwpgqk .exe
2007-12-31 20:45 . 2007-12-31 20:45 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-31 20:44 . 2008-01-08 22:37 d——– C:\Program Files\SUPERAntiSpyware
2007-12-31 20:44 . 2007-12-31 20:44 d——– C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2007-12-31 20:42 . 2008-01-06 17:11 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-12-31 08:27 . 2007-12-31 08:26 19,456 –a—— C:\Documents and Settings\Owner\Application Data\wwer.exe
2007-12-31 07:40 . 2008-01-08 21:23 101,615 –a—— C:\WINDOWS\GWMDMMSG .exe
2007-12-30 23:06 . 2007-12-30 23:06 19,456 –a—— C:\Documents and Settings\Owner\Application Data\sngwvidjdikg.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-09 04:25 ——— d—–w C:\Program Files\QuickTime
2008-01-01 19:03 ——— d—–w C:\Program Files\SIFXINST
2007-12-14 15:41 1,931,480 —-a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2007-12-04 14:56 93,264 —-a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 —-a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 —-a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 —-a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 —-a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 —-a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 —-a-w C:\WINDOWS\system32\AvastSS.scr
2007-11-21 20:52 ——— d—–w C:\Program Files\Millennium Gamepak Gold
2007-11-21 20:47 286,720 —-a-w C:\WINDOWS\iun506.exe
2007-11-21 16:15 ——— d—–w C:\Documents and Settings\Owner\Application Data\QQ Games Plugin
2007-11-21 16:14 ——— d—–w C:\Program Files\AIM6
2007-11-21 16:13 ——— d—–w C:\Program Files\Tencent
2007-11-21 16:12 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-11-21 16:11 ——— d—–w C:\Program Files\Viewpoint
2007-11-21 16:11 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-21 16:10 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
.
—-a-w			19,456 2008-01-01 22:57:26  C:\Documents and Settings\Owner\Application Data\ezvffleczn .exe
—-a-w			19,456 2008-01-01 20:47:37  C:\Documents and Settings\Owner\Application Data\fjidhoadt .exe
—-a-w			19,456 2008-01-01 19:05:48  C:\Documents and Settings\Owner\Application Data\grshyk .exe
—-a-w			19,456 2008-01-01 22:26:12  C:\Documents and Settings\Owner\Application Data\jmiafczfvn .exe
—-a-w			19,456 2008-01-01 20:18:15  C:\Documents and Settings\Owner\Application Data\pdtubkw .exe
—-a-w			19,456 2008-01-01 23:02:26  C:\Documents and Settings\Owner\Application Data\whxrvtyaz .exe
—-a-w			19,456 2008-01-01 05:09:18  C:\Documents and Settings\Owner\Application Data\wmwpgqk .exe
—-a-w			19,456 2008-01-01 18:57:28  C:\Documents and Settings\Owner\Application Data\wxcaiykyc .exe
—-a-w			39,792 2008-01-09 03:23:19  C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
—-a-w			79,224 2008-01-06 17:17:01  C:\Program Files\Alwil Software\Avast4\ashDisp .exe
—-a-w			49,152 2008-01-09 03:23:17  C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
—-a-w		   241,664 2008-01-09 03:23:19  C:\Program Files\HP\hpcoretech\hpcmpmgr .exe
—-a-w		 1,077,277 2008-01-09 03:23:30  C:\Program Files\Messenger\msmsgs .exe
—-a-w		   155,648 2008-01-06 17:17:05  C:\Program Files\QuickTime\qttask		   .exe
—-a-w			55,368 2008-01-09 03:23:20  C:\Program Files\SanDisk\Sansa Updater\SansaDispatch .exe
—-a-w		 1,318,912 2008-01-09 03:23:32  C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware .exe
—-a-w		   919,016 2008-01-09 03:23:27  C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe
—-a-w		   101,615 2008-01-09 03:23:17  C:\WINDOWS\GWMDMMSG .exe


((((((((((((((((((((((((((((( snapshot@2008-01-11_21.55.46.34 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-12 03:47:22 237,568 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-12 15:51:06 237,568 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-12 03:47:22 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-12 15:51:06 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-12 03:47:22 237,568 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-12 15:51:06 237,568 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-12 03:47:22 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-12 15:51:06 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-12 03:47:23 3,002,368 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\ntuser.dat
+ 2008-01-12 15:51:06 3,002,368 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\ntuser.dat
- 2008-01-12 03:47:23 57,344 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-12 15:51:06 57,344 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
- 2007-08-30 13:14:12 16,384 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-01-12 14:12:41 16,384 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-08-30 13:14:12 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-01-12 14:12:41 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-01-12 14:13:33 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-12-02 21:00:06 18,684,536 —-a-w C:\WINDOWS\system32\MRT.exe
+ 2008-01-02 18:21:36 17,642,616 —-a-w C:\WINDOWS\system32\MRT.exe
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="" []
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" []
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 07:00 79224]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [2008-01-06 11:17 155648]
"SansaDispatch"="C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe" [ ]
"843c3fa7"="C:\WINDOWS\System32\csmwqskl.dll" [ ]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 03:25 6731312]
"MRT"="C:\WINDOWS\System32\MRT.exe" [2008-01-02 12:21 17642616]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 21:31:38]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 22:06:36]
Install Pending Files.LNK - C:\Program Files\SIFXINST\SIFXINST.EXE [2007-08-25 14:45:27]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

R3 iadusb;Zoom USB Network Adapter;C:\WINDOWS\System32\DRIVERS\glauiad.sys [2004-07-02 14:20]
S3 iscFlash;iscFlash;C:\WINDOWS\SYSTEM32\DRIVERS\iscflash.sys []

*Newly Created Service* - PROCEXP90
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-12 09:53:51
Windows 5.1.2600 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-12 9:55:06
ComboFix-quarantined-files.txt 2008-01-12 15:54:54
ComboFix2.txt 2008-01-12 14:56:58
ComboFix3.txt 2008-01-12 03:56:22
.
2008-01-12 14:13:36 — E O F —


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:59:10 AM, on 1/12/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://r.office.microsoft.com/r/rlidOfficeUpdate?clid=1033
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [SansaDispatch] C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe
O4 - HKLM\..\Run: [843c3fa7] rundll32.exe "C:\WINDOWS\System32\csmwqskl.dll",b
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MRT] "C:\WINDOWS\System32\MRT.exe" /R
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 4807 bytes
These may look like duplicts but they're not. Notice the spaces like; C:\Program Files\QuickTime\qttask .exe

Do Not reboot until combofix runs and reboots your system

1.) Copy the following text to a new notepad file.
Save it as CFScript.txt but do NOT use it yet.

  • Copy the entire contents of the Code Box below to Notepad.
  • Name the file as CFScript.txt (Overwrite the existing one)
  • Change the Save as Type to All Files
  • and Save it on the desktop

File _linenums:0'>File::
C:\Documents and Settings\Owner\Application Data\vuyvfzznaf.exe
C:\Documents and Settings\Owner\Application Data\hdrobeoros.exe
C:\Documents and Settings\Owner\Application Data\brgks.exe
C:\Documents and Settings\Owner\Application Data\hzmycp.exe
C:\Documents and Settings\Owner\Application Data\whxrvtyaz .exe
C:\Documents and Settings\Owner\Application Data\ezvffleczn .exe
C:\Documents and Settings\Owner\Application Data\jmiafczfvn .exe
C:\Documents and Settings\Owner\Application Data\fjidhoadt .exe
C:\Documents and Settings\Owner\Application Data\pdtubkw .exe
C:\Documents and Settings\Owner\Application Data\grshyk .exe
C:\Documents and Settings\Owner\Application Data\wxcaiykyc .exe
C:\Documents and Settings\Owner\Application Data\wmwpgqk .exe
C:\Documents and Settings\Owner\Application Data\wwer.exe
C:\Documents and Settings\Owner\Application Data\sngwvidjdikg.exe
C:\WINDOWS\System32\csmwqskl.dll
C:\Documents and Settings\Owner\Application Data\ezvffleczn .exe
C:\Documents and Settings\Owner\Application Data\fjidhoadt .exe
C:\Documents and Settings\Owner\Application Data\grshyk .exe
C:\Documents and Settings\Owner\Application Data\jmiafczfvn .exe
C:\Documents and Settings\Owner\Application Data\pdtubkw .exe
C:\Documents and Settings\Owner\Application Data\whxrvtyaz .exe
C:\Documents and Settings\Owner\Application Data\wmwpgqk .exe
C:\Documents and Settings\Owner\Application Data\wxcaiykyc .exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
C:\Program Files\Alwil Software\Avast4\ashDisp .exe
C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
C:\Program Files\HP\hpcoretech\hpcmpmgr .exe
C:\Program Files\Messenger\msmsgs .exe
C:\Program Files\QuickTime\qttask           .exe
C:\Program Files\SanDisk\Sansa Updater\SansaDispatch .exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware .exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe
C:\WINDOWS\GWMDMMSG .exe

Folder::
C:\VundoFix Backups
C:\Program Files\Viewpoint
C:\Documents and Settings\All Users\Application Data\Viewpoint

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"843c3fa7"=-


2.) Drag log.txt from desktop that RenV created on top of RenV.exe
Follow the prompts.
Once done it makes a log.
Post its results.

3.) Drag CFScript on top of combofix.exe and let it run.
Post the new log it makes when machine reboots.

Let me know how machine is running.
Here is the RenV log


Ran on Sat 01/12/2008 - 10:55:28.81

——w			79,224 2008-01-06 17:17:01  C:\Program Files\Alwil Software\Avast4\ashDisp .exe
——w		   919,016 2008-01-09 03:23:27  C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe

 Entries:				2  (2)
 Directories:			0  Files:			 2
 Bytes:			998,240  Blocks:		1,950


Below is the Combofix log .
ComboFix 08-01-11.3 - Owner 2008-01-12 10:58:39.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.0.1252.1.1033.18.63 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-12-12 to 2008-01-12 )))))))))))))))))))))))))))))))
.

2008-01-12 08:13 . 2008-01-12 08:13 118 –a—— C:\WINDOWS\system32\MRT.INI
2008-01-11 21:45 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-11 11:48 . 2008-01-11 11:48 d——– C:\Program Files\Trend Micro
2008-01-11 09:25 . 2008-01-11 09:25 d——– C:\VundoFix Backups
2008-01-08 22:32 . 2008-01-08 22:32 d——– C:\Documents and Settings\Owner\Application Data\Grisoft
2008-01-08 22:32 . 2008-01-08 22:32 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-08 22:32 . 2007-05-30 06:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-08 21:23 . 2008-01-06 11:17 19,456 –a—— C:\Documents and Settings\Owner\Application Data\vuyvfzznaf.exe
2008-01-07 17:59 . 2008-01-06 11:17 19,456 –a—— C:\Documents and Settings\Owner\Application Data\hdrobeoros.exe
2008-01-06 17:12 . 2008-01-06 17:12 d——– C:\Program Files\Lavasoft
2008-01-06 17:12 . 2008-01-06 17:12 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-06 15:49 . 2008-01-06 11:17 19,456 –a—— C:\Documents and Settings\Owner\Application Data\brgks.exe
2008-01-06 11:17 . 2008-01-06 11:17 19,456 –a—— C:\Documents and Settings\Owner\Application Data\hzmycp.exe
2008-01-03 08:14 . 2008-01-03 08:14 552 –a—— C:\WINDOWS\system32\d3d8caps.dat
2008-01-01 16:46 . 2008-01-08 21:11 2,580 –a—— C:\WINDOWS\system32\tmp.reg
2008-01-01 11:24 . 2008-01-01 11:24 d–h—– C:\WINDOWS\PIF
2008-01-01 11:24 . 2008-01-01 11:24 2,855 –a—— C:\SMARTDRV.PIF
2007-12-31 20:45 . 2007-12-31 20:45 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-31 20:44 . 2008-01-12 10:55 d——– C:\Program Files\SUPERAntiSpyware
2007-12-31 20:44 . 2007-12-31 20:44 d——– C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2007-12-31 20:42 . 2008-01-06 17:11 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-12-31 08:27 . 2007-12-31 08:26 19,456 –a—— C:\Documents and Settings\Owner\Application Data\wwer.exe
2007-12-30 23:06 . 2007-12-30 23:06 19,456 –a—— C:\Documents and Settings\Owner\Application Data\sngwvidjdikg.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-12 16:55 ——— d—–w C:\Program Files\QuickTime
2008-01-01 19:03 ——— d—–w C:\Program Files\SIFXINST
2007-12-14 15:41 1,931,480 —-a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2007-12-04 14:56 93,264 —-a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 —-a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 —-a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 —-a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 —-a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 —-a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 —-a-w C:\WINDOWS\system32\AvastSS.scr
2007-11-21 20:52 ——— d—–w C:\Program Files\Millennium Gamepak Gold
2007-11-21 20:47 286,720 —-a-w C:\WINDOWS\iun506.exe
2007-11-21 16:15 ——— d—–w C:\Documents and Settings\Owner\Application Data\QQ Games Plugin
2007-11-21 16:14 ——— d—–w C:\Program Files\AIM6
2007-11-21 16:13 ——— d—–w C:\Program Files\Tencent
2007-11-21 16:12 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-11-21 16:11 ——— d—–w C:\Program Files\Viewpoint
2007-11-21 16:11 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-21 16:10 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
.
——w			79,224 2008-01-06 17:17:01  C:\Program Files\Alwil Software\Avast4\ashDisp .exe
——w		   919,016 2008-01-09 03:23:27  C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe


((((((((((((((((((((((((((((( snapshot_2008-01-12_ 9.54.22.95 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-12 15:51:06 237,568 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-12 16:58:28 237,568 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-12 15:51:06 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-12 16:58:28 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-12 15:51:06 237,568 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-12 16:58:28 237,568 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-12 15:51:06 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-12 16:58:28 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-12 15:51:06 3,002,368 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\ntuser.dat
+ 2008-01-12 16:58:28 3,002,368 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\ntuser.dat
- 2008-01-12 15:51:06 57,344 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-12 16:58:28 57,344 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="" []
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" []
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 07:00 79224]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"SansaDispatch"="C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe" [ ]
"843c3fa7"="C:\WINDOWS\System32\csmwqskl.dll" [ ]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 03:25 6731312]
"MRT"="C:\WINDOWS\System32\MRT.exe" [2008-01-02 12:21 17642616]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 21:31:38]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 22:06:36]
Install Pending Files.LNK - C:\Program Files\SIFXINST\SIFXINST.EXE [2007-08-25 14:45:27]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

R3 iadusb;Zoom USB Network Adapter;C:\WINDOWS\System32\DRIVERS\glauiad.sys [2004-07-02 14:20]
S3 iscFlash;iscFlash;C:\WINDOWS\SYSTEM32\DRIVERS\iscflash.sys []

*Newly Created Service* - PROCEXP90
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-12 11:01:00
Windows 5.1.2600 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-12 11:02:14
ComboFix-quarantined-files.txt 2008-01-12 17:02:02
ComboFix2.txt 2008-01-12 15:55:08
ComboFix3.txt 2008-01-12 14:56:58
ComboFix4.txt 2008-01-12 03:56:22
.
2008-01-12 14:13:36 — E O F —
Your Zonealarm and Avast4 will need to be re-installed.

I don't want you running without a anti-virus so get this free one for now. We can uninstall it after we kill the bad guys. Let me know when you have it running and I'll then give you another fix.

Click HERE Click the Download Now and Save, Install, and Update.
Having a bit of a problem. When the computer restarted after the combofix an Error RunDLL came up c;\windows\system32\csmwqskl.dll could not be found. then a small popup came from taskbar stating"malicious software has been removed" I downloaded AVG7.5 free edition but cannot get updates "update server connection failed" In the taskbar my Avast seems to be working. Can we continue with this?
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Documents and Settings\Owner\Application Data\vuyvfzznaf.exe
C:\Documents and Settings\Owner\Application Data\hdrobeoros.exe
C:\Documents and Settings\Owner\Application Data\brgks.exe
C:\Documents and Settings\Owner\Application Data\hzmycp.exe
C:\Documents and Settings\Owner\Application Data\wwer.exe
C:\Documents and Settings\Owner\Application Data\sngwvidjdikg.exe

Folder::
C:\Program Files\Viewpoint
C:\Documents and Settings\All Users\Application Data\Viewpoint

RenV::
C:\Program Files\Alwil Software\Avast4\ashDisp .exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI