Ok fisrt off my typing skills SUCK so please do not use that agenst me. Oh yea chalk spelling to that to.
I am running XP Pro I pride myself on not having to many of these problems. I went to a site that I knew always has malware and well being late for work I downloaded a file that I had been looking for on some tips for another program. I always scan these files and really do not have a problem. Well you guessed it I forgot to scann this said file and well you know what happened.
I have been able to remove a lot of the problems and well kinda had to learn how to back door windows to even be allowed to start removing this carp**. The virus I down loaded loacked anything and everything that an administrator could lock, ie., taskmanager, control center, regedit, cmd, could not see my c:\ drive, removed the programs menu from the start button, well removed almost all of the start button functions and disabled some of my protection.
The first thing I had to do was to get to where I could use regedit. I had to do this so that I could install new malware programs. I had to disable the admin functions via a VB script. That inturn allowed me to get to the comand prompt and use regedit. I have had to do an extensive amount of reading and searching to get that problem nailed down. I enjoy my cmd and have learned to love it threw the years. Once I was able to get CMD up I ran a few cmd scripts I had collected threw the years to enable a lot of the functions I needed to even be able to find part of the problem.
Now as long as I did not reboot I could work around and found a fix to a nasty piece of malware. Sorry I am at work right so I cannot remember the name of the fix. It was a batch file that some great person wrote to remove this "ONE" virus. I was able to get my desktop back, reverted my changes to the regestry to the default for the start button ect. I will be more than happy to post the virus/Trojan or what ever it was as soon as I get home as it would be a great help to many.
The virus that I downloaded also downloaded a bunch of others with it. some I have been able to remove and some I am having a hard time with. I am going to list all the logs I have from the various programs I have used to help.
Go ahead and kick me now I was not aware of this site untill yesterday. I will also add a list of the stuff I found today after running a new program.
THANKS YOU AHEAD OF TIME YET AGAIN.
carp** I cannot seem to rid myself of:
1.w32.picrate
2.nvrsma.dll
3.stubinstaller.exe "(Just found this today)"
4.llbp.exe
5.axer.exe
6.userinit.exe "This apeared in my startup folder after I infected myself." This is a pain in the but to remove at least at my level anyways.
I have read that 18.exe is most likely a big player with these or a dirivative of 18.exe
I hope I have given enough info to help. I am a firm believer that you cannot have to much information.
Listed bellow are the logs I have:
Logfile of HijackThis v1.99.1
Scan saved at 3:01:43 AM, on 6/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\drivers\services.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\NOTEPAD.EXE
F:\Com virus work\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.yahoo.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
O4 - HKLM\..\Run: [[system]] C:\WINDOWS\system32\drivers\services.exe
O4 - HKLM\..\Run: [winlogon] C:\Documents and Settings\Administrator\svchost.exe
O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdhio.exe] C:\WINDOWS\system32\kdhio.exe
O4 - HKLM\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
O4 - HKLM\..\Run: [412f54de] rundll32.exe "C:\WINDOWS\system32\hycwkmkp.dll",b
O4 - HKLM\..\Run: [BM421c6742] Rundll32.exe "C:\WINDOWS\system32\ctrxgevy.dll",s
O4 - HKCU\..\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [[system]] C:\WINDOWS\system32\drivers\services.exe
O4 - HKCU\..\Run: [winlogon] C:\Documents and Settings\Administrator\svchost.exe
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\csrssc.exe
O4 - Startup: userinit.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1134415597281
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: xvorfwbd - {CAB01645-315D-4285-959D-2D94B02DC835} - (no file)
O21 - SSODL: wpvmqosg - {877243CA-0714-4211-937E-885FC7788366} - (no file)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: dlcx_device - - C:\WINDOWS\system32\dlcxcoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\services.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe" -service (file missing)
******************************************************************************
Process Viewer
aawservice.exe 1752 C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe Ad-Aware 2007 Service 7,0,2,6. Copyright © 2007
AppleMobileDeviceService.exe 440 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe Apple Mobile Device Service 1, 14, 0, 0. Copyright 2007 Apple, Inc. All Rights Reserved.
csrss.exe 792 C:\WINDOWS\system32\csrss.exe Client Server Runtime Process 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
csrss.exe 2096 C:\WINDOWS\system32\csrss.exe Client Server Runtime Process 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
dlcxcoms.exe 524 C:\WINDOWS\system32\dlcxcoms.exe Printer Communication System 99.99.99.99.
Explorer.EXE 732 C:\WINDOWS\Explorer.EXE Windows Explorer 6.00.2900.3156. © Microsoft Corporation. All rights reserved.
Explorer.EXE 1156 C:\WINDOWS\Explorer.EXE Windows Explorer 6.00.2900.3156. © Microsoft Corporation. All rights reserved.
InCDsrv.exe 1312 C:\Program Files\Ahead\InCD\InCDsrv.exe incdsrv 4, 3, 16, 1. Copyright 1995-2005 Nero AG and its licensors. All Rights Reserved.
lsass.exe 876 C:\WINDOWS\system32\lsass.exe LSA Shell (Export Version) 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
LSSrvc.exe 604 C:\Program Files\Common Files\LightScribe\LSSrvc.exe LightScribe Service © Copyright 2003-2006 Hewlett-Packard Development Company, LP
msmsgs.exe 3340 C:\Program Files\Messenger\msmsgs.exe Windows Messenger Version 4.7.3001. Copyright © Microsoft Corporation 2004
PCTAVSvc.exe 748 C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe PC Tools AntiVirus Engine 4, 0, 0, 26. Copyright PC Tools Research Pty Ltd 2006
PhnxCDSvr.exe 1196 C:\WINDOWS\system32\PhnxCDSvr.exe Phoenix VCD Service Application 2.1.1.13. Copyright © 1999-2005 Phoenix Technologies Ltd.
PrcView.exe 2276 C:\Documents and Settings\Administrator\Desktop\Process viewer\PrcView.exe Process Viewer Application 3.7.3.1. Developed by Igor Nys, 1995-2003
rundll32.exe 996 C:\WINDOWS\system32\rundll32.exe Run a DLL as an App 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
Rundll32.exe 2224 C:\WINDOWS\system32\Rundll32.exe Run a DLL as an App 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
rundll32.exe 3932 C:\WINDOWS\system32\rundll32.exe Run a DLL as an App 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
rundll32.exe 4084 C:\WINDOWS\system32\rundll32.exe Run a DLL as an App 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
services.exe 548 C:\WINDOWS\system32\drivers\services.exe services.exe
services.exe 864 C:\WINDOWS\system32\services.exe Services and Controller app 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
services.exe 3736 C:\WINDOWS\system32\drivers\services.exe services.exe
smss.exe 704 C:\WINDOWS\System32\smss.exe Windows NT Session Manager 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
spoolsv.exe 1948 C:\WINDOWS\system32\spoolsv.exe Spooler SubSystem App 5.1.2600.2696. © Microsoft Corporation. All rights reserved.
sqlservr.exe 624 C:\Program Files\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlservr.exe SQL Server Windows NT 8.00.760. © 1988-2003 Microsoft Corp. All rights reserved.
svchost.exe 504 C:\WINDOWS\system32\svchost.exe Generic Host Process for Win32 Services 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
svchost.exe 1084 C:\WINDOWS\system32\svchost.exe Generic Host Process for Win32 Services 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
svchost.exe 1132 C:\WINDOWS\system32\svchost.exe Generic Host Process for Win32 Services 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
svchost.exe 1240 C:\WINDOWS\system32\svchost.exe Generic Host Process for Win32 Services 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
svchost.exe 1280 C:\WINDOWS\System32\svchost.exe Generic Host Process for Win32 Services 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
svchost.exe 1452 C:\WINDOWS\system32\svchost.exe Generic Host Process for Win32 Services 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
svchost.exe 1504 C:\WINDOWS\system32\svchost.exe Generic Host Process for Win32 Services 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
svchost.exe 1628 C:\WINDOWS\system32\svchost.exe Generic Host Process for Win32 Services 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
winlogon.exe 816 C:\WINDOWS\system32\winlogon.exe Windows NT Logon Application 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
winlogon.exe 1328 C:\WINDOWS\system32\winlogon.exe Windows NT Logon Application 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
WinVNC.exe 1612 C:\Program Files\TightVNC\WinVNC.exe TightVNC Win32 Server 1, 2, 9, 0. Copyright © 1998-2002 [many holders]
wscntfy.exe 2728 C:\WINDOWS\system32\wscntfy.exe Windows Security Center Notification App 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
wscntfy.exe 3864 C:\WINDOWS\system32\wscntfy.exe Windows Security Center Notification App 5.1.2600.2180. © Microsoft Corporation. All rights reserved.
********************************************************************
Spyware Terminator
Logfile of Spyware Terminator v2.2.1.433 (db:2.006.023.000)
Scan Time: 6/23/2008 2:36:07 PM length: 667 s
Platform: WXP (5.1.0.2600)
User: Admin
Boot Mode: Normal
Scan type: %Custom_Scan%
Scanned Objects: 150805 (Critical:15)
Filter: No System items, No Safe items, No Invalid items
Running Processes
InCDsrv.exe [Nero AG] : C:\Program Files\Ahead\InCD\InCDsrv.exe
aawservice.exe [Lavasoft] : C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
prevxcsi.exe [Prevx] : C:\Program Files\PrevxCSI\prevxcsi.exe
dlcxcoms.exe [ ] : C:\WINDOWS\system32\dlcxcoms.exe
prevxcsi.exe [Prevx] : C:\Program Files\PrevxCSI\prevxcsi.exe
LSSrvc.exe [Hewlett-Packard Company] : C:\Program Files\Common Files\LightScribe\LSSrvc.exe
sqlservr.exe [Microsoft Corporation] : C:\Program Files\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlservr.exe
PCTAVSvc.exe [PC Tools Research Pty Ltd] : C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
WinVNC.exe [Constantin Kaplinsky] : C:\Program Files\TightVNC\WinVNC.exe
services.exe : C:\WINDOWS\system32\drivers\services.exe
Internet Settings
R - HKLM\Software\Microsoft\Internet Explorer\Main, Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
R - HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
R - HKLM\Software\Microsoft\Internet Explorer\Search, CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
R - HKLM\System\CurrentControlSet\Services\Tcpip\Parameters, Domain =
R - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony, DomainName =
BHO
02 - BHO: - {1DC01F38-2C8F-45EF-84A5-8C0D72FA3E3D} - : C:\WINDOWS\system32\nnnnNfCV.dll
02 - BHO: - {4335E25B-2CC3-41EA-B419-4123924DED36} - : C:\WINDOWS\system32\efcBuvWO.dll
02 - BHO: - {cf4dfb1d-ff8e-4c2e-87d2-93d391d7e0d3} - : C:\WINDOWS\system32\yatvjjvf.dll
02 - BHO: Messenger Class - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - [Yahoo! Inc.] : C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
StartUps
04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, [system] : : C:\WINDOWS\system32\drivers\services.exe
04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, winlogon : : C:\Documents and Settings\Adam\svchost.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, C:\WINDOWS\system32\kdhio.exe : : C:\WINDOWS\system32\kdhio.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, [system] : : C:\WINDOWS\system32\drivers\services.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, winlogon : : C:\Documents and Settings\Adam\svchost.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, 412f54de : : C:\WINDOWS\system32\xjmivvol.dll
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, BM421c6742 : : C:\WINDOWS\system32\hsrtpaff.dll
04 - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows, AppInit_DLLs : : C:\WINDOWS\system32\yatvjjvf.dll
04 - HKLM\System\CurrentControlSet\Control\Session Manager, BootExecute : : C:\WINDOWS\system32\lsdelete.exe
04 - Startup: : C:\Documents and Settings\Adam\Start Menu\Programs\Startup\userinit.exe
Shell Extensions
YMailShellExt Class - {5464D816-CF16-4784-B9F3-75C0DB52B499} - [Yahoo! Inc.] : C:\Program Files\Yahoo!\Common\ymmapi.dll
Outlook File Icon Extension - {0006F045-0000-0000-C000-000000000046} - [Microsoft Corporation] : C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL
dBpShell Class - {FED7043D-346A-414D-ACD7-550D052499A7} - : C:\Program Files\Illustrate\dBpowerAMP\dBShell.dll
dMCIShell Class - {2C49B5D0-ACE7-4D17-9DF0-A254A6C5A0C5} - : C:\Program Files\Illustrate\dBpowerAMP\dMCShell.dll
WinRAR - {B41DB860-8EE4-11D2-9906-E49FADC173CA} - : C:\Program Files\WinRAR\rarext.dll
Desktop Explorer - {1CDB2949-8F65-4355-8456-263E7C208A5D} - [NVIDIA Corporation] : C:\WINDOWS\system32\nvshell.dll
- {1E9B04FB-F9E5-4718-997B-B8DA88302A47} - [NVIDIA Corporation] : C:\WINDOWS\system32\nvshell.dll
Shell Extension for CDRW - {950FF917-7A57-46BC-8017-59D9BF474000} - [Nero AG] : C:\Program Files\Ahead\InCD\incdshx.dll
ConvShlExt Class - {DB7CFAED-842B-47E7-9FF4-92852D617958} - : C:\Program Files\BeeThink MP3 WMA To Wav 2.0\YJ.dll
ConvShlExt Class - {DB7CFAEE-842B-47E7-9FF4-92852D617958} - : C:\Program Files\BeeThink MP3 WMA To Wav 2.0\TL.dll
Acrobat Elements Context Menu - {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} - [Adobe Systems Inc.] : C:\Program Files\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll
iTunes - {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} - [Apple Inc.] : C:\Program Files\iTunes\iTunesMiniPlayer.dll
Shell Extecute Hooks
- {{1DC01F38-2C8F-45EF-84A5-8C0D72FA3E3D}} - : C:\WINDOWS\system32\nnnnNfCV.dll
Protocol Handler
mctp: Asynchronous Pluggable Protocol Handler - {d7b95390-b1c5-11d0-b111-0080c712fe82} - [Microsoft Corporation] : C:\Program Files\Microsoft ActiveSync\aatp.dll
Services
23 - [Lavasoft] : C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
23 - [Realtek Semiconductor Corp.] : C:\WINDOWS\system32\drivers\ALCXWDM.SYS
23 - [PC Tools Research Pty Ltd] : C:\WINDOWS\system32\drivers\AVFilter.sys
23 - [PC Tools Research Pty Ltd.] : C:\WINDOWS\system32\drivers\AVHook.sys
23 - [PC Tools Research Pty Ltd] : C:\WINDOWS\system32\drivers\AVRec.sys
23 - [IVT Corporation] : C:\WINDOWS\system32\DRIVERS\blueletaudio.sys
23 - [IVT Corporation] : C:\WINDOWS\system32\DRIVERS\btnetdrv.sys
23 - : C:\WINDOWS\system32\DRIVERS\vbtenum.sys
23 - [IVT Corporation] : C:\WINDOWS\system32\Drivers\BTHidMgr.sys
23 - [Prevx] : C:\Program Files\PrevxCSI\prevxcsi.exe
23 - [VIA Technologies, Inc.] : C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys
23 - [GEAR Software Inc.] : C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
23 - [Intel Corporation] : C:\WINDOWS\system32\DRIVERS\iaStor.sys
23 - [Nero AG] : C:\WINDOWS\system32\DRIVERS\InCDPass.sys
23 - [Nero AG] : C:\Program Files\Ahead\InCD\InCDsrv.exe
23 - [Hewlett-Packard Company] : C:\Program Files\Common Files\LightScribe\LSSrvc.exe
23 - [PC Tools Research Pty Ltd] : C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
23 - [Silicon Image, Inc] : C:\WINDOWS\system32\DRIVERS\pnp680r.sys
23 - [Prevx] : C:\WINDOWS\system32\drivers\pxark.sys
23 - [Trend Micro Inc.] : C:\WINDOWS\system32\drivers\tmcomm.sys
23 - [Promise Technology, Inc.] : C:\WINDOWS\system32\DRIVERS\ultra.sys
23 - [IVT Corporation] : C:\WINDOWS\system32\DRIVERS\VComm.sys
23 - [IVT Corporation] : C:\WINDOWS\system32\Drivers\VcommMgr.sys
23 - [VIA Technologies inc,.ltd] : C:\WINDOWS\system32\DRIVERS\viamraid.sys
23 - [Jungo] : C:\WINDOWS\system32\drivers\windrvr6.sys
23 - [Constantin Kaplinsky] : C:\Program Files\TightVNC\WinVNC.exe
Winlogon Notify
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\nnnnnfcv, DLLName : : C:\WINDOWS\system32\nnnnNfCV.dll
System Policies
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFolderOptions : :
Threat Files
[Constantin Kaplinsky] : C:\Program Files\TightVNC\WinVNC.exe
: C:\Program Files\TightVNC\VNCHOOKS.DLL
: C:\Documents and Settings\Adam\Start Menu\Programs\Startup\userinit.exe
: C:\Documents and Settings\Adam\Desktop\SmitfraudFix\Reboot.exe
: C:\Documents and Settings\Adam\Desktop\SmitfraudFix\restart.exe
: C:\axer.exe
: C:\llbp.exe
<180searchAssistant> : C:\StubInstaller.exe
: C:\WINDOWS\system32\nvrsma.dll.ren
: C:\Documents and Settings\Administrator\Desktop\SmitfraudFix\Reboot.exe
: C:\Documents and Settings\Administrator\Desktop\SmitfraudFix\restart.exe
: C:\Documents and Settings\Deej\Local Settings\Temp\csrssc.exe
: C:\Program Files\Mozilla Firefox\SmitfraudFix\Reboot.exe
: C:\Program Files\Mozilla Firefox\SmitfraudFix\restart.exe
Advanced Files Report
%COMMONFILES%\PC Tools\Lsp\PCTLsp.dll [PC Tools Research Pty Ltd.] [PC Tools Content Filter] MD5=65CCD937502870F0464582B190571E34 SIZE=190360
%PROGRAMFILES%\Ahead\InCD\InCDsrv.exe [Nero AG] [Nero AG incdsrv] MD5=26F6FF6832756F6662DBDD7B3C9AF5FF SIZE=869888
%PROGRAMFILES%\Ahead\InCD\incdshx.dll [Nero AG] [Nero AG InCD Shell Extension] MD5=66FFA80DA375A0867BD4AD208D1C3C51 SIZE=103424
%PROGRAMFILES%\Lavasoft\Ad-Aware 2007\aawservice.exe [Lavasoft] [Ad-Aware 2007 Service] MD5=0629361FAC4576BA48AB39F4903DCE9E SIZE=587096
%PROGRAMFILES%\Lavasoft\Ad-Aware 2007\CEAPI.dll [Lavasoft] [CEAPI Dynamic Link Library] MD5=759C45CA544A92DE4B88618894A15587 SIZE=738664
%PROGRAMFILES%\Lavasoft\Ad-Aware 2007\PKArchive85u.dll [PKWARE, Inc.] [PKWARE Archive API] MD5=46374252AFA0A37F4F7AF528F6F16B96 SIZE=907096
%PROGRAMFILES%\Lavasoft\Ad-Aware 2007\Update.dll [Update Dynamic Link Library] MD5=72CCE73551D24D7863369F3BFD6548C9 SIZE=525664
%SYSDIR%\AdobePDF.dll [Adobe Systems Incorporated.] [Acrobat ® PDF Port for Windows] MD5=381915766C2A5E47A7DB95423CE09A16 SIZE=21099
%PROGRAMFILES%\Adobe\Acrobat 6.0\Distillr\adistres.dll [Adobe Systems Incorporated.] [Acrobat Distiller for Windows] MD5=F41A8F6E80DB4853CFC8613F72B53E12 SIZE=155648
%SYSDIR%\dlcxlmpm.dll [Printer Communication System] MD5=2A0C32CB84C6313400EF1B8626307C55 SIZE=585728
%SYSDIR%\DLPRMON.DLL [Dell Fax Solutions Software] MD5=6048E9C383F1807187ABB4517ABC8BA5 SIZE=45056
%SYSDIR%\IMGMAN32.dll [Data Techniques, Inc.] [ImageMan Image Processing Toolkit] MD5=86C5AAC31EA7909121327701045F74BD SIZE=339968
%SYSDIR%\IM31IMG.DIL [Data Techniques, Inc.] [ImageMan Image Processing Toolkit] MD5=9F22E3CE1639917EB07DCC730CD0D410 SIZE=49152
%PROGRAMFILES%\Dell PC Fax\DlCtrStr.dll [Dell Fax Solutions Software] MD5=FCB4DCFDE1EAF2189DFD2F016E1A27A1 SIZE=16384
%PROGRAMFILES%\Dell PC Fax\ipcmt.dll [Dell Fax Solutions Software] MD5=6F0335CD580DAD17EAB0963A6C434CFE SIZE=32768
%SYSDIR%\spool\PRTPROCS\W32X86\dlcxdrpp.dll [Windows 2K/XP Printer Driver] MD5=C4C21FB6300A27BAA8331917199484E9 SIZE=117760
%PROGRAMFILES%\PrevxCSI\prevxcsi.exe [Prevx] [Prevx] MD5=3D49D3FDB4BBE1FE1A07C133EDA1D8C0 SIZE=623160
%SYSDIR%\dlcxcoms.exe [Printer Communication System] MD5=D71B2CD799AD3AEEED2C29D02B0B5170 SIZE=537480
%COMMONFILES%\LightScribe\LSSrvc.exe [Hewlett-Packard Company] [LightScribe] MD5=F34B35F6F74E28A460749DA11D1117F8 SIZE=79136
%COMMONFILES%\LightScribe\LSSProxy.dll [Hewlett-Packard Company] [LightScribe] MD5=B0EA38637D86C6BEF855801F741E5027 SIZE=110592
%COMMONFILES%\LightScribe\LSLog.dll [Hewlett-Packard Company] [LightScribe] MD5=469BD51B465887FD4C78A6A0D598902C SIZE=33280
%PROGRAMFILES%\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlservr.exe [Microsoft Corporation] [Microsoft SQL Server] MD5=F80EEC5E1D6CDF82CB974DAADA0C57DD SIZE=7520337
%PROGRAMFILES%\PC Tools AntiVirus\PCTAVSvc.exe [PC Tools Research Pty Ltd] [PC Tools AntiVirus Engine] MD5=3E2F12850B761E9D0CBE0EA18ED448D4 SIZE=767888
%PROGRAMFILES%\PC Tools AntiVirus\xerdom.dll MD5=52D92DC73C8272C9DC8498C599143DC1 SIZE=321432
%PROGRAMFILES%\PC Tools AntiVirus\Xerces.dll [Apache Software Foundation] [Xerces-C Version 2.7.0] MD5=1D5FDBCDC25F2D3287DEBDBDCDF1B2C6 SIZE=1812376
%PROGRAMFILES%\PC Tools AntiVirus\PCTCFilter.dll [PCTOOLS AV Content Filter Wrapper DLL] MD5=33FC3D13F13B7537E1639095F25089AF SIZE=83864
%PROGRAMFILES%\PC Tools AntiVirus\engine.dll [PC Tools Research Pty Ltd] [PC Tools Engine DLL for Windows NT/2000/XP] MD5=4701AD16BB6D611FD921DFE5B951BC2D SIZE=956312
%PROGRAMFILES%\PC Tools AntiVirus\refdb.dll MD5=21BAE2C469EC1BF208CAE0B288AB381F SIZE=92056
%SYSDIR%\dlcxdrs.dll MD5=3130314CC9B6C17DBD2B55F6B0D71E19 SIZE=692224
%SYSDIR%\dlcxcfg.dll [config] MD5=D806B1FD27277E66C2A87D13D1161896 SIZE=73728
%SYSDIR%\dlcxcaps.dll MD5=A7177E54F8B624843DD6BF0B599BA74A SIZE=65536
%SYSDIR%\dlcxcnv4.dll MD5=EAE8F7F4A870B9BD705464E93D824F9E SIZE=61440
%PROGRAMFILES%\ArcSoft\PhotoImpression 5\share\pihook.dll MD5=9064D871EF0125B58CC58AFC767F1E47 SIZE=53248
%PROGRAMFILES%\BeeThink MP3 WMA To Wav 2.0\TL.dll [AudioConverter Module] MD5=D34EEE032136A9FB60E330DC3D398F7A SIZE=69632
%PROGRAMFILES%\WinRAR\rarext.dll MD5=7F24AABF0ABD066BEA68F09B999DC1FE SIZE=119808
%SystemDiskRoot%\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
%SYSDIR%\jfiehayd.dll
%PROGRAMFILES%\Yahoo!\Messenger\YahooMessenger.exe [Yahoo! Inc.] [Yahoo! Messenger] MD5=3A756D4066CC3BB8426EB08ABB6B5B10 SIZE=4662776
deskpan.dll
%PROGRAMFILES%\Yahoo!\Common\ymmapi.dll [Yahoo! Inc.] [YMMAPI Module] MD5=A0C86DB296BBE76145377D56C5975175 SIZE=190496
%PROGRAMFILES%\Microsoft Office\Office10\OLKFSTUB.DLL [Microsoft Corporation] [Microsoft Outlook] MD5=3756445FEBC6CBC90AFC22E5E38F7294 SIZE=54688
%PROGRAMFILES%\Illustrate\dBpowerAMP\dBShell.dll [dBShell Module] MD5=D6AA02CE1F8A522543CE9AA2572685E6 SIZE=86016
%PROGRAMFILES%\Illustrate\dBpowerAMP\dMCShell.dll [dMCShell Module] MD5=BD433F12577C40839588F0BDB790173E SIZE=110592
%SYSDIR%\nvshell.dll [NVIDIA Corporation] [NVIDIA Desktop Explorer, Version 44.03] MD5=08063F7DF5DC0146534725745010CE91 SIZE=467016
%PROGRAMFILES%\BeeThink MP3 WMA To Wav 2.0\YJ.dll [AudioConverter Module] MD5=34CD87529E63E0609CE9F22D1379970A SIZE=69632
%PROGRAMFILES%\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll [Adobe Systems Inc.] [Adobe Acrobat Elements] MD5=CDDBD1E9B24C0CDF9C8C5BE2DC27B5D4 SIZE=409687
%PROGRAMFILES%\iTunes\iTunesMiniPlayer.dll [Apple Inc.] [iTunes] MD5=CB77693D6E94DA5DF7AA007B0671D42C SIZE=132392
%SYSDIR%\drivers\ALCXWDM.SYS [Realtek Semiconductor Corp.] [Windows ® WDM driver for Realtek AC'97 Audio(HRTF data Copyright 1994 by MIT Media Lab)] MD5=36223C0FF66AFD94D1D73FCB8FDFE91E SIZE=3797632
%SYSDIR%\svchost.exe -k netsvcs
%SYSDIR%\drivers\AVFilter.sys [PC Tools Research Pty Ltd] [AVFilter Device Driver] MD5=1E238735F42CFA3429BEE1E7C52D360F SIZE=21904
%SYSDIR%\drivers\AVHook.sys [PC Tools Research Pty Ltd.] [PC Tools AntiVirus] MD5=C7D6AEAE29826584CC24A10ADAFF86FC SIZE=28568
%SYSDIR%\drivers\AVRec.sys [PC Tools Research Pty Ltd] [PC Tools AntiVirus] MD5=D38DD9338AE5038833E1308D84418708 SIZE=21912
%SYSDIR%\DRIVERS\blueletaudio.sys [IVT Corporation] [Windows ® 2000 DDK driver] MD5=04E84C8049EE93614A2FF6D676D1E247 SIZE=20480
%SYSDIR%\DRIVERS\btnetdrv.sys [IVT Corporation] [BlueSoleil] MD5=D1813668A0117AE05BC0B81C874F91D4 SIZE=10804
%SYSDIR%\DRIVERS\vbtenum.sys MD5=161969D2DD1D39CD2F1EDBC60C61FA99 SIZE=11860
%SYSDIR%\Drivers\BTHidMgr.sys [IVT Corporation] [BlueSoleil©] MD5=A9164C2A39BD917B9F42AE087560AC3D SIZE=28271
%SYSDIR%\svchost -k DcomLaunch
%SYSDIR%\dlcxcoms.exe -service
%SYSDIR%\svchost.exe -k NetworkService
%SYSDIR%\DRIVERS\fetnd5bv.sys [VIA Technologies, Inc.] [VIA Rhine Family Fast Ethernet Adapter] MD5=CFC4CC73C903152A23E1DB28EABA1F03 SIZE=42496
%SYSDIR%\Drivers\GEARAspiWDM.sys [GEAR Software Inc.] [CD DVD Filter] MD5=5DC17164F66380CBFEFD895C18467773 SIZE=16168
%SYSDIR%\DRIVERS\iaStor.sys [Intel Corporation] [Intel Matrix Storage Manager driver] MD5=309C4D86D989FB1FCF64BD30DC81C51B SIZE=874240
%SYSDIR%\DRIVERS\InCDPass.sys [Nero AG] [InCD] MD5=40F9A7FD0CA8548E51C2703AB864FFC8 SIZE=29696
%SYSDIR%\svchost.exe -k LocalService
%PROGRAMFILES%\Microsoft SQL Server\MSSQL$INVENTORCONTENT\Binn\sqlservr.exe -sINVENTORCONTENT
%SYSDIR%\DRIVERS\pnp680r.sys [Silicon Image, Inc] [Medley] MD5=A1D7A9214B71EBBB6F31CB84AAC15525 SIZE=76976
%SYSDIR%\drivers\pxark.sys [Prevx] [Prevx CSI] MD5=0ADCCE30DC59528C32D7288F16FD1A25 SIZE=17408
%SYSDIR%\svchost -k rpcss
%SYSDIR%\svchost.exe -k imgsvc
%SYSDIR%\drivers\tmcomm.sys [Trend Micro Inc.] [ActiveClean] MD5=DF8444A8FA8FD38D8848BDD40A8403B3 SIZE=102664
%SYSDIR%\DRIVERS\ultra.sys [Promise Technology, Inc.] [Promise ultra66 Miniport Driver for WindowsNT] MD5=1B698A51CD528D8DA4FFAED66DFC51B9 SIZE=36736
%SYSDIR%\DRIVERS\VComm.sys [IVT Corporation] [BlueSoleil] MD5=9EBEE4A060C5364A31AEAA04EAC2AF1E SIZE=61312
%SYSDIR%\Drivers\VcommMgr.sys [IVT Corporation] [BlueSoleil] MD5=630BBDBF5490F8F57ABE650DA63661A0 SIZE=82148
%SYSDIR%\DRIVERS\viamraid.sys [VIA Technologies inc,.ltd] [VIA RAID driver] MD5=F199939205DCCC7836AE5AB8B5DD5E83 SIZE=74112
%SYSDIR%\drivers\windrvr6.sys [Jungo] [WinDriver Device Driver] MD5=2C7D830E86B378771AF5DAFEAE428A09 SIZE=256568
%SYSDIR%\svchost.exe -k WudfServiceGroup
%PROGRAMFILES%\Microsoft ActiveSync\aatp.dll [Microsoft Corporation] [Microsoft Windows CE Services] MD5=2A57FFC89F27DCE24A5F9365C5946AF6 SIZE=77903
%SYSDIR%\MACROMED\SHOCKWAVE 10\GTAPI.DLL MD5=AE5CDA196A69F583DD356E7487AF3B49 SIZE=52288
End of Report
Remove Process:
Preparing structures
Remove Trojan.W32.VB.URT
Deleted File: C:\Documents and Settings\Adam\Start Menu\Programs\Startup\userinit.exe
Remove Trojan.Crypt.XPACK.Gen
Deleted File: c:\axer.exe
Deleted File: c:\llbp.exe
Remove Trojan.Agent.qrb
File selected for deletion does not exist: c:\WINDOWS\system32\nvrsma.dll.ren
Remove 180searchAssistant
Deleted File: c:\StubInstaller.exe
Remove Trojan.Downloader.Suurch.ef
Deleted File: c:\Documents and Settings\Deej\Local Settings\Temp\csrssc.exe
Done
*****************************************************************
File Find of "userinit.exe"
C:\userinit.exe - 13824 Bytes
C:\WINDOWS\system32\userinit.exe - 24576 Bytes
C:\WINDOWS\system32\dllcache\userinit.exe - 24576 Bytes
C:\Documents and Settings\Adam\Start Menu\Programs\Startup\userinit.exe - 13824 Bytes
C:\Documents and Settings\Deej\Start Menu\Programs\Startup\userinit.exe - 13824 Bytes
Again I hope this is enough info to help me out. You guys really do seem to know your stuff. I am not completely unsavy but I am limited. I am also willing to learn any and all.
Thanks you
ndt