This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan Dropper Agent GIT

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I am new here and new to this stuff. I ran AVG and that is how I found out that was the Trojan Dropper Agent GIT. AVG healed the files that were infected, which I believe deleted a bunch of my programs I had installed, which didn't help. That is all I have done so far. Thanks in advanced as I am new to all this.

Hijack log is:

Logfile of HijackThis v1.99.1
Scan saved at 1:31:51 PM, on 1/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

F3 - REG:win.ini: load=C:\WINDOWS\system32\awtqp.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: {5606482c-e353-cb8a-86b4-a2314d40acc0} - {0cca04d4-132a-4b68-a8bc-353ec2846065} - C:\WINDOWS\system32\dclkcmsq.dll
O2 - BHO: (no name) - {4B673BF0-4B39-4E26-A133-AA94D05E3C6C} - C:\WINDOWS\system32\awtqp.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\efcawuv.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [08ce933f] rundll32.exe "C:\WINDOWS\system32\umtytodc.dll",b
O4 - Startup: OpenOffice.org 2.2.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1167123641483
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1167123629639
O16 - DPF: {F5D98C43-DB16-11CF-8ECA-0000C0FD59C7} (ActiveCGM Control) - http://www.webmap.niu.edu/campus/ACGM/Acgm.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: efcawuv - C:\WINDOWS\SYSTEM32\efcawuv.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\gknowcvb.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
Welcome to What the Tech, sorry if there was a delay, it's a busy forum.

Please either print these instructions or save them to Notepad because you wont have Internet access during some of them.

You don't seem to be running a firewall. If you're not running any firewall or are not sure please follow these instructions to turn Windows Firewall on.

Click on the Windows Start button in the left hand corner of your screen.
Go to Control Panel or settings Control Panel
Double click on Windows Firewall
The two main options are On and Off.
Check to see if there's a checkmark next to On and if not please select it.

Please now let me know if you are using Windows Firewall or another one.


Please download ComboFix by sUBs from HERE or HERE

You must download it to your Desktop

Go to [external image: Posted Image] -> Run -> paste in the following single line command & click OK


"%userprofile%\desktop\combofix.exe" /killall



[external image: Posted Image]

ComboFix will automatically start, any monitoring programs will be shut down like your antivirus, antispyware programs for example.

ComboFix may restart your computer, this is normal.

When finished, it will produce a log. Please save its log to post in your next reply .

Note:
Do not mouse-click Combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

If CombFix did not reboot your computer, please do so now.


I'd like to see an Uninstall List.
Please open up HijackThis.
Click on Open the Misc Tools section button
Click on Open Uninstall Manager
Click on Save list
A Notepad document will open with a list of your installed programs. Please copy that into your reply.

Now please post a new HijackThis(HJT) and let me know how your computer is running.

Logs to include in your reply
ComboFix
Uninstall List
HJT
Computer is running fine or so it seems. The first time I ran AVG it deleted a file called umtytodc.dll and it comes up with an error when I start Windows.

ComboFix 08-01-29.1 - Scotty Potty 2008-01-28 15:54:03.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.670 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\QdrDrive
C:\Program Files\Temporary
C:\WINDOWS\racle~1
C:\WINDOWS\system32\awtqp.dll
C:\WINDOWS\system32\cdotytmu.ini
C:\WINDOWS\system32\dclkcmsq.dll
C:\WINDOWS\system32\fjhhiwvb.ini
C:\WINDOWS\system32\pqtwa.ini
C:\WINDOWS\system32\pqtwa.ini2
C:\WINDOWS\system32\RCX1F.tmp
C:\WINDOWS\system32\ssqfcvoh.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_DOMAINSERVICE
——-\DomainService


((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-29 )))))))))))))))))))))))))))))))
.

2008-01-28 12:01 . 2008-01-28 12:34 d——– C:\Documents and Settings\Scotty Potty\Application Data\AVG7
2008-01-28 12:01 . 2008-01-28 12:01 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-28 12:01 . 2008-01-28 12:34 d——– C:\Documents and Settings\All Users\Application Data\avg7
2008-01-28 12:01 . 2008-01-28 12:01 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2008-01-28 12:01 . 2008-01-28 12:01 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2008-01-27 18:23 . 2008-01-27 18:23 155,648 –a—— C:\WINDOWS\system32\NeroCheck .exe
2008-01-26 14:39 . 2008-01-28 12:32 344,064 –a—— C:\WINDOWS\system32\awtqp.exe
2008-01-26 14:30 . 2008-01-26 14:30 270,698 –a—— C:\WINDOWS\system32\L57DE.tmp
2008-01-26 14:30 . 2008-01-26 14:30 181,965 –a—— C:\WINDOWS\system32\L1567.tmp
2008-01-26 14:30 . 2008-01-26 14:30 39,936 –a—— C:\WINDOWS\system32\efcawuv.dll
2008-01-15 01:53 . 2004-08-03 23:08 31,616 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys
2008-01-15 01:53 . 2004-08-03 23:08 31,616 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-01-15 01:53 . 2004-08-04 00:56 21,504 –a—— C:\WINDOWS\system32\hidserv.dll
2008-01-15 01:53 . 2004-08-04 00:56 21,504 –a–c— C:\WINDOWS\system32\dllcache\hidserv.dll
2008-01-15 01:53 . 2004-08-03 22:58 14,848 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys
2008-01-15 01:53 . 2004-08-03 22:58 14,848 –a–c— C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-01-15 01:53 . 2001-08-17 13:48 12,160 –a—— C:\WINDOWS\system32\drivers\mouhid.sys
2008-01-15 01:53 . 2001-08-17 13:48 12,160 –a–c— C:\WINDOWS\system32\dllcache\mouhid.sys
2008-01-14 12:04 . 2008-01-14 12:04 34 –a—— C:\WINDOWS\NPinfotl.INI
2008-01-06 23:31 . 2008-01-28 08:02 d——– C:\Documents and Settings\Scotty Potty\Application Data\skypePM
2008-01-06 23:31 . 2008-01-06 23:31 32 –a—— C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-01-06 23:20 . 2008-01-28 11:58 d——– C:\Documents and Settings\Scotty Potty\Application Data\Skype
2008-01-06 23:17 . 2008-01-06 23:18 d——– C:\Program Files\Skype
2008-01-06 23:17 . 2008-01-06 23:17 d——– C:\Program Files\Common Files\Skype
2008-01-06 23:17 . 2008-01-06 23:18 d——– C:\Documents and Settings\All Users\Application Data\Skype
2008-01-03 13:21 . 2008-01-03 13:21 d——– C:\WINDOWS\system32\Futuremark
2008-01-03 13:21 . 2008-01-03 13:21 d——– C:\Program Files\Common Files\Futuremark Shared
2008-01-03 13:21 . 2008-01-03 13:21 d——– C:\Documents and Settings\Scotty Potty\Application Data\InstallShield
2008-01-03 13:21 . 2007-10-11 11:55 27,672 -ra—— C:\WINDOWS\system32\drivers\Entech.sys
2007-12-31 18:21 . 2007-12-31 18:35 620 –a—— C:\WINDOWS\tlknw10.ini
2007-12-29 12:57 . 2007-12-29 13:19 627 –a—— C:\WINDOWS\tlknw20.ini
2007-12-29 02:30 . 2008-01-28 12:32 d——– C:\Program Files\DAEMON Tools Lite
2007-12-29 02:30 . 2007-12-29 02:41 d——– C:\Documents and Settings\Scotty Potty\Application Data\DAEMON Tools
2007-12-29 02:26 . 2007-12-29 02:26 715,248 –a—— C:\WINDOWS\system32\drivers\sptd.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-28 21:43 ——— d—–w C:\Documents and Settings\Scotty Potty\Application Data\OpenOffice.org2
2008-01-28 19:14 ——— d—–w C:\Program Files\QuickTime
2008-01-28 18:32 ——— d—–w C:\Program Files\Steam
2008-01-28 18:32 ——— d—–w C:\Program Files\Linksys EasyLink Advisor
2008-01-28 18:26 ——— d—–w C:\Program Files\PeerGuardian2
2008-01-28 18:01 ——— d—–w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-28 17:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-28 17:50 12,632 —-a-w C:\WINDOWS\system32\lsdelete.exe
2008-01-28 07:13 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-01-17 16:31 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-01-17 16:31 107,832 —-a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-01-09 19:41 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-03 19:21 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-12 08:55 ——— d—–w C:\Program Files\Java
2007-11-28 23:36 ——— d–ha-w C:\Documents and Settings\All Users\Application Data\GTek
2007-11-28 23:36 ——— d–h–w C:\Documents and Settings\Scotty Potty\Application Data\GTek
2007-11-28 23:36 ——— d—–w C:\Documents and Settings\Default User\Application Data\Gtek
2007-11-28 07:39 102,664 —-a-w C:\WINDOWS\system32\drivers\tmcomm.sys
2007-11-13 01:07 66,872 —-a-w C:\WINDOWS\system32\PnkBstrA.exe
2007-11-12 21:36 22,328 —-a-w C:\Documents and Settings\Scotty Potty\Application Data\PnkBstrK.sys
2007-10-10 21:53 67,888 —-a-w C:\Documents and Settings\Scotty Potty\Application Data\GDIPFONTCACHEV1.DAT
.
—-a-w		   790,528 2008-01-28 00:23:27  C:\Program Files\Analog Devices\SoundMAX\SMax4PNP .exe
—-a-w		   335,872 2008-01-28 00:23:25  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
—-a-w		   486,856 2008-01-28 00:23:34  C:\Program Files\DAEMON Tools Lite\daemon .exe
—-a-w		   579,072 2008-01-28 18:33:11  C:\Program Files\Grisoft\AVG7\avgcc .exe
—-a-w		   132,496 2008-01-28 00:23:30  C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
—-a-w		   454,784 2008-01-28 00:23:34  C:\Program Files\Linksys EasyLink Advisor\LinksysAgent .exe
—-a-w		 1,667,584 2008-01-28 00:23:32  C:\Program Files\Messenger\msmsgs .exe
—-a-w		 1,266,936 2008-01-28 00:23:35  C:\Program Files\Steam\steam .exe
—-a-w		   155,648 2008-01-28 00:23:30  C:\WINDOWS\system32\NeroCheck .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 09:50 19968 C:\WINDOWS\LOGI_MWX.EXE]
"08ce933f"="C:\WINDOWS\system32\umtytodc.dll" [ ]

C:\Documents and Settings\Scotty Potty\Start Menu\Programs\Startup\
OpenOffice.org 2.2.lnk - C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe [2007-02-02 17:54:56 393216]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2007-02-08 02:18:39 184320]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcawuv]
efcawuv.dll 2008-01-26 14:30 39936 C:\WINDOWS\system32\efcawuv.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\awtqp

R3 LCcfltr;Logitech USB Filter Driver;C:\WINDOWS\system32\Drivers\LCcFltr.Sys [2003-12-17 09:50]
S3 ASUSHWIO;ASUSHWIO;C:\WINDOWS\system32\drivers\ASUSHWIO.sys []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f21acfd8-efb8-11db-adfa-000ea6aaaa62}]
\Shell\AutoRun\command - H:\wd_windows_tools\setup.exe

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-29 15:57:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN
.
**************************************************************************
.
Completion time: 2008-01-29 15:59:46 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-29 21:59:44

Uninstall List
µTorrent
Ad-Aware 2007
Adobe Acrobat 5.0
Adobe Flash Player ActiveX
Adobe Shockwave Player
ASUS Probe V2.21.07
AsusUpdate
ATI - Software Uninstall Utility
ATI Control Panel
ATI Display Driver
ATI HydraVision
ATITool Overclocking Utility
AVG 7.5
Azureus Vuze
Call of Duty® 2
Call of Duty® 4 - Modern Warfare™
Digital Photo Navigator 1.5
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
Drivers Install For Linksys Easylink Advisor
Futuremark SystemInfo
Google Earth
Hijackthis 1.99.1
HijackThis 1.99.1
Hotfix for Windows XP (KB926239)
Intel® PRO Network Adapters and Drivers
InterVideo WinDVD 5
J2SE Runtime Environment 5.0 Update 10
Java™ 6 Update 2
Java™ 6 Update 3
Java™ SE Runtime Environment 6
JetShell PRO
Linksys EasyLink Advisor 1.6 (0032)
Logitech MouseWare 9.79.1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office XP Professional with FrontPage
Microsoft Publisher 2002
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (2.0.0.11)
Mozilla Thunderbird ([removed])
Nero - Burning Rom
OpenOffice.org 2.2
PeerGuardian 2.0
QuickTime
Rhapsody Player Engine
Sierra Utilities
Skype™ 3.6
SoundMAX
Starcraft
Steam
System Requirements Lab
Team Fortress 2
Windows Installer 3.1 (KB893803)
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Service Pack 2
WinRAR archiver
WinZip
ZIP Reader 8.00.0018


HijackThis

Logfile of HijackThis v1.99.1
Scan saved at 4:06:14 PM, on 1/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [08ce933f] rundll32.exe "C:\WINDOWS\system32\umtytodc.dll",b
O4 - Startup: OpenOffice.org 2.2.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1167123641483
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1167123629639
O16 - DPF: {F5D98C43-DB16-11CF-8ECA-0000C0FD59C7} (ActiveCGM Control) - http://www.webmap.niu.edu/campus/ACGM/Acgm.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: efcawuv - C:\WINDOWS\SYSTEM32\efcawuv.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
Please save the code below to Notepad and save it as CFScript.txt to your Desktop.
File::
C:\WINDOWS\system32\awtqp.exe
C:\WINDOWS\system32\efcawuv.dll

Driver::
ASUSHWIO

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"08ce933f"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcawuv]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00

RENV::
—-a-w		   790,528 2008-01-28 00:23:27  C:\Program Files\Analog Devices\SoundMAX\SMax4PNP .exe
—-a-w		   335,872 2008-01-28 00:23:25  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
—-a-w		   486,856 2008-01-28 00:23:34  C:\Program Files\DAEMON Tools Lite\daemon .exe
—-a-w		   579,072 2008-01-28 18:33:11  C:\Program Files\Grisoft\AVG7\avgcc .exe
—-a-w		   132,496 2008-01-28 00:23:30  C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
—-a-w		   454,784 2008-01-28 00:23:34  C:\Program Files\Linksys EasyLink Advisor\LinksysAgent .exe
—-a-w		 1,667,584 2008-01-28 00:23:32  C:\Program Files\Messenger\msmsgs .exe
—-a-w		 1,266,936 2008-01-28 00:23:35  C:\Program Files\Steam\steam .exe
—-a-w		   155,648 2008-01-28 00:23:30  C:\WINDOWS\system32\NeroCheck .exe

Now please drag CFScript.txt on the ComboFix icon on your Desktop as shown below.
[external image: Posted Image]

ComboFix will automatically start up and run, please save it's log when finished.

If ComboFix does not reboot your system, please do so now.


Click on the Windows Start button in the left hand corner of your screen.
Go to Control Panel or Settings>Control Panel
Double click on Add or Remove Programs and uninstall
J2SE Runtime Environment 5.0 Update 10
Java™ 6 Update 2


Please post a new HJT log.

Logs to include in your reply
ComboFix
HJT
Everything seems okay still, I do not have that umtydodc.dll error message anymore.


ComboFix 08-01-29.1 - Scotty Potty 2008-01-30 10:59:43.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.623 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Scotty Potty\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\system32\awtqp.exe
C:\WINDOWS\system32\efcawuv.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\awtqp.exe
C:\WINDOWS\system32\efcawuv.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_ASUSHWIO
——-\ASUSHWIO


((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-30 )))))))))))))))))))))))))))))))
.

2008-01-28 12:01 . 2008-01-28 12:34 d——– C:\Documents and Settings\Scotty Potty\Application Data\AVG7
2008-01-28 12:01 . 2008-01-28 12:01 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-28 12:01 . 2008-01-28 12:34 d——– C:\Documents and Settings\All Users\Application Data\avg7
2008-01-28 12:01 . 2008-01-28 12:01 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2008-01-28 12:01 . 2008-01-28 12:01 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2008-01-27 18:23 . 2008-01-27 18:23 155,648 –a—— C:\WINDOWS\system32\NeroCheck.exe
2008-01-26 14:30 . 2008-01-26 14:30 270,698 –a—— C:\WINDOWS\system32\L57DE.tmp
2008-01-26 14:30 . 2008-01-26 14:30 181,965 –a—— C:\WINDOWS\system32\L1567.tmp
2008-01-15 01:53 . 2004-08-03 23:08 31,616 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys
2008-01-15 01:53 . 2004-08-03 23:08 31,616 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-01-15 01:53 . 2004-08-04 00:56 21,504 –a—— C:\WINDOWS\system32\hidserv.dll
2008-01-15 01:53 . 2004-08-04 00:56 21,504 –a–c— C:\WINDOWS\system32\dllcache\hidserv.dll
2008-01-15 01:53 . 2004-08-03 22:58 14,848 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys
2008-01-15 01:53 . 2004-08-03 22:58 14,848 –a–c— C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-01-15 01:53 . 2001-08-17 13:48 12,160 –a—— C:\WINDOWS\system32\drivers\mouhid.sys
2008-01-15 01:53 . 2001-08-17 13:48 12,160 –a–c— C:\WINDOWS\system32\dllcache\mouhid.sys
2008-01-14 12:04 . 2008-01-14 12:04 34 –a—— C:\WINDOWS\NPinfotl.INI
2008-01-06 23:31 . 2008-01-28 08:02 d——– C:\Documents and Settings\Scotty Potty\Application Data\skypePM
2008-01-06 23:31 . 2008-01-06 23:31 32 –a—— C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-01-06 23:20 . 2008-01-28 11:58 d——– C:\Documents and Settings\Scotty Potty\Application Data\Skype
2008-01-06 23:17 . 2008-01-06 23:18 d——– C:\Program Files\Skype
2008-01-06 23:17 . 2008-01-06 23:17 d——– C:\Program Files\Common Files\Skype
2008-01-06 23:17 . 2008-01-06 23:18 d——– C:\Documents and Settings\All Users\Application Data\Skype
2008-01-03 13:21 . 2008-01-03 13:21 d——– C:\WINDOWS\system32\Futuremark
2008-01-03 13:21 . 2008-01-03 13:21 d——– C:\Program Files\Common Files\Futuremark Shared
2008-01-03 13:21 . 2008-01-03 13:21 d——– C:\Documents and Settings\Scotty Potty\Application Data\InstallShield
2008-01-03 13:21 . 2007-10-11 11:55 27,672 -ra—— C:\WINDOWS\system32\drivers\Entech.sys
2007-12-31 18:21 . 2007-12-31 18:35 620 –a—— C:\WINDOWS\tlknw10.ini
2007-12-29 12:57 . 2007-12-29 13:19 627 –a—— C:\WINDOWS\tlknw20.ini
2007-12-29 02:30 . 2008-01-30 10:59 d——– C:\Program Files\DAEMON Tools Lite
2007-12-29 02:30 . 2007-12-29 02:41 d——– C:\Documents and Settings\Scotty Potty\Application Data\DAEMON Tools
2007-12-29 02:26 . 2007-12-29 02:26 715,248 –a—— C:\WINDOWS\system32\drivers\sptd.sys
2007-12-28 03:30 . 2008-01-09 13:41 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-12 17:27 . 2004-12-07 11:33 0 –a—— C:\WINDOWS\9780073191867.mh

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-30 17:02 ——— d—–w C:\Documents and Settings\Scotty Potty\Application Data\OpenOffice.org2
2008-01-30 16:59 ——— d—–w C:\Program Files\Steam
2008-01-30 16:59 ——— d—–w C:\Program Files\Linksys EasyLink Advisor
2008-01-28 19:14 ——— d—–w C:\Program Files\QuickTime
2008-01-28 18:26 ——— d—–w C:\Program Files\PeerGuardian2
2008-01-28 18:01 ——— d—–w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-28 17:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-28 17:50 12,632 —-a-w C:\WINDOWS\system32\lsdelete.exe
2008-01-28 07:13 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-01-17 16:31 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-01-17 16:31 107,832 —-a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-01-03 19:21 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-12 08:55 ——— d—–w C:\Program Files\Java
2007-11-28 23:36 ——— d–ha-w C:\Documents and Settings\All Users\Application Data\GTek
2007-11-28 23:36 ——— d–h–w C:\Documents and Settings\Scotty Potty\Application Data\GTek
2007-11-28 23:36 ——— d—–w C:\Documents and Settings\Default User\Application Data\Gtek
2007-11-28 07:39 102,664 —-a-w C:\WINDOWS\system32\drivers\tmcomm.sys
2007-11-13 01:07 66,872 —-a-w C:\WINDOWS\system32\PnkBstrA.exe
2007-11-12 21:36 22,328 —-a-w C:\Documents and Settings\Scotty Potty\Application Data\PnkBstrK.sys
2007-10-10 21:53 67,888 —-a-w C:\Documents and Settings\Scotty Potty\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2008-01-27 18:23 335872]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 09:50 19968 C:\WINDOWS\LOGI_MWX.EXE]

C:\Documents and Settings\Scotty Potty\Start Menu\Programs\Startup\
OpenOffice.org 2.2.lnk - C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe [2007-02-02 17:54:56 393216]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2007-02-08 02:18:39 184320]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]

R3 LCcfltr;Logitech USB Filter Driver;C:\WINDOWS\system32\Drivers\LCcFltr.Sys [2003-12-17 09:50]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f21acfd8-efb8-11db-adfa-000ea6aaaa62}]
\Shell\AutoRun\command - H:\wd_windows_tools\setup.exe

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-30 11:02:48
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN
.
**************************************************************************
.
Completion time: 2008-01-30 11:04:08 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-30 17:04:05
ComboFix2.txt 2008-01-29 21:59:46


HijackThis

Logfile of HijackThis v1.99.1
Scan saved at 11:07:57 AM, on 1/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - Startup: OpenOffice.org 2.2.lnk = C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1167123641483
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1167123629639
O16 - DPF: {F5D98C43-DB16-11CF-8ECA-0000C0FD59C7} (ActiveCGM Control) - http://www.webmap.niu.edu/campus/ACGM/Acgm.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
Both logs look clean. :thumbup:

Download: CCleaner (freeware)
http://www.majorgeeks.com/download4191.html
Run the installer, and uncheck the option to install Yahoo toolbar (unless you want Yahoo toolbar).
Once installed, run CCleaner click the Windows
The following should be selected by default, if not, please select:
[external image: Posted Image]
Next: click Options click the Settings tab
Uncheck: "Only delete files older than 48 hrs.", click Ok
Then click Run Cleaner (bottom right) then Exit

* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, Click Options > Change settings
  • Choose the "Scan"-tab, remove the mark at "Heuristic analysis".
  • Back at the main window, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found: [external image: Posted Image]
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    [external image: Posted Image]
    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.

Please let me know how your computer is running now. Are you having any problems running any programs?

Logs to include in your reply
Dr.Web CureIt
Computer is running faster than before. All the programs seem to be working fine =) 02598703.FIL;C:\$VAULT$.AVG;Trojan.MulDrop.10006;Deleted.; 02600843.FIL;C:\$VAULT$.AVG;Trojan.MulDrop.10006;Deleted.; 02602015.FIL;C:\$VAULT$.AVG;Trojan.MulDrop.10006;Deleted.; 02603000.FIL;C:\$VAULT$.AVG;Trojan.MulDrop.10006;Deleted.; 02603750.FIL;C:\$VAULT$.AVG;Trojan.MulDrop.10006;Deleted.; 02604250.FIL;C:\$VAULT$.AVG;Trojan.MulDrop.10006;Deleted.; 02605250.FIL;C:\$VAULT$.AVG;Trojan.MulDrop.10006;Deleted.; 02607000.FIL;C:\$VAULT$.AVG;Trojan.MulDrop.10006;Deleted.; 02608218.FIL;C:\$VAULT$.AVG;Trojan.MulDrop.10006;Deleted.; 02608859.FIL;C:\$VAULT$.AVG;Trojan.MulDrop.10006;Deleted.; 02608906.FIL;C:\$VAULT$.AVG;Trojan.DownLoader.45546;Deleted.; 02609015.FIL;C:\$VAULT$.AVG;Trojan.Juan.29;Deleted.; 02609484.FIL;C:\$VAULT$.AVG;Trojan.DownLoader.45546;Deleted.; 02610343.FIL;C:\$VAULT$.AVG;Trojan.Juan.29;Deleted.; 02610796.FIL;C:\$VAULT$.AVG;Trojan.EzulaAd;Deleted.; 02611921.FIL;C:\$VAULT$.AVG;Trojan.MulDrop.10006;Deleted.; 02613265.FIL;C:\$VAULT$.AVG;Trojan.MulDrop.10006;Deleted.; 02614781.FIL;C:\$VAULT$.AVG;Trojan.MulDrop.10006;Deleted.; 02616515.FIL;C:\$VAULT$.AVG;Trojan.MulDrop.10006;Deleted.; awtqp.exe.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.MulDrop.10006;Deleted.; dclkcmsq.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Juan.29;Deleted.; efcawuv.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.origin;Incurable.Moved.; RCX1F.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.MulDrop.10006;Deleted.; ssqfcvoh.dll.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.Juan.29;Deleted.; A0030782.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP198;Trojan.MulDrop.10006;Deleted.; A0030792.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP198;Trojan.MulDrop.10006;Deleted.; A0030794.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP198;Trojan.MulDrop.10006;Deleted.; A0030795.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP198;Trojan.MulDrop.10006;Deleted.; A0030801.dll;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP198;Adware.ClickSpring.origin;Moved.; <— moved that myself A0030803.dll;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP198;Adware.ClickSpring - read error;; A0030804.dll;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP198;Adware.SearchAid.origin;Moved.; <—- moved also myself A0030810.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP198;Trojan.MulDrop.10006;Deleted.; A0030811.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP198;Trojan.MulDrop.10006;Deleted.; A0030812.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP198;Trojan.MulDrop.10006;Deleted.; A0030813.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP198;Trojan.MulDrop.10006;Deleted.; A0030814.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP198;Trojan.MulDrop.10006;Deleted.; A0030815.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP198;Trojan.MulDrop.10006;Deleted.; A0030816.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP198;Trojan.MulDrop.10006;Deleted.; A0030817.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP198;Trojan.MulDrop.10006;Deleted.; A0030818.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP198;Trojan.MulDrop.10006;Deleted.; A0030865.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP200;Trojan.EzulaAd;Deleted.; A0030866.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP200;Trojan.Winpop.origin;Incurable.Moved.; A0030873.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP200;Trojan.EzulaAd;Deleted.; A0030876.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP200;Trojan.MulDrop.10006;Deleted.; A0030878.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP200;Trojan.MulDrop.10006;Deleted.; A0030879.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP200;Trojan.MulDrop.10006;Deleted.; A0030880.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP200;Trojan.MulDrop.10006;Deleted.; A0030882.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP200;Trojan.MulDrop.10006;Deleted.; A0030883.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP200;Trojan.MulDrop.10006;Deleted.; A0030885.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP200;Trojan.MulDrop.10006;Deleted.; A0030886.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP200;Trojan.MulDrop.10006;Deleted.; A0030889.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP200;Trojan.MulDrop.10006;Deleted.; A0030892.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP200;Trojan.MulDrop.10006;Deleted.; A0030893.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP200;Trojan.MulDrop.10006;Deleted.; A0030894.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP200;Trojan.MulDrop.10006;Deleted.; A0030903.dll;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP201;Trojan.Juan.29;Deleted.; A0030904.dll;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP201;Trojan.Juan.29;Deleted.; A0030962.exe;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP203;Trojan.MulDrop.10006;Deleted.; A0030963.dll;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP203;Trojan.Virtumod.origin;Incurable.Moved.;
Glad to hear your computer is running much better :thumbup: and I'm glad to have been able to have to help you with it.

Reconfigure Windows XP to show hidden files:
Click Start. Go to All Programs, go to Accessories and then click Windows Explorer

In Windows Explorer click the Tools Menu, then click Folder Options. Switch to the View tab. Under Hidden files and folders check the Show hidden files and folders circle. Uncheck the Hide protected operating system files circle. A warning box will come up asking if you want to do this, press Yes. Press Apply and then OK.

Please delete these folders listed below in bold.
C:\Documents and Settings\Scotty Potty\DoctorWeb\Quarantine\QooBox <– This folder
C:\Documents and Settings\Scotty Potty\DoctorWeb\Quarantine\System Volume Information <– This folder

Reconfigure Windows XP to hide hidden files:
Click Start. Go to All Programs, go to Accessories and then click Windows Explorer

In Windows Explorer click the Tools Menu, then click Folder Options. Switch to the View tab. Under Hidden files and folders check the Do not show hidden files and folders circle. Check the Hide protected operating system files circle.Press Apply and then OK.

b]Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.


    • [external image: Posted Image]

  • When shown the disclaimer, Select "2"

The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Set a new, clean Restore Point.


Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)

1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.

Now please reboot.



Windows Firewall is not very adequate as it only blocks incoming connections and not outgoing, while this is better than nothing, a 3rd party firewall will block both and increase your security. Therefore I highly recommend you install one of the following free versions of commercial products.
FREE Comodo Firewall Pro
Outpost Free Firewall
Once either of these programs are installed Windows Firewall will automatically turn itself off.


Your version of Java is outdated and needs to be updated to take advantage of fixes that have eliminated security vulnerabilities.
Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 4".
  • Click the "Download" button to the right.
  • In the Window that opens, select Windows, your Language, check the "agree" box and click Continue.
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    - Examples of older versions in Add or Remove Programs:
    • Java 2 Runtime Environment, SE v1.4.2
    • J2SE Runtime Environment 5.0
    • J2SE Runtime Environment 5.0 Update 2
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u4-windows-i586-p.exe that you downloaded to install the newest version.


You aren't running the latest version of Adobe Reader. There are security exploits in previous versions that have been addressed in the latest version. For more information please see this site. Please uninstall your current version and go to this site and install the latest version.


Now here's some advice to help prevent reinfection.

1)Please either enable Automatic Updates under Start -> Control Panel -> Automatic Updates , or get into the habit of checking for Windows updates regularly. I cannot stress enough how important this is.

2) In order to protect yourself against spyware, you should consider installing and running the following free programs:

One important thing to note, if you decide to install more than one antispyware program(and at least 2 are advisable these days) please make sure only 1 has resident protection enabled to avoid conflicts, however the latter 2 shouldn't conflict with similar programs or each other.

Spybot-Search & Destroy
A tutorial on using Spybot to remove spyware from your computer may be found here. Please also remember to enable Spybot's "Immunize" and "TeaTimer" features.

SpywareBlaster
A tutorial on using SpywareBlaster to prevent spyware from ever installing on your computer may be found here.

SpywareGuard
A tutorial on using SpywareGuard for realtime protection against spyware and hijackers may be found here.

Make sure to keep these programs up-to-date and to run them regularly, as this can prevent a great deal of spyware hassle.

3) Also make sure to run your antivirus software regularly, and to keep it up-to-date.

Please also read Tony Klein's excellent article: How I got Infected in the First Place
Please delete these folders listed below in bold. C:\Documents and Settings\Scotty Potty\DoctorWeb\Quarantine\QooBox <– This folder C:\Documents and Settings\Scotty Potty\DoctorWeb\Quarantine\System Volume Information <– This folder I did not have either of these in the Quarantine folder. I did a search and QooBox is located at C:\QooBox. Should I delete it? System Volume Information is under C:\System Volume Information but it is empty. Delete it anyways? Just want to make sure I am deleting the right files =)
No, please don't delete those folders.
Instead delete these files listed in bold.
C:\Documents and Settings\Scotty Potty\DoctorWeb\Quarantine\efcawuv.dll.vir
C:\Documents and Settings\Scotty Potty\DoctorWeb\Quarantine\A0030801.dll
C:\Documents and Settings\Scotty Potty\DoctorWeb\Quarantine\A0030804.dll
C:\Documents and Settings\Scotty Potty\DoctorWeb\Quarantine\A0030866.exe
C:\Documents and Settings\Scotty Potty\DoctorWeb\Quarantine\A0030963.dll

What did you mean when you added these sentences to these files?

A0030801.dll;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP198;Adware.ClickSpring.origin;Moved.; <— moved that myself


A0030804.dll;C:\System Volume Information\_restore{2BB0292E-49A4-4779-873A-85849D134795}\RP198;Adware.SearchAid.origin;Moved.; <—- moved also myself


Also how many of the other instructions I gave you have you already done?
I have not done anything yet. Wanted to make sure that I did not delete anything I was not supposed to. When I ran the program it did not do anything with those 2 files found and I misread your instructions. I then highlighted those 2 files and click move.
That explains it, please do not choose to move or delete any files when a program gives you the option unless instructed or given information in advance about such things that may instruct you how to handle such things, doing so could mean moving or deleting a false positive or legitimate file, etc. and therefore cause problems on your computer. If it didn't want to do anything with it then that's because the program didn't feel it needed to and although the program is not infallible, it usually has a good reason for choosing what actions for files, etc. it makes.

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.


    • [external image: Posted Image]

  • When shown the disclaimer, Select "2"

The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Set a new, clean Restore Point.


Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)

1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.

Now please reboot.



Windows Firewall is not very adequate as it only blocks incoming connections and not outgoing, while this is better than nothing, a 3rd party firewall will block both and increase your security. Therefore I highly recommend you install one of the following free versions of commercial products.
FREE Comodo Firewall Pro
Outpost Free Firewall
Once either of these programs are installed Windows Firewall will automatically turn itself off.


Your version of Java is outdated and needs to be updated to take advantage of fixes that have eliminated security vulnerabilities.
Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 4".
  • Click the "Download" button to the right.
  • In the Window that opens, select Windows, your Language, check the "agree" box and click Continue.
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    - Examples of older versions in Add or Remove Programs:
    • Java 2 Runtime Environment, SE v1.4.2
    • J2SE Runtime Environment 5.0
    • J2SE Runtime Environment 5.0 Update 2
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u4-windows-i586-p.exe that you downloaded to install the newest version.


You aren't running the latest version of Adobe Reader. There are security exploits in previous versions that have been addressed in the latest version. For more information please see this site. Please uninstall your current version and go to this site and install the latest version.


Now here's some advice to help prevent reinfection.

1)Please either enable Automatic Updates under Start -> Control Panel -> Automatic Updates , or get into the habit of checking for Windows updates regularly. I cannot stress enough how important this is.

2) In order to protect yourself against spyware, you should consider installing and running the following free programs:

One important thing to note, if you decide to install more than one antispyware program(and at least 2 are advisable these days) please make sure only 1 has resident protection enabled to avoid conflicts, however the latter 2 shouldn't conflict with similar programs or each other.

Spybot-Search & Destroy
A tutorial on using Spybot to remove spyware from your computer may be found here. Please also remember to enable Spybot's "Immunize" and "TeaTimer" features.

SpywareBlaster
A tutorial on using SpywareBlaster to prevent spyware from ever installing on your computer may be found here.

SpywareGuard
A tutorial on using SpywareGuard for realtime protection against spyware and hijackers may be found here.

Make sure to keep these programs up-to-date and to run them regularly, as this can prevent a great deal of spyware hassle.

3) Also make sure to run your antivirus software regularly, and to keep it up-to-date.

Please also read Tony Klein's excellent article: How I got Infected in the First Place
Should I remove Java 6 Update 3? Will that Java Runtime Environment (JRE) 6 Update 4 replace that or are they two separate programs?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI