This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] got a malware: Win32:TratBHO [Trj]- help!

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm sure there are lots of posts for this, but if you can please help me out. I don't have much experience getting rid of these things. I have Win2000 SP4 and IE keeps popping up websites with ads- some of them pretty lewd. I wouldn't want the kids to have to see it. I have Avast and it can't seem to get rid of this Trojan. Here is the info from Avast virus alert:

file name: C:\WINNT\system32\fcyxw.dll
malware name: Win32:TratBHO [Trj]
malware type: Trojan Horse
vps version: 080127-1, 01/27/2008

how can I get rid of this???

I'm posting my Hijack log below- thanks in advance.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:02:13 AM, on 1/28/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINNT\system32\CTsvcCDA.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\MacOpener\FORMATM.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\snmp.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\WINNT\System32\msdtc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\mqsvc.exe
C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S4I2R1.EXE
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\Java\jre1.5.0_03\bin\jucheck.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Sony Handheld\HOTSYNC.EXE
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Alwil Software\Avast4\ashLogV.exe
C:\WINNT\system32\notepad.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\David\Desktop\HiJackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper -

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {51ACB68D-2C03-4062-AF4F-522F8F9F2F22} -

C:\WINNT\system32\wvuts.dll (file missing)
O2 - BHO: Canon Easy Web Print Helper -

{68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program

Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: (no name) - {A051B1FF-8D7E-418B-AABE-4FF82F4280A2} -

C:\WINNT\system32\pmnolmm.dll
O2 - BHO: (no name) - {D929C51A-951F-41AF-9FFD-F6E829FC4E89} -

C:\Program Files\Common

Files\hokerC:\WINNT\system32\wnis6\enamd83122.exe.dll (file missing)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio -

{8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar -

{EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program

Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C}

- C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [EPSON Stylus C86 Series]

C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S4I2R1.EXE /P23 "EPSON

Stylus C86 Series" /O6 "USB001" /M "Stylus C86"
O4 - HKLM\..\Run: [MaxtorOneTouch]

C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [MacLicense] "C:\Program

Files\MacOpener\MacLic.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program

Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program

Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program

Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program

Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [runner1] C:\WINNT\mrofinu572.exe

61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C88332017491

39
O4 - HKCU\..\Run: [Creative Detector] C:\Program

Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat

7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program

Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop

(User 'Default user')
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Sony

Handheld\HOTSYNC.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program

Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program

Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel -

res://C:\PROGRA~1\MSOFFICE\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List -

res://C:\Program

Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print -

res://C:\Program

Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview -

res://C:\Program

Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program

Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a}

- C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links -

{c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes

Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} -

http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) -

http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} (AMI DicomDir

TreeView Control 2.1) - file://F:\CDVIEWER\CdViewer.cab
O20 - Winlogon Notify: pmnolmm - C:\WINNT\SYSTEM32\pmnolmm.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL

Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program

Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program

Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program

Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Creative Service for CDROM Access - Creative

Technology Ltd - C:\WINNT\system32\CTsvcCDA.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin)

- VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision

Corporation - C:\Program Files\Common

Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program

Files\iPod\bin\iPodService.exe
O23 - Service: MacFormatService - DataViz Inc. - C:\Program

Files\MacOpener\FORMATM.EXE
O23 - Service: SolidWorks Licensing Service - SolidWorks -

C:\Program Files\Common Files\SolidWorks

Shared\Service\SolidWorksLicensing.exe

–
End of file - 7045 bytes
Hello mrdear and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem.


I need you to remove the double spacing that exists in your log to make it easier to read:

To remove the double spacing in your log, please do the following:
  • Please go to Start >> Run… and type notepad.exe
  • Hit OK.
  • Now go to Format and uncheck WordWrap.
  • Close Notepad.


Now please run HijackThis again and post the results.

Thank you,

Trevuren
Hi,

Thanks for the help. I really need it- the problem is getting worse and worse. IE is popping up stuff every second. I tried running VundoFix V6.7.7 and it found some stuff and I was able to delete it, except for one file C:\WINNT\system32\pmnolmm.dll.. Then I got a dialog saying "cannot import C:\vundoFix.reg:error opening the file. There may be a disk of file system error". Then I read your email and tried to run hijackthis.exe again but now that keeps crashing with a dialog saying hijackthis had to be shutdown, etc. and creating a ~dummy.tmp file on the desktop. It did create a log- don't know if it is complete but here it is. Any help would be much appreciated. Who needs this?!?!?!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:24:40 PM, on 1/28/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINNT\system32\CTsvcCDA.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\MacOpener\FORMATM.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\snmp.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\msdtc.exe
C:\WINNT\system32\mqsvc.exe
C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S4I2R1.EXE
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Sony Handheld\HOTSYNC.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\David\Desktop\HiJackThis.exe

O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [EPSON Stylus C86 Series] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S4I2R1.EXE /P23 "EPSON Stylus C86 Series" /O6 "USB001" /M "Stylus C86"
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [MacLicense] "C:\Program Files\MacOpener\MacLic.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [runner1] C:\WINNT\mrofinu572.exe 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C8833201749139
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Sony Handheld\HOTSYNC.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MSOFFICE\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} (AMI DicomDir TreeView Control 2.1) - file://F:\CDVIEWER\CdViewer.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\system32\CTsvcCDA.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MacFormatService - DataViz Inc. - C:\Program Files\MacOpener\FORMATM.EXE
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe

–
End of file - 6365 bytes
Please download ComboFix by sUBs from HERE or HERE
  • You must download it to and run it from your Desktop
  • First, physically disconnect your computer from the internet.
  • Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log
  • Re-enable all the programs that were disabled during the running of ComboFix.
  • Now you may reconnect your machine to the internet and post the logs

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
Thank you for the help. Here are the logs: By the way things are still popping up in IE

ComboFix 08-01-29.3 - David 01/28/2008 23:21:22.1 - FAT32x86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.397 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINNT\system32\efcay.dll
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
C:\Program Files\Temporary
C:\Program Files\Temporary\kernInst.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\WINNT\b122.exe
C:\WINNT\system32\Cache
C:\WINNT\system32\drivers\core.cache.dsk . . . . failed to delete
C:\WINNT\system32\efcay.dll
C:\WINNT\system32\mcrh.tmp
C:\WINNT\system32\pac.txt
C:\WINNT\system32\pmnolmm.dll
C:\WINNT\system32\stuvw.ini
C:\WINNT\system32\stuvw.ini2
C:\WINNT\system32\ttsru.ini
C:\WINNT\system32\ttsru.ini2
C:\WINNT\system32\yacfe.ini
C:\WINNT\system32\yacfe.ini2
C:\WINNT\Web\default.htt
C:\WINNT\system32\drivers\core.cache.dsk . . . . failed to delete

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_IPRIP
——-\Iprip


((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-29 )))))))))))))))))))))))))))))))
.

2008-01-28 23:28 . 08-01-28 23:28 d——– C:\temp\tn3
2008-01-28 23:27 . 08-01-28 23:27 16,384 –a—-t- C:\WINNT\system32\Perflib_Perfdata_1f0.dat
2008-01-28 20:53 . 08-01-28 20:53 d——– C:\VundoFix Backups
2008-01-28 08:12 . 07-09-24 23:31 69,632 –a—— C:\WINNT\system32\javacpl.cpl
2008-01-27 03:17 . 02-12-11 17:34 208,896 –a—— C:\WINNT\system32\wmpns.dll
2008-01-27 03:04 . 08-01-27 03:04 957 –a—— C:\WINNT\setup.inf
2008-01-27 03:04 . 08-01-27 03:04 283 –a—— C:\WINNT\setup.rpt
2008-01-27 00:12 . 06-07-25 00:08 840,976 ——— C:\WINNT\system32\dllcache\mmcndmgr.dll
2008-01-27 00:05 . 08-01-27 00:05 d——– C:\Program Files\Dot1XCfg
2008-01-27 00:05 . 07-07-30 19:18 34,136 –a—— C:\WINNT\system32\wucltui.dll.mui
2008-01-27 00:05 . 07-07-30 19:19 25,944 –a—— C:\WINNT\system32\wuaucpl.cpl.mui
2008-01-27 00:05 . 07-07-30 19:19 25,944 –a—— C:\WINNT\system32\wuapi.dll.mui
2008-01-27 00:05 . 07-07-30 19:18 20,312 –a—— C:\WINNT\system32\wuaueng.dll.mui
2008-01-26 23:58 . 08-01-26 23:58 d——– C:\WINNT\system32\wnis6
2008-01-26 23:58 . 08-01-26 23:58 d——– C:\WINNT\system32\ets1
2008-01-26 23:58 . 08-01-26 23:58 d——– C:\WINNT\system32\deb3
2008-01-26 23:58 . 08-01-26 23:58 86,016 –a—— C:\WINNT\system32\drivers\kss.sys
2008-01-26 23:58 . 08-01-28 23:26 932 ——— C:\WINNT\system32\drivers\core.cache.dsk
2008-01-26 23:53 . 08-01-26 23:53 d——– C:\WINNT\system32\nip4
2008-01-26 23:53 . 08-01-26 23:53 d——– C:\WINNT\system32\nGpxx01
2008-01-26 23:53 . 08-01-26 23:53 d——– C:\temp\gTiis19
2008-01-26 23:53 . 08-01-26 23:53 d——– C:\temp\cXzz9
2008-01-26 23:53 . 08-01-26 23:53 346,800 –a—— C:\temp\tOncha0119.exe
2008-01-26 23:53 . 08-01-26 23:53 36,864 –a—— C:\WINNT\17PHolmes572.exe
2008-01-17 07:10 . 08-01-27 21:23 54,156 –ah—– C:\WINNT\QTFont.qfn
2008-01-17 07:10 . 08-01-17 07:10 1,409 –a—— C:\WINNT\QTFont.for
2008-01-13 23:26 . 08-01-13 23:26 d——– C:\Garmin

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-04 14:56 93,264 —-a-w C:\WINNT\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 —-a-w C:\WINNT\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 —-a-w C:\WINNT\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 —-a-w C:\WINNT\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 —-a-w C:\WINNT\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 —-a-w C:\WINNT\system32\aswBoot.exe
2007-12-04 12:54 95,608 —-a-w C:\WINNT\system32\AVASTSS.scr
2007-10-31 07:17 230,912 —-a-w C:\WINNT\system32\wmasf.dll
2007-10-31 07:17 230,912 ——w C:\WINNT\system32\dllcache\wmasf.dll
2007-10-31 07:17 2,109,440 ——w C:\WINNT\system32\dllcache\wmvcore.dll
2007-10-29 15:31 2,705,408 —-a-w C:\WINNT\system32\dllcache\MSHTML.DLL
2007-02-26 15:21 8,191 —-a-w C:\Documents and Settings\David\Application Data\unins000.dat
2007-02-26 15:19 678,682 —-a-w C:\Documents and Settings\David\Application Data\unins000.exe
2005-07-09 03:19 271 —h–w C:\Program Files\desktop.ini
2005-07-09 03:19 21,952 —h–w C:\Program Files\folder.htt
1999-12-07 17:00 32,528 —-a-w C:\WINNT\inf\wbfirdma.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{130D8368-F363-4565-BA45-4581A6BD576B}]
C:\WINNT\system32\sstss.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{33fd6486-e31f-4315-8d7f-ecffc09c6ae8}]
C:\WINNT\system32\ncenseiu.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51ACB68D-2C03-4062-AF4F-522F8F9F2F22}]
C:\WINNT\system32\wvuts.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D929C51A-951F-41AF-9FFD-F6E829FC4E89}]
C:\Program Files\Common Files\hokerC:\WINNT\system32\wnis6\enamd83122.exe.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [04-12-02 18:23 102400]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [06-03-30 16:45 313472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [03-06-19 12:05 111376 C:\WINNT\system32\mobsync.exe]
"EPSON Stylus C86 Series"="C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S4I2R1.exe" [03-11-25 03:00 99840]
"MaxtorOneTouch"="C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe" [03-05-21 15:30 45056]
"MacLicense"="C:\Program Files\MacOpener\MacLic.exe" [00-07-06 22:19 151616]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [07-12-04 08:00 79224]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [06-02-23 15:45 278528]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [06-04-08 08:23 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [07-09-25 01:11 132496]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [06-03-21 20:30 1191936]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [03-06-19 12:05 186640]

C:\Documents and Settings\David\Start Menu\Programs\Startup\
HotSync Manager.lnk - C:\Program Files\Sony Handheld\HOTSYNC.EXE [2005-07-10 23:10:05 299008]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-07-10 23:19:53 113664]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINNT\system32\efcay

R0 MacOpen;MacOpen;C:\WINNT\system32\drivers\MacOpen.sys [00-07-06 22:15 ]
R0 ultra66;ultra66;C:\WINNT\system32\DRIVERS\ultra66.sys [99-12-07 12:00 ]
R1 kss;kss;C:\WINNT\system32\drivers\kss.sys [08-01-26 23:58 ]
R2 aswMon;avast! Standard Shield Support;C:\WINNT\system32\drivers\aswMon.sys [07-12-04 09:56 ]
R2 SMTPSVC;Simple Mail Transport Protocol (SMTP);C:\WINNT\system32\inetsrv\inetinfo.exe [03-06-19 12:05 ]
R3 3cpciadi;3Com Windows Modem Driver PCI ADI;C:\WINNT\system32\DRIVERS\3cpciadi.sys [99-11-01 16:42 ]
R3 Usr79n5;U.S. Robotics 10/100 PCI NIC TX Driver ;C:\WINNT\system32\DRIVERS\Usr79n5.sys [03-01-04 15:18 ]
R3 voodoo3;voodoo3;C:\WINNT\system32\DRIVERS\voodoo3.sys [99-10-29 15:00 ]
R3 wdm_au8830;Aureal Vortex 8830 Audio Driver (WDM);C:\WINNT\system32\drivers\adm8830.sys [99-11-01 16:56 ]

*Newly Created Service* - IPNAT
*Newly Created Service* - RASAUTO
*Newly Created Service* - SHAREDACCESS
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-28 23:28:15
Windows 5.0.2195 Service Pack 4 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINNT\system32\CTsvcCDA.EXE
C:\Program Files\MacOpener\FORMATM.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\snmp.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\WINNT\System32\msdtc.exe
C:\WINNT\system32\mqsvc.exe
C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S4I2R1.EXE
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Sony Handheld\HOTSYNC.EXE
.
**************************************************************************
.
Completion time: 2008-01-28 23:30:10 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-29 04:30:06
.
2008-01-28 11:54:53 — E O F —


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:32:43 PM, on 1/28/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINNT\system32\CTsvcCDA.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\MacOpener\FORMATM.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\snmp.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\WINNT\System32\msdtc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\mqsvc.exe
C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S4I2R1.EXE
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Sony Handheld\HOTSYNC.EXE
C:\WINNT\system32\notepad.exe
C:\Documents and Settings\David\Desktop\HiJackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {130D8368-F363-4565-BA45-4581A6BD576B} - C:\WINNT\system32\sstss.dll (file missing)
O2 - BHO: {8ea6c90c-ffce-f7d8-5134-f13e6846df33} - {33fd6486-e31f-4315-8d7f-ecffc09c6ae8} - C:\WINNT\system32\ncenseiu.dll (file missing)
O2 - BHO: (no name) - {51ACB68D-2C03-4062-AF4F-522F8F9F2F22} - C:\WINNT\system32\wvuts.dll (file missing)
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {D929C51A-951F-41AF-9FFD-F6E829FC4E89} - C:\Program Files\Common Files\hokerC:\WINNT\system32\wnis6\enamd83122.exe.dll (file missing)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [EPSON Stylus C86 Series] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S4I2R1.EXE /P23 "EPSON Stylus C86 Series" /O6 "USB001" /M "Stylus C86"
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [MacLicense] "C:\Program Files\MacOpener\MacLic.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Sony Handheld\HOTSYNC.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MSOFFICE\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} (AMI DicomDir TreeView Control 2.1) - file://F:\CDVIEWER\CdViewer.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\system32\CTsvcCDA.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MacFormatService - DataViz Inc. - C:\Program Files\MacOpener\FORMATM.EXE
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe

–
End of file - 7055 bytes
1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\WINNT\system32\drivers\kss.sys
C:\WINNT\system32\drivers\core.cache.dsk
C:\WINNT\system32\efcay.dll

Folder::
C:\WINNT\system32\wnis6
C:\WINNT\system32\ets1
C:\WINNT\system32\deb3
C:\WINNT\system32\nip4
C:\WINNT\system32\nGpxx01
C:\temp\gTiis19
C:\temp\cXzz9
C:\temp\tn3
C:\temp

Driver::
kss

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{130D8368-F363-4565-BA45-4581A6BD576B}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{33fd6486-e31f-4315-8d7f-ecffc09c6ae8}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51ACB68D-2C03-4062-AF4F-522F8F9F2F22}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D929C51A-951F-41AF-9FFD-F6E829FC4E89}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Next, re-enable all the programs that you disabled prior to running ComboFix.

8. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ran into a hitch: I dragged the script on top of combofix, it started but then the window just disappeared and I think it just quit? I had to reboot and now I'm going to try it again
Please post the entire content of the script that you are submitting to ComboFix ( as found on your desktop) and please provide me with the exact name and extension of the script as you see it on your desktop. Trevuren
Here is the script which I copy and pasted from the message board. I named the file CFScript.txt and drapped the whole file over the ComboFix icon. KillAll:: File:: C:\WINNT\system32\drivers\kss.sys C:\WINNT\system32\drivers\core.cache.dsk C:\WINNT\system32\efcay.dll Folder:: C:\WINNT\system32\wnis6 C:\WINNT\system32\ets1 C:\WINNT\system32\deb3 C:\WINNT\system32\nip4 C:\WINNT\system32\nGpxx01 C:\temp\gTiis19 C:\temp\cXzz9 C:\temp\tn3 C:\temp Driver:: kss Registry:: [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{130D8368-F363-4565-BA45-4581A6BD576B}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{33fd6486-e31f-4315-8d7f-ecffc09c6ae8}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51ACB68D-2C03-4062-AF4F-522F8F9F2F22}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D929C51A-951F-41AF-9FFD-F6E829FC4E89}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA] "Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00
That looks OK. We will try using another tool for this. If this tool does not work properly, we are probably dealing with a very messy infection. Let us keep our fingers crossed that it is not the case.


1. Please download The Avenger by Swandog46 to your Desktop.
  • Click on Avenger.zip to open the file
  • Extract avenger.exe to your desktop

2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Files to delete:
C:\WINNT\system32\drivers\kss.sys
C:\WINNT\system32\drivers\core.cache.dsk
C:\WINNT\system32\efcay.dll

Folders to delete:
C:\WINNT\system32\wnis6
C:\WINNT\system32\ets1
C:\WINNT\system32\deb3
C:\WINNT\system32\nip4
C:\WINNT\system32\nGpxx01
C:\temp\gTiis19
C:\temp\cXzz9
C:\temp\tn3
C:\temp

Drivers to unload:
kss

Registry keys to delete:
HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{130D8368-F363-4565-BA45-4581A6BD576B}
HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{33fd6486-e31f-4315-8d7f-ecffc09c6ae8}
HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51ACB68D-2C03-4062-AF4F-522F8F9F2F22}
Hkey_classes_root\clsid\{130D8368-F363-4565-BA45-4581A6BD576B}
Hkey_classes_root\clsid\{33fd6486-e31f-4315-8d7f-ecffc09c6ae8}
Hkey_classes_root\clsid\{51ACB68D-2C03-4062-AF4F-522F8F9F2F22}

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, start The Avenger program by clicking on its icon on your desktop.
  • Under "Script file to execute" choose "Input Script Manually".
  • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
  • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
  • Click Done
  • Now click on the Green Light to begin execution of the script
  • Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log by using Add/Reply
Well that didn't go well. First the Avenger had many errors before it even rebooted. Then the avenger.txt file came up blank. This I'm sure is not a good sign. I copied most of the error messages to a file before the reboot- here they are:

syntax error in line—does not appear to be a valid registry path. Line will be ignored.
(pressed OK)
Press OK to log error and continue or Cancel to abort
(pressed OK)
Error code: 5
line:
(pressed OK)
Hkey_classes_root\clsid\{130D8368-F363-4565-BA45-4581A6BD576B}
(pressed OK)
syntax error in line—does not appear to be a valid registry path. Line will be ignored.
(pressed OK)
Press OK to log error and continue or Cancel to abort
(pressed OK)
Error code: 1813
Line:
(pressed OK)
Hkey_classes_root\clsid\{33fd6486-e31f-4315-8d7f-ecffc09c6ae8}
(pressed OK)
syntax error in line—does not appear to be a valid registry path. Line will be ignored.
(pressed OK)
Press OK to log error and continue or Cancel to abort
(pressed OK)
Error code: 1813
Line:
(pressed OK)
Hkey_classes_root\clsid\{51ACB68D-2C03-4062-AF4F-522F8F9F2F22}
(pressed OK)
Error: could not create zip file.
(pressed OK)
Press OK to log error and continue or Cancel to abort
(pressed OK)
Error code: 1813

Now here is the latest hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:23, on 2008-01-29
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINNT\system32\CTsvcCDA.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\MacOpener\FORMATM.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\snmp.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\WINNT\System32\msdtc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\mqsvc.exe
C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S4I2R1.EXE
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Sony Handheld\HOTSYNC.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\David\Desktop\HiJackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {130D8368-F363-4565-BA45-4581A6BD576B} - C:\WINNT\system32\sstss.dll (file missing)
O2 - BHO: {8ea6c90c-ffce-f7d8-5134-f13e6846df33} - {33fd6486-e31f-4315-8d7f-ecffc09c6ae8} - C:\WINNT\system32\ncenseiu.dll (file missing)
O2 - BHO: (no name) - {51ACB68D-2C03-4062-AF4F-522F8F9F2F22} - C:\WINNT\system32\wvuts.dll (file missing)
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {D929C51A-951F-41AF-9FFD-F6E829FC4E89} - C:\Program Files\Common Files\hokerC:\WINNT\system32\wnis6\enamd83122.exe.dll (file missing)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [EPSON Stylus C86 Series] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S4I2R1.EXE /P23 "EPSON Stylus C86 Series" /O6 "USB001" /M "Stylus C86"
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [MacLicense] "C:\Program Files\MacOpener\MacLic.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Sony Handheld\HOTSYNC.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MSOFFICE\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} (AMI DicomDir TreeView Control 2.1) - file://F:\CDVIEWER\CdViewer.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\system32\CTsvcCDA.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MacFormatService - DataViz Inc. - C:\Program Files\MacOpener\FORMATM.EXE
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe

–
End of file - 7145 bytes
Please run this through the Avenger program and expect error messages. Some last time were my fault, I ws using ComboFix registry short forms instead of the long form. After you have saved the new Avenger log, please run ComboFix again and also post that log. We will get this one yet.

Files to delete:
C:\WINNT\system32\drivers\kss.sys
C:\WINNT\system32\drivers\core.cache.dsk
C:\WINNT\system32\efcay.dll

Folders to delete:
C:\WINNT\system32\wnis6
C:\WINNT\system32\ets1
C:\WINNT\system32\deb3
C:\WINNT\system32\nip4
C:\WINNT\system32\nGpxx01
C:\temp\gTiis19
C:\temp\cXzz9
C:\temp\tn3
C:\temp

Drivers to unload:
kss

Registry keys to delete:
hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{130D8368-F363-4565-BA45-4581A6BD576B}
hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{33fd6486-e31f-4315-8d7f-ecffc09c6ae8}
hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{51ACB68D-2C03-4062-AF4F-522F8F9F2F22}
Hkey_classes_root\clsid\{130D8368-F363-4565-BA45-4581A6BD576B}
Hkey_classes_root\clsid\{33fd6486-e31f-4315-8d7f-ecffc09c6ae8}
Hkey_classes_root\clsid\{51ACB68D-2C03-4062-AF4F-522F8F9F2F22}
thank you for your determined approach!

Avenger worked a little better but still had a bunch of errors. It did make a log but unfortunately after I ran combofix and rebooted the avenger.txt file disappeared! I even clicked save before running the combofix but it is gone. I remember it could not find and delete many items from your list. It could not delete the following:
Files to delete:
C:\WINNT\system32\drivers\kss.sys
C:\WINNT\system32\drivers\core.cache.dsk
C:\WINNT\system32\efcay.dll

Folders to delete:
C:\WINNT\system32\wnis6
C:\WINNT\system32\ets1
C:\WINNT\system32\deb3
C:\WINNT\system32\nip4
C:\WINNT\system32\nGpxx01
C:\temp\gTiis19
C:\temp\cXzz9
C:\temp\tn3
C:\temp

Drivers to unload:
kss

It was able to delete these:

Registry keys to delete:
hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{130D8368-F363-4565-BA45-4581A6BD576B}
hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{33fd6486-e31f-4315-8d7f-ecffc09c6ae8}
hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{51ACB68D-2C03-4062-AF4F-522F8F9F2F22}

Here is my combofix log:

ComboFix 08-01-29.3 - David 2008-01-29 22:20:42.2 - FAT32x86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.466 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-30 )))))))))))))))))))))))))))))))
.

2008-01-29 22:26 . 08-01-29 22:26 16,384 –a—-t- C:\WINNT\system32\Perflib_Perfdata_30c.dat
2008-01-29 22:26 . 08-01-29 22:26 16,384 –a—-t- C:\WINNT\system32\Perflib_Perfdata_1f0.dat
2008-01-29 21:10 . 08-01-29 21:10 1,238,929 –a—— C:\zia01648
2008-01-29 00:15 . 08-01-29 06:18 830,246 —h—– C:\WINNT\ShellIconCache
2008-01-28 20:53 . 08-01-28 20:53 d——– C:\VundoFix Backups
2008-01-28 08:12 . 07-09-24 23:31 69,632 –a—— C:\WINNT\system32\javacpl.cpl
2008-01-27 03:17 . 02-12-11 17:34 208,896 –a—— C:\WINNT\system32\wmpns.dll
2008-01-27 03:04 . 08-01-27 03:04 957 –a—— C:\WINNT\setup.inf
2008-01-27 03:04 . 08-01-27 03:04 283 –a—— C:\WINNT\setup.rpt
2008-01-27 00:12 . 06-07-25 00:08 840,976 ——— C:\WINNT\system32\dllcache\mmcndmgr.dll
2008-01-27 00:05 . 08-01-27 00:05 d——– C:\Program Files\Dot1XCfg
2008-01-27 00:05 . 07-07-30 19:18 34,136 –a—— C:\WINNT\system32\wucltui.dll.mui
2008-01-27 00:05 . 07-07-30 19:19 25,944 –a—— C:\WINNT\system32\wuaucpl.cpl.mui
2008-01-27 00:05 . 07-07-30 19:19 25,944 –a—— C:\WINNT\system32\wuapi.dll.mui
2008-01-27 00:05 . 07-07-30 19:18 20,312 –a—— C:\WINNT\system32\wuaueng.dll.mui
2008-01-26 23:53 . 08-01-26 23:53 36,864 –a—— C:\WINNT\17PHolmes572.exe
2008-01-17 07:10 . 08-01-29 19:03 54,156 –ah—– C:\WINNT\QTFont.qfn
2008-01-17 07:10 . 08-01-17 07:10 1,409 –a—— C:\WINNT\QTFont.for
2008-01-13 23:26 . 08-01-13 23:26 d——– C:\Garmin

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-04 14:56 93,264 —-a-w C:\WINNT\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 —-a-w C:\WINNT\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 —-a-w C:\WINNT\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 —-a-w C:\WINNT\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 —-a-w C:\WINNT\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 —-a-w C:\WINNT\system32\aswBoot.exe
2007-12-04 12:54 95,608 —-a-w C:\WINNT\system32\AVASTSS.scr
2007-10-31 07:17 230,912 —-a-w C:\WINNT\system32\wmasf.dll
2007-10-31 07:17 230,912 ——w C:\WINNT\system32\dllcache\wmasf.dll
2007-10-31 07:17 2,109,440 ——w C:\WINNT\system32\dllcache\wmvcore.dll
2007-10-29 15:31 2,705,408 —-a-w C:\WINNT\system32\dllcache\MSHTML.DLL
2007-10-28 01:20 1,222,656 —-a-w C:\WINNT\system32\quartz.dll
2007-10-28 01:20 1,222,656 —-a-w C:\WINNT\system32\dllcache\quartz.dll
2007-10-17 07:22 96,016 —-a-w C:\WINNT\system32\mqlogmgr.dll
2007-10-17 07:22 96,016 —-a-w C:\WINNT\system32\dllcache\mqlogmgr.dll
2007-10-17 07:22 8,464 ——w C:\WINNT\system32\dllcache\mqrperf.dll
2007-10-17 07:22 77,072 —-a-w C:\WINNT\system32\mqdscli.dll
2007-10-17 07:22 77,072 —-a-w C:\WINNT\system32\dllcache\mqdscli.dll
2007-10-17 07:22 70,928 —-a-w C:\WINNT\system32\mqsec.dll
2007-10-17 07:22 70,928 —-a-w C:\WINNT\system32\dllcache\mqsec.dll
2007-10-17 07:22 50,448 —-a-w C:\WINNT\system32\dllcache\mqclus.dll
2007-10-17 07:22 440,592 —-a-w C:\WINNT\system32\mqqm.dll
2007-10-17 07:22 440,592 —-a-w C:\WINNT\system32\dllcache\mqqm.dll
2007-10-17 07:22 42,256 —-a-w C:\WINNT\system32\mqdssrv.dll
2007-10-17 07:22 42,256 —-a-w C:\WINNT\system32\dllcache\mqdssrv.dll
2007-10-17 07:22 400,656 —-a-w C:\WINNT\system32\mqsnap.dll
2007-10-17 07:22 400,656 —-a-w C:\WINNT\system32\dllcache\mqsnap.dll
2007-10-17 07:22 292,112 —-a-w C:\WINNT\system32\dllcache\mq1repl.dll
2007-10-17 07:22 29,968 ——w C:\WINNT\system32\dllcache\mqdbodbc.dll
2007-10-17 07:22 29,456 —-a-w C:\WINNT\system32\mqcertui.dll
2007-10-17 07:22 29,456 ——w C:\WINNT\system32\dllcache\mqcertui.dll
2007-10-17 07:22 267,536 —-a-w C:\WINNT\system32\dllcache\mqmigrat.dll
2007-10-17 07:22 23,824 —-a-w C:\WINNT\system32\mqupgrd.dll
2007-10-17 07:22 23,824 —-a-w C:\WINNT\system32\dllcache\mqupgrd.dll
2007-10-17 07:22 222,480 —-a-w C:\WINNT\system32\mqoa.dll
2007-10-17 07:22 222,480 —-a-w C:\WINNT\system32\dllcache\mqoa.dll
2007-10-17 07:22 218,384 —-a-w C:\WINNT\system32\mqads.dll
2007-10-17 07:22 218,384 —-a-w C:\WINNT\system32\dllcache\mqads.dll
2007-10-17 07:22 159,504 ——w C:\WINNT\system32\dllcache\msmqocm.dll
2007-10-17 07:22 111,888 —-a-w C:\WINNT\system32\mqutil.dll
2007-10-17 07:22 111,888 —-a-w C:\WINNT\system32\dllcache\mqutil.dll
2007-10-17 07:22 102,672 —-a-w C:\WINNT\system32\mqrt.dll
2007-10-17 07:22 102,672 —-a-w C:\WINNT\system32\dllcache\mqrt.dll
2007-10-17 07:22 10,000 —-a-w C:\WINNT\system32\mqperf.dll
2007-10-17 07:22 10,000 —-a-w C:\WINNT\system32\dllcache\mqperf.dll
2007-10-16 13:51 98,064 —-a-w C:\WINNT\system32\dllcache\mqmig.exe
2007-10-16 13:51 77,712 ——w C:\WINNT\system32\dllcache\mqac.sys
2007-10-16 13:51 25,360 —-a-w C:\WINNT\system32\mqbkup.exe
2007-10-16 13:51 25,360 ——w C:\WINNT\system32\dllcache\mqbkup.exe
2007-10-16 13:51 14,096 —-a-w C:\WINNT\system32\mqsvc.exe
2007-10-16 13:51 14,096 —-a-w C:\WINNT\system32\dllcache\mq1sync.exe
2007-10-16 13:51 14,096 ——w C:\WINNT\system32\dllcache\mqsvc.exe
2007-10-16 11:34 513,808 —-a-w C:\WINNT\system32\LSASRV.DLL
2007-10-11 15:38 143,360 —-a-w C:\WINNT\system32\dllcache\CDFVIEW.DLL
2007-10-11 15:38 132,096 —-a-w C:\WINNT\system32\dllcache\MSRATING.DLL
2007-10-11 15:37 402,944 —-a-w C:\WINNT\system32\dllcache\SHLWAPI.DLL
2007-10-11 15:37 1,340,416 —-a-w C:\WINNT\system32\dllcache\SHDOCVW.DLL
2007-10-11 15:37 1,018,368 —-a-w C:\WINNT\system32\dllcache\BROWSEUI.DLL
2007-10-11 15:31 575,488 —-a-w C:\WINNT\system32\WININET.DLL
2007-10-11 15:31 575,488 —-a-w C:\WINNT\system32\dllcache\WININET.DLL
2007-10-11 15:31 462,336 —-a-w C:\WINNT\system32\dllcache\URLMON.DLL
2007-10-11 15:31 12,288 —-a-w C:\WINNT\system32\dllcache\JSPROXY.DLL
2007-10-11 15:30 69,632 —-a-w C:\WINNT\system32\dllcache\INSENG.DLL
2007-10-11 15:30 498,176 —-a-w C:\WINNT\system32\dllcache\MSTIME.DLL
2007-10-11 15:30 351,744 —-a-w C:\WINNT\system32\dllcache\DXTMSFT.DLL
2007-10-11 15:30 34,816 —-a-w C:\WINNT\system32\dllcache\PNGFILT.DLL
2007-10-11 15:30 236,032 —-a-w C:\WINNT\system32\dllcache\IEPEERS.DLL
2007-10-11 15:30 192,512 —-a-w C:\WINNT\system32\dllcache\DXTRANS.DLL
2007-10-05 06:54 320,368 ——w C:\WINNT\system32\dllcache\tcpip.sys
2007-02-26 15:21 8,191 —-a-w C:\Documents and Settings\David\Application Data\unins000.dat
2007-02-26 15:19 678,682 —-a-w C:\Documents and Settings\David\Application Data\unins000.exe
2005-07-09 03:19 271 —h–w C:\Program Files\desktop.ini
2005-07-09 03:19 21,952 —h–w C:\Program Files\folder.htt
1999-12-07 17:00 32,528 —-a-w C:\WINNT\inf\wbfirdma.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D929C51A-951F-41AF-9FFD-F6E829FC4E89}]
C:\Program Files\Common Files\hokerC:\WINNT\system32\wnis6\enamd83122.exe.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [04-12-02 18:23 102400]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [06-03-30 16:45 313472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [03-06-19 12:05 111376 C:\WINNT\system32\mobsync.exe]
"EPSON Stylus C86 Series"="C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S4I2R1.exe" [03-11-25 03:00 99840]
"MaxtorOneTouch"="C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe" [03-05-21 15:30 45056]
"MacLicense"="C:\Program Files\MacOpener\MacLic.exe" [00-07-06 22:19 151616]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [07-12-04 08:00 79224]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [06-02-23 15:45 278528]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [06-04-08 08:23 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [07-09-25 01:11 132496]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [06-03-21 20:30 1191936]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [03-06-19 12:05 186640]

C:\Documents and Settings\David\Start Menu\Programs\Startup\
HotSync Manager.lnk - C:\Program Files\Sony Handheld\HOTSYNC.EXE [2005-07-10 23:10:05 299008]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-07-10 23:19:53 113664]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]

R0 MacOpen;MacOpen;C:\WINNT\system32\drivers\MacOpen.sys [00-07-06 22:15 ]
R0 ultra66;ultra66;C:\WINNT\system32\DRIVERS\ultra66.sys [99-12-07 12:00 ]
R2 aswMon;avast! Standard Shield Support;C:\WINNT\system32\drivers\aswMon.sys [07-12-04 09:56 ]
R2 SMTPSVC;Simple Mail Transport Protocol (SMTP);C:\WINNT\system32\inetsrv\inetinfo.exe [03-06-19 12:05 ]
R3 3cpciadi;3Com Windows Modem Driver PCI ADI;C:\WINNT\system32\DRIVERS\3cpciadi.sys [99-11-01 16:42 ]
R3 Usr79n5;U.S. Robotics 10/100 PCI NIC TX Driver ;C:\WINNT\system32\DRIVERS\Usr79n5.sys [03-01-04 15:18 ]
R3 voodoo3;voodoo3;C:\WINNT\system32\DRIVERS\voodoo3.sys [99-10-29 15:00 ]
R3 wdm_au8830;Aureal Vortex 8830 Audio Driver (WDM);C:\WINNT\system32\drivers\adm8830.sys [99-11-01 16:56 ]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-29 22:27:46
Windows 5.0.2195 Service Pack 4 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINNT\system32\CTsvcCDA.EXE
C:\Program Files\MacOpener\FORMATM.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\snmp.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\WINNT\System32\msdtc.exe
C:\WINNT\system32\mqsvc.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S4I2R1.EXE
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Sony Handheld\HOTSYNC.EXE
.
**************************************************************************
.
Completion time: 2008-01-29 22:30:29 - machine was rebooted [David]
ComboFix-quarantined-files.txt 2008-01-30 03:30:24
ComboFix2.txt 2008-01-29 04:30:12
.
2008-01-28 11:54:53 — E O F —

I noticed that another person on the forum was having similar problems with dropping a script onto combofix.Did you know about that? It is the post subject: vundo by redwingsoh

Thanks for the help! IE is not popping up right now.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI