This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Problem Removing Virtumonde

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi
I'm having problems removing Virtumonde!

I'm running XP SP2. I've turned off System Restore & disconected the internet connection.

Then I ran Spybot & VunoFix v6.7.8.

This is the HJ This log after the VundoFix has re booted

Logfile of HijackThis v1.99.1
Scan saved at 16:08:00, on 25/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\pavsrv51.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\AVENGINE.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\frxhser.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\WINDOWS\system32\frxhapp.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrls.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\PsImSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Panda Security\Panda Antivirus 2008\ApvxdWin.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\WebProxy.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {15DA087A-10AB-44C1-A711-83881EA119EB} - C:\WINDOWS\system32\vtutq.dll (file missing)
O2 - BHO: (no name) - {1ACB5862-DCEE-419D-8F79-3FE50536EBD3} - (no file)
O2 - BHO: (no name) - {4C475C04-6A52-44C8-B891-C7FADA46CFFF} - C:\WINDOWS\system32\jkhhh.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {6A0DAC94-72AB-44D3-9127-8441D5A246CA} - C:\WINDOWS\system32\ddayy.dll (file missing)
O2 - BHO: (no name) - {6abb042f-f1e4-4215-9350-78772dc7f92c} - (no file)
O2 - BHO: (no name) - {6B32AA37-97F8-4A4B-98EF-9D33A5E1747F} - (no file)
O2 - BHO: {996cb574-b68e-b9da-6e14-6c67a3d14be8} - {8eb41d3a-76c6-41e6-ad9b-e86b475bc699} - C:\WINDOWS\system32\bniewjma.dll
O2 - BHO: (no name) - {D85530E8-D39D-49D0-9F36-300D594556D2} - C:\WINDOWS\system32\byxyxyx.dll
O4 - HKLM\..\Run: [frxmxins] frxmxins
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Antivirus 2008\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [38f333cb] rundll32.exe "C:\WINDOWS\system32\mdmnrcfx.dll",b
O4 - HKLM\..\Run: [BM3bc00057] Rundll32.exe "C:\WINDOWS\system32\tudlibks.dll",s
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe -s
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) - http://zone.msn.com/bingame/amad/default/atomaders.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/luxr/default/mjolauncher.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN Games – Texas Holdem Poker) - http://zone.msn.com/bingame/zpagames/zpa_txhe.cab60231.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} (CBankshotZoneCtrl Class) - http://zone.msn.com/bingame/zpagames/zpa_pool.cab56649.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {F773E7B2-62A9-4524-9109-87D2F0BEFAA4} (ChessControl Class) - http://zone.msn.com/bingame/zpagames/zpa_kqrp.cab56961.cab
O16 - DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} (MSN Games – Backgammon) - http://zone.msn.com/bingame/zpagames/ZPA_B…on.cab64162.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Bolda.bolda.co.uk
O17 - HKLM\Software\..\Telephony: DomainName = Bolda.bolda.co.uk
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Bolda.bolda.co.uk
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = Bolda.bolda.co.uk
O20 - Winlogon Notify: avldr - C:\WINDOWS\SYSTEM32\avldr.dll
O20 - Winlogon Notify: byxyxyx - C:\WINDOWS\SYSTEM32\byxyxyx.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: FGLRXUTIL (FGLRXUtil) - ATI Technologies, Inc. - C:\WINDOWS\System32\frxhser.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrls.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\pavsrv51.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\PsImSvc.exe
Hello Bulldogmark and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem.

Befoe we can start to help you, we need to change a few things to ensure a smoother fix.

A. Turn your System Restore back on. We need a safety net in case something does not go as planned. With System Restore turned off, if anything went wrong we could be looking at a reformat.


B. I notice from the log that there are running more than one different Anti-Virus programs with Auto-protect enabled. Never install more than one Antivirus and Firewall! Rather than giving you extra protection, it will decrease the reliability of it seriously!
The reason for this is that if both products have their automatic (Real-Time) protection switched on, your system may lock up due to both software products attempting to access the same file at the same time.
Also because more than one Antivirus and Firewall installed are not compatible with each other, it can cause system performance problems and a serious system slowdown.

So you have to make a decision here and keep the Antivirus you prefer and uninstall the other one.
Then reboot after uninstalling.

Once you have done the above, please post a fresh HijackThis log.
Hi Trevuren

Thanks for your reply.

I have turned System Restore back on now.

I used to run Norton 360 but cahnged to Panda anti virus last week when Norton wasn't picking up the problem. I thought I had completly removed Norton but when I checked the add / remove Norton's Live Update program was still there.
I've removed all the Norton programs, rebooted & here is the new Hijack This log.

Logfile of HijackThis v1.99.1
Scan saved at 22:02:45, on 25/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\pavsrv51.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\AVENGINE.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\frxhser.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrls.exe
C:\WINDOWS\system32\frxhapp.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\PsImSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Panda Security\Panda Antivirus 2008\ApvxdWin.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\WebProxy.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {15DA087A-10AB-44C1-A711-83881EA119EB} - C:\WINDOWS\system32\vtutq.dll (file missing)
O2 - BHO: (no name) - {1ACB5862-DCEE-419D-8F79-3FE50536EBD3} - (no file)
O2 - BHO: (no name) - {4C475C04-6A52-44C8-B891-C7FADA46CFFF} - C:\WINDOWS\system32\jkhhh.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {6A0DAC94-72AB-44D3-9127-8441D5A246CA} - C:\WINDOWS\system32\ddayy.dll (file missing)
O2 - BHO: (no name) - {6abb042f-f1e4-4215-9350-78772dc7f92c} - (no file)
O2 - BHO: (no name) - {6B32AA37-97F8-4A4B-98EF-9D33A5E1747F} - (no file)
O2 - BHO: {996cb574-b68e-b9da-6e14-6c67a3d14be8} - {8eb41d3a-76c6-41e6-ad9b-e86b475bc699} - C:\WINDOWS\system32\bniewjma.dll
O2 - BHO: (no name) - {D85530E8-D39D-49D0-9F36-300D594556D2} - C:\WINDOWS\system32\byxyxyx.dll
O4 - HKLM\..\Run: [frxmxins] frxmxins
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Antivirus 2008\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [38f333cb] rundll32.exe "C:\WINDOWS\system32\mdmnrcfx.dll",b
O4 - HKLM\..\Run: [BM3bc00057] Rundll32.exe "C:\WINDOWS\system32\tudlibks.dll",s
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe -s
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) - http://zone.msn.com/bingame/amad/default/atomaders.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/luxr/default/mjolauncher.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN Games – Texas Holdem Poker) - http://zone.msn.com/bingame/zpagames/zpa_txhe.cab60231.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} (CBankshotZoneCtrl Class) - http://zone.msn.com/bingame/zpagames/zpa_pool.cab56649.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {F773E7B2-62A9-4524-9109-87D2F0BEFAA4} (ChessControl Class) - http://zone.msn.com/bingame/zpagames/zpa_kqrp.cab56961.cab
O16 - DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} (MSN Games – Backgammon) - http://zone.msn.com/bingame/zpagames/ZPA_B…on.cab64162.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Bolda.bolda.co.uk
O17 - HKLM\Software\..\Telephony: DomainName = Bolda.bolda.co.uk
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Bolda.bolda.co.uk
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = Bolda.bolda.co.uk
O20 - Winlogon Notify: avldr - C:\WINDOWS\SYSTEM32\avldr.dll
O20 - Winlogon Notify: byxyxyx - C:\WINDOWS\SYSTEM32\byxyxyx.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: FGLRXUTIL (FGLRXUtil) - ATI Technologies, Inc. - C:\WINDOWS\System32\frxhser.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrls.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\pavsrv51.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\PsImSvc.exe
With the malignancy of some of these infections these days, we have to make sure that we have additional means through which to access system files and registry entries in case of emergency. This report will tell us if your system is set up to be able to recover in case of disaster.

Please download BootCheck.exe to your desktop.
  • Double click BootCheck.exe to run the check
  • When complete, a Notepad window will open with a report
  • Please copy and paste the contents of this report in your next reply
Hi Trevuren

Here is the Bootcheck Report

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !

Contents of C:\boot.ini:

[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

Mark
A. Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

DO NOT RUN THE TOOL YET


B. 1. Download the following file from Microsoft to your Desktop.

This file is specific to your Operating System XP Home Service Pack 2

http://www.microsoft.com/downloads/details…3D-81C2137FF464

2. Save it as it's originally named. Place it next to ComboFix.exe.

[external image: Posted Image]

3. Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it (As illustrated in the above animation). Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console. When complete, a log named CF_RC.txt will open. Please post the contents of that log.

Please do not reboot your machine until we have reviewed the log.
Hi Trevuren Here is the Combo Fix log. I have just loticed that the Microsoft download is for XP Home - I'm running XP Pro is that still the same file? WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
No, it is the wrong version. DO NOT REBOOT at this time.

To remove the RC installed by CF, please do the following:

A. Show hidden files and Folders:
  • Go Start>>Settings>>Control Panel>>Folder Options>>View
    • Under Hidden Files and Folders<==== Select "Show Hidden Files and Folders
    • Uncheck "Hide extensions for known filw types.
    • Uncheck "Hide protected operating files (Recommended)
  • Click "Apply"
  • Exit the module

B. Delete the following files/folders:

C:\cmdcons
C:\cmldr

Do next step ONLY IF C:\boot.bak exist

Delete - C:\boot.ini
Rename - C:\boot.bak —> to —> C:\boot.ini

Then DELETE the Microsoft file you just downloadded and restart your system.

=====================================================

Do this next:


1.Go to Microsoft's website => http://support.microsoft.com/kb/310994

2. Select the download that's appropriate for your Operating System.

[external image: Posted Image]



Microsoft Windows XP Home Edition
Service Pack 1
http://www.microsoft.com/downloads/details…05-719F45C382A4

Service Pack 2
http://www.microsoft.com/downloads/details…3D-81C2137FF464

Microsoft Windows XP Professional
Without Service Packs

http://www.microsoft.com/downloads/details…B7-4FED408EA73F

Service Pack 1
http://www.microsoft.com/downloads/details…C2-631504EF5E26

Service Pack 2
http://www.microsoft.com/downloads/details…0C-0A0205368124



3. Download the file & save it as it's originally named. Place it next to ComboFix.exe.

[external image: Posted Image]

4. Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it (As illustrated in the above animation). Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console. When complete, a log named CF_RC.txt will open. Please post the contents of that log.

Please do not reboot your machine until we have reviewed the log.
Hi Trevuren

OK I have deleted the folder
C:\cmdcons
& the file
C:\cmldr

A file called C\boot.bak existed so I deleted C:\BOOT.INI & renamed C\boot.bak > C:\BOOT.INI

I've downloaded the Microsoft file http://www.microsoft.com/downloads/details…0C-0A0205368124
& dragged it onto ComboFix.

The Log that ComboFix produced is here

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
You are so good. I just love working with you :thumbup:


A. Rehide those system files so we do not trip over them while we are working. Just do the reverse of what you did to show them.


B. Reboot your system.


C. Next we must temporarily disable some security programs so that they do not interfere with our tool:

Panda Internet Security Suite
Please navigate to the system tray on the bottom right hand corner and look for a sign that looks like a Pandabear head.
  • Right click it-> select "Close automatic protection.".
  • A message will pop up and warn you about disabling the protection. Chose "Yes."
  • The above sign in the systemtray will now disapear.
You succesfully disabled the Panda Internet Security Guard.

D. Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • ComboFix will automatically start. Any monitoring programs will be shut down like your antivirus, antispyware programs for example.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hi Trevuren

Good Instuctions are always easy to follow!! :thumbup:

OK - System files all hidden away

System Rebooted & Panda disabled - that just doesn't sound right but you know what I mean!!

ComboFix run & system rebooted by ComboFix

After the Reboot a dialog box opened
RUNDLL
Error loading C:\WINDOWSsystem32\mdmnrcfx.dll
The specified moule colud not be found

ComboFix 08-02-25.3 - mark_pb 2008-02-26 3:06:46.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3115 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\mark_pb\Application Data\macromedia\Flash Player\#SharedObjects\3J6M3NQU\www.inter-focus.cn
C:\Documents and Settings\mark_pb\Application Data\macromedia\Flash Player\#SharedObjects\3J6M3NQU\www.inter-focus.cn\flashad-v5-stop_firstput_mute.swf\IFFLASHAD.sol
C:\Documents and Settings\mark_pb\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.inter-focus.cn
C:\Documents and Settings\mark_pb\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.inter-focus.cn\settings.sol
C:\Temp\isgTi19
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\bniewjma.dll
C:\WINDOWS\system32\boclwtgd.dll
C:\WINDOWS\system32\dcgwehtn.dll
C:\WINDOWS\system32\dxemeiaw.dll
C:\WINDOWS\system32\dxursvsv.dll
C:\WINDOWS\SYSTEM32\eglbmjdc.ini
C:\WINDOWS\system32\elqssatk.dll
C:\WINDOWS\system32\fcyfxhle.dll
C:\WINDOWS\system32\fdvagcpm.dll
C:\WINDOWS\system32\ffvoumsv.dll
C:\WINDOWS\system32\fnewbtxp.dll
C:\WINDOWS\SYSTEM32\gjllm.ini
C:\WINDOWS\SYSTEM32\gjllm.ini2
C:\WINDOWS\system32\gplrdppp.dll
C:\WINDOWS\system32\hwukyoea.dll
C:\WINDOWS\system32\idtobrtd.dll
C:\WINDOWS\system32\iksibsuq.dll
C:\WINDOWS\system32\iskbqbcj.dll
C:\WINDOWS\system32\mlljg.dll
C:\WINDOWS\system32\mmdleuhh.dll
C:\WINDOWS\SYSTEM32\mpcgavdf.ini
C:\WINDOWS\system32\nGpxx01
C:\WINDOWS\system32\oaxqysip.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\phpwngfi.dll
C:\WINDOWS\system32\tivripbc.dll
C:\WINDOWS\system32\tudlibks.dll
C:\WINDOWS\system32\vchyljju.dll
C:\WINDOWS\system32\vxaddytm.dll
C:\WINDOWS\system32\wcnvkijs.dll
C:\WINDOWS\system32\wpqsutmx.dll
C:\WINDOWS\SYSTEM32\xfcrnmdm.ini
C:\WINDOWS\system32\yohvblda.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\nm


((((((((((((((((((((((((( Files Created from 2008-01-26 to 2008-02-26 )))))))))))))))))))))))))))))))
.

2008-02-26 00:57 . 2008-02-26 00:57 84,544 –a—— C:\WINDOWS\SYSTEM32\2AF.tmp
2008-02-26 00:57 . 2008-02-26 00:57 37,376 –a—— C:\WINDOWS\SYSTEM32\2AE.tmp
2008-02-25 21:53 . 2008-02-25 21:57 d——– C:\WINDOWS\SxsCaPendDel
2008-02-24 01:50 . 2008-02-24 16:21 354 –ahs—- C:\WINDOWS\SYSTEM32\vmqxptxx.ini
2008-02-23 01:48 . 2008-02-23 01:48 294 –ahs—- C:\WINDOWS\SYSTEM32\iqgndtrt.ini
2008-02-22 21:32 . 2008-02-26 02:11 188 –a—— C:\WINDOWS\wininit.ini
2008-02-22 10:50 . 2008-02-22 10:50 d——– C:\Documents and Settings\All Users\Application Data\sentinel
2008-02-22 10:49 . 2008-02-22 11:12 d——– C:\WINDOWS\SYSTEM32\PAV
2008-02-22 10:49 . 2007-09-28 13:24 83,896 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\pavdrv51.sys
2008-02-22 10:49 . 2008-02-22 10:49 248 –a—— C:\WINDOWS\SYSTEM32\PavCPL.dat
2008-02-22 10:48 . 2008-02-22 10:48 d——– C:\Program Files\Panda Security
2008-02-22 10:48 . 2007-03-15 17:38 54,832 –a—— C:\WINDOWS\SYSTEM32\pavcpl.cpl
2008-02-22 10:48 . 2007-02-15 19:02 50,736 –a—— C:\WINDOWS\SYSTEM32\avldr.dll
2008-02-22 10:40 . 2007-07-12 13:49 178,872 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\PavProc.sys
2008-02-22 10:40 . 2007-05-23 15:40 38,968 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\ShlDrv51.sys
2008-02-22 10:27 . 2008-02-22 10:27 274 –a—— C:\WINDOWS\AvDetected.ini
2008-02-22 10:26 . 2008-02-22 10:26 d——– C:\Program Files\Common Files\Panda Software
2008-02-22 01:50 . 2008-02-22 16:07 1,674 –ahs—- C:\WINDOWS\SYSTEM32\ectliqwh.ini
2008-02-22 00:10 . 2007-06-08 09:44 8,576 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\sassfdswmuus.sys
2008-02-21 22:42 . 2007-06-08 09:44 8,576 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\fvtkjumnpblr.sys
2008-02-21 22:10 . 2007-06-08 09:44 8,576 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\actadanpckdd.sys
2008-02-21 21:40 . 2008-02-22 00:10 d——– C:\WINDOWS\SYSTEM32\ActiveScan
2008-02-21 21:40 . 2008-02-22 01:39 30,590 –a—— C:\WINDOWS\SYSTEM32\pavas.ico
2008-02-21 21:40 . 2008-02-22 01:39 2,550 –a—— C:\WINDOWS\SYSTEM32\Uninstall.ico
2008-02-21 21:40 . 2008-02-22 01:39 1,406 –a—— C:\WINDOWS\SYSTEM32\Help.ico
2008-02-21 21:28 . 2008-02-25 14:49 d——– C:\VundoFix Backups
2008-02-21 21:22 . 2008-02-22 01:36 1,314 –ahs—- C:\WINDOWS\SYSTEM32\vhuymqrk.ini
2008-02-21 19:22 . 2008-02-21 19:23 1,014 –ahs—- C:\WINDOWS\SYSTEM32\siqmsxwm.ini
2008-02-21 19:11 . 2008-02-26 03:04 70,866 –a—— C:\WINDOWS\BM3bc00057.xml
2008-02-21 19:11 . 2008-02-26 03:01 22 –a—— C:\WINDOWS\pskt.ini
2008-02-21 11:01 . 2008-02-21 19:06 954 –ahs—- C:\WINDOWS\SYSTEM32\xbdngcaf.ini
2008-02-20 11:00 . 2008-02-21 11:00 834 –ahs—- C:\WINDOWS\SYSTEM32\ytahneyd.ini
2008-02-19 11:01 . 2008-02-20 10:51 594 –ahs—- C:\WINDOWS\SYSTEM32\ynouvyvy.ini
2008-02-18 10:56 . 2008-02-19 10:56 354 –ahs—- C:\WINDOWS\SYSTEM32\cvdhguau.ini

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-25 21:54 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-02-25 21:54 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-22 20:50 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-22 20:32 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-02-22 10:48 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-22 10:39 ——— d—–w C:\Program Files\Norton 360
2008-02-17 01:17 255,640 -c–a-w C:\Documents and Settings\mark_pb\Application Data\GDIPFONTCACHEV1.DAT
2008-01-09 23:34 ——— d—–w C:\Documents and Settings\mark_pb\Application Data\DeepBurner
2008-01-09 23:28 ——— d—–w C:\Program Files\Astonsoft
2005-02-11 15:29 4,354,084 -c–a-w C:\Program Files\spybotsd13.exe
2003-02-01 16:56 592 -c–a-w C:\Program Files\INSTALL.LOG
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{15DA087A-10AB-44C1-A711-83881EA119EB}]
C:\WINDOWS\system32\vtutq.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1ACB5862-DCEE-419D-8F79-3FE50536EBD3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{37e4565e-c060-4055-a6a2-3c482ba41501}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4C475C04-6A52-44C8-B891-C7FADA46CFFF}]
C:\WINDOWS\system32\jkhhh.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6A0DAC94-72AB-44D3-9127-8441D5A246CA}]
C:\WINDOWS\system32\ddayy.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abb042f-f1e4-4215-9350-78772dc7f92c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6B32AA37-97F8-4A4B-98EF-9D33A5E1747F}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{76AAE1A2-ED2A-4948-B336-B22DD586A4AD}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8eb41d3a-76c6-41e6-ad9b-e86b475bc699}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D85530E8-D39D-49D0-9F36-300D594556D2}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 16:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:56 15360]
"Uniblue SpeedUpMyPC"="C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe" [2007-05-22 10:09 8631840]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"frxmxins"="frxmxins" []
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 21:32 53248]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 10:09 63712]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06 40048]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-04-10 16:44 679936]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [ ]
"38f333cb"="C:\WINDOWS\system32\mdmnrcfx.dll" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 07:56 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-12-04 10:10:00 110592]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
avldr.dll 2007-02-15 19:02 50736 C:\WINDOWS\SYSTEM32\avldr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byxyxyx]
byxyxyx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Anconia\\RktSales\\RocketTrack.exe"=
"C:\\Program Files\\JavaSoft\\JRE\\1.3.1_03\\bin\\javaw.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Macromedia\\Dreamweaver MX\\Dreamweaver.exe"=
"C:\\Program Files\\Microsoft Office\\Office10\\EXCEL.EXE"=

R1 ShldDrv;Panda File Shield Driver;C:\WINDOWS\system32\Drivers\ShlDrv51.sys [2007-05-23 15:40]
R2 ASFAgent;ASF Agent;C:\Program Files\Intel\ASF Agent\ASFAgent.exe [2002-08-07 05:34]
R2 FGLRXUtil;FGLRXUTIL;C:\WINDOWS\System32\frxhser.exe [2002-09-04 18:57]
R2 NetAlrt;NetAlrt;C:\WINDOWS\System32\drivers\NetAlrt.sys [2002-05-07 16:05]
R2 PavProc;Panda Process Protection Driver;C:\WINDOWS\system32\DRIVERS\PavProc.sys [2007-07-12 13:49]
R2 PlatAlrt;PlatAlrt;C:\WINDOWS\System32\drivers\PlatAlrt.sys [2002-05-07 16:06]
R3 atifglrx;atifglrx;C:\WINDOWS\system32\DRIVERS\fglrxm.sys [2002-09-04 18:51]
S3 NMSCFG;NIC Management Service Configuration Driver;C:\WINDOWS\System32\drivers\NMSCFG.SYS [2002-07-30 16:15]
S3 NMSSvc;Intel® NMS;C:\WINDOWS\System32\NMSSvc.exe [2002-07-30 16:15]
S3 SaiHA503;SaiHA503;C:\WINDOWS\system32\DRIVERS\SaiHA503.sys [2006-07-07 16:50]
S3 SaiLA503;SaiLA503;C:\WINDOWS\system32\DRIVERS\SaiLA503.sys [2006-07-07 16:50]
S3 SaiUA503;SaiUA503;C:\WINDOWS\system32\DRIVERS\SaiUA503.sys [2006-07-07 16:50]
S4 hpt3xx;hpt3xx;C:\WINDOWS\system32\DRIVERS\hpt3xx.sys [2001-08-17 13:52]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-18 22:57:01 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2007-07-03 16:25:04 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-26 03:15:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Panda Security\Panda Antivirus 2008\pavsrv51.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\AVENGINE.EXE
C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrls.exe
C:\WINDOWS\system32\frxhapp.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\PsImSvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\ApvxdWin.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\WebProxy.exe
.
**************************************************************************
.
Completion time: 2008-02-26 3:19:19 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-26 03:19:15
.
2008-02-13 12:03:58 — E O F —


Logfile of HijackThis v1.99.1
Scan saved at 03:31, on 2008-02-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\pavsrv51.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\AVENGINE.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\frxhser.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrls.exe
C:\WINDOWS\system32\frxhapp.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\PsImSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Panda Security\Panda Antivirus 2008\ApvxdWin.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\WebProxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {15DA087A-10AB-44C1-A711-83881EA119EB} - C:\WINDOWS\system32\vtutq.dll (file missing)
O2 - BHO: (no name) - {4C475C04-6A52-44C8-B891-C7FADA46CFFF} - C:\WINDOWS\system32\jkhhh.dll (file missing)
O2 - BHO: (no name) - {6A0DAC94-72AB-44D3-9127-8441D5A246CA} - C:\WINDOWS\system32\ddayy.dll (file missing)
O4 - HKLM\..\Run: [frxmxins] frxmxins
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [38f333cb] rundll32.exe "C:\WINDOWS\system32\mdmnrcfx.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe -s
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) - http://zone.msn.com/bingame/amad/default/atomaders.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/luxr/default/mjolauncher.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN Games – Texas Holdem Poker) - http://zone.msn.com/bingame/zpagames/zpa_txhe.cab60231.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {CAC181B0-4D70-402D-B571-C596A47D0CE0} (CBankshotZoneCtrl Class) - http://zone.msn.com/bingame/zpagames/zpa_pool.cab56649.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {F773E7B2-62A9-4524-9109-87D2F0BEFAA4} (ChessControl Class) - http://zone.msn.com/bingame/zpagames/zpa_kqrp.cab56961.cab
O16 - DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} (MSN Games – Backgammon) - http://zone.msn.com/bingame/zpagames/ZPA_B…on.cab64162.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Bolda.bolda.co.uk
O17 - HKLM\Software\..\Telephony: DomainName = Bolda.bolda.co.uk
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Bolda.bolda.co.uk
O20 - Winlogon Notify: avldr - C:\WINDOWS\SYSTEM32\avldr.dll
O20 - Winlogon Notify: byxyxyx - byxyxyx.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: FGLRXUTIL (FGLRXUtil) - ATI Technologies, Inc. - C:\WINDOWS\System32\frxhser.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrls.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\pavsrv51.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\PsImSvc.exe
I was unable to find much reliable info on this:

C:\WINDOWS\SxsCaPendDel

So let me know if you recognize it… If you don't, check Properties to see who it is from… If that doesn't reveal anything helpful, find and .exe file in the folder and submit it here:

Please go to Jotti's malware scan at http://virusscan.jotti.org/ and upload the file for scanning and post the results here.
Hi Trevuren

I'm not sure what C:\WINDOWS\SxsCaPendDel is!!

When I tried to up load to Jotti a window opened saying "The file you uploaded is 0 bytes. It is very likely a firewall or a piece of malware is prohibiting you from uploading this file"

I had a look and C:\WINDOWS\SxsCaPendDel is a folder which is empty.

Mark
I got that too. Thanks for the extra effort. We will get rid of it. 0 bytes very often means malware.


A. Once again, we must disable some security programs so that our tools run properly:

SPYBOT TEATIMER
  • Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • On the left hand side, click on Tools, then click on the Resident Icon in the list.
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • Click on the "System Startup" icon in the List
  • Uncheck the "TeaTimer" box and "OK" any prompts.
  • If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
  • Exit Spybot S&D when done.
  • (When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.]


Panda Internet Security Suite
Please navigate to the system tray on the bottom right hand corner and look for a sign that looks like a Pandabear head.
  • Right click it-> select "Close automatic protection.".
  • A message will pop up and warn you about disabling the protection. Chose "Yes."
  • The above sign in the systemtray will now disapear.
You succesfully disabled the Panda Internet Security Guard.


B. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\WINDOWS\SYSTEM32\2AF.tmp
C:\WINDOWS\SYSTEM32\2AE.tmp
C:\WINDOWS\SYSTEM32\vmqxptxx.ini
C:\WINDOWS\SYSTEM32\iqgndtrt.ini
C:\WINDOWS\SYSTEM32\xbdngcaf.ini
C:\WINDOWS\SYSTEM32\ytahneyd.ini
C:\WINDOWS\SYSTEM32\ynouvyvy.ini
C:\WINDOWS\SYSTEM32\cvdhguau.ini
C:\WINDOWS\SYSTEM32\vhuymqrk.ini
C:\WINDOWS\SYSTEM32\siqmsxwm.ini
C:\WINDOWS\SYSTEM32\DRIVERS\sassfdswmuus.sys
C:\WINDOWS\SYSTEM32\DRIVERS\fvtkjumnpblr.sys
C:\WINDOWS\SYSTEM32\DRIVERS\actadanpckdd.sys
C:\WINDOWS\SYSTEM32\pavas.ico
C:\WINDOWS\SYSTEM32\Uninstall.ico
C:\WINDOWS\SYSTEM32\Help.ico
C:\WINDOWS\SYSTEM32\ectliqwh.ini
C:\WINDOWS\AvDetected.ini
C:\WINDOWS\BM3bc00057.xml
C:\WINDOWS\pskt.ini

Folder::
C:\WINDOWS\SxsCaPendDel

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{15DA087A-10AB-44C1-A711-83881EA119EB}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1ACB5862-DCEE-419D-8F79-3FE50536EBD3}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{37e4565e-c060-4055-a6a2-3c482ba41501}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4C475C04-6A52-44C8-B891-C7FADA46CFFF}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6A0DAC94-72AB-44D3-9127-8441D5A246CA}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abb042f-f1e4-4215-9350-78772dc7f92c}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6B32AA37-97F8-4A4B-98EF-9D33A5E1747F}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{76AAE1A2-ED2A-4948-B336-B22DD586A4AD}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8eb41d3a-76c6-41e6-ad9b-e86b475bc699}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D85530E8-D39D-49D0-9F36-300D594556D2}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"frxmxins"="-
"38f333cb"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byxyxyx]
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

5. All your monitoring programs (Antivirus/Antispyware, Guards and Shields) will be stopped.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


C. Using Internet Explorer, please do a Kaspersky Online Scan

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will provide a report if your system is infected. It does not provide an option to clean/disinfect. We only require a report from it.

    [external image: Posted Image]

  • Click the Save as Text button to save the file to your desktop and post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI