This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Trojan and worm viruses

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi All, over the past couple of days my AVG has been finding Trojan viruses and moving them to the vault, the next day more viruses are appearing almost the same as the day before and AVG keeps moving them into the vault. These viruses are unable to be fixed by AVG and once deleted from the vault they still keep reappearing on the next scan or when I am on the net.

Here are the following viruses:-
1.Trojan Horse SHeur.AMXK (C:\msets.exe)
2.Trojan Horse BackDoor.VB.CZ (C:\pants.exe)
3.Trojan Horse Proxy.KJB (C:\windows\system32\helpersssves.exe)
4.Trojan Horse generic9.AVSN (C:\windows\runll32.exe)
5.Trojan Horse IRC/BackDoor.SDbot3.XJD
6.Trojan Horse generic 2.ims
7.Worm/spybot.BMA (c:\rahn.exe)

Here is my Hijack log

unning processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\explorer.exe
C:\Program Files\TalkTalk\bin\sprtcmd.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\mmdmm.exe
C:\WINDOWS\System32\mdm.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\wuauclt.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\ftp.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\WINDOWS\system32\cmd.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.co.uk/
F2 - REG:system.ini: Shell=explorer.exe winsock2.7.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\System32\ntos.exe,
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [TalkTalk] "C:\Program Files\TalkTalk\bin\sprtcmd.exe" /P TalkTalk
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmsass] mmdmm.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Windows Networking Monitoring] C:\WINDOWS\System32\mdm.exe
O4 - HKLM\..\RunServices: [hotfix] msnnmaneger.exe
O4 - HKLM\..\RunServices: [mmsass] mmdmm.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo R265 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBNE.EXE /FU "C:\WINDOWS\TEMP\E_SD6.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Windows Networking Monitoring] C:\WINDOWS\System32\mdm.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{084F06B2-0D4A-4265-B4ED-232F44A520C1}: NameServer = 62.24.218.50 62.24.218.51
O17 - HKLM\System\CS1\Services\Tcpip\..\{084F06B2-0D4A-4265-B4ED-232F44A520C1}: NameServer = 62.24.218.50 62.24.218.51
O17 - HKLM\System\CS2\Services\Tcpip\..\{084F06B2-0D4A-4265-B4ED-232F44A520C1}: NameServer = 62.24.218.50 62.24.218.51
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: k7h08c9m4w4 - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: k9q1t9 - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Microsoft Windows AutoUpdate Service - Unknown owner - C:\WINDOWS\wuauclt.exe
O23 - Service: NET Service - Unknown owner - C:\WINDOWS\wmssvc.exe (file missing)

Good luck

Your help would be much appreciated

Billy :unsure:
Billy,

Welcome to the forum, let me tell ya, you have a real mess going on. :smack: When you post a HJT log I need to see the entire log including the header.

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log


======================================================

Download ComboFix from Here to your Desktop.

**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**

  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.


I don't know what version of HJT your running, if its version 1.99.1 remove it via the Add remove programs and download and install the latest version by Trendmicro.

Download Trendmicros Hijackthis to your desktop.
Double click it to install
Follow the prompts and by default it will install in C:\Program Files\Trendmicro\Hijackthis\Highjackthis.exe

  • Open HJT Scan and Save a Log File, it will open in Notepad
  • Go to Format and make sure Wordwrap is Unchecked
  • Go to Edit> Select All…..Edit > Copy and Paste the new log into this thread by using the Post Reply and not start a New Thread.
DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.


Let me see the SDbot log, the Combofix log and a New and Complete HJT log by Trendmicro.
As Requested


SDFix: Version 1.136

Run by [removed] on 05/02/2008 at 16:37

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:

Name:
srtwe

Path:
\??\C:\WINDOWS\System32\drivers\srtwe.sys

srtwe - Deleted



Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:

C:\WINDOWS\SYSTEM32\FTPUPD.EXE - Deleted
C:\WINDOWS\SYSTEM32\SETUP_~4.EXE - Deleted
C:\81588875 - Deleted
C:\WINDOWS\system32\eraseme_62781.exe - Deleted
C:\Program Files\Helper\1202204882.dll - Deleted
C:\Program Files\Helper\1202205177.dll - Deleted
C:\Program Files\Helper\1202205179.dll - Deleted
C:\Program Files\Helper\1202205233.dll - Deleted
C:\Program Files\Helper\1202205578.dll - Deleted
C:\Program Files\Helper\1202205579.dll - Deleted
C:\Program Files\Helper\1202205580.dll - Deleted
C:\Program Files\Helper\1202224157.dll - Deleted
C:\Program Files\Helper\1202224160.dll - Deleted
C:\Program Files\Helper\1202224162.dll - Deleted
C:\Program Files\Helper\1202226480.dll - Deleted
C:\Program Files\Helper\1202226482.dll - Deleted
C:\Program Files\Helper\1202226485.dll - Deleted
C:\Program Files\Helper\1202226911.dll - Deleted
C:\Program Files\Helper\1202226912.dll - Deleted
C:\Program Files\Helper\1202226914.dll - Deleted
C:\d.exe - Deleted
C:\WINDOWS\system32\setup_00234.exe - Deleted
C:\WINDOWS\system32\setup_00765.exe - Deleted
C:\WINDOWS\system32\setup_07382.exe - Deleted
C:\WINDOWS\system32\setup_10381.exe - Deleted
C:\WINDOWS\system32\setup_14644.exe - Deleted
C:\WINDOWS\system32\setup_16135.exe - Deleted
C:\WINDOWS\system32\setup_23234.exe - Deleted
C:\WINDOWS\system32\setup_35161.exe - Deleted
C:\WINDOWS\system32\setup_36636.exe - Deleted
C:\WINDOWS\system32\setup_48035.exe - Deleted
C:\WINDOWS\system32\setup_51241.exe - Deleted
C:\WINDOWS\system32\setup_54228.exe - Deleted
C:\WINDOWS\system32\setup_56641.exe - Deleted
C:\WINDOWS\system32\setup_63510.exe - Deleted
C:\WINDOWS\system32\setup_76108.exe - Deleted
C:\WINDOWS\system32\setup_80254.exe - Deleted
C:\WINDOWS\system32\cmds.txt - Deleted
C:\WINDOWS\system32\conf.dat - Deleted
C:\WINDOWS\system32\halifax1.dll - Deleted
C:\WINDOWS\system32\halifax2.dll - Deleted
C:\WINDOWS\system32\i - Deleted
C:\WINDOWS\system32\ps1.dat - Deleted
C:\WINDOWS\system32\rc.dat - Deleted
C:\WINDOWS\usnsvc.exe - Deleted
C:\WINDOWS\wuauclt.exe - Deleted
C:\WINDOWS\system32\drivers\srtwe.sys - Deleted
C:\WINDOWS\system32\ntos.exe - Deleted
C:\WINDOWS\system32\wsnpoem\audio.dll - Deleted
C:\WINDOWS\system32\wsnpoem\video.dll - Deleted



Folder C:\Program Files\Helper - Removed
Folder C:\WINDOWS\system32\wsnpoem - Removed


Removing Temp Files…

ADS Check:



Final Check:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-05 16:47:24
Windows 5.1.2600 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:00000000
"TracesSuccessful"=dword:00000000
"LastTraceFailure"=dword:00000000

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
——————



Authorized Application Key Export:

Remaining Files:
—————

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Thu 10 Jan 2008 157,184 ..SHR — "C:\WINDOWS\msdav.exe"
Sat 2 Feb 2008 61,881 ..SHR — "C:\WINDOWS\whssvc.exe"
Mon 28 Jan 2008 1,404,240 A.SHR — "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR — "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR — "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"

Finished!


Combo Txt

ComboFix 08-02.05.3 - Amy Kemp 2008-02-05 16:55:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.0.1252.1.1033.18.69 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-05 to 2008-02-05 )))))))))))))))))))))))))))))))
.

2008-02-05 16:35 . 2008-02-05 16:35 d——– C:\WINDOWS\ERUNT
2008-02-05 16:23 . 2008-02-05 16:23 d——– C:\Program Files\Trend Micro
2008-02-05 16:10 . 2008-02-05 16:49 d——– C:\SDFix
2008-02-04 19:48 . 2008-02-04 19:48 147,456 –a—— C:\WINDOWS\system32\msnmsgsls.exe
2008-02-04 13:46 . 2008-02-05 15:54 170,895 –a—— C:\prox.exe
2008-02-02 20:29 . 2008-02-02 20:29 121,179 –a—— C:\finl.exe
2008-02-02 20:26 . 2008-02-02 20:26 388 –a—— C:\fil.exe
2008-02-02 15:47 . 2008-02-02 15:47 61,881 -r-hs—- C:\WINDOWS\whssvc.exe
2008-02-02 15:47 . 2008-02-02 15:47 5,624 –a—— C:\jobxxc.exe
2008-02-01 17:42 . 2008-02-01 17:48 d——– C:\Documents and Settings\billy kemp\Application Data\Spyware Terminator
2008-02-01 16:38 . 2008-02-01 22:50 d——– C:\Program Files\Spyware Terminator
2008-02-01 16:27 . 2008-02-01 22:56 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-01 16:26 . 2008-02-01 23:02 d——– C:\Program Files\Spyware Doctor
2008-02-01 16:26 . 2008-02-01 22:57 d——– C:\Program Files\Common Files\PC Tools
2008-01-31 21:36 . 2008-01-31 21:36 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-31 15:00 . 2008-01-31 15:00 335 –a—— C:\WINDOWS\mozregistry.dat
2008-01-31 11:28 . 2008-01-31 11:28 1,167 –a—— C:\WINDOWS\mozver.dat
2008-01-30 19:10 . 2008-01-30 19:10 0 –a—— C:\WINDOWS\nsreg.dat
2008-01-30 15:49 . 2008-01-30 16:16 d——– C:\Documents and Settings\Sue Jones\Application Data\AVG7
2008-01-30 15:02 . 2008-01-31 22:29 215 –a—— C:\WINDOWS\wininit.ini
2008-01-29 10:10 . 2008-02-05 16:29 d——– C:\Program Files\Spybot - Search & Destroy
2008-01-21 15:31 . 2008-01-21 16:30 d——– C:\Program Files\Cossacks
2008-01-21 15:26 . 2002-04-22 07:15 4,284,416 -ra—— C:\WINDOWS\uncsetup.exe
2008-01-21 15:26 . 2008-01-21 15:26 53,248 –a—— C:\WINDOWS\system32\unrar.dll
2008-01-20 18:34 . 2008-01-20 18:34 4,321 –a—— C:\DVDIMAGE.MDS
2008-01-20 18:30 . 2008-01-20 18:34 1,990,754,304 –a—— C:\I'm a legend.ISO
2008-01-20 18:28 . 2008-01-20 18:28 d——– C:\Program Files\DVD Decrypter
2008-01-19 15:09 . 2008-01-19 15:09 1,024 –a—— C:\chezza.exe
2008-01-18 19:57 . 2008-01-18 20:15 25,600 –a—— C:\check.exe
2008-01-17 19:10 . 2008-02-01 17:17 d——– C:\Documents and Settings\billy kemp\Application Data\AVG7
2008-01-17 14:48 . 2008-01-17 14:49 168,960 –a—— C:\WINDOWS\system32\avvg.exe
2008-01-16 19:43 . 2008-01-16 19:43 0 –a—— C:\WINDOWS\TEXTART.INI
2008-01-14 22:42 . 2003-08-19 15:16 98,459 –a—— C:\WINDOWS\system32\EEGenFn1.dll
2008-01-14 22:42 . 1999-11-12 07:37 61,440 –a—— C:\WINDOWS\system32\Eeshellx.dll
2008-01-14 22:42 . 2002-03-19 15:34 32,768 –a—— C:\WINDOWS\system32\eetransx.exe
2008-01-14 22:41 . 2008-01-17 19:06 d——– C:\Program Files\Evidence Eliminator
2008-01-14 22:41 . 2002-02-01 07:20 368,912 –a—— C:\WINDOWS\system32\vbar332.dll
2008-01-14 22:41 . 2001-03-13 14:49 140,288 –a—— C:\WINDOWS\system32\COMDLG32.OCX
2008-01-14 22:41 . 1996-05-03 22:05 28,672 –a—— C:\WINDOWS\system32\MSGHOO32.OCX
2008-01-12 18:56 . 2008-01-17 14:10 d——– C:\Program Files\VideoLAN
2008-01-12 18:22 . 2008-01-12 18:22 d——– C:\Documents and Settings\Amy Kemp\Application Data\Media Player Classic
2008-01-12 16:57 . 2008-01-12 16:57 d——– C:\Program Files\Common Files\xing shared
2008-01-12 16:56 . 2008-01-12 16:56 d——– C:\Program Files\Real
2008-01-12 16:56 . 2008-01-12 16:57 d——– C:\Program Files\Common Files\Real
2008-01-11 00:35 . 2008-01-30 16:00 42,078 –a—— C:\WINDOWS\PFP80JPR.{PB
2008-01-11 00:35 . 2008-01-30 16:00 8,438 –a—— C:\WINDOWS\PFP80JCM.{PB
2008-01-10 16:00 . 2001-08-17 14:03 21,760 –a–c— C:\WINDOWS\system32\dllcache\usbstor.sys
2008-01-10 15:34 . 2008-01-10 15:34 157,184 -r-hs—- C:\WINDOWS\msdav.exe
2008-01-10 14:42 . 2008-01-10 14:42 d—s—- C:\WINDOWS\system32\Microsoft
2008-01-10 14:42 . 2008-01-10 14:42 d——– C:\Program Files\Lavasoft
2008-01-10 14:19 . 2008-01-31 11:56 d——– C:\Documents and Settings\All Users\Application Data\WinZip
2008-01-10 14:10 . 2008-02-05 16:51 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-10 14:10 . 2001-03-13 14:51 1,066,176 –a—— C:\WINDOWS\system32\MSCOMCTL.OCX
2008-01-10 14:10 . 2005-08-25 18:18 118,784 –a—— C:\WINDOWS\system32\MSSTDFMT.DLL
2008-01-10 14:10 . 2000-05-22 00:00 115,920 –a—— C:\WINDOWS\system32\MSINET.OCX
2008-01-10 14:09 . 2008-01-10 14:09 d——– C:\Program Files\TweakNow RegCleaner Std
2008-01-10 14:04 . 2008-01-10 14:04 d——– C:\Program Files\CCleaner
2008-01-10 14:02 . 2008-01-10 14:02 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-10 14:02 . 2008-02-05 15:23 d——– C:\Documents and Settings\Amy Kemp\Application Data\AVG7
2008-01-10 14:02 . 2008-01-10 14:02 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2008-01-10 14:02 . 2008-01-10 14:02 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2008-01-10 14:01 . 2008-01-10 14:01 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-10 14:01 . 2008-01-11 15:54 d——– C:\Documents and Settings\All Users\Application Data\avg7

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-31 21:31 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-21 15:32 28,400 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2008-01-10 13:50 ——— d—–w C:\Program Files\TalkTalk
2008-01-10 13:50 ——— d—–w C:\Program Files\SupportSoft
2008-01-10 13:50 ——— d—–w C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-01-10 13:47 23 —-a-w C:\WINDOWS\system32\drivers\adidsl.cfg
2008-01-10 13:47 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-10 13:47 ——— d—–w C:\Program Files\SAGEM
2008-01-10 13:46 ——— d—–w C:\Program Files\Common Files\SupportSoft
2008-01-10 13:40 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-01-10 13:39 ——— d—–w C:\Documents and Settings\All Users\Application Data\UDL
2008-01-10 13:38 ——— d—–w C:\Program Files\EPSON Print CD
2008-01-10 13:38 ——— d—–w C:\Program Files\EPSON
2008-01-10 13:37 ——— d—–w C:\Documents and Settings\All Users\Application Data\EPSON
2008-01-10 13:22 ——— d—–w C:\Program Files\microsoft frontpage
2007-12-14 11:32 12,632 —-a-w C:\WINDOWS\system32\lsdelete.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2001-08-23 12:00 13312]
"EPSON Stylus Photo R265 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBNE.exe" [2006-05-19 04:00 139264]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2001-08-02 07:14 1077277]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TalkTalk"="C:\Program Files\TalkTalk\bin\sprtcmd.exe" [2005-08-16 00:12 192512]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-10 14:01 579072]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-01-12 16:56 185896]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-08-23 12:00 13312]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-10 14:01 219136]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"winsockdriver"="winsock2.7.exe" []

R2 Microsoft Whois Service;Microsoft Whois Service;"C:\WINDOWS\whssvc.exe" [2008-02-02 15:47]
S1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\System32\drivers\sp_rsdrv2.sys []
S2 k7h08c9m4w4;k7h08c9m4w4;"C:\WINDOWS\system32\svshost.exe" []
S2 k9q1t9;k9q1t9;"C:\WINDOWS\system32\svshost.exe" []
S2 ko6t86v0z4z2;ko6t86v0z4z2;"C:\WINDOWS\system32\svshost.exe" []
S2 NET Service;NET Service;"C:\WINDOWS\wmssvc.exe" []

*Newly Created Service* - ALG
*Newly Created Service* - IPNAT
*Newly Created Service* - SHAREDACCESS
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-05 16:56:34
Windows 5.1.2600 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-05 16:57:22
Hijack log

Logfile of HijackThis v1.99.1
Scan saved at 17:00:11, on 05/02/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\whssvc.exe
C:\Program Files\TalkTalk\bin\sprtcmd.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.co.uk/
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [TalkTalk] "C:\Program Files\TalkTalk\bin\sprtcmd.exe" /P TalkTalk
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo R265 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBNE.EXE /FU "C:\WINDOWS\TEMP\E_SD6.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related; Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: k7h08c9m4w4 - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: k9q1t9 - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: ko6t86v0z4z2 - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Microsoft Whois Service - Unknown owner - C:\WINDOWS\whssvc.exe
O23 - Service: NET Service - Unknown owner - C:\WINDOWS\wmssvc.exe (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

I have to goto work now and will be back online tomorrow evening
Good luck and thanks for replying
Billy :thumbup:
Billy,

Lets go over a few things before we proceed.


Platform: Windows XP
<– Very outdated version of windows. Is there any reason you have not run Windows Update to download and install all the patches that help keep your system more secure. When I see this it tells me either that your not aware of the importance of installing the updates , or that you can't install the updates because your copy of windows may be illegal. Lets hope you dont fall in the later catagory or your just going to keep getting infected with all this garbage.


Search & Destroy\TeaTimer.exe <– I asked you to disable it, it most times interferes with the fixes, so do this now.


Trendmicro HJT <– The older version of HJT maynot be showing everything and you have not downloaded the newer version like I asked.



Do not do any windows updates until your system is clean, disable the TeaTimer, uninstall the older version of HJT and download the newer one by Trendmicro. Do this before you proceed.



Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

O23 - Service: k7h08c9m4w4 - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: k9q1t9 - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: ko6t86v0z4z2 - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
O23 - Service: Microsoft Whois Service - Unknown owner - C:\WINDOWS\whssvc.exe
O23 - Service: NET Service - Unknown owner - C:\WINDOWS\wmssvc.exe (file missing)




Open Notepad ( only use windows notepad…. the script will fail if you use another text editor ) and copy all the text inside the quote box by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above File::

File::
C:\finl.exe
C:\fil.exe
C:\prox.exe
C:\jobxxc.exe
C:\WINDOWS\msdav.exe
C:\WINDOWS\whssvc.exe
C:\WINDOWS\system32\msnmsgsls.exe

Registry::
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"winsockdriver"=-


Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI