This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] popups/outerinfo

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi WTT

HJT log pasted below.

Not sure where or when it got invected the user mentioned it late Friday. He attempted to uninstall outinfo, and while I was on the sys attempting to get HJT on the sys, I had several popups mostily reporting he was invected with malware and it needs to be corrected yada yada yada :)

I don't beleive anything was install from those, but there are a couple new icons on his desktop, windows shield is the icon I can't remember what the text/discription was though.

Logfile of HijackThis v1.99.1
Scan saved at 6:05:51 AM, on 1/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\YWRhdmlz\command.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\COMMON~1\FNTS~1\rundll.exe
C:\Program Files\Words\Words.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\cmcdaniel\Application Data\??pPatch\?ttrib.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = GTR ENGINEERING, LLC
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = gtr1:8080
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1044.exe 61A847B5BBF72813329F3C466188719AB689201522886B092CBD44BD8689220221DD3257
O4 - HKLM\..\Run: [2F293233303032332] EEE8F1F2EFEFF1F.exe
O4 - HKLM\..\Run: [70af9248] rundll32.exe "C:\WINDOWS\system32\nhuepiim.dll",b
O4 - HKLM\..\RunOnce: [RemoveInstallPath] cmd.exe C:\WINDOWS\system32\cmd.exe /c rmdir /S /Q "C:\PROGRA~1\Router" > nul
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Tair] "C:\PROGRA~1\COMMON~1\FNTS~1\rundll.exe" -vt yazb
O4 - HKCU\..\Run: [Xhpv] "C:\Documents and Settings\cmcdaniel\Application Data\??pPatch\?ttrib.exe"
O4 - HKCU\..\Run: [qkii] C:\PROGRA~1\COMMON~1\qkii\qkiim.exe
O4 - HKCU\..\Run: [Dot1XCfg] C:\Program Files\Dot1XCfg\Dot1XCfg.exe
O4 - HKCU\..\Run: [Router] C:\Program Files\Router\Router.exe
O4 - HKCU\..\Run: [Words] C:\Program Files\Words\Words.exe
O4 - HKCU\..\Run: [70af9248] rundll32.exe "C:\WINDOWS\system32\etayfotq.dll",b
O4 - Startup: E-mail.lnk = ?
O4 - Startup: MicroStation.lnk = C:\Bentley\Program\MicroStation\ustation.exe
O4 - Global Startup: Kodak EasyShare software.lnk.disabled
O4 - Global Startup: PKZIP Attachments Status.lnk.disabled
O8 - Extra context menu item: &Search - ?p=ZSzed001MSUS_ZNxmk788YYUS
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7Pro.dll
O9 - Extra 'Tools' menuitem: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7Pro.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200705…ex/qtplugin.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/1452/ftp…02/cpbrkpie.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = GTRENGINEERING.local
O17 - HKLM\Software\..\Telephony: DomainName = GTRENGINEERING.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = GTRENGINEERING.local
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\YWRhdmlz\command.exe
O23 - Service: DB2 JDBC Applet Server (DB2JDS) - Unknown owner - C:\SQLLIB\bin\db2jds.exe
O23 - Service: DB2 Security Server (DB2NTSECSERVER) - International Business Machines Corporation - C:\SQLLIB\bin\db2sec.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\dvejwwrr.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

Thanks for any help you can provide.
A Davis
Welcome to the forum. :woot: I will help you get rid of your spyware. Please give me some time to analyze your log and I will get back to you shortly. All fixes here are specific to your computer and souldn't be used randomly on any other computer. All fixes are checked by experts, which sometimes can take a little extra time. (but necessary) Please stay with me until the end. Then we can be sure you are entirely clean. Thanks and I'll be back. DR
Download ComboFix from one of the locations below, and save it to your Desktop.

Link 1
Link 2
Link 3

Double click combofix.exe and follow the prompts.
When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall


Thanks

DR
DR, thanks for your help.

Incoming logs.

ComboFix 08-01-30.6 - cmcdaniel 2008-01-30 7:43:31.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.673 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Common Files\qkii\qkiia.lck
C:\Program Files\Common Files\qkii\qkiid\class-barrel
C:\Program Files\Common Files\qkii\qkiim.lck
C:\WINDOWS\system32\byxvvwv.dll
C:\WINDOWS\system32\ddccd.dll
C:\WINDOWS\system32\qszbhtem.dll
C:\Documents and Settings\cmcdaniel\Application Data\PPATCH~1
C:\Program Files\Common Files\curity~1
C:\Program Files\Common Files\fnts~1
C:\Program Files\Common Files\qkii\qkiia.exe
C:\Program Files\Common Files\qkii\qkiia.lck
C:\Program Files\Common Files\qkii\qkiid\class-barrel
C:\Program Files\Common Files\qkii\qkiid\qkiic.dll
C:\Program Files\Common Files\qkii\qkiid\vocabulary
C:\Program Files\Common Files\qkii\qkiih
C:\Program Files\Common Files\qkii\qkiil.exe
C:\Program Files\Common Files\qkii\qkiil.lck
C:\Program Files\Common Files\qkii\qkiim.exe
C:\Program Files\Common Files\qkii\qkiim.lck
C:\Program Files\Common Files\qkii\qkiip.exe
C:\Program Files\fnts~1
C:\Program Files\Temporary
C:\Program Files\Words
C:\WINDOWS\b103.exe
C:\WINDOWS\b104.exe
C:\WINDOWS\b116.exe
C:\WINDOWS\b122.exe
C:\WINDOWS\b138.exe
C:\WINDOWS\b143.exe
C:\WINDOWS\b149.exe
C:\WINDOWS\b151.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\mrofinu1044.exe
C:\WINDOWS\qkii
C:\WINDOWS\qkii\qkii.dat
C:\WINDOWS\qkii\wu
C:\WINDOWS\system32\acuomvtx.dll
C:\WINDOWS\system32\afumycrs.dll
C:\WINDOWS\system32\awtrrom.dll
C:\WINDOWS\system32\bkpsdjcb.dll
C:\WINDOWS\system32\bpasxuyo.dll
C:\WINDOWS\system32\byxvvwv.dll
C:\WINDOWS\system32\clvubrka.dll
C:\WINDOWS\system32\coeqwqym.dll
C:\WINDOWS\system32\dccdd.ini
C:\WINDOWS\system32\dccdd.ini2
C:\WINDOWS\system32\ddccd.dll
C:\WINDOWS\system32\fcywtrq.dll
C:\WINDOWS\system32\ihkeocdq.ini
C:\WINDOWS\system32\ikegsanr.ini
C:\WINDOWS\system32\kgarrpkh.dll
C:\WINDOWS\system32\llfjdaky.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mdhpulax.ini
C:\WINDOWS\system32\miipeuhn.ini
C:\WINDOWS\system32\oepkegjj.dll
C:\WINDOWS\system32\qdcoekhi.dll
C:\WINDOWS\system32\qsjnqidg.dll
C:\WINDOWS\system32\qszbhtem.dll
C:\WINDOWS\system32\qszbhtem.dllbox
C:\WINDOWS\system32\qtofyate.ini
C:\WINDOWS\system32\sumnsrtj.ini
C:\WINDOWS\system32\twaevvyy.ini
C:\WINDOWS\system32\vcmedryy.dll
C:\WINDOWS\system32\vtutrss.dll
C:\WINDOWS\system32\wscajkeb.exe
C:\WINDOWS\YWRhdmlz\
C:\WINDOWS\YWRhdmlz\\asappsrv.dll
C:\WINDOWS\YWRhdmlz\\command.exe
C:\WINDOWS\YWRhdmlz\\sql1xA5W.vbs
C:\WINDOWS\YWRhdmlz\command.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CMDSERVICE
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_NETWORK_MONITOR
——-\cmdService
——-\DomainService


((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-30 )))))))))))))))))))))))))))))))
.

2008-01-28 16:51 . 2008-01-29 12:08 2,934,669 –ahs—- C:\WINDOWS\system32\fupxrjas.ini
2008-01-28 16:51 . 2008-01-28 16:51 147,520 –a—— C:\WINDOWS\system32\sajrxpuf.dll
2008-01-28 06:35 . 2008-01-28 06:35 d——– C:\Documents and Settings\LocalService\Application Data\Yahoo!
2008-01-28 06:34 . 2008-01-28 06:34 d——– C:\Documents and Settings\LocalService\Application Data\IE7Pro
2008-01-25 19:30 . 2008-01-25 19:30 d——– C:\WINDOWS\system32\A19BA4A5A2A2A4A
2008-01-25 19:30 . 2007-12-14 05:40 120,832 –a—— C:\WINDOWS\system32\EEE8F1F2EFEFF1F.exe
2008-01-24 16:32 . 2008-01-24 16:32 36,864 –a—— C:\WINDOWS\mrofinu1044.exe.tmp
2008-01-24 16:27 . 2008-01-24 16:39 d——– C:\Documents and Settings\cmcdaniel\Application Data\BitTorrent
2008-01-23 09:27 . 2008-01-28 06:46 d——– C:\Program Files\Yahoo!

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-28 13:41 ——— d–h–r C:\Documents and Settings\cmcdaniel\Application Data\yahoo!
2008-01-28 13:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\yahoo!
2007-12-31 13:43 ——— d—–w C:\Program Files\Winamp Toolbar
2007-12-31 13:43 ——— d—–w C:\Program Files\Winamp
2007-12-03 15:28 ——— d—–w C:\Program Files\PKWARE
2007-12-03 15:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\WinZip
2007-12-03 15:26 ——— d—–w C:\Program Files\SoundSpectrum
2007-11-29 19:42 ——— d—–w C:\Documents and Settings\cmcdaniel\Application Data\SoundSpectrum
2007-11-19 15:12 73,216 —-a-w C:\WINDOWS\ST6UNST.EXE
2007-11-19 15:12 286,720 ——w C:\WINDOWS\Setup1.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-12-13 09:49 1185120 –a—— C:\Program Files\Winamp Toolbar\winamptb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}

[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-12-13 09:49 1185120]

[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 14:49 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 14:46 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 14:50 114688]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-05-14 13:28 282624]
"2F293233303032332"="EEE8F1F2EFEFF1F.exe" [2007-12-14 05:40 120832 C:\WINDOWS\system32\EEE8F1F2EFEFF1F.exe]
"70af9248"="C:\WINDOWS\system32\qdcoekhi.dll" [ ]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk.disabled [2007-10-18 07:59:55 1876]
PKZIP Attachments Status.lnk.disabled [2007-11-16 14:22:25 844]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 01000000
"NoWinKeys"= 01000000
"NoSMMyDocs"= 01000000
"NoSMMyPictures"= 01000000

[HKLM\~\startupfolder\C:^Documents and Settings^cmcdaniel^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=C:\Documents and Settings\cmcdaniel\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=C:\WINDOWS\pss\HotSync Manager.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\MsnMsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2007-05-14 13:28 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"WinampAgent"=C:\Program Files\Winamp\wianmpa.exe

R3 Eacfilt;Eacfilt Miniport;C:\WINDOWS\system32\DRIVERS\eacfilt.sys [2003-03-28 11:37]
R3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2003-03-28 11:36]
S2 IPSECEXT;Nortel Extranet Access Protocol;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2003-03-28 11:36]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-30 07:51:47
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\EEE8F1F2EFEFF1F.exe
.
**************************************************************************
.
Completion time: 2008-01-30 7:54:03 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-30 14:53:54
.
2008-01-09 10:01:40 — E O F —

And the HJT log

Logfile of HijackThis v1.99.1
Scan saved at 07:54, on 2008-01-30
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\EEE8F1F2EFEFF1F.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = gtr1:8080
O2 - BHO: IE7pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IE7pro\IE7Pro.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [2F293233303032332] EEE8F1F2EFEFF1F.exe
O4 - HKLM\..\Run: [70af9248] rundll32.exe "C:\WINDOWS\system32\qdcoekhi.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: E-mail.lnk = ?
O4 - Startup: MicroStation.lnk = C:\Bentley\Program\MicroStation\ustation.exe
O4 - Global Startup: Kodak EasyShare software.lnk.disabled
O4 - Global Startup: PKZIP Attachments Status.lnk.disabled
O8 - Extra context menu item: &Search - ?p=ZSzed001MSUS_ZNxmk788YYUS
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7Pro.dll
O9 - Extra 'Tools' menuitem: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7Pro.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200705…ex/qtplugin.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/1452/ftp…02/cpbrkpie.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = GTRENGINEERING.local
O17 - HKLM\Software\..\Telephony: DomainName = GTRENGINEERING.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = GTRENGINEERING.local
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: DB2 JDBC Applet Server (DB2JDS) - Unknown owner - C:\SQLLIB\bin\db2jds.exe
O23 - Service: DB2 Security Server (DB2NTSECSERVER) - International Business Machines Corporation - C:\SQLLIB\bin\db2sec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe


A Davis
Well, it sure got a lot. :thumbup: But there is more….


1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\system32\fupxrjas.ini
C:\WINDOWS\system32\sajrxpuf.dll
C:\WINDOWS\system32\EEE8F1F2EFEFF1F.exe
C:\WINDOWS\mrofinu1044.exe.tmp

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"2F293233303032332"=-
"70af9248"=-


Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next replyafter you re-enable all the programs that were disabled during the running of ComboFix:
  • Combofix.txt
  • A new HijackThis log.
Please take note:

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Thanks,

DR
More log incoming:

ComboFix 08-01-30.6 - cmcdaniel 2008-01-30 10:32:48.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.700 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\cmcdaniel\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\mrofinu1044.exe.tmp
C:\WINDOWS\system32\EEE8F1F2EFEFF1F.exe
C:\WINDOWS\system32\fupxrjas.ini
C:\WINDOWS\system32\sajrxpuf.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\mrofinu1044.exe.tmp
C:\WINDOWS\system32\EEE8F1F2EFEFF1F.exe
C:\WINDOWS\system32\fupxrjas.ini
C:\WINDOWS\system32\sajrxpuf.dll

.
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-30 )))))))))))))))))))))))))))))))
.

2008-01-30 10:32 . 2008-01-30 10:33 53,248 –a—— C:\WINDOWS\PSEXESVC.EXE
2008-01-28 06:35 . 2008-01-28 06:35 d——– C:\Documents and Settings\LocalService\Application Data\Yahoo!
2008-01-28 06:34 . 2008-01-28 06:34 d——– C:\Documents and Settings\LocalService\Application Data\IE7Pro
2008-01-25 19:30 . 2008-01-25 19:30 d——– C:\WINDOWS\system32\A19BA4A5A2A2A4A
2008-01-24 16:27 . 2008-01-24 16:39 d——– C:\Documents and Settings\cmcdaniel\Application Data\BitTorrent
2008-01-23 09:27 . 2008-01-28 06:46 d——– C:\Program Files\Yahoo!

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-28 13:41 ——— d–h–r C:\Documents and Settings\cmcdaniel\Application Data\yahoo!
2008-01-28 13:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\yahoo!
2007-12-31 13:43 ——— d—–w C:\Program Files\Winamp Toolbar
2007-12-31 13:43 ——— d—–w C:\Program Files\Winamp
2007-12-03 15:28 ——— d—–w C:\Program Files\PKWARE
2007-12-03 15:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\WinZip
2007-12-03 15:26 ——— d—–w C:\Program Files\SoundSpectrum
2007-11-29 19:42 ——— d—–w C:\Documents and Settings\cmcdaniel\Application Data\SoundSpectrum
2007-11-19 15:12 73,216 —-a-w C:\WINDOWS\ST6UNST.EXE
2007-11-19 15:12 286,720 ——w C:\WINDOWS\Setup1.exe
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ——w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 17:20 360,064 ——w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-28 00:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-10 23:56 824,832 —-a-w C:\WINDOWS\system32\wininet.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-12-13 09:49 1185120 –a—— C:\Program Files\Winamp Toolbar\winamptb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}

[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-12-13 09:49 1185120]

[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 14:49 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 14:46 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 14:50 114688]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-05-14 13:28 282624]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk.disabled [2007-10-18 07:59:55 1876]
PKZIP Attachments Status.lnk.disabled [2007-11-16 14:22:25 844]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 01000000
"NoWinKeys"= 01000000
"NoSMMyDocs"= 01000000
"NoSMMyPictures"= 01000000

[HKLM\~\startupfolder\C:^Documents and Settings^cmcdaniel^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=C:\Documents and Settings\cmcdaniel\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=C:\WINDOWS\pss\HotSync Manager.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\MsnMsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2007-05-14 13:28 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"WinampAgent"=C:\Program Files\Winamp\wianmpa.exe

R3 Eacfilt;Eacfilt Miniport;C:\WINDOWS\system32\DRIVERS\eacfilt.sys [2003-03-28 11:37]
R3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2003-03-28 11:36]
S2 IPSECEXT;Nortel Extranet Access Protocol;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2003-03-28 11:36]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-30 10:33:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-30 10:34:08
ComboFix-quarantined-files.txt 2008-01-30 17:33:52
ComboFix2.txt 2008-01-30 14:54:04
.
2008-01-09 10:01:40 — E O F —

Logfile of HijackThis v1.99.1
Scan saved at 10:34, on 2008-01-30
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = gtr1:8080
O2 - BHO: IE7pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IE7pro\IE7Pro.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: E-mail.lnk = ?
O4 - Startup: MicroStation.lnk = C:\Bentley\Program\MicroStation\ustation.exe
O4 - Global Startup: Kodak EasyShare software.lnk.disabled
O4 - Global Startup: PKZIP Attachments Status.lnk.disabled
O8 - Extra context menu item: &Search - ?p=ZSzed001MSUS_ZNxmk788YYUS
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7Pro.dll
O9 - Extra 'Tools' menuitem: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7Pro.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200705…ex/qtplugin.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/1452/ftp…02/cpbrkpie.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = GTRENGINEERING.local
O17 - HKLM\Software\..\Telephony: DomainName = GTRENGINEERING.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = GTRENGINEERING.local
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: DB2 JDBC Applet Server (DB2JDS) - Unknown owner - C:\SQLLIB\bin\db2jds.exe
O23 - Service: DB2 Security Server (DB2NTSECSERVER) - International Business Machines Corporation - C:\SQLLIB\bin\db2sec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

A Davis
cool. :woot:

I was wondering if you deleted the program MyWebSearch through the add or remove programs?

If you did not, you should do that first. Start>Control Panel>Add or Remove Programs and remove MyWebSearch.



We need to remove a couple of HJT entries and then do an on-line scan.

Run HJT (scan only) and put a check next to the following entries:

O8 - Extra context menu item: &Search - ?p=ZSzed001MSUS_ZNxmk788YYUS
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/1452/ftp…02/cpbrkpie.cab


Then hit the Fix Checked button and let HJT do its thing.


Now, please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

Thanks.

DR
DR thanks again for all your efforts btw. Working on the KasperSky scan now (diff sys) Just wanted to update you a on couple things I noticed while following your directions. 1st I couldn't find anything in add/remove for mywebsearch /shrug I have worked on other user computers and been advised to go to Kaspersky before and the install setup seemed alot different this time. I couldn't seem to find anything for "online scan" It had me download the kasper software, after the install and definition update it needed a reboot. Setting for the downloaded "trail" version was different that what I had seen before. I do believe I have all the setting correct, I'm not sure if it will still generate the log file though. Also, you didn't ask for another HJT log file, did you want that with the KasperSky log(if I can get one) A Davis P.S. edited to add info. The kaspersky scan finsihed, it found and repaired more infections. The log file is still being generated, 3-4min, the resulting log file is hugh 53meg plus or minus. So, much to large to C&P into post. Please advise on what the next step is that you'd like me to take.
It's a pleasure to help folks. That is some file size. You can insert it in more than 1 post. Chances are (hopefully) that those infections Kaspersky found are in System Restore or a temp file but we need to see some of it to be sure. See how much of the log you can insert and in particular, the areas where the cleanings happened. Otherwise, how is everything else running? DR BTW, if you see MyWebSA in your Add/Remove Programs, you would want to remove that also.
DR The sytems seems to be running really well, no popup or internet redirect at all. There were no entrys at all in add/remove for any thing close to "my" anything. I checked all loaded programs and everything there looked good. From what I could tell Kaspersky found the infections in the users mail archives, I deleted all that Kaspery found. I'll try and past some of the log as you suggest, but after Kaspery completed it did say it took care of the threats. Below is the 1st section of the log. I will also review the log and see if any of the other sections seem important. I over lapped the 2nd section a bit to show you the next area. I also noted a few same things I will need to mention to the user (keygen. Shame! Shame! Shame!) well now at least I have a good idea of why/how he got inficted. Scan —- Scanned: 387255 Detected: 43 Untreated: 0 Start time: 2008-01-30 12:10 Duration: 01:10:52 Finish time: 2008-01-30 13:21 Signatures published: 2008-01-30 08:37 Detected ——– Status Object —— —— deleted: Trojan program Trojan-Spy.HTML.Fraud.gen (modification) Email message body: Outlook\Personal Folders\Top of Personal Folders\Deleted Items\[From:None][Subject:online account suspended][Time:2007/12/27 14:57:32]/PlainBody//html//[Date Thu, 27 Dec 2007 22:55:42 +0100 (CET)]/UNNAMED quarantined: Trojan program Trojan-Spy.HTML.Fraud.gen (modification) Email message body: Outlook\Personal Folders\Top of Personal Folders\Deleted Items\[From:RegionsNet Online Banking][Subject:Message has a suspicious part : – Spam – online account suspended][Time:2008/01/08 06:52:18]/HTMLBody deleted: adware not-a-virus:AdWare.Win32.Virtumonde.dij Email message attachment: Outlook\Personal Folders\Top of Personal Folders\Sent Items\[From:Chris McDaniel][Subject:][Time:2008/01/24 16:53:10]/keygen.exe//data0003 deleted: adware not-a-virus:AdWare.Win32.Virtumonde.dij Email message attachment: Outlook\Personal Folders\Top of Personal Folders\Sent Items\[From:Chris McDaniel][Subject:][Time:2008/01/24 16:53:10]/keygen.exe//data0004 deleted: adware not-a-virus:AdWare.Win32.Virtumonde.dij Email message attachment: Outlook\Personal Folders\Top of Personal Folders\Sent Items\[From:Chris McDaniel][Subject:][Time:2008/01/24 16:53:10]/keygen.exe//data0005 deleted: Trojan program Trojan.Java.ClassLoader.as File: C:\Documents and Settings\cmcdaniel\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-4037b5ea-3bf289d1.zip/BnnnnBaa.class deleted: Trojan program Trojan.Java.ClassLoader.as File: C:\Documents and Settings\cmcdaniel\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-4037b5ea-3bf289d1.zip/VaannnaaBaa.class deleted: Trojan program Trojan.Java.ClassLoader.as File: C:\Documents and Settings\cmcdaniel\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-4037b5ea-3bf289d1.zip/Bnnnnn.class deleted: adware not-a-virus:AdWare.Win32.Virtumonde.dij File: C:\Documents and Settings\cmcdaniel\My Documents\keygen.exe//data0003 deleted: adware not-a-virus:AdWare.Win32.Virtumonde.dij File: C:\Documents and Settings\cmcdaniel\My Documents\keygen.exe//data0004 deleted: adware not-a-virus:AdWare.Win32.Virtumonde.dij File: C:\Documents and Settings\cmcdaniel\My Documents\keygen.exe//data0005 deleted: adware not-a-virus:AdWare.Win32.Virtumonde.dij File: C:\Documents and Settings\cmcdaniel\My Documents\Downloads\Microsoft Office 2007 Activation Crack.zip/keygen.exe//data0003 deleted: adware not-a-virus:AdWare.Win32.Virtumonde.dij File: C:\Documents and Settings\cmcdaniel\My Documents\Downloads\Microsoft Office 2007 Activation Crack.zip/keygen.exe//data0004 deleted: adware not-a-virus:AdWare.Win32.Virtumonde.dij File: C:\Documents and Settings\cmcdaniel\My Documents\Downloads\Microsoft Office 2007 Activation Crack.zip/keygen.exe//data0005 deleted: adware not-a-virus:AdWare.Win32.Virtumonde.dhx File: C:\QooBox\Quarantine\catchme2008-01-30_ 75135.65.zip/byxvvwv.dll deleted: adware not-a-virus:AdWare.Win32.Virtumonde.edx File: C:\QooBox\Quarantine\catchme2008-01-30_ 75135.65.zip/ddccd.dll deleted: adware not-a-virus:AdWare.Win32.Virtumonde.dnn File: C:\QooBox\Quarantine\catchme2008-01-30_ 75135.65.zip/qszbhtem.dll deleted: Trojan program Trojan-Downloader.Win32.TSUpdate.l File: C:\QooBox\Quarantine\C\Program Files\Common Files\qkii\qkiia.exe.vir//UPX deleted: Trojan program Trojan-Downloader.Win32.TSUpdate.r File: C:\QooBox\Quarantine\C\Program Files\Common Files\qkii\qkiil.exe.vir//UPX deleted: Trojan program Trojan-Downloader.Win32.TSUpdate.n File: C:\QooBox\Quarantine\C\Program Files\Common Files\qkii\qkiim.exe.vir//UPX deleted: Trojan program Trojan-Downloader.Win32.TSUpdate.f File: C:\QooBox\Quarantine\C\Program Files\Common Files\qkii\qkiip.exe.vir//UPX deleted: adware not-a-virus:AdWare.Win32.Rond.d File: C:\QooBox\Quarantine\C\WINDOWS\b103.exe.vir deleted: Trojan program Trojan-Downloader.Win32.Small.buy File: C:\QooBox\Quarantine\C\WINDOWS\b104.exe.vir//stream//data0002//UPX deleted: adware not-a-virus:AdWare.Win32.Mostofate.u File: C:\QooBox\Quarantine\C\WINDOWS\b104.exe.vir//stream//data0004 deleted: Trojan program Trojan-Downloader.Win32.Agent.ezc File: C:\QooBox\Quarantine\C\WINDOWS\b116.exe.vir deleted: Trojan program Trojan-Downloader.Win32.Agent.hvj File: C:\QooBox\Quarantine\C\WINDOWS\b122.exe.vir deleted: Trojan program Trojan-Downloader.Win32.Agent.cbx File: C:\QooBox\Quarantine\C\WINDOWS\b138.exe.vir deleted: Trojan program Trojan-Downloader.Win32.Agent.fjn File: C:\QooBox\Quarantine\C\WINDOWS\b151.exe.vir deleted: Trojan program Trojan-Downloader.Win32.Agent.hvx File: C:\QooBox\Quarantine\C\WINDOWS\mrofinu1044.exe.tmp.vir deleted: Trojan program Trojan-Downloader.Win32.Agent.hvx File: C:\QooBox\Quarantine\C\WINDOWS\mrofinu1044.exe.vir deleted: adware not-a-virus:AdWare.Win32.Virtumonde.dhx File: C:\QooBox\Quarantine\C\WINDOWS\system32\awtrrom.dll.vir deleted: adware not-a-virus:AdWare.Win32.SuperJuan.kp File: C:\QooBox\Quarantine\C\WINDOWS\system32\bkpsdjcb.dll.vir deleted: adware not-a-virus:AdWare.Win32.Virtumonde.dnn File: C:\QooBox\Quarantine\C\WINDOWS\system32\bpasxuyo.dll.vir deleted: Trojan program Trojan-Downloader.Win32.VB.chy File: C:\QooBox\Quarantine\C\WINDOWS\system32\EEE8F1F2EFEFF1F.exe.vir//ASPack//PE_Patch deleted: adware not-a-virus:AdWare.Win32.Virtumonde.dhx File: C:\QooBox\Quarantine\C\WINDOWS\system32\fcywtrq.dll.vir deleted: adware not-a-virus:AdWare.Win32.Virtumonde.dnn File: C:\QooBox\Quarantine\C\WINDOWS\system32\qszbhtem.dll.vir deleted: adware not-a-virus:AdWare.Win32.Virtumonde.edz File: C:\QooBox\Quarantine\C\WINDOWS\system32\sajrxpuf.dll.vir deleted: adware not-a-virus:AdWare.Win32.Virtumonde.dhx File: C:\QooBox\Quarantine\C\WINDOWS\system32\vtutrss.dll.vir deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\QooBox\Quarantine\C\WINDOWS\system32\wscajkeb.exe.vir deleted: adware not-a-virus:AdWare.Win32.CommAd.a File: C:\QooBox\Quarantine\C\WINDOWS\YWRhdmlz\asappsrv.dll.vir//UPX deleted: adware not-a-virus:AdWare.Win32.CommAd.a File: C:\QooBox\Quarantine\C\WINDOWS\YWRhdmlz\command.exe.vir//UPX deleted: adware not-a-virus:AdWare.Win32.Virtumonde.dij File: C:\Documents and Settings\cmcdaniel\My Documents\keygen.exe deleted: adware not-a-virus:AdWare.Win32.Virtumonde.dij File: C:\Documents and Settings\cmcdaniel\My Documents\Downloads\Microsoft Office 2007 Activation Crack.zip/keygen.exe Events —— Time Name Status Reason —- —- —— —— 2008-01-30 12:11 Email message: Outlook\Archive Folders\Top of Personal Folders\BORGATA @ SANTAN\[From:Barker Michael J][Subject:RE: KE1-11452 Part 1][Time:2007/01/26 07:08:51] archive outlook message object system 2008-01-30 12:11 Email message body: Outlook\Archive Folders\Top of Personal Folders\BORGATA @ SANTAN\[From:Barker Michael J][Subject:RE: KE1-11452 Part 1][Time:2007/01/26 07:08:51]/PlainBody archive Mail Everything between here and the end of the file were files on the system that were scanned. all that I noticed said "scanned" & "OK" the Stats I'm pasting below. Statistics ———- Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted —— ——- ——– ——— ——- ——————- ——– ———— —————— ——— All objects 387255 43 0 33 1 18600 2836 771 11 Mailboxes 54833 5 0 2 1 14927 2674 0 11 Local Disk (C:) 332422 38 0 31 0 3673 162 771 0 Settings ——– Parameter Value ——— —– Security Level Recommended Action Prompt for action when the scan is complete Run mode Manually File types Scan all files Scan only new and changed files No Scan archives All Scan embedded OLE objects All Skip if object is larger than No Skip if scan takes longer than No Parse email formats No Scan password-protected archives No Enable iChecker technology Yes Enable iSwift technology Yes Record information about dangerous objects to program statistics Yes
That looks good. You did the right thing. :thumbup: Could you send us another HJT log? Then we should be able to see for certain how clean you are. Thanks. DR
Thanks DR.

HJT log below. I also started a "full system scan" with kaspersky and it has detected more problem files in the \restore folder. I was planning on letting Kaspersky handle those when it finishs it's scan. But will just leave it up untill I hear back from you on how to handle what Kasper is finding now.

Logfile of HijackThis v1.99.1
Scan saved at 14:51, on 2008-01-30
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = gtr1:8080
O2 - BHO: IE7pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IE7pro\IE7Pro.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: E-mail.lnk = ?
O4 - Startup: MicroStation.lnk = C:\Bentley\Program\MicroStation\ustation.exe
O4 - Global Startup: Kodak EasyShare software.lnk.disabled
O4 - Global Startup: PKZIP Attachments Status.lnk.disabled
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7Pro.dll
O9 - Extra 'Tools' menuitem: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7Pro.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200705…ex/qtplugin.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = GTRENGINEERING.local
O17 - HKLM\Software\..\Telephony: DomainName = GTRENGINEERING.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = GTRENGINEERING.local
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe" -r (file missing)
O23 - Service: DB2 JDBC Applet Server (DB2JDS) - Unknown owner - C:\SQLLIB\bin\db2jds.exe
O23 - Service: DB2 Security Server (DB2NTSECSERVER) - International Business Machines Corporation - C:\SQLLIB\bin\db2sec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

A Davis

P.S. checking out for the day. Will check back tomorrow. Thanks again DR and have a good eve.
You are good to go. :thumbup:

If you like the Kaspersky AV, you could keep it but don't run more than 1 AV software at any one time. They conflict with each other. I see you still have the Kaspersky but I have listed some free ones below.


Lets Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)

1. Turn OFF System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check Turn off System Restore.
Click Apply, and then click OK.



Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

  • Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

    See this link for a listing of some online & their stand-alone antivirus programs:

    Virus, Spyware, and Malware Protection and Removal Resources

  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:


    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.

    A tutorial on installing & using this product can be found here:

    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

    A tutorial on installing & using this product can be found here:

    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.

Glad I was able to help.


DR
Thanks DR. I will read and follow your advise. Just 1 last thing if I could bother you for, I would like to un install combofix, I believe the uninstall is the same for any/all systems. but would like your input before I search and follow another threads uninstall instructions. Thanks A Davis
Yes, I agree about uninstalling ComboFix. You do that by going to Start>Run and type in combofix /u (don't forget the space between x and /).

You can also uninstall HijackThis and any other tools that we might have used.

Good luck.

DR

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI