This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Crapy carp** PLEASE HELP

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Thanks up front I have read a lot of the threads and you guys really do a great job of helping.

Ok fisrt off my typing skills SUCK so please do not use that agenst me. Oh yea chalk spelling to that to.

I am running XP Pro I pride myself on not having to many of these problems. I went to a site that I knew always has malware and well being late for work I downloaded a file that I had been looking for on some tips for another program. I always scan these files and really do not have a problem. Well you guessed it I forgot to scann this said file and well you know what happened.

I have been able to remove a lot of the problems and well kinda had to learn how to back door windows to even be allowed to start removing this carp**. The virus I down loaded loacked anything and everything that an administrator could lock, ie., taskmanager, control center, regedit, cmd, could not see my c:\ drive, removed the programs menu from the start button, well removed almost all of the start button functions and disabled some of my protection.

The first thing I had to do was to get to where I could use regedit. I had to do this so that I could install new malware programs. I had to disable the admin functions via a VB script. That inturn allowed me to get to the comand prompt and use regedit. I have had to do an extensive amount of reading and searching to get that problem nailed down. I enjoy my cmd and have learned to love it threw the years. Once I was able to get CMD up I ran a few cmd scripts I had collected threw the years to enable a lot of the functions I needed to even be able to find part of the problem.

Now as long as I did not reboot I could work around and found a fix to a nasty piece of malware. Sorry I am at work right so I cannot remember the name of the fix. It was a batch file that some great person wrote to remove this "ONE" virus. I was able to get my desktop back, reverted my changes to the regestry to the default for the start button ect. I will be more than happy to post the virus/Trojan or what ever it was as soon as I get home as it would be a great help to many.

The virus that I downloaded also downloaded a bunch of others with it. some I have been able to remove and some I am having a hard time with. I am going to list all the logs I have from the various programs I have used to help.

Go ahead and kick me now I was not aware of this site untill yesterday. I will also add a list of the stuff I found today after running a new program.

THANKS YOU AHEAD OF TIME YET AGAIN.

carp** I cannot seem to rid myself of:
1.w32.picrate
2.nvrsma.dll
3.stubinstaller.exe "(Just found this today)"
4.llbp.exe
5.axer.exe
6.userinit.exe "This apeared in my startup folder after I infected myself." This is a pain in the but to remove at least at my level anyways.

I have read that 18.exe is most likely a big player with these or a dirivative of 18.exe

I hope I have given enough info to help. I am a firm believer that you cannot have to much information.

Listed bellow are the logs I have:

Logfile of HijackThis v1.99.1
Scan saved at 3:01:43 AM, on 6/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\drivers\services.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\NOTEPAD.EXE
F:\Com virus work\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.yahoo.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
O4 - HKLM\..\Run: [[system]] C:\WINDOWS\system32\drivers\services.exe
O4 - HKLM\..\Run: [winlogon] C:\Documents and Settings\Administrator\svchost.exe
O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdhio.exe] C:\WINDOWS\system32\kdhio.exe
O4 - HKLM\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
O4 - HKLM\..\Run: [412f54de] rundll32.exe "C:\WINDOWS\system32\hycwkmkp.dll",b
O4 - HKLM\..\Run: [BM421c6742] Rundll32.exe "C:\WINDOWS\system32\ctrxgevy.dll",s
O4 - HKCU\..\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [[system]] C:\WINDOWS\system32\drivers\services.exe
O4 - HKCU\..\Run: [winlogon] C:\Documents and Settings\Administrator\svchost.exe
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\csrssc.exe
O4 - Startup: userinit.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1134415597281
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: xvorfwbd - {CAB01645-315D-4285-959D-2D94B02DC835} - (no file)
O21 - SSODL: wpvmqosg - {877243CA-0714-4211-937E-885FC7788366} - (no file)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: dlcx_device - - C:\WINDOWS\system32\dlcxcoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\services.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe" -service (file missing)

******************************************************************************
Process Viewer

aawservice.exe 1752 C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe Ad-Aware 2007 Service 7,0,2,6. Copyright © 2007
AppleMobileDeviceService.exe 440 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe Apple Mobile Device Service 1, 14, 0, 0. Copyright 2007 Apple, Inc. All Rights Reserved.
csrss.exe 792 C:\WINDOWS\system32\csrss.exe Client Server Runtime Process 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
csrss.exe 2096 C:\WINDOWS\system32\csrss.exe Client Server Runtime Process 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
dlcxcoms.exe 524 C:\WINDOWS\system32\dlcxcoms.exe Printer Communication System 99.99.99.99.
Explorer.EXE 732 C:\WINDOWS\Explorer.EXE Windows Explorer 6.00.2900.3156. © Microsoft Corporation. All rights reserved.
Explorer.EXE 1156 C:\WINDOWS\Explorer.EXE Windows Explorer 6.00.2900.3156. © Microsoft Corporation. All rights reserved.
InCDsrv.exe 1312 C:\Program Files\Ahead\InCD\InCDsrv.exe incdsrv 4, 3, 16, 1. Copyright 1995-2005 Nero AG and its licensors. All Rights Reserved.
lsass.exe 876 C:\WINDOWS\system32\lsass.exe LSA Shell (Export Version) 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
LSSrvc.exe 604 C:\Program Files\Common Files\LightScribe\LSSrvc.exe LightScribe Service © Copyright 2003-2006 Hewlett-Packard Development Company, LP
msmsgs.exe 3340 C:\Program Files\Messenger\msmsgs.exe Windows Messenger Version 4.7.3001. Copyright © Microsoft Corporation 2004
PCTAVSvc.exe 748 C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe PC Tools AntiVirus Engine 4, 0, 0, 26. Copyright PC Tools Research Pty Ltd 2006
PhnxCDSvr.exe 1196 C:\WINDOWS\system32\PhnxCDSvr.exe Phoenix VCD Service Application 2.1.1.13. Copyright © 1999-2005 Phoenix Technologies Ltd.
PrcView.exe 2276 C:\Documents and Settings\Administrator\Desktop\Process viewer\PrcView.exe Process Viewer Application 3.7.3.1. Developed by Igor Nys, 1995-2003
rundll32.exe 996 C:\WINDOWS\system32\rundll32.exe Run a DLL as an App 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
Rundll32.exe 2224 C:\WINDOWS\system32\Rundll32.exe Run a DLL as an App 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
rundll32.exe 3932 C:\WINDOWS\system32\rundll32.exe Run a DLL as an App 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
rundll32.exe 4084 C:\WINDOWS\system32\rundll32.exe Run a DLL as an App 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
services.exe 548 C:\WINDOWS\system32\drivers\services.exe services.exe
services.exe 864 C:\WINDOWS\system32\services.exe Services and Controller app 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
services.exe 3736 C:\WINDOWS\system32\drivers\services.exe services.exe
smss.exe 704 C:\WINDOWS\System32\smss.exe Windows NT Session Manager 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
spoolsv.exe 1948 C:\WINDOWS\system32\spoolsv.exe Spooler SubSystem App 5.1.2600.2696. © Microsoft Corporation. All rights reserved.
sqlservr.exe 624 C:\Program Files\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlservr.exe SQL Server Windows NT 8.00.760. © 1988-2003 Microsoft Corp. All rights reserved.
svchost.exe 504 C:\WINDOWS\system32\svchost.exe Generic Host Process for Win32 Services 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
svchost.exe 1084 C:\WINDOWS\system32\svchost.exe Generic Host Process for Win32 Services 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
svchost.exe 1132 C:\WINDOWS\system32\svchost.exe Generic Host Process for Win32 Services 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
svchost.exe 1240 C:\WINDOWS\system32\svchost.exe Generic Host Process for Win32 Services 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
svchost.exe 1280 C:\WINDOWS\System32\svchost.exe Generic Host Process for Win32 Services 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
svchost.exe 1452 C:\WINDOWS\system32\svchost.exe Generic Host Process for Win32 Services 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
svchost.exe 1504 C:\WINDOWS\system32\svchost.exe Generic Host Process for Win32 Services 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
svchost.exe 1628 C:\WINDOWS\system32\svchost.exe Generic Host Process for Win32 Services 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
winlogon.exe 816 C:\WINDOWS\system32\winlogon.exe Windows NT Logon Application 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
winlogon.exe 1328 C:\WINDOWS\system32\winlogon.exe Windows NT Logon Application 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
WinVNC.exe 1612 C:\Program Files\TightVNC\WinVNC.exe TightVNC Win32 Server 1, 2, 9, 0. Copyright © 1998-2002 [many holders]
wscntfy.exe 2728 C:\WINDOWS\system32\wscntfy.exe Windows Security Center Notification App 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
wscntfy.exe 3864 C:\WINDOWS\system32\wscntfy.exe Windows Security Center Notification App 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
********************************************************************
Spyware Terminator

Logfile of Spyware Terminator v2.2.1.433 (db:2.006.023.000)
Scan Time: 6/23/2008 2:36:07 PM length: 667 s
Platform: WXP (5.1.0.2600)
User: Admin
Boot Mode: Normal
Scan type: %Custom_Scan%
Scanned Objects: 150805 (Critical:15)
Filter: No System items, No Safe items, No Invalid items

Running Processes
InCDsrv.exe [Nero AG] : C:\Program Files\Ahead\InCD\InCDsrv.exe
aawservice.exe [Lavasoft] : C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
prevxcsi.exe [Prevx] : C:\Program Files\PrevxCSI\prevxcsi.exe
dlcxcoms.exe [ ] : C:\WINDOWS\system32\dlcxcoms.exe
prevxcsi.exe [Prevx] : C:\Program Files\PrevxCSI\prevxcsi.exe
LSSrvc.exe [Hewlett-Packard Company] : C:\Program Files\Common Files\LightScribe\LSSrvc.exe
sqlservr.exe [Microsoft Corporation] : C:\Program Files\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlservr.exe
PCTAVSvc.exe [PC Tools Research Pty Ltd] : C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
WinVNC.exe [Constantin Kaplinsky] : C:\Program Files\TightVNC\WinVNC.exe
services.exe : C:\WINDOWS\system32\drivers\services.exe

Internet Settings
R - HKLM\Software\Microsoft\Internet Explorer\Main, Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
R - HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
R - HKLM\Software\Microsoft\Internet Explorer\Search, CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
R - HKLM\System\CurrentControlSet\Services\Tcpip\Parameters, Domain =
R - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony, DomainName =

BHO
02 - BHO: - {1DC01F38-2C8F-45EF-84A5-8C0D72FA3E3D} - : C:\WINDOWS\system32\nnnnNfCV.dll
02 - BHO: - {4335E25B-2CC3-41EA-B419-4123924DED36} - : C:\WINDOWS\system32\efcBuvWO.dll
02 - BHO: - {cf4dfb1d-ff8e-4c2e-87d2-93d391d7e0d3} - : C:\WINDOWS\system32\yatvjjvf.dll
02 - BHO: Messenger Class - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - [Yahoo! Inc.] : C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

StartUps
04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, [system] : : C:\WINDOWS\system32\drivers\services.exe
04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, winlogon : : C:\Documents and Settings\Adam\svchost.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, C:\WINDOWS\system32\kdhio.exe : : C:\WINDOWS\system32\kdhio.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, [system] : : C:\WINDOWS\system32\drivers\services.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, winlogon : : C:\Documents and Settings\Adam\svchost.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 412f54de : : C:\WINDOWS\system32\xjmivvol.dll
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, BM421c6742 : : C:\WINDOWS\system32\hsrtpaff.dll
04 - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows, AppInit_DLLs : : C:\WINDOWS\system32\yatvjjvf.dll
04 - HKLM\System\CurrentControlSet\Control\Session Manager, BootExecute : : C:\WINDOWS\system32\lsdelete.exe
04 - Startup: : C:\Documents and Settings\Adam\Start Menu\Programs\Startup\userinit.exe

Shell Extensions
YMailShellExt Class - {5464D816-CF16-4784-B9F3-75C0DB52B499} - [Yahoo! Inc.] : C:\Program Files\Yahoo!\Common\ymmapi.dll
Outlook File Icon Extension - {0006F045-0000-0000-C000-000000000046} - [Microsoft Corporation] : C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL
dBpShell Class - {FED7043D-346A-414D-ACD7-550D052499A7} - : C:\Program Files\Illustrate\dBpowerAMP\dBShell.dll
dMCIShell Class - {2C49B5D0-ACE7-4D17-9DF0-A254A6C5A0C5} - : C:\Program Files\Illustrate\dBpowerAMP\dMCShell.dll
WinRAR - {B41DB860-8EE4-11D2-9906-E49FADC173CA} - : C:\Program Files\WinRAR\rarext.dll
Desktop Explorer - {1CDB2949-8F65-4355-8456-263E7C208A5D} - [NVIDIA Corporation] : C:\WINDOWS\system32\nvshell.dll
- {1E9B04FB-F9E5-4718-997B-B8DA88302A47} - [NVIDIA Corporation] : C:\WINDOWS\system32\nvshell.dll
Shell Extension for CDRW - {950FF917-7A57-46BC-8017-59D9BF474000} - [Nero AG] : C:\Program Files\Ahead\InCD\incdshx.dll
ConvShlExt Class - {DB7CFAED-842B-47E7-9FF4-92852D617958} - : C:\Program Files\BeeThink MP3 WMA To Wav 2.0\YJ.dll
ConvShlExt Class - {DB7CFAEE-842B-47E7-9FF4-92852D617958} - : C:\Program Files\BeeThink MP3 WMA To Wav 2.0\TL.dll
Acrobat Elements Context Menu - {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} - [Adobe Systems Inc.] : C:\Program Files\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll
iTunes - {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} - [Apple Inc.] : C:\Program Files\iTunes\iTunesMiniPlayer.dll

Shell Extecute Hooks
- {{1DC01F38-2C8F-45EF-84A5-8C0D72FA3E3D}} - : C:\WINDOWS\system32\nnnnNfCV.dll

Protocol Handler
mctp: Asynchronous Pluggable Protocol Handler - {d7b95390-b1c5-11d0-b111-0080c712fe82} - [Microsoft Corporation] : C:\Program Files\Microsoft ActiveSync\aatp.dll

Services
23 - [Lavasoft] : C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
23 - [Realtek Semiconductor Corp.] : C:\WINDOWS\system32\drivers\ALCXWDM.SYS
23 - [PC Tools Research Pty Ltd] : C:\WINDOWS\system32\drivers\AVFilter.sys
23 - [PC Tools Research Pty Ltd.] : C:\WINDOWS\system32\drivers\AVHook.sys
23 - [PC Tools Research Pty Ltd] : C:\WINDOWS\system32\drivers\AVRec.sys
23 - [IVT Corporation] : C:\WINDOWS\system32\DRIVERS\blueletaudio.sys
23 - [IVT Corporation] : C:\WINDOWS\system32\DRIVERS\btnetdrv.sys
23 - : C:\WINDOWS\system32\DRIVERS\vbtenum.sys
23 - [IVT Corporation] : C:\WINDOWS\system32\Drivers\BTHidMgr.sys
23 - [Prevx] : C:\Program Files\PrevxCSI\prevxcsi.exe
23 - [VIA Technologies, Inc.] : C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys
23 - [GEAR Software Inc.] : C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
23 - [Intel Corporation] : C:\WINDOWS\system32\DRIVERS\iaStor.sys
23 - [Nero AG] : C:\WINDOWS\system32\DRIVERS\InCDPass.sys
23 - [Nero AG] : C:\Program Files\Ahead\InCD\InCDsrv.exe
23 - [Hewlett-Packard Company] : C:\Program Files\Common Files\LightScribe\LSSrvc.exe
23 - [PC Tools Research Pty Ltd] : C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
23 - [Silicon Image, Inc] : C:\WINDOWS\system32\DRIVERS\pnp680r.sys
23 - [Prevx] : C:\WINDOWS\system32\drivers\pxark.sys
23 - [Trend Micro Inc.] : C:\WINDOWS\system32\drivers\tmcomm.sys
23 - [Promise Technology, Inc.] : C:\WINDOWS\system32\DRIVERS\ultra.sys
23 - [IVT Corporation] : C:\WINDOWS\system32\DRIVERS\VComm.sys
23 - [IVT Corporation] : C:\WINDOWS\system32\Drivers\VcommMgr.sys
23 - [VIA Technologies inc,.ltd] : C:\WINDOWS\system32\DRIVERS\viamraid.sys
23 - [Jungo] : C:\WINDOWS\system32\drivers\windrvr6.sys
23 - [Constantin Kaplinsky] : C:\Program Files\TightVNC\WinVNC.exe

Winlogon Notify
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\nnnnnfcv, DLLName : : C:\WINDOWS\system32\nnnnNfCV.dll

System Policies
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFolderOptions : :

Threat Files
[Constantin Kaplinsky] : C:\Program Files\TightVNC\WinVNC.exe
: C:\Program Files\TightVNC\VNCHOOKS.DLL
: C:\Documents and Settings\Adam\Start Menu\Programs\Startup\userinit.exe
: C:\Documents and Settings\Adam\Desktop\SmitfraudFix\Reboot.exe
: C:\Documents and Settings\Adam\Desktop\SmitfraudFix\restart.exe
: C:\axer.exe
: C:\llbp.exe
<180searchAssistant> : C:\StubInstaller.exe
: C:\WINDOWS\system32\nvrsma.dll.ren
: C:\Documents and Settings\Administrator\Desktop\SmitfraudFix\Reboot.exe
: C:\Documents and Settings\Administrator\Desktop\SmitfraudFix\restart.exe
: C:\Documents and Settings\Deej\Local Settings\Temp\csrssc.exe
: C:\Program Files\Mozilla Firefox\SmitfraudFix\Reboot.exe
: C:\Program Files\Mozilla Firefox\SmitfraudFix\restart.exe

Advanced Files Report
%COMMONFILES%\PC Tools\Lsp\PCTLsp.dll [PC Tools Research Pty Ltd.] [PC Tools Content Filter] MD5=65CCD937502870F0464582B190571E34 SIZE=190360
%PROGRAMFILES%\Ahead\InCD\InCDsrv.exe [Nero AG] [Nero AG incdsrv] MD5=26F6FF6832756F6662DBDD7B3C9AF5FF SIZE=869888
%PROGRAMFILES%\Ahead\InCD\incdshx.dll [Nero AG] [Nero AG InCD Shell Extension] MD5=66FFA80DA375A0867BD4AD208D1C3C51 SIZE=103424
%PROGRAMFILES%\Lavasoft\Ad-Aware 2007\aawservice.exe [Lavasoft] [Ad-Aware 2007 Service] MD5=0629361FAC4576BA48AB39F4903DCE9E SIZE=587096
%PROGRAMFILES%\Lavasoft\Ad-Aware 2007\CEAPI.dll [Lavasoft] [CEAPI Dynamic Link Library] MD5=759C45CA544A92DE4B88618894A15587 SIZE=738664
%PROGRAMFILES%\Lavasoft\Ad-Aware 2007\PKArchive85u.dll [PKWARE, Inc.] [PKWARE Archive API] MD5=46374252AFA0A37F4F7AF528F6F16B96 SIZE=907096
%PROGRAMFILES%\Lavasoft\Ad-Aware 2007\Update.dll [Update Dynamic Link Library] MD5=72CCE73551D24D7863369F3BFD6548C9 SIZE=525664
%SYSDIR%\AdobePDF.dll [Adobe Systems Incorporated.] [Acrobat ® PDF Port for Windows] MD5=381915766C2A5E47A7DB95423CE09A16 SIZE=21099
%PROGRAMFILES%\Adobe\Acrobat 6.0\Distillr\adistres.dll [Adobe Systems Incorporated.] [Acrobat Distiller for Windows] MD5=F41A8F6E80DB4853CFC8613F72B53E12 SIZE=155648
%SYSDIR%\dlcxlmpm.dll [Printer Communication System] MD5=2A0C32CB84C6313400EF1B8626307C55 SIZE=585728
%SYSDIR%\DLPRMON.DLL [Dell Fax Solutions Software] MD5=6048E9C383F1807187ABB4517ABC8BA5 SIZE=45056
%SYSDIR%\IMGMAN32.dll [Data Techniques, Inc.] [ImageMan Image Processing Toolkit] MD5=86C5AAC31EA7909121327701045F74BD SIZE=339968
%SYSDIR%\IM31IMG.DIL [Data Techniques, Inc.] [ImageMan Image Processing Toolkit] MD5=9F22E3CE1639917EB07DCC730CD0D410 SIZE=49152
%PROGRAMFILES%\Dell PC Fax\DlCtrStr.dll [Dell Fax Solutions Software] MD5=FCB4DCFDE1EAF2189DFD2F016E1A27A1 SIZE=16384
%PROGRAMFILES%\Dell PC Fax\ipcmt.dll [Dell Fax Solutions Software] MD5=6F0335CD580DAD17EAB0963A6C434CFE SIZE=32768
%SYSDIR%\spool\PRTPROCS\W32X86\dlcxdrpp.dll [Windows 2K/XP Printer Driver] MD5=C4C21FB6300A27BAA8331917199484E9 SIZE=117760
%PROGRAMFILES%\PrevxCSI\prevxcsi.exe [Prevx] [Prevx] MD5=3D49D3FDB4BBE1FE1A07C133EDA1D8C0 SIZE=623160
%SYSDIR%\dlcxcoms.exe [Printer Communication System] MD5=D71B2CD799AD3AEEED2C29D02B0B5170 SIZE=537480
%COMMONFILES%\LightScribe\LSSrvc.exe [Hewlett-Packard Company] [LightScribe] MD5=F34B35F6F74E28A460749DA11D1117F8 SIZE=79136
%COMMONFILES%\LightScribe\LSSProxy.dll [Hewlett-Packard Company] [LightScribe] MD5=B0EA38637D86C6BEF855801F741E5027 SIZE=110592
%COMMONFILES%\LightScribe\LSLog.dll [Hewlett-Packard Company] [LightScribe] MD5=469BD51B465887FD4C78A6A0D598902C SIZE=33280
%PROGRAMFILES%\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlservr.exe [Microsoft Corporation] [Microsoft SQL Server] MD5=F80EEC5E1D6CDF82CB974DAADA0C57DD SIZE=7520337
%PROGRAMFILES%\PC Tools AntiVirus\PCTAVSvc.exe [PC Tools Research Pty Ltd] [PC Tools AntiVirus Engine] MD5=3E2F12850B761E9D0CBE0EA18ED448D4 SIZE=767888
%PROGRAMFILES%\PC Tools AntiVirus\xerdom.dll MD5=52D92DC73C8272C9DC8498C599143DC1 SIZE=321432
%PROGRAMFILES%\PC Tools AntiVirus\Xerces.dll [Apache Software Foundation] [Xerces-C Version 2.7.0] MD5=1D5FDBCDC25F2D3287DEBDBDCDF1B2C6 SIZE=1812376
%PROGRAMFILES%\PC Tools AntiVirus\PCTCFilter.dll [PCTOOLS AV Content Filter Wrapper DLL] MD5=33FC3D13F13B7537E1639095F25089AF SIZE=83864
%PROGRAMFILES%\PC Tools AntiVirus\engine.dll [PC Tools Research Pty Ltd] [PC Tools Engine DLL for Windows NT/2000/XP] MD5=4701AD16BB6D611FD921DFE5B951BC2D SIZE=956312
%PROGRAMFILES%\PC Tools AntiVirus\refdb.dll MD5=21BAE2C469EC1BF208CAE0B288AB381F SIZE=92056
%SYSDIR%\dlcxdrs.dll MD5=3130314CC9B6C17DBD2B55F6B0D71E19 SIZE=692224
%SYSDIR%\dlcxcfg.dll [config] MD5=D806B1FD27277E66C2A87D13D1161896 SIZE=73728
%SYSDIR%\dlcxcaps.dll MD5=A7177E54F8B624843DD6BF0B599BA74A SIZE=65536
%SYSDIR%\dlcxcnv4.dll MD5=EAE8F7F4A870B9BD705464E93D824F9E SIZE=61440
%PROGRAMFILES%\ArcSoft\PhotoImpression 5\share\pihook.dll MD5=9064D871EF0125B58CC58AFC767F1E47 SIZE=53248
%PROGRAMFILES%\BeeThink MP3 WMA To Wav 2.0\TL.dll [AudioConverter Module] MD5=D34EEE032136A9FB60E330DC3D398F7A SIZE=69632
%PROGRAMFILES%\WinRAR\rarext.dll MD5=7F24AABF0ABD066BEA68F09B999DC1FE SIZE=119808
%SystemDiskRoot%\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
%SYSDIR%\jfiehayd.dll
%PROGRAMFILES%\Yahoo!\Messenger\YahooMessenger.exe [Yahoo! Inc.] [Yahoo! Messenger] MD5=3A756D4066CC3BB8426EB08ABB6B5B10 SIZE=4662776
deskpan.dll
%PROGRAMFILES%\Yahoo!\Common\ymmapi.dll [Yahoo! Inc.] [YMMAPI Module] MD5=A0C86DB296BBE76145377D56C5975175 SIZE=190496
%PROGRAMFILES%\Microsoft Office\Office10\OLKFSTUB.DLL [Microsoft Corporation] [Microsoft Outlook] MD5=3756445FEBC6CBC90AFC22E5E38F7294 SIZE=54688
%PROGRAMFILES%\Illustrate\dBpowerAMP\dBShell.dll [dBShell Module] MD5=D6AA02CE1F8A522543CE9AA2572685E6 SIZE=86016
%PROGRAMFILES%\Illustrate\dBpowerAMP\dMCShell.dll [dMCShell Module] MD5=BD433F12577C40839588F0BDB790173E SIZE=110592
%SYSDIR%\nvshell.dll [NVIDIA Corporation] [NVIDIA Desktop Explorer, Version 44.03] MD5=08063F7DF5DC0146534725745010CE91 SIZE=467016
%PROGRAMFILES%\BeeThink MP3 WMA To Wav 2.0\YJ.dll [AudioConverter Module] MD5=34CD87529E63E0609CE9F22D1379970A SIZE=69632
%PROGRAMFILES%\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll [Adobe Systems Inc.] [Adobe Acrobat Elements] MD5=CDDBD1E9B24C0CDF9C8C5BE2DC27B5D4 SIZE=409687
%PROGRAMFILES%\iTunes\iTunesMiniPlayer.dll [Apple Inc.] [iTunes] MD5=CB77693D6E94DA5DF7AA007B0671D42C SIZE=132392
%SYSDIR%\drivers\ALCXWDM.SYS [Realtek Semiconductor Corp.] [Windows ® WDM driver for Realtek AC'97 Audio(HRTF data Copyright 1994 by MIT Media Lab)] MD5=36223C0FF66AFD94D1D73FCB8FDFE91E SIZE=3797632
%SYSDIR%\svchost.exe -k netsvcs
%SYSDIR%\drivers\AVFilter.sys [PC Tools Research Pty Ltd] [AVFilter Device Driver] MD5=1E238735F42CFA3429BEE1E7C52D360F SIZE=21904
%SYSDIR%\drivers\AVHook.sys [PC Tools Research Pty Ltd.] [PC Tools AntiVirus] MD5=C7D6AEAE29826584CC24A10ADAFF86FC SIZE=28568
%SYSDIR%\drivers\AVRec.sys [PC Tools Research Pty Ltd] [PC Tools AntiVirus] MD5=D38DD9338AE5038833E1308D84418708 SIZE=21912
%SYSDIR%\DRIVERS\blueletaudio.sys [IVT Corporation] [Windows ® 2000 DDK driver] MD5=04E84C8049EE93614A2FF6D676D1E247 SIZE=20480
%SYSDIR%\DRIVERS\btnetdrv.sys [IVT Corporation] [BlueSoleil] MD5=D1813668A0117AE05BC0B81C874F91D4 SIZE=10804
%SYSDIR%\DRIVERS\vbtenum.sys MD5=161969D2DD1D39CD2F1EDBC60C61FA99 SIZE=11860
%SYSDIR%\Drivers\BTHidMgr.sys [IVT Corporation] [BlueSoleil©] MD5=A9164C2A39BD917B9F42AE087560AC3D SIZE=28271
%SYSDIR%\svchost -k DcomLaunch
%SYSDIR%\dlcxcoms.exe -service
%SYSDIR%\svchost.exe -k NetworkService
%SYSDIR%\DRIVERS\fetnd5bv.sys [VIA Technologies, Inc.] [VIA Rhine Family Fast Ethernet Adapter] MD5=CFC4CC73C903152A23E1DB28EABA1F03 SIZE=42496
%SYSDIR%\Drivers\GEARAspiWDM.sys [GEAR Software Inc.] [CD DVD Filter] MD5=5DC17164F66380CBFEFD895C18467773 SIZE=16168
%SYSDIR%\DRIVERS\iaStor.sys [Intel Corporation] [Intel Matrix Storage Manager driver] MD5=309C4D86D989FB1FCF64BD30DC81C51B SIZE=874240
%SYSDIR%\DRIVERS\InCDPass.sys [Nero AG] [InCD] MD5=40F9A7FD0CA8548E51C2703AB864FFC8 SIZE=29696
%SYSDIR%\svchost.exe -k LocalService
%PROGRAMFILES%\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlservr.exe -sINVENTORCONTENT
%SYSDIR%\DRIVERS\pnp680r.sys [Silicon Image, Inc] [Medley] MD5=A1D7A9214B71EBBB6F31CB84AAC15525 SIZE=76976
%SYSDIR%\drivers\pxark.sys [Prevx] [Prevx CSI] MD5=0ADCCE30DC59528C32D7288F16FD1A25 SIZE=17408
%SYSDIR%\svchost -k rpcss
%SYSDIR%\svchost.exe -k imgsvc
%SYSDIR%\drivers\tmcomm.sys [Trend Micro Inc.] [ActiveClean] MD5=DF8444A8FA8FD38D8848BDD40A8403B3 SIZE=102664
%SYSDIR%\DRIVERS\ultra.sys [Promise Technology, Inc.] [Promise ultra66 Miniport Driver for WindowsNT] MD5=1B698A51CD528D8DA4FFAED66DFC51B9 SIZE=36736
%SYSDIR%\DRIVERS\VComm.sys [IVT Corporation] [BlueSoleil] MD5=9EBEE4A060C5364A31AEAA04EAC2AF1E SIZE=61312
%SYSDIR%\Drivers\VcommMgr.sys [IVT Corporation] [BlueSoleil] MD5=630BBDBF5490F8F57ABE650DA63661A0 SIZE=82148
%SYSDIR%\DRIVERS\viamraid.sys [VIA Technologies inc,.ltd] [VIA RAID driver] MD5=F199939205DCCC7836AE5AB8B5DD5E83 SIZE=74112
%SYSDIR%\drivers\windrvr6.sys [Jungo] [WinDriver Device Driver] MD5=2C7D830E86B378771AF5DAFEAE428A09 SIZE=256568
%SYSDIR%\svchost.exe -k WudfServiceGroup
%PROGRAMFILES%\Microsoft ActiveSync\aatp.dll [Microsoft Corporation] [Microsoft Windows CE Services] MD5=2A57FFC89F27DCE24A5F9365C5946AF6 SIZE=77903
%SYSDIR%\MACROMED\SHOCKWAVE 10\GTAPI.DLL MD5=AE5CDA196A69F583DD356E7487AF3B49 SIZE=52288

End of Report


Remove Process:

Preparing structures
Remove Trojan.W32.VB.URT
Deleted File: C:\Documents and Settings\Adam\Start Menu\Programs\Startup\userinit.exe
Remove Trojan.Crypt.XPACK.Gen
Deleted File: c:\axer.exe
Deleted File: c:\llbp.exe
Remove Trojan.Agent.qrb
File selected for deletion does not exist: c:\WINDOWS\system32\nvrsma.dll.ren
Remove 180searchAssistant
Deleted File: c:\StubInstaller.exe
Remove Trojan.Downloader.Suurch.ef
Deleted File: c:\Documents and Settings\Deej\Local Settings\Temp\csrssc.exe
Done
*****************************************************************
File Find of "userinit.exe"

C:\userinit.exe - 13824 Bytes
C:\WINDOWS\system32\userinit.exe - 24576 Bytes
C:\WINDOWS\system32\dllcache\userinit.exe - 24576 Bytes
C:\Documents and Settings\Adam\Start Menu\Programs\Startup\userinit.exe - 13824 Bytes
C:\Documents and Settings\Deej\Start Menu\Programs\Startup\userinit.exe - 13824 Bytes

Again I hope this is enough info to help me out. You guys really do seem to know your stuff. I am not completely unsavy but I am limited. I am also willing to learn any and all.

Thanks you
ndt
[external image: Posted Image]

Sorry about the delay in responding :(

If you still need help, Scan again with HijackThis, and "copy/paste" a new log file into this thread.

Also please describe how your computer behaves at the moment.
Here is the new scan you requested,

Logfile of HijackThis v1.99.1
Scan saved at 09:19:14, on 7/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\dlcxcoms.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlservr.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TightVNC\WinVNC.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Adam\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: {3d0e7d19-3d39-2d78-e2c4-e8ffd1bfd4fc} - {cf4dfb1d-ff8e-4c2e-87d2-93d391d7e0d3} - C:\WINDOWS\system32\yatvjjvf.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdhio.exe] C:\WINDOWS\system32\kdhio.exe
O4 - HKLM\..\Run: [DLCXCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: crawler search - tbr:iemenu
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1134415597281
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O20 - AppInit_DLLs: yatvjjvf.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: dlcx_device - - C:\WINDOWS\system32\dlcxcoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe" -service (file missing)


Thanks again in advance.
ndt
No not by any means I enjoy my computer way to much. How ever I do have a new fascination with how these virus work and how hard one works to create one. It took me several days just to get my computer to where I was even able to post a hijackthis log here. I had to set my LP up on my desk and Google search any and everything I could find. I had to learn how to write batch files so I could do common things such as bring up the command prompt. Every time I would find a virus and get it removed the original virus would just reinstall it or what ever it does. I had to write batch files and save them to the desktop in a folder so I could quickly gain access to everything. I did this so I would not have to manually go threw these steps every time I tried to work on my computer. Threw this I have gained a new found want to understand why people create these viruses. That is what I was ranting about in my first post was how awesome and aggressive the virus or viruses that i downloaded. I said that I had downloaded them myself. I downloaded a file that I needed and forgot to scan the file before I opened it. So that is why I said I infected myself. I have read many of these threads in here and most people have no idea when or how they got the virus well I know exactly when and where I got my virus. That was all I was attempting to explain with a little enthusiasm. ndt
Please stay with this topic until I post the all clean.

You might want to print this out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Ok downloaded and ran the programs as you asked and logs requested are posted bellow.

Malwarebytes' Anti-Malware 1.19
Database version: 918
Windows 5.1.2600 Service Pack 2

12:19:01 PM 7/3/2008
mbam-log-7-3-2008 (12-19-01).txt

Scan type: Quick Scan
Objects scanned: 46531
Time elapsed: 3 minute(s), 13 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\dwnxhxti.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ldbtjjrw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ftodqegr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hivipcjs.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ctrxgevy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

Logfile of HijackThis v1.99.1
Scan saved at 12:20:05, on 7/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\dlcxcoms.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlservr.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TightVNC\WinVNC.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Documents and Settings\Adam\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: {3d0e7d19-3d39-2d78-e2c4-e8ffd1bfd4fc} - {cf4dfb1d-ff8e-4c2e-87d2-93d391d7e0d3} - C:\WINDOWS\system32\yatvjjvf.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdhio.exe] C:\WINDOWS\system32\kdhio.exe
O4 - HKLM\..\Run: [DLCXCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: crawler search - tbr:iemenu
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1134415597281
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O20 - AppInit_DLLs: yatvjjvf.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: dlcx_device - - C:\WINDOWS\system32\dlcxcoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe" -service (file missing)
Lets be safe and dig deeper.

Download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Give it atleast 20-30 minutes to finish
ComboFix 08-07-02.5 - Adam 2008-07-03 12:59:04.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.264 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\BM421c6742.txt
C:\WINDOWS\system32\hsrtpaff.dll
C:\WINDOWS\system32\kukaovsw.dll
C:\WINDOWS\system32\puwdwhve.dll
C:\WINDOWS\system32\uydgvtpk.dll
C:\WINDOWS\system32\wfvirmce.dll
C:\WINDOWS\system32\xjmivvol.dll
C:\WINDOWS\system32\yatvjjvf.dll
C:\WINDOWS\system32\ykpypkkm.dll

.
((((((((((((((((((((((((( Files Created from 2008-06-03 to 2008-07-03 )))))))))))))))))))))))))))))))
.

2008-06-25 17:50 . 2008-06-25 17:50 d——– C:\Documents and Settings\Deej\Application Data\Corel Photo Album
2008-06-25 15:27 . 2008-06-25 15:27 d——– C:\Documents and Settings\Adam\Application Data\Corel Photo Album
2008-06-24 02:25 . 2008-06-24 02:25 d——– C:\Program Files\Exterminate It!
2008-06-24 01:03 . 2008-06-24 01:03 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-06-24 01:03 . 2008-06-24 01:03 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-24 01:03 . 2008-06-24 01:03 d——– C:\Documents and Settings\Adam\Application Data\Malwarebytes
2008-06-24 01:03 . 2008-06-28 14:16 34,296 –a—— C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-24 01:03 . 2008-06-28 14:16 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-06-24 00:58 . 2008-06-24 00:58 d——– C:\Deckard
2008-06-23 14:08 . 2008-06-23 14:08 d——– C:\Program Files\Spyware Terminator
2008-06-23 14:08 . 2008-06-23 14:08 d——– C:\Program Files\Crawler
2008-06-23 14:08 . 2008-06-23 14:08 d——– C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-06-23 14:08 . 2008-06-23 14:08 d——– C:\Documents and Settings\Adam\Application Data\Spyware Terminator
2008-06-23 14:08 . 2008-06-23 14:08 141,312 –a—— C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-06-22 03:11 . 2008-06-22 03:11 d——– C:\Documents and Settings\All Users\Application Data\PrevxCSI
2008-06-21 16:05 . 2008-06-21 15:54 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-06-21 15:51 . 2008-06-21 15:51 d——– C:\Documents and Settings\Administrator\.housecall6.6
2008-06-21 13:30 . 2008-06-21 13:30 d–hs—- C:\FOUND.002
2008-06-21 13:01 . 2008-06-20 11:55 d——– C:\SDFix
2008-06-20 14:44 . 2008-06-20 14:44 d——– C:\Documents and Settings\Deej\Application Data\PC Tools
2008-06-20 14:19 . 2008-06-20 14:19 d——– C:\Documents and Settings\Adam\Application Data\PC Tools
2008-06-20 13:47 . 2008-06-20 13:47 d——– C:\Documents and Settings\All Users\Application Data\McAfee
2008-06-20 04:49 . 2008-06-20 04:49 d——– C:\Documents and Settings\Administrator\Application Data\PC Tools
2008-06-20 04:48 . 2008-06-20 04:48 d——– C:\Program Files\PC Tools AntiVirus
2008-06-20 04:48 . 2008-06-20 04:48 d——– C:\Program Files\Common Files\PC Tools
2008-06-20 04:48 . 2008-06-20 04:48 d——– C:\Documents and Settings\All Users\Application Data\PC Tools
2008-06-20 04:48 . 2007-12-06 15:51 28,568 –a—— C:\WINDOWS\system32\drivers\AVHook.sys
2008-06-20 04:48 . 2007-12-06 15:51 21,912 –a—— C:\WINDOWS\system32\drivers\AVRec.sys
2008-06-20 04:48 . 2008-02-12 10:44 21,904 –a—— C:\WINDOWS\system32\drivers\AVFilter.sys
2008-06-20 04:40 . 2008-06-20 04:40 d——– C:\Documents and Settings\Administrator\Application Data\AVGTOOLBAR
2008-06-20 04:39 . 2008-06-20 04:40 262,144 –a—— C:\Documents and Settings\LOGMEI~1
2008-06-20 04:25 . 2008-06-20 04:25 d——– C:\Documents and Settings\Administrator\Application Data\Talkback
2008-06-20 04:22 . 2008-06-20 04:22 d——– C:\Documents and Settings\Administrator\Application Data\Corel
2008-06-20 03:59 . 2008-06-20 03:59 d——– C:\Program Files\RegistryFix
2008-06-20 01:20 . 2008-06-20 01:20 d——– C:\Program Files\SpywareBlaster
2008-06-20 00:33 . 2008-06-20 00:33 d——– C:\!KillBox
2008-06-19 02:48 . 2008-06-22 02:57 1,052 –a—— C:\WINDOWS\system32\tmp.reg
2008-06-18 15:30 . 2008-06-19 03:23 878 —hs—- C:\WINDOWS\system32\ryceaepd.ini
2008-06-18 13:24 . 2008-06-18 13:24 d–hs—- C:\FOUND.001
2008-06-18 13:12 . 2008-06-18 13:13 2 –a—— C:\1093620849
2008-06-17 12:50 . 2008-06-17 12:50 d——– C:\Documents and Settings\Deej\Application Data\DellFaxCtr
2008-06-17 11:45 . 2008-06-17 11:45 d——– C:\Documents and Settings\Grant\Application Data\DellFaxCtr
2008-06-16 17:15 . 2008-06-16 17:15 d——– C:\Documents and Settings\Adam\Application Data\DellFaxCtr
2008-06-16 14:09 . 2008-06-25 17:51 6,580 –ahs—- C:\WINDOWS\system32\KGyGaAvL.sys
2008-06-16 14:09 . 2008-06-25 17:50 104 -r-hs—- C:\WINDOWS\system32\82F859A308.sys
2008-06-16 14:00 . 2008-06-16 14:00 d——– C:\Documents and Settings\Adam\Application Data\Corel
2008-06-16 13:59 . 2008-06-16 13:59 d——– C:\Documents and Settings\All Users\Application Data\InstallShield
2008-06-16 13:58 . 2008-06-16 13:58 d——– C:\Program Files\Corel
2008-06-16 13:58 . 2008-06-16 13:58 d——– C:\Program Files\Common Files\Corel
2008-06-16 13:57 . 2008-06-16 13:57 d——– C:\Program Files\Dell
2008-06-16 13:57 . 2008-06-16 13:57 d——– C:\Program Files\Abbyy FineReader 6.0 Sprint
2008-06-16 13:56 . 2008-06-16 13:56 d——– C:\Program Files\Dell Photo AIO Printer 926
2008-06-16 13:56 . 2008-06-16 13:56 d——– C:\Program Files\Dell PC Fax
2008-06-16 13:56 . 2008-06-16 13:56 d——– C:\Documents and Settings\All Users\Application Data\DellFaxCtr
2008-06-16 13:56 . 2006-04-24 14:58 339,968 –a—— C:\WINDOWS\system32\IMGMAN32.DLL
2008-06-16 13:56 . 2006-10-11 16:38 323,584 –a—— C:\WINDOWS\system32\dlcxhcp.dll
2008-06-16 13:56 . 2006-10-11 16:51 274,432 –a—— C:\WINDOWS\system32\dlcxinst.dll
2008-06-16 13:56 . 2006-04-24 14:58 98,345 –a—— C:\WINDOWS\system32\IMHOST32.DLL
2008-06-16 13:56 . 2006-04-24 14:58 98,304 –a—— C:\WINDOWS\system32\IM31XPNG.DEL
2008-06-16 13:56 . 2006-04-24 14:58 69,632 –a—— C:\WINDOWS\system32\IM31XTIF.DEL
2008-06-16 13:56 . 2006-04-24 14:58 49,152 –a—— C:\WINDOWS\system32\IM31IMG.DIL
2008-06-16 13:56 . 2006-10-06 07:06 45,056 –a—— C:\WINDOWS\system32\DLPRMON.DLL
2008-06-16 13:56 . 2006-10-06 07:05 32,768 –a—— C:\WINDOWS\system32\DLPMONUI.DLL
2008-06-16 13:55 . 2008-06-16 14:01 25,214 –a—— C:\WINDOWS\system32\LexFiles.ulf
2008-06-16 13:48 . 2008-06-16 13:48 d——– C:\Program Files\Dl_cats
2008-06-16 13:15 . 2008-06-16 13:15 d——– C:\Program Files\PrintMaster Scrapbook Creator
2008-06-16 13:13 . 2004-08-04 07:52 413,696 -ra—— C:\WINDOWS\system32\msvc1b2d.rra
2008-06-16 13:13 . 2006-12-18 15:43 147,456 –a—— C:\WINDOWS\system32\PhotoBase Screen Saver.scr

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-24 06:10 62,464 ——w C:\WINDOWS\system32\kdhio.exe
2008-06-18 18:12 577,536 —-a-w C:\WINDOWS\system32\user32.DLL
2008-06-18 18:12 577,536 —-a-w C:\WINDOWS\system32\dllcache\user32.dll
2008-06-13 13:10 272,128 —-a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-13 13:10 272,128 —-a-w C:\WINDOWS\system32\dllcache\bthport.sys
2008-05-29 20:43 ——— d—–w C:\Documents and Settings\Grant\Application Data\Apple Computer
2008-05-22 01:41 ——— d—–w C:\Documents and Settings\Deej\Application Data\Snapfish
2008-05-17 00:52 ——— d—–w C:\Program Files\Common Files\HP
2008-05-17 00:52 ——— d—–w C:\Documents and Settings\Deej\Application Data\Walgreens
2008-05-17 00:52 ——— d—–w C:\Documents and Settings\Deej\Application Data\W Photo Studio
2008-05-17 00:52 ——— d—–w C:\Documents and Settings\All Users\Application Data\Walgreens
2008-05-17 00:51 ——— d—–w C:\Program Files\Walgreens
2008-05-17 00:38 ——— d—–w C:\Documents and Settings\Deej\Application Data\W Photo Studio Viewer
2008-05-17 00:02 ——— d—–w C:\Program Files\Kodak
2008-05-16 23:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kodak
2008-05-16 02:06 ——— d—–w C:\Program Files\iTunes
2008-05-16 02:06 ——— d—–w C:\Program Files\iPod
2008-05-16 02:04 ——— d—–w C:\Program Files\QuickTime
2008-05-16 01:50 ——— d—–w C:\Program Files\Apple Software Update
2008-05-08 12:28 202,752 —-a-w C:\WINDOWS\system32\drivers\RMCast.sys
2008-05-08 12:28 202,752 —-a-w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:18 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:18 1,287,680 —-a-w C:\WINDOWS\system32\dllcache\quartz.dll
2008-05-06 21:33 ——— d—–w C:\Documents and Settings\Grant\Application Data\Yahoo!
2008-04-21 06:57 666,624 —-a-w C:\WINDOWS\system32\wininet.dll
2008-04-21 06:57 666,624 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2008-04-17 10:47 18,432 —-a-w C:\WINDOWS\system32\dllcache\iedw.exe
2005-04-01 03:17 40,960 —-a-w C:\Program Files\Uninstall_CDS.exe
2005-03-09 15:53 36,352 —-a-w C:\WINDOWS\inf\AMDK8.SYS
.
C:\WINDOWS\system32\user32.dll … is infected !! (additional data below)
577,536 2008-06-18 18:12:22 C:\WINDOWS\system32\user32.DLL
577,536 2008-06-18 18:12:22 C:\WINDOWS\system32\dllcache\user32.dll
263,547 2004-08-04 10:00:00 C:\WINDOWS\I386\USER32.DL_
577,024 2005-03-02 18:19:56 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
578,048 2007-03-08 15:48:36 C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
577,024 2005-03-02 18:09:30 C:\WINDOWS\$NtUninstallKB925902$\user32.dll


——- Sigcheck ——-

2008-06-18 13:12 577536 e14ff7874e97a0ba6d57d186283cbe2f C:\WINDOWS\system32\user32.DLL
2008-06-18 13:12 577536 e14ff7874e97a0ba6d57d186283cbe2f C:\WINDOWS\system32\dllcache\user32.dll
2005-03-02 13:19 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 10:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2005-03-02 13:09 577024 de2db164bbb35db061af0997e4499054 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
.
((((((((((((((((((((((((((((( snapshot@2008-06-24_ 1.20.37.60 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-24 06:17:54 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-02 05:55:14 2,048 –s-a-w C:\WINDOWS\bootstat.dat
- 2008-04-14 11:01:02 272,128 ——w C:\WINDOWS\Driver Cache\i386\bthport.sys
+ 2008-06-13 13:10:50 272,128 ——w C:\WINDOWS\Driver Cache\i386\bthport.sys
+ 2008-07-02 05:55:30 16,384 —-a-w C:\WINDOWS\Temp\Perflib_Perfdata_90.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C:\WINDOWS\system32\kdhio.exe"="C:\WINDOWS\system32\kdhio.exe" [2008-06-24 01:10 62464]
"DLCXCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 01:31 106496]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSimpleStartMenu"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=yatvjjvf.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.CEGSM"= mobilev.acm

[HKLM\~\startupfolder\C:^Documents and Settings^Adam^Start Menu^Programs^Startup^userinit.exe]
path=C:\Documents and Settings\Adam\Start Menu\Programs\Startup\userinit.exe
backup=C:\WINDOWS\pss\userinit.exeStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\WINDOWS
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\WINDOWS\system32

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\WINDOWS\system32\kdhio.exe]
——— 2008-06-24 01:10 62464 C:\WINDOWS\system32\kdhio.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
–a—— 2004-02-03 16:42 401491 C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\isuspm startup]
–a—— 2005-06-10 10:44 249856 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2004-10-13 11:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pctavapp]
–a—— 2008-03-05 09:37 1238928 C:\Program Files\PC Tools AntiVirus\PCTAV.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinVNC]
–a—— 2003-08-01 18:28 474624 C:\Program Files\TightVNC\WinVNC.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESMGR.EXE"=
"C:\\Documents and Settings\\Adam\\My Documents\\My Music\\temp lime junk\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\NovaLogic\\Delta Force Black Hawk Down\\update.exe"=
"C:\\Program Files\\NovaLogic\\Delta Force Black Hawk Down\\dfbhd.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Documents and Settings\\Deej\\My Documents\\LimeWire\\Saved\\LimeWire\\LimeWire.exe"=
"C:\\WINDOWS\\System32\\DLCXCOMS.EXE"=
"C:\\Program Files\\Mozilla Firefox\\FIREFOX.EXE"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"3386:TCP"= 3386:TCP:rdp86

R2 dlcx_device;dlcx_device;C:\WINDOWS\system32\dlcxcoms.exe [2006-11-03 17:07]
R2 MSSQL$INVENTORCONTENT;MSSQL$INVENTORCONTENT;C:\Program Files\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlservr.exe [2002-12-17 17:26]
S3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys [2002-04-03 16:06]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2004-10-29 15:14]
S3 PhnxVcd;PhnxVcd;C:\WINDOWS\system32\Drivers\PhnxVcd.sys [2005-07-20 19:12]
S3 SQLAgent$INVENTORCONTENT;SQLAgent$INVENTORCONTENT;C:\Program Files\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlagent.EXE [2002-12-17 17:23]

*Newly Created Service* - CATCHME

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
"2008-06-12 16:15:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-412f54de - C:\WINDOWS\system32\qgewwbij.dll
MSConfigStartUp-bm421c6742 - C:\WINDOWS\system32\ftodqegr.dll
MSConfigStartUp-jdgf894jrghoiiskd - C:\DOCUME~1\Adam\LOCALS~1\Temp\winlogan.exe
MSConfigStartUp-run - C:\Documents and Settings\Adam\Application Data\sp1\qtfinal.dll
MSConfigStartUp-winlogon - C:\Documents and Settings\Adam\svchost.exe
MSConfigStartUp-[system] - C:\WINDOWS\system32\drivers\services.exe


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-03 13:01:23
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCXCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-07-03 13:01:46
ComboFix-quarantined-files.txt 2008-07-03 18:01:46
ComboFix2.txt 2008-06-24 06:21:00

Pre-Run: 12,105,465,856 bytes free
Post-Run: 12,090,081,280 bytes free

234 — E O F — 2008-06-24 06:23:23


Logfile of HijackThis v1.99.1
Scan saved at 13:02:42, on 7/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\dlcxcoms.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlservr.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TightVNC\WinVNC.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Adam\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdhio.exe] C:\WINDOWS\system32\kdhio.exe
O4 - HKLM\..\Run: [DLCXCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16
O8 - Extra context menu item: crawler search - tbr:iemenu
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1134415597281
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O20 - AppInit_DLLs: yatvjjvf.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: dlcx_device - - C:\WINDOWS\system32\dlcxcoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe" -service (file missing)
rightclick on -> C:\WINDOWS\system32\user32.dll and rename it to user32.old

Then copy ->C:\WINDOWS\system32\dllcache\user32.dll to -> C:\WINDOWS\system32 folder



Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\1093620849
C:\WINDOWS\system32\msvc1b2d.rra
C:\WINDOWS\system32\kdhio.exe

Folder::
C:\FOUND.002
C:\FOUND.001

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C:\WINDOWS\system32\kdhio.exe"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\WINDOWS\system32\kdhio.exe]


Save this as CFScript.txt


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.
ComboFix 08-07-02.5 - Adam 2008-07-03 14:27:02.3 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.248 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Adam\Desktop\cfscript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\1093620849
C:\WINDOWS\system32\kdhio.exe
C:\WINDOWS\system32\msvc1b2d.rra
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\1093620849
C:\FOUND.001
C:\FOUND.001\FILE0000.CHK
C:\FOUND.001\FILE0001.CHK
C:\FOUND.001\FILE0002.CHK
C:\FOUND.002
C:\FOUND.002\FILE0000.CHK
C:\WINDOWS\b.exe
C:\WINDOWS\system32\kdhio.exe
C:\WINDOWS\system32\msvc1b2d.rra

.
((((((((((((((((((((((((( Files Created from 2008-06-03 to 2008-07-03 )))))))))))))))))))))))))))))))
.

2008-06-25 17:50 . 2008-06-25 17:50 d——– C:\Documents and Settings\Deej\Application Data\Corel Photo Album
2008-06-25 15:27 . 2008-06-25 15:27 d——– C:\Documents and Settings\Adam\Application Data\Corel Photo Album
2008-06-24 02:25 . 2008-06-24 02:25 d——– C:\Program Files\Exterminate It!
2008-06-24 01:03 . 2008-06-24 01:03 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-06-24 01:03 . 2008-06-24 01:03 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-24 01:03 . 2008-06-24 01:03 d——– C:\Documents and Settings\Adam\Application Data\Malwarebytes
2008-06-24 01:03 . 2008-06-28 14:16 34,296 –a—— C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-24 01:03 . 2008-06-28 14:16 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-06-24 00:58 . 2008-06-24 00:58 d——– C:\Deckard
2008-06-23 14:08 . 2008-06-23 14:08 d——– C:\Program Files\Spyware Terminator
2008-06-23 14:08 . 2008-06-23 14:08 d——– C:\Program Files\Crawler
2008-06-23 14:08 . 2008-06-23 14:08 d——– C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-06-23 14:08 . 2008-06-23 14:08 d——– C:\Documents and Settings\Adam\Application Data\Spyware Terminator
2008-06-23 14:08 . 2008-06-23 14:08 141,312 –a—— C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-06-22 03:11 . 2008-06-22 03:11 d——– C:\Documents and Settings\All Users\Application Data\PrevxCSI
2008-06-21 16:05 . 2008-06-21 15:54 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-06-21 15:51 . 2008-06-21 15:51 d——– C:\Documents and Settings\Administrator\.housecall6.6
2008-06-21 13:01 . 2008-06-20 11:55 d——– C:\SDFix
2008-06-20 14:44 . 2008-06-20 14:44 d——– C:\Documents and Settings\Deej\Application Data\PC Tools
2008-06-20 14:19 . 2008-06-20 14:19 d——– C:\Documents and Settings\Adam\Application Data\PC Tools
2008-06-20 13:47 . 2008-06-20 13:47 d——– C:\Documents and Settings\All Users\Application Data\McAfee
2008-06-20 04:49 . 2008-06-20 04:49 d——– C:\Documents and Settings\Administrator\Application Data\PC Tools
2008-06-20 04:48 . 2008-06-20 04:48 d——– C:\Program Files\PC Tools AntiVirus
2008-06-20 04:48 . 2008-06-20 04:48 d——– C:\Program Files\Common Files\PC Tools
2008-06-20 04:48 . 2008-06-20 04:48 d——– C:\Documents and Settings\All Users\Application Data\PC Tools
2008-06-20 04:48 . 2007-12-06 15:51 28,568 –a—— C:\WINDOWS\system32\drivers\AVHook.sys
2008-06-20 04:48 . 2007-12-06 15:51 21,912 –a—— C:\WINDOWS\system32\drivers\AVRec.sys
2008-06-20 04:48 . 2008-02-12 10:44 21,904 –a—— C:\WINDOWS\system32\drivers\AVFilter.sys
2008-06-20 04:40 . 2008-06-20 04:40 d——– C:\Documents and Settings\Administrator\Application Data\AVGTOOLBAR
2008-06-20 04:39 . 2008-06-20 04:40 262,144 –a—— C:\Documents and Settings\LOGMEI~1
2008-06-20 04:25 . 2008-06-20 04:25 d——– C:\Documents and Settings\Administrator\Application Data\Talkback
2008-06-20 04:22 . 2008-06-20 04:22 d——– C:\Documents and Settings\Administrator\Application Data\Corel
2008-06-20 03:59 . 2008-06-20 03:59 d——– C:\Program Files\RegistryFix
2008-06-20 01:20 . 2008-06-20 01:20 d——– C:\Program Files\SpywareBlaster
2008-06-20 00:33 . 2008-06-20 00:33 d——– C:\!KillBox
2008-06-19 02:48 . 2008-06-22 02:57 1,052 –a—— C:\WINDOWS\system32\tmp.reg
2008-06-18 15:30 . 2008-06-19 03:23 878 —hs—- C:\WINDOWS\system32\ryceaepd.ini
2008-06-17 12:50 . 2008-06-17 12:50 d——– C:\Documents and Settings\Deej\Application Data\DellFaxCtr
2008-06-17 11:45 . 2008-06-17 11:45 d——– C:\Documents and Settings\Grant\Application Data\DellFaxCtr
2008-06-16 17:15 . 2008-06-16 17:15 d——– C:\Documents and Settings\Adam\Application Data\DellFaxCtr
2008-06-16 14:09 . 2008-06-25 17:51 6,580 –ahs—- C:\WINDOWS\system32\KGyGaAvL.sys
2008-06-16 14:09 . 2008-06-25 17:50 104 -r-hs—- C:\WINDOWS\system32\82F859A308.sys
2008-06-16 14:00 . 2008-06-16 14:00 d——– C:\Documents and Settings\Adam\Application Data\Corel
2008-06-16 13:59 . 2008-06-16 13:59 d——– C:\Documents and Settings\All Users\Application Data\InstallShield
2008-06-16 13:58 . 2008-06-16 13:58 d——– C:\Program Files\Corel
2008-06-16 13:58 . 2008-06-16 13:58 d——– C:\Program Files\Common Files\Corel
2008-06-16 13:57 . 2008-06-16 13:57 d——– C:\Program Files\Dell
2008-06-16 13:57 . 2008-06-16 13:57 d——– C:\Program Files\Abbyy FineReader 6.0 Sprint
2008-06-16 13:56 . 2008-06-16 13:56 d——– C:\Program Files\Dell Photo AIO Printer 926
2008-06-16 13:56 . 2008-06-16 13:56 d——– C:\Program Files\Dell PC Fax
2008-06-16 13:56 . 2008-06-16 13:56 d——– C:\Documents and Settings\All Users\Application Data\DellFaxCtr
2008-06-16 13:56 . 2006-04-24 14:58 339,968 –a—— C:\WINDOWS\system32\IMGMAN32.DLL
2008-06-16 13:56 . 2006-10-11 16:38 323,584 –a—— C:\WINDOWS\system32\dlcxhcp.dll
2008-06-16 13:56 . 2006-10-11 16:51 274,432 –a—— C:\WINDOWS\system32\dlcxinst.dll
2008-06-16 13:56 . 2006-04-24 14:58 98,345 –a—— C:\WINDOWS\system32\IMHOST32.DLL
2008-06-16 13:56 . 2006-04-24 14:58 98,304 –a—— C:\WINDOWS\system32\IM31XPNG.DEL
2008-06-16 13:56 . 2006-04-24 14:58 69,632 –a—— C:\WINDOWS\system32\IM31XTIF.DEL
2008-06-16 13:56 . 2006-04-24 14:58 49,152 –a—— C:\WINDOWS\system32\IM31IMG.DIL
2008-06-16 13:56 . 2006-10-06 07:06 45,056 –a—— C:\WINDOWS\system32\DLPRMON.DLL
2008-06-16 13:56 . 2006-10-06 07:05 32,768 –a—— C:\WINDOWS\system32\DLPMONUI.DLL
2008-06-16 13:55 . 2008-06-16 14:01 25,214 –a—— C:\WINDOWS\system32\LexFiles.ulf
2008-06-16 13:48 . 2008-06-16 13:48 d——– C:\Program Files\Dl_cats
2008-06-16 13:15 . 2008-06-16 13:15 d——– C:\Program Files\PrintMaster Scrapbook Creator
2008-06-16 13:13 . 2006-12-18 15:43 147,456 –a—— C:\WINDOWS\system32\PhotoBase Screen Saver.scr

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-13 13:10 272,128 —-a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-13 13:10 272,128 —-a-w C:\WINDOWS\system32\dllcache\bthport.sys
2008-05-29 20:43 ——— d—–w C:\Documents and Settings\Grant\Application Data\Apple Computer
2008-05-22 01:41 ——— d—–w C:\Documents and Settings\Deej\Application Data\Snapfish
2008-05-17 00:52 ——— d—–w C:\Program Files\Common Files\HP
2008-05-17 00:52 ——— d—–w C:\Documents and Settings\Deej\Application Data\Walgreens
2008-05-17 00:52 ——— d—–w C:\Documents and Settings\Deej\Application Data\W Photo Studio
2008-05-17 00:52 ——— d—–w C:\Documents and Settings\All Users\Application Data\Walgreens
2008-05-17 00:51 ——— d—–w C:\Program Files\Walgreens
2008-05-17 00:38 ——— d—–w C:\Documents and Settings\Deej\Application Data\W Photo Studio Viewer
2008-05-17 00:02 ——— d—–w C:\Program Files\Kodak
2008-05-16 23:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kodak
2008-05-16 02:06 ——— d—–w C:\Program Files\iTunes
2008-05-16 02:06 ——— d—–w C:\Program Files\iPod
2008-05-16 02:04 ——— d—–w C:\Program Files\QuickTime
2008-05-16 01:50 ——— d—–w C:\Program Files\Apple Software Update
2008-05-08 12:28 202,752 —-a-w C:\WINDOWS\system32\drivers\RMCast.sys
2008-05-08 12:28 202,752 —-a-w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:18 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:18 1,287,680 —-a-w C:\WINDOWS\system32\dllcache\quartz.dll
2008-05-06 21:33 ——— d—–w C:\Documents and Settings\Grant\Application Data\Yahoo!
2008-04-21 06:57 666,624 —-a-w C:\WINDOWS\system32\wininet.dll
2008-04-21 06:57 666,624 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2008-04-17 10:47 18,432 —-a-w C:\WINDOWS\system32\dllcache\iedw.exe
2005-04-01 03:17 40,960 —-a-w C:\Program Files\Uninstall_CDS.exe
2005-03-09 15:53 36,352 —-a-w C:\WINDOWS\inf\AMDK8.SYS
.

((((((((((((((((((((((((((((( snapshot@2008-06-24_ 1.20.37.60 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-24 06:17:54 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-02 05:55:14 2,048 –s-a-w C:\WINDOWS\bootstat.dat
- 2008-04-14 11:01:02 272,128 ——w C:\WINDOWS\Driver Cache\i386\bthport.sys
+ 2008-06-13 13:10:50 272,128 ——w C:\WINDOWS\Driver Cache\i386\bthport.sys
- 2008-06-18 18:12:22 577,536 —-a-w C:\WINDOWS\system32\dllcache\user32.dll
+ 2004-08-04 10:00:00 577,024 —-a-w C:\WINDOWS\system32\dllcache\user32.dll
- 2008-06-18 18:12:22 577,536 —-a-w C:\WINDOWS\system32\user32.DLL
+ 2004-08-04 10:00:00 577,024 —-a-w C:\WINDOWS\system32\user32.dll
+ 2008-07-02 05:55:30 16,384 —-a-w C:\WINDOWS\Temp\Perflib_Perfdata_90.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DLCXCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 01:31 106496]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSimpleStartMenu"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.CEGSM"= mobilev.acm

[HKLM\~\startupfolder\C:^Documents and Settings^Adam^Start Menu^Programs^Startup^userinit.exe]
path=C:\Documents and Settings\Adam\Start Menu\Programs\Startup\userinit.exe
backup=C:\WINDOWS\pss\userinit.exeStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\WINDOWS
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\WINDOWS\system32

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
–a—— 2004-02-03 16:42 401491 C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\isuspm startup]
–a—— 2005-06-10 10:44 249856 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2004-10-13 11:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pctavapp]
–a—— 2008-03-05 09:37 1238928 C:\Program Files\PC Tools AntiVirus\PCTAV.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinVNC]
–a—— 2003-08-01 18:28 474624 C:\Program Files\TightVNC\WinVNC.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESMGR.EXE"=
"C:\\Documents and Settings\\Adam\\My Documents\\My Music\\temp lime junk\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\NovaLogic\\Delta Force Black Hawk Down\\update.exe"=
"C:\\Program Files\\NovaLogic\\Delta Force Black Hawk Down\\dfbhd.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Documents and Settings\\Deej\\My Documents\\LimeWire\\Saved\\LimeWire\\LimeWire.exe"=
"C:\\WINDOWS\\System32\\DLCXCOMS.EXE"=
"C:\\Program Files\\Mozilla Firefox\\FIREFOX.EXE"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"3386:TCP"= 3386:TCP:rdp86

R2 dlcx_device;dlcx_device;C:\WINDOWS\system32\dlcxcoms.exe [2006-11-03 17:07]
R2 MSSQL$INVENTORCONTENT;MSSQL$INVENTORCONTENT;C:\Program Files\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlservr.exe [2002-12-17 17:26]
S3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys [2002-04-03 16:06]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2004-10-29 15:14]
S3 PhnxVcd;PhnxVcd;C:\WINDOWS\system32\Drivers\PhnxVcd.sys [2005-07-20 19:12]
S3 SQLAgent$INVENTORCONTENT;SQLAgent$INVENTORCONTENT;C:\Program Files\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlagent.EXE [2002-12-17 17:23]

*Newly Created Service* - CATCHME

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
"2008-06-12 16:15:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-C:\WINDOWS\system32\kdhio.exe - C:\WINDOWS\system32\kdhio.exe


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-03 14:29:08
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCXCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-07-03 14:29:33
ComboFix-quarantined-files.txt 2008-07-03 19:29:30
ComboFix3.txt 2008-06-24 06:21:00
ComboFix2.txt 2008-07-03 18:01:48

Pre-Run: 12,010,389,504 bytes free
Post-Run: 11,995,463,680 bytes free

214 — E O F — 2008-06-24 06:23:23


Logfile of HijackThis v1.99.1
Scan saved at 10:21:18, on 7/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\dlcxcoms.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlservr.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TightVNC\WinVNC.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Adam\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdhio.exe] C:\WINDOWS\system32\kdhio.exe
O4 - HKLM\..\Run: [DLCXCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16
O8 - Extra context menu item: crawler search - tbr:iemenu
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1134415597281
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: dlcx_device - - C:\WINDOWS\system32\dlcxcoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe" -service (file missing)
Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdhio.exe] C:\WINDOWS\system32\kdhio.exe

Close ALL windows and browsers except HijackThis and click "Fix checked"

Delete these Files if listed:
C:\WINDOWS\system32\kdhio.exe


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Logfile of HijackThis v1.99.1
Scan saved at 12:15:33, on 7/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\dlcxcoms.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlservr.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TightVNC\WinVNC.exe
C:\Documents and Settings\Adam\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [DLCXCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16
O8 - Extra context menu item: crawler search - tbr:iemenu
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1134415597281
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: dlcx_device - - C:\WINDOWS\system32\dlcxcoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe" -service (file missing)


It seems to be running rather well. I do nto have any problems to note other than my system time is on military time "24hour" instead of the normal time.

ndt
Good job :thumbup:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]


    Here's my usual all clean post

    Log looks good :D


    You need to create a new Clean restore point.

    Note: This will remove all previous Restore Points

    Click Start Menu > Run > copy and paste

    %SystemRoot%\System32\restore\rstrui.exe

    Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.

    Double-click My Computer.
    Click the Tools menu, and then click Folder Options.
    Click the View tab.
    Check "Hide file extensions for known file types."
    Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
    Check "Hide protected operating system files."
    Click Apply, and then click OK.

    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
      • From within Internet Explorer click on the Tools menu and then click on Options.
      • Click once on the Security tab
      • Click once on the Internet icon so it becomes highlighted.
      • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:
    Note: I no longer suggest Zone Alarm

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
  • Winpatrol

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI