This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware problems

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Help!!!! Our computer is going crazy. I have used adaware, spybot, and vondufix and none of them are able to delete the problems. They all find things but then either are not able to delete them or delete them and they appear again. We have pop-ups when IE is not even open and the cpu usage is at 94% when looking at the device manager. The computer is beyond slow. This is my only hope. I have downloaded hijack this off your website and have provided the log below. Thank you so much for any help that you can provide.

Logfile of HijackThis v1.99.1
Scan saved at 3:05:20 PM, on 1/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\WINDOWS\system32\hkcmd .exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Dell\Media Experience\PCMService .exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Common Files\Real\Update_OB\realsched .exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray .exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind .exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection .exe
C:\Program Files\QuickTime\qttask .exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\SYSTEM32\F?nts\s?ool32.exe
C:\Program Files\Dot1XCfg\Dot1XCfg.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
C:\Program Files\Dot1XCfg\Dot1XCfg .exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Reception\Local Settings\Temporary Internet Files\Content.IE5\6HN0XC7A\HijackThis[1].exe
C:\DOCUME~1\RECEPT~1\MYDOCU~1\STEM32~1\iexplore.exe
C:\DOCUME~1\RECEPT~1\MYDOCU~1\STEM32~1\iexplore.exe
C:\DOCUME~1\RECEPT~1\MYDOCU~1\STEM32~1\iexplore.exe
C:\DOCUME~1\RECEPT~1\MYDOCU~1\STEM32~1\iexplore.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: OLE (Part 1 of 5) - - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
F3 - REG:win.ini: load=C:\WINDOWS\system32\pmnnk.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2f7b3109-1a04-4395-bf39-873dc9f1b437} - C:\WINDOWS\system32\jehwgxw.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {7B3950FB-0C39-46D5-BA7E-7637AB8F67DB} - (no file)
O2 - BHO: (no name) - {A704D4F8-80CC-49A3-8E13-D64805CBC406} - C:\WINDOWS\system32\pmnnk.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {D4576C73-52BD-4401-B966-5A128C4433D4} - C:\WINDOWS\system32\xxyyyyw.dll
O2 - BHO: (no name) - {EABADC0B-A750-41D2-B446-340FF0F8721F} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA998] command /c del "C:\WINDOWS\SYSTEM32\pmnnk.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9409] cmd /c del "C:\WINDOWS\SYSTEM32\pmnnk.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2222] command /c del "C:\WINDOWS\SYSTEM32\pmnnk.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5641] cmd /c del "C:\WINDOWS\SYSTEM32\pmnnk.dll"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [Aida] "C:\DOCUME~1\RECEPT~1\MYDOCU~1\STEM32~1\iexplore.exe" -vt yazb
O4 - HKCU\..\Run: [Zyzj] C:\WINDOWS\SYSTEM32\F?nts\s?ool32.exe
O4 - HKCU\..\Run: [Dot1XCfg] C:\Program Files\Dot1XCfg\Dot1XCfg.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: xxyyyyw - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
Hello and Welcome to the forum.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.

Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here to your Desktop.

**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Thank you LDTate!!!

I have done what you asked and here is the combofix log:

ComboFix 08-01-16.4 - Reception 2008-01-16 8:28:56.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Reception\My Documents\STEM32~1
C:\Documents and Settings\Reception\My Documents\STEM32~1\??stem32\
C:\Documents and Settings\Reception\My Documents\STEM32~1\iexplore .exe
C:\Documents and Settings\Reception\My Documents\STEM32~1\iexplore.exe
C:\Program Files\Messenger\rtenelujuj.html
C:\Program Files\Temporary
C:\Program Files\Temporary\kernInst.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\b122.exe
C:\WINDOWS\mrofinu1000106.exe
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\fnts~1
C:\WINDOWS\system32\fnts~1\s?ool32.exe
C:\WINDOWS\SYSTEM32\knnmp.ini
C:\WINDOWS\SYSTEM32\knnmp.ini2
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pmnnk.dll
C:\WINDOWS\system32\pmnnk.exe
C:\WINDOWS\system32\RCX2B.tmp
C:\WINDOWS\system32\RCX2E.tmp
C:\WINDOWS\system32\RCX31.tmp
C:\WINDOWS\system32\wcpsvtr.exe
C:\WINDOWS\system32\xxyyyyw.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CMDSERVICE
——-\LEGACY_NETWORK_MONITOR
——-\cmdService


((((((((((((((((((((((((( Files Created from 2007-12-16 to 2008-01-16 )))))))))))))))))))))))))))))))
.

2008-01-16 08:43 . 2008-01-16 08:43 333,312 –a—— C:\WINDOWS\SYSTEM32\pmnnk.exe
2008-01-16 08:42 . 2008-01-16 08:42 319 –ahs—- C:\WINDOWS\SYSTEM32\knnmp.ini2
2008-01-16 08:41 . 2008-01-16 08:41 329,728 –a—— C:\WINDOWS\SYSTEM32\pmnnk.dll
2008-01-16 08:41 . 2008-01-16 08:43 319 –ahs—- C:\WINDOWS\SYSTEM32\knnmp.ini
2008-01-16 08:16 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-14 15:11 . 2008-01-14 15:11 63 –a—— C:\WINDOWS\mdm.ini
2008-01-14 14:58 . 2008-01-16 08:43 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-14 14:58 . 2008-01-16 08:38 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-14 13:22 . 2008-01-14 13:22 d——– C:\VundoFix Backups
2008-01-14 11:53 . 2004-04-26 12:32 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2008-01-14 11:53 . 2005-04-24 14:18 d——– C:\Documents and Settings\Administrator\Application Data\Gtek
2008-01-14 10:20 . 2008-01-15 08:00 413 –a—— C:\WINDOWS\wininit.ini
2008-01-11 16:27 . 2008-01-14 10:21 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-11 14:50 . 2008-01-11 14:50 d——– C:\Documents and Settings\LocalService\Application Data\Yahoo!
2008-01-11 14:33 . 2008-01-14 13:18 155,648 –a—— C:\WINDOWS\SYSTEM32\igfxtray .exe
2008-01-11 14:33 . 2008-01-16 08:41 126,976 –a—— C:\WINDOWS\SYSTEM32\hkcmd .exe
2008-01-11 14:33 . 2008-01-14 13:19 15,360 –a—— C:\WINDOWS\SYSTEM32\ctfmon .exe
2008-01-11 14:28 . 2008-01-16 08:42 d——– C:\Program Files\Dot1XCfg
2008-01-11 14:24 . 2008-01-11 15:17 d–hs—- C:\WINDOWS\UmVjZXB0aW9u
2008-01-11 14:24 . 2008-01-11 15:44 d——– C:\WINDOWS\SYSTEM32\vt8
2008-01-11 14:24 . 2008-01-11 15:44 d——– C:\WINDOWS\SYSTEM32\mp2
2008-01-11 14:24 . 2008-01-11 14:32 d——– C:\WINDOWS\SYSTEM32\ez4
2008-01-11 14:24 . 2008-01-11 14:24 d——– C:\WINDOWS\SYSTEM32\che9
2008-01-11 14:24 . 2008-01-11 14:39 374,272 –a—— C:\WINDOWS\mrofinu572.exe.tmp
2008-01-11 14:23 . 2008-01-11 14:23 d——– C:\WINDOWS\SYSTEM32\edcA01
2008-01-11 14:23 . 2008-01-11 14:24 d——– C:\Temp\Ryuan1
2008-01-10 13:23 . 2008-01-10 13:23 48 –a—— C:\WINDOWS\VistaEmail.ini
2008-01-10 13:18 . 2008-01-10 13:18 23 –a—— C:\WINDOWS\kodakpcd.Reception.ini
2008-01-10 13:03 . 2008-01-10 13:03 d——– C:\WINDOWS\SYSTEM32\BWKDLogs
2008-01-10 12:59 . 2008-01-11 13:53 d——– C:\Documents and Settings\All Users\Application Data\Kodak
2008-01-10 12:58 . 2008-01-11 13:51 d——– C:\Program Files\Kodak

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-16 14:43 ——— d—–w C:\Program Files\QuickTime
2008-01-16 14:41 20,480 —-a-w C:\WINDOWS\SYSTEM32\ctfmon.exe
2008-01-15 22:44 51,588 —-a-w C:\Documents and Settings\Reception\Application Data\wklnhst.dat
2008-01-15 16:55 461,312 —-a-w C:\WINDOWS\SYSTEM32\hkcmd.exe
2008-01-14 17:55 ——— d—–w C:\Program Files\Dell Support
2007-11-14 07:26 450,560 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\jscript.dll
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\SYSTEM32\lsasrv.dll
2007-11-07 09:26 721,920 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\lsasrv.dll
2007-10-30 17:20 360,064 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip.sys
2007-10-30 09:55 3,065,856 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\SYSTEM32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\quartz.dll
2007-10-27 23:40 222,720 —-a-w C:\WINDOWS\SYSTEM32\wmasf.dll
2007-10-27 23:40 222,720 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
2005-07-29 22:24 472 –sha-r C:\WINDOWS\UmVjZXB0aW9u\oAp3tr1Xuq6R.vbs
.
—-a-w		   483,328 2008-01-16 14:41:59  C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray .exe
—-a-w			50,688 2008-01-16 14:41:52  C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind .exe
—-a-w		   180,269 2008-01-16 14:41:52  C:\Program Files\Common Files\Real\Update_OB\realsched .exe
—-a-w		   204,800 2008-01-16 14:41:49  C:\Program Files\Dell\Media Experience\PCMService .exe
—-a-w			61,440 2008-01-16 14:42:07  C:\Program Files\Dot1XCfg\Dot1XCfg .exe
—-a-w			68,856 2008-01-16 14:42:05  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w			53,248 2008-01-16 14:41:50  C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask .exe
—-a-w		   421,376 2008-01-16 14:43:06  C:\Program Files\QuickTime\qttask		  .exe
—-a-w		   421,376 2008-01-16 14:29:42  C:\Program Files\QuickTime\qttask		 .exe
—-a-w		   421,376 2008-01-15 16:55:27  C:\Program Files\QuickTime\qttask		.exe
—-a-w		   421,376 2008-01-14 23:00:52  C:\Program Files\QuickTime\qttask	   .exe
—-a-w		   421,376 2008-01-14 16:27:18  C:\Program Files\QuickTime\qttask	  .exe
—-a-w		   421,376 2008-01-14 15:41:52  C:\Program Files\QuickTime\qttask	 .exe
—-a-w		   421,376 2008-01-11 22:40:06  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   421,376 2008-01-11 22:12:40  C:\Program Files\QuickTime\qttask   .exe
—-a-w		   421,376 2008-01-11 21:17:46  C:\Program Files\QuickTime\qttask  .exe
—-a-w		   421,376 2008-01-11 20:39:48  C:\Program Files\QuickTime\qttask .exe
—-a-w		 1,460,560 2008-01-16 14:42:29  C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
—-a-w		   224,248 2008-01-16 14:42:02  C:\Program Files\Yahoo!\Search Protection\SearchProtection .exe
—-a-w			15,360 2008-01-14 19:19:14  C:\WINDOWS\SYSTEM32\ctfmon .exe
—-a-w		   126,976 2008-01-16 14:41:49  C:\WINDOWS\SYSTEM32\hkcmd .exe
—-a-w		   155,648 2008-01-14 19:18:59  C:\WINDOWS\SYSTEM32\igfxtray .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2f7b3109-1a04-4395-bf39-873dc9f1b437}]
C:\WINDOWS\system32\jehwgxw.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7B3950FB-0C39-46D5-BA7E-7637AB8F67DB}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{84B7DC9C-27BC-4A71-BA5D-F6EA76C1E8DA}]
2008-01-16 08:41 329728 –a—— C:\WINDOWS\system32\pmnnk.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A704D4F8-80CC-49A3-8E13-D64805CBC406}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4576C73-52BD-4401-B966-5A128C4433D4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EABADC0B-A750-41D2-B446-340FF0F8721F}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-15 10:55 430080]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-01-15 10:55 583168]
"Zyzj"="C:\WINDOWS\SYSTEM32\F?nts\s?ool32.exe" [ ]
"Dot1XCfg"="C:\Program Files\Dot1XCfg\Dot1XCfg.exe" [2008-01-15 10:55 394752]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-16 08:29 1797632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [ ]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2008-01-15 10:55 461312]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2008-01-15 10:55 562176]
"mmtask"="c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2008-01-15 10:55 387584]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-01-15 10:55 514560]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2008-01-15 10:55 390144]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-01-15 10:55 822784]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-01-15 10:55 583168]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [2008-01-16 08:43 421376]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-15 10:55 430080]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-F400-8796-100000000002}\SC_Acrobat.exe [2006-02-24 10:57:49]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2004-04-26 12:15:11]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 14:05:56]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-06-24 07:42:07]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyyyyw]

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\WINDOWS\system32\pmnnk.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\pmnnk


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{23394df2-7e37-11db-be74-000d566c77fa}]
\Shell\AutoRun\command - E:\Installer.exe

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-16 08:42:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

C:\WINDOWS\TEMP
C:\WINDOWS\system32\pmnnk.exe 333312 bytes executable

scan completed successfully
hidden files: 2

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\pmnnk.dll
.
Completion time: 2008-01-16 8:46:29 - machine was rebooted [Reception]
ComboFix-quarantined-files.txt 2008-01-16 14:46:23
.
2008-01-09 09:02:08 — E O F —


And here is the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:54:45 AM, on 1/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell\Media Experience\PCMService .exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\hkcmd .exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask .exe
C:\Program Files\Common Files\Real\Update_OB\realsched .exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind .exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray .exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Dot1XCfg\Dot1XCfg.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection .exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
C:\Program Files\Dot1XCfg\Dot1XCfg .exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Documents and Settings\Reception\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - URLSearchHook: OLE (Part 1 of 5) - - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
F3 - REG:win.ini: load=C:\WINDOWS\system32\pmnnk.exe
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [Zyzj] C:\WINDOWS\SYSTEM32\F?nts\s?ool32.exe
O4 - HKCU\..\Run: [Dot1XCfg] C:\Program Files\Dot1XCfg\Dot1XCfg.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

–
End of file - 7702 bytes
Open notepad and copy/paste the text in the Codebox below into it:

File::
C:\WINDOWS\SYSTEM32\pmnnk.exe
C:\WINDOWS\SYSTEM32\knnmp.ini2
C:\WINDOWS\SYSTEM32\pmnnk.dll
C:\WINDOWS\SYSTEM32\knnmp.ini
C:\WINDOWS\wininit.ini
C:\WINDOWS\mrofinu572.exe.tmp
C:\WINDOWS\system32\jehwgxw.dll

RenV::
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray .exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind .exe
C:\Program Files\Common Files\Real\Update_OB\realsched .exe
C:\Program Files\Dell\Media Experience\PCMService .exe
C:\Program Files\Dot1XCfg\Dot1XCfg .exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask .exe
C:\Program Files\QuickTime\qttask          .exe
C:\Program Files\QuickTime\qttask         .exe
C:\Program Files\QuickTime\qttask        .exe
C:\Program Files\QuickTime\qttask       .exe
C:\Program Files\QuickTime\qttask      .exe
C:\Program Files\QuickTime\qttask     .exe
C:\Program Files\QuickTime\qttask    .exe
C:\Program Files\QuickTime\qttask   .exe
C:\Program Files\QuickTime\qttask  .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection .exe
C:\WINDOWS\SYSTEM32\ctfmon .exe
C:\WINDOWS\SYSTEM32\hkcmd .exe
C:\WINDOWS\SYSTEM32\igfxtray .exe
C:\WINDOWS\SYSTEM32\F?nts\s?ool32.exe

Folder::
C:\VundoFix Backups
C:\WINDOWS\UmVjZXB0aW9u
C:\WINDOWS\SYSTEM32\mp2
C:\WINDOWS\SYSTEM32\ez4
C:\WINDOWS\SYSTEM32\che9
C:\WINDOWS\SYSTEM32\edcA01
C:\Temp\Ryuan1

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2f7b3109-1a04-4395-bf39-873dc9f1b437}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7B3950FB-0C39-46D5-BA7E-7637AB8F67DB}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{84B7DC9C-27BC-4A71-BA5D-F6EA76C1E8DA}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A704D4F8-80CC-49A3-8E13-D64805CBC406}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4576C73-52BD-4401-B966-5A128C4433D4}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EABADC0B-A750-41D2-B446-340FF0F8721F}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Zyzj"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyyyyw]
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{23394df2-7e37-11db-be74-000d566c77fa}]


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
thank you for all your help. I got the problem taken care of, AVG found an old trojan and was able to get rid of it. Dont know why spybot was not able to.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI