This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trogen.Win32.Monderc.Gen doesn't go away!

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello there, I've gotten myself an annoying problem! Hope you guys can help!

I don't know exactly when this started or how it started in the first place.

I ran Kaspersky Antivirus and found a couple trojans, got them removed except for one.
Kaspersky Antivirus fails to remove it or quarantene it. It's located C:\WINNT\SYSTEM32\jJBtrqR.dll.
Whilst on my PC, my explorer.exe crashes everynow and then and I have to restart it, my computer
loads pretty slower and my other progams rush quite slow aswell. It also seems that as long as
I have this trojan, others come along with it, it'll be some abstract named .dll and other problems
associated with those trojans ensue such as slower cpu time, unable to surf the web and start
other programs and again more frequent explore.exe crashing, windows saying certain .dlls files
aren't the right "image" (the ones that are randomly spawned).

before I post my HijackThis Log, I'd like to also put in that… my clock was changed to 24 hour clock
type! I did not change this! Could this be related to my problem? My computer says its on 12 hour time,
but in my task bar it displays as 24 hours.

Here is my log, thanks in advance.




Logfile of HijackThis v1.99.1
Scan saved at 14:24:39, on 7/20/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINNT\system32\cisvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\System32\msdtc.exe
C:\WINNT\system32\mqsvc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\SxgTkBar.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\Wireless LAN\WlanUtil.exe
C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ultralinks.info/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,C:\WINNT\system32\svcinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {142630B9-B0DF-4058-9C32-BB7FC23B1A65} - C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WXAVGLQZ\3077ahntdksr[1].dll
O2 - BHO: (no name) - {A260787B-911C-49A1-AE73-EC76A3CEC27E} - (no file)
O2 - BHO: (no name) - {F08D08A3-B63F-46FC-8272-2EB3117EC084} - C:\WINNT\system32\tqejxaxk.dll
O2 - BHO: (no name) - {FE203CBF-2980-4E9E-AD02-7FCB018DFAFF} - C:\WINNT\system32\ljJBtrqR.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [SxgTkBar] SxgTkBar.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtray.exe SetReg
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [intdctrr] C:\WINNT\system32\idctup20.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\Program Files\PestPatrol\PPControl.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [NetPumper] "C:\Program Files\NetPumper\NetPumperIEProxy.exe"
O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: IEEE 802.11g USB Wireless LAN Utility.lnk = C:\Program Files\Wireless LAN\WlanUtil.exe
O4 - Global Startup: Microsoft Broadband Networking.lnk = C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.1.1.74.cab
O16 - DPF: {f760cb9e-c60f-4a89-890e-fae8b849493e} -
O17 - HKLM\System\CCS\Services\Tcpip\..\{1E0A612D-E7DA-448E-A7BD-665A904BCCCB}: NameServer = 192.168.254.254
O17 - HKLM\System\CCS\Services\Tcpip\..\{95EFE720-4E19-4D5E-A91A-9815B45BAB71}: Domain = frontiernet.net
O17 - HKLM\System\CCS\Services\Tcpip\..\{D111BF2D-EC5C-4063-AF53-46D3782FF089}: NameServer = 192.168.1.1,192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{1E0A612D-E7DA-448E-A7BD-665A904BCCCB}: NameServer = 192.168.254.254
O17 - HKLM\System\CS2\Services\Tcpip\..\{1E0A612D-E7DA-448E-A7BD-665A904BCCCB}: NameServer = 192.168.254.254
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll
O20 - Winlogon Notify: klogon - C:\WINNT\system32\klogon.dll
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O20 - Winlogon Notify: vtutu - C:\WINNT\system32\vtutu.dll (file missing)
O20 - Winlogon Notify: yayWnoOg - C:\WINNT\
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
Hi Dave_63, and Welcome to WhatTheTech

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

You appear to be running two Anti-Virus programs: Kaspersky and Norton. Running two Anti-Virus programs simultaneously can cause problems. Please uninstall one of them. Please keep the one that is current and up-to-date. Because you mentioned Kaspersky rather than Norton, I'm assuming you'll want to keep Kaspersky.

  • Click Start, then Settings, then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, Remove all programs that mention Norton or Symantec


A. Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

B. Now we must disable some of your security programs so that they do not interfere with the running of our tools:

KASPERSKY ANTIVIRUS
Please navigate to the system tray on the bottom right hand corner and look for a [external image: Posted Image] sign.
  • right click it-> select Pause Protection.
  • click on -> By User Request
  • a popup will claim that protection is now disabled and a sign like this: [external image: Posted Image] will now be shown.
You succesfully disabled the Kaspersky Antivirus Guard.


C.Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • DO NOT USE your computer for any other purpose while ComboFix is running.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hi! Thank you for replying! I ran the combofix and an error came up saying it couldn't create some registry keys.
Other than that, the scan ran perfectly.

Here's the combofix log:

ComboFix 08-07-23.3 - Administrator 2008-07-23 17:09:00.2 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.1733 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINNT\t\
.
—- Previous Run ——-
.
C:\WINNT\pskt.ini
C:\WINNT\SYSTEM32\bfnqkgri.ini
C:\WINNT\system32\ckluhagv.ini
C:\WINNT\system32\ddspgwbw.ini
C:\WINNT\system32\gipiyhel.dll
C:\WINNT\system32\ihlcqh.dll
C:\WINNT\system32\ijeipvqx.ini
C:\WINNT\system32\ljJBtrqR.dll
C:\WINNT\system32\lpwareld.dll
C:\WINNT\system32\mcrh.tmp
C:\WINNT\system32\mdm.exe
C:\WINNT\system32\mstneawn.dll
C:\WINNT\system32\nnfqobdt.dll
C:\WINNT\system32\pirjoifo.ini
C:\WINNT\SYSTEM32\ptyemcij.ini
C:\WINNT\system32\rmsvvvup.ini
C:\WINNT\SYSTEM32\RqrtBJjl.ini
C:\WINNT\SYSTEM32\RqrtBJjl.ini2
C:\WINNT\SYSTEM32\tdboqfnn.ini
C:\WINNT\system32\tqejxaxk.dll
C:\WINNT\system32\ugdigybq.dll
C:\WINNT\SYSTEM32\ututv.bak1
C:\WINNT\SYSTEM32\ututv.bak2
C:\WINNT\SYSTEM32\ututv.ini
C:\WINNT\system32\vahxgiqt.dll
C:\WINNT\system32\vpljaolv.ini
C:\WINNT\system32\xdpjmg.dll
C:\WINNT\system32\xfsnxuqu.dll
C:\WINNT\t\
C:\WINNT\Web\default.htt

.
((((((((((((((((((((((((( Files Created from 2008-06-24 to 2008-07-24 )))))))))))))))))))))))))))))))
.

2008-07-23 17:09 . 08-07-23 17:09 16,384 –a—-t- C:\WINNT\SYSTEM32\Perflib_Perfdata_34c.dat
2008-07-20 12:13 . 08-07-20 12:13 2,923 –a—— C:\WINNT\SYSTEM32\rmyukqbw.dll
2008-07-20 12:10 . 08-07-20 12:10 2,923 –a—— C:\WINNT\SYSTEM32\epbvfcgt.dll
2008-07-18 16:42 . 08-07-18 16:42 2,923 –a—— C:\WINNT\SYSTEM32\qhwcmkcp.dll
2008-07-18 16:40 . 08-07-18 16:40 2,923 –a—— C:\WINNT\SYSTEM32\uvfpinlt.dll
2008-07-18 16:40 . 08-07-18 16:40 2,923 –a—— C:\WINNT\SYSTEM32\mdumyrsx.dll
2008-07-17 23:28 . 05-01-22 12:12 679,936 –a—— C:\WINNT\SYSTEM32\D3DX81ab.dll
2008-07-17 23:23 . 08-07-17 23:23

d——– C:\Program Files\WinPcap
2008-07-17 23:22 . 08-07-17 23:43 d——– C:\Program Files\WC3Banlist
2008-07-16 10:33 . 08-07-16 10:33 2,923 –a—— C:\WINNT\SYSTEM32\esttblve.dll
2008-07-16 10:30 . 08-07-16 10:30 2,923 –a—— C:\WINNT\SYSTEM32\wefoiulw.dll
2008-07-16 10:27 . 08-07-16 10:27 2,923 –a—— C:\WINNT\SYSTEM32\rfwbelfg.dll
2008-07-14 00:39 . 08-07-22 18:14 643,086 —h—– C:\WINNT\ShellIconCache
2008-07-11 23:49 . 99-12-17 10:13 86,016 –a—— C:\WINNT\unvise32.exe
2008-07-11 23:45 . 08-07-11 23:45 d——– C:\sierra
2008-07-06 22:49 . 08-07-06 22:49 d——– C:\Documents and Settings\Administrator\.dracis_client
2008-07-06 12:35 . 08-07-06 12:35 d——– C:\Program Files\MagicISO
2008-07-06 10:44 . 08-07-06 10:44 2,923 –a—— C:\WINNT\SYSTEM32\bppmbkos.dll
2008-07-06 10:15 . 08-07-06 10:15 2,923 –a—— C:\WINNT\SYSTEM32\stfxfndn.dll
2008-07-05 22:28 . 08-07-05 22:28 0 –ahs—- C:\WINNT\klif.spi
2008-07-05 22:09 . 08-07-05 22:23 96,966 –a—— C:\WINNT\SYSTEM32\DRIVERS\klin.dat
2008-07-05 22:09 . 08-07-05 22:23 88,774 –a—— C:\WINNT\SYSTEM32\DRIVERS\klick.dat
2008-07-05 22:07 . 08-07-05 22:07 d——– C:\Program Files\Kaspersky Lab
2008-07-05 22:07 . 08-07-23 16:56 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-05 21:54 . 08-07-05 21:54 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-07-05 10:16 . 08-07-05 10:16 2,923 –a—— C:\WINNT\SYSTEM32\houfrkvd.dll
2008-07-05 10:13 . 08-07-05 10:13 2,923 –a—— C:\WINNT\SYSTEM32\yawfuyet.dll
2008-07-03 20:52 . 08-07-03 20:52 d——– C:\Program Files\SCi
2008-07-03 14:00 . 08-07-23 11:26 110,498 –a—— C:\WINNT\BMbf1217c8.xml
2008-07-03 13:52 . 08-07-03 13:52 d——– C:\Documents and Settings\All Users\Application Data\ADSL Software Ltd
2008-07-02 20:03 . 08-07-10 09:04 d——– C:\Program Files\Microsoft Games
2008-07-02 10:59 . 08-07-02 10:59 d——– C:\Program Files\Acclaim
2008-06-24 15:37 . 08-06-24 15:37 d——– C:\Documents and Settings\Administrator\Application Data\Viewpoint

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-23 21:22 ——— d—–w C:\Program Files\Warcraft III
2008-07-14 19:55 ——— d—–w C:\Program Files\Starcraft
2008-07-06 09:36 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Lavasoft
2008-07-06 05:16 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-07-06 05:00 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-07-04 06:45 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-07-04 05:30 ——— d—–w C:\Program Files\Symantec
2008-07-03 23:05 ——— d—–w C:\Program Files\AIM
2008-06-29 20:09 ——— d—–w C:\Program Files\Viewpoint
2008-06-24 02:18 65,536 —-a-w C:\WINNT\IFinst27.exe
2008-06-24 02:18 ——— d—–w C:\Program Files\Gravity
2008-06-18 23:47 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Winamp
2008-06-18 23:24 ——— d—–w C:\Program Files\Winamp
2008-06-18 13:49 ——— d—–w C:\Program Files\EA GAMES
2008-06-08 19:02 ——— d—–w C:\Program Files\Ventrilo
2008-04-26 01:22 206,088 —-a-w C:\WINNT\SYSTEM32\klogon.dll
2004-06-19 23:23 1,589 —ha-w C:\Program Files\INSTALL.LOG
2001-04-10 12:58 271 —ha-w C:\Program Files\DESKTOP.INI
2001-04-10 12:58 21,952 —ha-w C:\Program Files\FOLDER.HTT
2000-07-26 12:00 32,528 —-a-w C:\WINNT\INF\WBFIRDMA.SYS
1998-12-09 10:53 99,840 —-a-w C:\Program Files\Common Files\IRAABOUT.DLL
1998-12-09 10:53 70,144 —-a-w C:\Program Files\Common Files\IRAMDMTR.DLL
1998-12-09 10:53 48,640 —-a-w C:\Program Files\Common Files\IRALPTTR.DLL
1998-12-09 10:53 31,744 —-a-w C:\Program Files\Common Files\IRAWEBTR.DLL
1998-12-09 10:53 186,368 —-a-w C:\Program Files\Common Files\IRAREG.DLL
1998-12-09 10:53 17,920 —-a-w C:\Program Files\Common Files\IRASRIAL.DLL
2006-04-08 21:23 11,270 –sha-w C:\WINNT\SYSTEM32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B3781912-3F31-4C6F-96F7-667D54C52312}]
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\0HYZKHUR\3077ahntdksr[1].dll [BU]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccRegVfy"="C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" [BU]
"SymTray - Norton SystemWorks"="C:\Program Files\Common Files\Symantec Shared\Symtray.exe" [BU]
"PPMemCheck"="C:\PROGRA~1\PESTPA~1\PPMemCheck.exe" [BU]
"NvCplDaemon"="C:\WINNT\system32\NvCpl.dll" [05-05-12 00:34 6729728]
"intdctrr"="C:\WINNT\system32\idctup20.exe" [BU]
"POINTER"="C:\Program Files\Microsoft Hardware\Mouse\point32.exe" [00-05-19 12:24 73728]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [04-06-16 07:03 221184]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [08-04-01 11:49 36352]
"BMbf1217c8"="C:\WINNT\system32\xfsnxuqu.dll" [BU]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [08-04-25 18:21 201992]
"SxgTkBar"="SxgTkBar.exe" [00-04-10 06:10 40960 C:\WINNT\SYSTEM32\sxgtkbar.exe]
"Synchronization Manager"="mobsync.exe" [03-06-19 12:05 111376 C:\WINNT\SYSTEM32\mobsync.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [03-06-19 12:05 186640]

C:\Documents and Settings\Default User\Start Menu\Programs\Startup\
discfix.lnk - C:\DELL\discfix.cmd [2000-04-13 08:16:02 75]

C:\Documents and Settings\SYSTEM\Start Menu\Programs\Startup\
discfix.lnk - C:\DELL\discfix.cmd [2000-04-13 08:16:02 75]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-10-28 14:37:17 113664]
IEEE 802.11g USB Wireless LAN Utility.lnk - C:\Program Files\Wireless LAN\WlanUtil.exe [2005-07-10 10:14:00 413696]
Microsoft Broadband Networking.lnk - C:\WINNT\Installer\{06B2B442-19FE-4398-BD4B-F5C00928DD8E}\_18be6784.exe [2002-11-08 20:16:58 25214]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 01:15:54 65588]
Symantec Fax Starter Edition Port.lnk - C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE [1998-12-23 22:51:54 45568]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nwprovau]
06-08-31 22:49 140048 C:\WINNT\SYSTEM32\NWPROVAU.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yayWnoOg]
[BU]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= mmdrv.dll
"midi1"= sxgb.dll
"mixer1"= sxgb.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

R0 aaatimeo;aaatimeo;C:\WINNT\system32\DRIVERS\aaatimeo.sys [00-11-21 14:19 ]
R0 Fd16_700;Fd16_700;C:\WINNT\system32\DRIVERS\fd16_700.sys [99-09-25 09:11 ]
R0 IntelATA;Intel Ultra ATA Controller;C:\WINNT\system32\DRIVERS\IntelAta.sys [01-03-22 22:00 ]
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINNT\system32\drivers\klbg.sys [08-01-29 18:29 ]
R1 NPPTNT;NPPTNT;C:\WINNT\system32\npptNT.sys [03-07-21 23:14 ]
R1 sxgbvswp;sxgbvswp;C:\WINNT\system32\drivers\sxgbvswp.SYS [00-09-01 09:08 ]
R2 tcaicchg;tcaicchg;C:\WINNT\System32\tcaicchg.sys [00-06-04 19:08 ]
R2 TCAITDI;TCAITDI Protocol;C:\WINNT\system32\DRIVERS\TCAITDI.sys [00-09-06 15:57 ]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINNT\system32\DRIVERS\klim5.sys [08-03-25 20:07 ]
R3 ZD1211U(WLAN);IEEE 802.11g USB Wireless LAN Driver(WLAN);C:\WINNT\system32\DRIVERS\zd1211u.sys [05-02-04 15:48 ]
S0 cda1000;cda1000;C:\WINNT\system32\DRIVERS\cda1000.sys [00-12-14 11:14 ]
S2 BridDfu;LINKSYS WAP11 USB Device Driver;C:\WINNT\system32\Drivers\BridDfu.sys [01-07-06 02:02 ]
S3 ATE_PROCMON;ATE_PROCMON;C:\Program Files\Anti Trojan Elite\ATEPMon.sys []
S3 EL98x;3Com 3C98x 10/100 Server NIC Driver;C:\WINNT\system32\DRIVERS\el98xn5.sys [00-09-19 12:46 ]
S3 ISLNDIS5;ISLNDIS5 Protocol Driver;C:\PROGRA~1\MIF7A5~1\ISLNDIS5.SYS [02-08-06 15:23 ]
S3 NPF;NetGroup Packet Filter Driver;C:\WINNT\system32\drivers\npf.sys [05-08-02 14:10 ]
S3 ZDBRGSYS;ZDBRGSYS NDIS Protocol Driver;C:\WINNT\system32\ZDBRGSYS.SYS [04-06-30 13:54 ]
.
Contents of the 'Scheduled Tasks' folder
"2005-09-21 22:53:44 C:\WINNT\Tasks\XoftSpy.job"
- C:\Program Files\XoftSpy\XoftSpy.exe
.
.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://www.yahoo.com/
R0 -: HKCU-Main,Local Page =
R0 -: HKLM-Main,Window Title = Microsoft Internet Explorer
R0 -: HKLM-Main,Search Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
R0 -: HKLM-Main,Local Page =
O17 -: HKLM\CCS\Interface\{1E0A612D-E7DA-448E-A7BD-665A904BCCCB}: NameServer = 192.168.254.254
O17 -: HKLM\CCS\Interface\{D111BF2D-EC5C-4063-AF53-46D3782FF089}: NameServer = 192.168.1.1,192.168.1.1

O16 -: DirectAnimation Java Classes - file://C:\WINNT\Java\classes\dajava.cab
C:\WINNT\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - file://C:\WINNT\Java\classes\xmldso.cab
C:\WINNT\Downloaded Program Files\Microsoft XML Parser for Java.osd


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-23 17:11:35
Windows 5.0.2195 Service Pack 4 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-07-23 17:14:09
ComboFix-quarantined-files.txt 2008-07-24 00:13:40

Pre-Run: 12,518,182,400 bytes free
Post-Run: 12,506,823,680 bytes free

203



And here's the new HiJackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 17:30, on 2008-07-23
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINNT\system32\cisvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\msdtc.exe
C:\WINNT\system32\mqsvc.exe
C:\WINNT\system32\SxgTkBar.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {B3781912-3F31-4C6F-96F7-667D54C52312} - C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\0HYZKHUR\3077ahntdksr[1].dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [SxgTkBar] SxgTkBar.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtray.exe SetReg
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [intdctrr] C:\WINNT\system32\idctup20.exe
O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [BMbf1217c8] Rundll32.exe "C:\WINNT\system32\xfsnxuqu.dll",s
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: IEEE 802.11g USB Wireless LAN Utility.lnk = C:\Program Files\Wireless LAN\WlanUtil.exe
O4 - Global Startup: Microsoft Broadband Networking.lnk = C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{1E0A612D-E7DA-448E-A7BD-665A904BCCCB}: NameServer = 192.168.254.254
O17 - HKLM\System\CCS\Services\Tcpip\..\{95EFE720-4E19-4D5E-A91A-9815B45BAB71}: Domain = frontiernet.net
O17 - HKLM\System\CCS\Services\Tcpip\..\{D111BF2D-EC5C-4063-AF53-46D3782FF089}: NameServer = 192.168.1.1,192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{1E0A612D-E7DA-448E-A7BD-665A904BCCCB}: NameServer = 192.168.254.254
O17 - HKLM\System\CS2\Services\Tcpip\..\{1E0A612D-E7DA-448E-A7BD-665A904BCCCB}: NameServer = 192.168.254.254
O20 - Winlogon Notify: klogon - C:\WINNT\system32\klogon.dll
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O20 - Winlogon Notify: yayWnoOg - C:\WINNT\
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe


As I look at this myself, I notice I still have some items that I have long removed from my computer (or so I thought) but they still remain.
Do you know of any way to remove these items? (IE: Norton AV.)

Thanks!

(Also my clock is still in 2400 time, how can I change it back to 12:00 time?)

-Dave
Dave_63,

(Also my clock is still in 2400 time, how can I change it back to 12:00 time?)

We'll take care of that once you're clean. You still have a lot of "slime" in there.

Do you know of any way to remove these items? (IE: Norton AV.)

Use the link below to see how to run the Norton Removal Tool
http://service1.symantec.com/SUPPORT/tsgen…005033108162039

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    KILLALL::
    
    File::
    C:\WINNT\SYSTEM32\rmyukqbw.dll
    C:\WINNT\SYSTEM32\epbvfcgt.dll
    C:\WINNT\SYSTEM32\qhwcmkcp.dll
    C:\WINNT\SYSTEM32\uvfpinlt.dll
    C:\WINNT\SYSTEM32\mdumyrsx.dll
    C:\WINNT\SYSTEM32\esttblve.dll
    C:\WINNT\SYSTEM32\wefoiulw.dll
    C:\WINNT\SYSTEM32\rfwbelfg.dll
    C:\WINNT\SYSTEM32\bppmbkos.dll
    C:\WINNT\SYSTEM32\stfxfndn.dll
    C:\WINNT\SYSTEM32\houfrkvd.dll
    C:\WINNT\SYSTEM32\yawfuyet.dll
    C:\WINNT\BMbf1217c8.xml
    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\0HYZKHUR\3077ahntdksr[1].dll
    C:\WINNT\system32\xfsnxuqu.dll
    
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B3781912-3F31-4C6F-96F7-667D54C52312}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BMbf1217c8"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yayWnoOg]
    
    Driver::
    ATE_PROCMON
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

So in your next reply, please provide:
  • ComboFix.txt
  • Mbam report
  • New HijackThis log

Also please describe how your computer behaves at the moment.
Hey Tomk, I appreciate you helping me with this matter. :notworthy:

Here is my Combo Fix log:

ComboFix 08-07-23.3 - Administrator 2008-07-23 21:16:08.3 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.1702 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\0HYZKHUR\3077ahntdksr[1].dll
C:\WINNT\BMbf1217c8.xml
C:\WINNT\SYSTEM32\bppmbkos.dll
C:\WINNT\SYSTEM32\epbvfcgt.dll
C:\WINNT\SYSTEM32\esttblve.dll
C:\WINNT\SYSTEM32\houfrkvd.dll
C:\WINNT\SYSTEM32\mdumyrsx.dll
C:\WINNT\SYSTEM32\qhwcmkcp.dll
C:\WINNT\SYSTEM32\rfwbelfg.dll
C:\WINNT\SYSTEM32\rmyukqbw.dll
C:\WINNT\SYSTEM32\stfxfndn.dll
C:\WINNT\SYSTEM32\uvfpinlt.dll
C:\WINNT\SYSTEM32\wefoiulw.dll
C:\WINNT\system32\xfsnxuqu.dll
C:\WINNT\SYSTEM32\yawfuyet.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINNT\BMbf1217c8.xml
C:\WINNT\SYSTEM32\bppmbkos.dll
C:\WINNT\SYSTEM32\epbvfcgt.dll
C:\WINNT\SYSTEM32\esttblve.dll
C:\WINNT\SYSTEM32\houfrkvd.dll
C:\WINNT\SYSTEM32\mdumyrsx.dll
C:\WINNT\SYSTEM32\qhwcmkcp.dll
C:\WINNT\SYSTEM32\rfwbelfg.dll
C:\WINNT\SYSTEM32\rmyukqbw.dll
C:\WINNT\SYSTEM32\stfxfndn.dll
C:\WINNT\SYSTEM32\uvfpinlt.dll
C:\WINNT\SYSTEM32\wefoiulw.dll
C:\WINNT\SYSTEM32\yawfuyet.dll
C:\WINNT\t\

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_ATE_PROCMON
——-\Service_ATE_PROCMON


((((((((((((((((((((((((( Files Created from 2008-06-24 to 2008-07-24 )))))))))))))))))))))))))))))))
.

2008-07-17 23:28 . 05-01-22 12:12 679,936 –a—— C:\WINNT\SYSTEM32\D3DX81ab.dll
2008-07-17 23:23 . 08-07-17 23:23

d——– C:\Program Files\WinPcap
2008-07-17 23:22 . 08-07-17 23:43 d——– C:\Program Files\WC3Banlist
2008-07-14 00:39 . 08-07-23 18:21 643,132 —h—– C:\WINNT\ShellIconCache
2008-07-11 23:49 . 99-12-17 10:13 86,016 –a—— C:\WINNT\unvise32.exe
2008-07-11 23:45 . 08-07-11 23:45 d——– C:\sierra
2008-07-06 22:49 . 08-07-06 22:49 d——– C:\Documents and Settings\Administrator\.dracis_client
2008-07-06 12:35 . 08-07-06 12:35 d——– C:\Program Files\MagicISO
2008-07-05 22:28 . 08-07-05 22:28 0 –ahs—- C:\WINNT\klif.spi
2008-07-05 22:09 . 08-07-05 22:23 96,966 –a—— C:\WINNT\SYSTEM32\DRIVERS\klin.dat
2008-07-05 22:09 . 08-07-05 22:23 88,774 –a—— C:\WINNT\SYSTEM32\DRIVERS\klick.dat
2008-07-05 22:07 . 08-07-05 22:07 d——– C:\Program Files\Kaspersky Lab
2008-07-05 22:07 . 08-07-23 21:14 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-05 21:54 . 08-07-05 21:54 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-07-03 20:52 . 08-07-03 20:52 d——– C:\Program Files\SCi
2008-07-03 13:52 . 08-07-03 13:52 d——– C:\Documents and Settings\All Users\Application Data\ADSL Software Ltd
2008-07-02 20:03 . 08-07-10 09:04 d——– C:\Program Files\Microsoft Games
2008-07-02 10:59 . 08-07-02 10:59 d——– C:\Program Files\Acclaim
2008-06-24 15:37 . 08-06-24 15:37 d——– C:\Documents and Settings\Administrator\Application Data\Viewpoint

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-24 04:11 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-07-23 21:22 ——— d—–w C:\Program Files\Warcraft III
2008-07-14 19:55 ——— d—–w C:\Program Files\Starcraft
2008-07-06 09:36 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Lavasoft
2008-07-04 06:45 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-07-03 23:05 ——— d—–w C:\Program Files\AIM
2008-06-29 20:09 ——— d—–w C:\Program Files\Viewpoint
2008-06-24 02:18 65,536 —-a-w C:\WINNT\IFinst27.exe
2008-06-24 02:18 ——— d—–w C:\Program Files\Gravity
2008-06-18 23:47 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Winamp
2008-06-18 23:24 ——— d—–w C:\Program Files\Winamp
2008-06-18 13:49 ——— d—–w C:\Program Files\EA GAMES
2008-06-08 19:02 ——— d—–w C:\Program Files\Ventrilo
2004-06-19 23:23 1,589 —ha-w C:\Program Files\INSTALL.LOG
2001-04-10 12:58 271 —ha-w C:\Program Files\DESKTOP.INI
2001-04-10 12:58 21,952 —ha-w C:\Program Files\FOLDER.HTT
2000-07-26 12:00 32,528 —-a-w C:\WINNT\INF\WBFIRDMA.SYS
1998-12-09 10:53 99,840 —-a-w C:\Program Files\Common Files\IRAABOUT.DLL
1998-12-09 10:53 70,144 —-a-w C:\Program Files\Common Files\IRAMDMTR.DLL
1998-12-09 10:53 48,640 —-a-w C:\Program Files\Common Files\IRALPTTR.DLL
1998-12-09 10:53 31,744 —-a-w C:\Program Files\Common Files\IRAWEBTR.DLL
1998-12-09 10:53 186,368 —-a-w C:\Program Files\Common Files\IRAREG.DLL
1998-12-09 10:53 17,920 —-a-w C:\Program Files\Common Files\IRASRIAL.DLL
2006-04-08 21:23 11,270 –sha-w C:\WINNT\SYSTEM32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SymTray - Norton SystemWorks"="C:\Program Files\Common Files\Symantec Shared\Symtray.exe" [BU]
"PPMemCheck"="C:\PROGRA~1\PESTPA~1\PPMemCheck.exe" [BU]
"NvCplDaemon"="C:\WINNT\system32\NvCpl.dll" [05-05-12 00:34 6729728]
"intdctrr"="C:\WINNT\system32\idctup20.exe" [BU]
"POINTER"="C:\Program Files\Microsoft Hardware\Mouse\point32.exe" [00-05-19 12:24 73728]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [04-06-16 07:03 221184]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [08-04-01 11:49 36352]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [08-04-25 18:21 201992]
"SxgTkBar"="SxgTkBar.exe" [00-04-10 06:10 40960 C:\WINNT\SYSTEM32\sxgtkbar.exe]
"Synchronization Manager"="mobsync.exe" [03-06-19 12:05 111376 C:\WINNT\SYSTEM32\mobsync.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [03-06-19 12:05 186640]

C:\Documents and Settings\Default User\Start Menu\Programs\Startup\
discfix.lnk - C:\DELL\discfix.cmd [2000-04-13 08:16:02 75]

C:\Documents and Settings\SYSTEM\Start Menu\Programs\Startup\
discfix.lnk - C:\DELL\discfix.cmd [2000-04-13 08:16:02 75]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-10-28 14:37:17 113664]
IEEE 802.11g USB Wireless LAN Utility.lnk - C:\Program Files\Wireless LAN\WlanUtil.exe [2005-07-10 10:14:00 413696]
Microsoft Broadband Networking.lnk - C:\WINNT\Installer\{06B2B442-19FE-4398-BD4B-F5C00928DD8E}\_18be6784.exe [2002-11-08 20:16:58 25214]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 01:15:54 65588]
Symantec Fax Starter Edition Port.lnk - C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE [1998-12-23 22:51:54 45568]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nwprovau]
06-08-31 22:49 140048 C:\WINNT\SYSTEM32\NWPROVAU.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= mmdrv.dll
"midi1"= sxgb.dll
"mixer1"= sxgb.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

R0 aaatimeo;aaatimeo;C:\WINNT\system32\DRIVERS\aaatimeo.sys [00-11-21 14:19 ]
R0 Fd16_700;Fd16_700;C:\WINNT\system32\DRIVERS\fd16_700.sys [99-09-25 09:11 ]
R0 IntelATA;Intel Ultra ATA Controller;C:\WINNT\system32\DRIVERS\IntelAta.sys [01-03-22 22:00 ]
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINNT\system32\drivers\klbg.sys [08-01-29 18:29 ]
R1 NPPTNT;NPPTNT;C:\WINNT\system32\npptNT.sys [03-07-21 23:14 ]
R1 sxgbvswp;sxgbvswp;C:\WINNT\system32\drivers\sxgbvswp.SYS [00-09-01 09:08 ]
R2 tcaicchg;tcaicchg;C:\WINNT\System32\tcaicchg.sys [00-06-04 19:08 ]
R2 TCAITDI;TCAITDI Protocol;C:\WINNT\system32\DRIVERS\TCAITDI.sys [00-09-06 15:57 ]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINNT\system32\DRIVERS\klim5.sys [08-03-25 20:07 ]
R3 ZD1211U(WLAN);IEEE 802.11g USB Wireless LAN Driver(WLAN);C:\WINNT\system32\DRIVERS\zd1211u.sys [05-02-04 15:48 ]
S0 cda1000;cda1000;C:\WINNT\system32\DRIVERS\cda1000.sys [00-12-14 11:14 ]
S2 BridDfu;LINKSYS WAP11 USB Device Driver;C:\WINNT\system32\Drivers\BridDfu.sys [01-07-06 02:02 ]
S3 EL98x;3Com 3C98x 10/100 Server NIC Driver;C:\WINNT\system32\DRIVERS\el98xn5.sys [00-09-19 12:46 ]
S3 ISLNDIS5;ISLNDIS5 Protocol Driver;C:\PROGRA~1\MIF7A5~1\ISLNDIS5.SYS [02-08-06 15:23 ]
S3 NPF;NetGroup Packet Filter Driver;C:\WINNT\system32\drivers\npf.sys [05-08-02 14:10 ]
S3 ZDBRGSYS;ZDBRGSYS NDIS Protocol Driver;C:\WINNT\system32\ZDBRGSYS.SYS [04-06-30 13:54 ]
.
Contents of the 'Scheduled Tasks' folder
"2005-09-21 22:53:44 C:\WINNT\Tasks\XoftSpy.job"
- C:\Program Files\XoftSpy\XoftSpy.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-23 21:23:19
Windows 5.0.2195 Service Pack 4 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-07-23 21:29:19 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-24 04:29:11
ComboFix2.txt 2008-07-24 00:14:10

Pre-Run: 13,256,519,168 bytes free
Post-Run: 13,260,324,864 bytes free

167



Here's my Mbam report:

Malwarebytes' Anti-Malware 1.23
Database version: 985
Windows 5.0.2195 Service Pack 4

21:42:34 2008-07-23
mbam-log-7-23-2008 (21-42-34).txt

Scan type: Quick Scan
Objects scanned: 39176
Time elapsed: 3 minute(s), 42 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 8
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\cablerouting.cablerouting (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\cablerouting.cablerouting.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{830af45a-70fe-4f42-820c-478e6f07bd92} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{28eaf37d-f93d-4d40-8f70-654cc2fcba2e} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\All Users\Application Data\ADSL Software Ltd (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\ADSL Software Ltd\WinSpywareProtect (Rogue.Multiple) -> Quarantined and deleted successfully.

Files Infected:
C:\WINNT\bnetunin.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINNT\BMbf1217c8.txt (Trojan.Vundo) -> Quarantined and deleted successfully.


And here's my Hijack This log:

Logfile of HijackThis v1.99.1
Scan saved at 21:44, on 2008-07-23
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINNT\system32\cisvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\msdtc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\mqsvc.exe
C:\WINNT\system32\SxgTkBar.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Wireless LAN\WlanUtil.exe
C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\WINNT\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [SxgTkBar] SxgTkBar.exe
O4 - HKLM\..\Run: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtray.exe SetReg
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [intdctrr] C:\WINNT\system32\idctup20.exe
O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: IEEE 802.11g USB Wireless LAN Utility.lnk = C:\Program Files\Wireless LAN\WlanUtil.exe
O4 - Global Startup: Microsoft Broadband Networking.lnk = C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{1E0A612D-E7DA-448E-A7BD-665A904BCCCB}: NameServer = 192.168.254.254
O17 - HKLM\System\CCS\Services\Tcpip\..\{95EFE720-4E19-4D5E-A91A-9815B45BAB71}: Domain = frontiernet.net
O17 - HKLM\System\CCS\Services\Tcpip\..\{D111BF2D-EC5C-4063-AF53-46D3782FF089}: NameServer = 192.168.1.1,192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{1E0A612D-E7DA-448E-A7BD-665A904BCCCB}: NameServer = 192.168.254.254
O17 - HKLM\System\CS2\Services\Tcpip\..\{1E0A612D-E7DA-448E-A7BD-665A904BCCCB}: NameServer = 192.168.254.254
O20 - Winlogon Notify: klogon - C:\WINNT\system32\klogon.dll
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)


As for my computer, I noticed that at the startup, it says it fails to load one of those awkwardly named .DLL files and right now it's easier to surf the web as the loading times are faster now. Other than that I don't notice anything else.

Thanks for you help once again.

-Dave
Dave_63,

Your infection really doesn't want to stay dead. :pullhair:

Let's run another online scan so I can be comfortable that we got it all.

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
TomK, I don't know what to do now, whenver I try to update the online scanner, I get a blue screen of death, I've tried doing so three times now and the results are the same. What should I do? -Dave
Dave_63,

Either something has been damaged by the infection (which happens with this one) or there is still a piece clinging on in there. Lets try for a little different look at what is going on.

First let's do some general cleanup of temporary files.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next

Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt <-this one will be minimized
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and extra.txt in your reply
Hello again.
Just as a little side note, my explorer.exe isn't crashing anymore, everything loads up a little bit faster and when I surf the web the loading isn't as horrid as it was before.

Anyways here's my main.txt:

Deckard's System Scanner v20071014.68
Run by [removed] on 2008-07-24 10:18:19
Computer is in Normal Mode.
——————————————————————————–

Backed up registry hives.
Performed disk cleanup.



– HijackThis (run as Administrator.exe) —————————————

Logfile of HijackThis v1.99.1
Scan saved at 10:18, on 2008-07-24
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINNT\system32\cisvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\msdtc.exe
C:\WINNT\system32\mqsvc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\SxgTkBar.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\Wireless LAN\WlanUtil.exe
C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\DESKTOP\dss.exe
C:\PROGRA~1\HIJACK~1\Administrator.exe
C:\WINNT\system32\Notepad.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [SxgTkBar] SxgTkBar.exe
O4 - HKLM\..\Run: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtray.exe SetReg
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [intdctrr] C:\WINNT\system32\idctup20.exe
O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: IEEE 802.11g USB Wireless LAN Utility.lnk = C:\Program Files\Wireless LAN\WlanUtil.exe
O4 - Global Startup: Microsoft Broadband Networking.lnk = C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{1E0A612D-E7DA-448E-A7BD-665A904BCCCB}: NameServer = 192.168.254.254
O17 - HKLM\System\CCS\Services\Tcpip\..\{95EFE720-4E19-4D5E-A91A-9815B45BAB71}: Domain = frontiernet.net
O17 - HKLM\System\CCS\Services\Tcpip\..\{D111BF2D-EC5C-4063-AF53-46D3782FF089}: NameServer = 192.168.1.1,192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{1E0A612D-E7DA-448E-A7BD-665A904BCCCB}: NameServer = 192.168.254.254
O17 - HKLM\System\CS2\Services\Tcpip\..\{1E0A612D-E7DA-448E-A7BD-665A904BCCCB}: NameServer = 192.168.254.254
O20 - Winlogon Notify: klogon - C:\WINNT\system32\klogon.dll
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)


– HijackThis Fixed Entries (C:\PROGRA~1\HIJACK~1\backups\) ——————–

backup-20080723-150849-713 O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
backup-20080723-150849-861 O20 - Winlogon Notify: vtutu - C:\WINNT\system32\vtutu.dll (file missing)
backup-20080723-150849-934 O4 - HKLM\..\Run: [BMbf1217c8] Rundll32.exe "C:\WINNT\system32\xfsnxuqu.dll",s
backup-20080723-150944-704 O4 - HKLM\..\Run: [BMbf1217c8] Rundll32.exe "C:\WINNT\system32\xfsnxuqu.dll",s

– File Associations ———————————————————–

.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.reg - regfile - shell\open\command - regedit.exe "%1" %*
.scr - scrfile - shell\open\command - "%1" %*
.txt - txtfile - shell\open\command - Notepad.exe %1


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R0 aaatimeo - c:\winnt\system32\drivers\aaatimeo.sys


And here's my extra.txt:

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
——————————————————————————–

– System Information ———————————————————-

Microsoft Windows 2000 Professional (build 2195) SP 4.0
Architecture: X86; Language: English

CPU 0: Intel® Pentium® 4 CPU 1800MHz
Percentage of Memory in Use: 15%
Physical Memory (total/avail): 2047.02 MiB / 1736.91 MiB
Pagefile Memory (total/avail): 3938.03 MiB / 3759.98 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1960.46 MiB

A: is Removable (No Media)
C: is Fixed (NTFS) - 37.25 GiB total, 12.33 GiB free.
D: is CDROM (CDFS)
E: is CDROM (No Media)
F: is CDROM (No Media)
I: is Fixed (NTFS) - 37.26 GiB total, 5.9 GiB free.

\\.\PHYSICALDRIVE0 - IC35L040AVER07-0 - 37.27 GiB - 2 partitions
\PARTITION0 - Unknown - 15.66 MiB
\PARTITION1 (bootable) - Installable File System - 37.25 GiB - C:

\\.\PHYSICALDRIVE1 - WDC WD400BB-00AUA1 - 37.27 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 37.26 GiB - I:



– Security Center ————————————————————-

AUOptions is set to notify before install.


– Environment Variables ——————————————————-

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Administrator\Application Data
CLASSPATH=.;
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=RAWR
ComSpec=C:\WINNT\system32\cmd.exe
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Administrator
LOGONSERVER=\\RAWR
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Os2LibPath=C:\WINNT\system32\os2\dll;
Path=C:\Program Files\Mozilla Firefox\;C:\WINNT\system32;C:\WINNT;C:\WINNT\System32\Wbem
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 0 Stepping 10, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=000a
ProgramFiles=C:\Program Files
PROMPT=$P$G
sourcesdk=c:\valve\steam\steamapps\kaitrance\sourcesdk
SystemDrive=C:
SystemRoot=C:\WINNT
TEMP=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
TMP=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
USERDOMAIN=RAWR
USERNAME=Administrator
USERPROFILE=C:\Documents and Settings\Administrator
windir=C:\WINNT


– User Profiles —————————————————————

BenVu (admin)
andrew (admin)
andrew
Administrator (admin)


– Add/Remove Programs ———————————————————

–> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Adobe Acrobat 5.0 –> C:\WINNT\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll"
Adobe Flash Player Plugin –> C:\WINNT\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Photoshop 7.0 –> C:\WINNT\ISUNINST.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
Adobe Shockwave Player –> C:\WINNT\SYSTEM32\Macromed\SHOCKW~2\UNWISE.EXE C:\WINNT\SYSTEM32\Macromed\SHOCKW~2\Install.log
AOL Instant Messenger –> C:\Program Files\AIM\uninstll.exe -LOG= C:\Program Files\AIM\install.log -OEM=
Battlefield 1942 –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}\Setup.exe" -l0x9
Battlefield 1942: Secret Weapons of WWII –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B73B4A99-4173-4747-BBEC-0F05E966F9D2}\setup.exe" -l0x9
BitComet 0.58 –> C:\Program Files\BitComet\uninst.exe
Civilization III –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0AD84416-63A4-4CF3-BDDF-8FA866711FB0}\setup.exe"
Civilization III v1.29f –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{31E2413D-8AA1-43EC-8B8D-77B65ADA4611}\Setup.exe"
DAEMON Tools –> MsiExec.exe /I{3DED3A72-61A8-4B87-98A5-EF0BC8038AA0}
Desert Storm –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9FB2CE8C-E86C-4368-B3C9-F472898F926E}\Setup.exe" -l0x9
DivX –> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Player –> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
Dracis Chess Client –> C:\WINNT\system32\javaws.exe -uninstall "http://www.dracis.com/jnlp/CH.jnlp"
Hijackthis 1.99.1 –> "C:\Program Files\Hijackthis\unins000.exe"
HijackThis 1.99.1 –> C:\Program Files\Hijackthis\HijackThis.exe /uninstall
IEEE 802.11g USB Wireless LAN Adapter –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{581CE7EA-A30D-F000-1211-088635773309}\Setup.exe" -l0x9
Intel Ultra ATA Storage Driver –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9984DF60-1C5B-11D3-ACA1-908A4FC10801}\setup.exe" -K -INTELUNINST
Internet Explorer Q903235 –> C:\WINNT\ieuninst.exe C:\WINNT\INF\Q903235.inf
J2SE Runtime Environment 5.0 Update 4 –> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150040}
Java 2 Runtime Environment, SE v1.4.2_05 –> MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142050}
Kaspersky Anti-Virus 2009 –> MsiExec.exe /I{6580C5A3-2336-4EC5-85F1-3448C5F6208A}
Kaspersky Anti-Virus 2009 –> MsiExec.exe /I{6580C5A3-2336-4EC5-85F1-3448C5F6208A}
Lavasoft VX2 Cleaner –> C:\PROGRA~1\Lavasoft\AD-AWA~1\Plugins\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\Plugins\INSTALL.LOG
Macromedia Flash Player 8 –> RunDll32 advpack.dll,LaunchINFSection C:\WINNT\INF\swflash.inf,DefaultUninstall,5
Magic ISO Maker v5.4 (build 0239) –> C:\PROGRA~1\MagicISO\UNWISE.EXE C:\PROGRA~1\MagicISO\INSTALL.LOG
Malwarebytes' Anti-Malware –> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 1.1 –> msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1 –> MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1 Hotfix (KB886903) –> "C:\WINNT\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINNT\Microsoft.NET\Framework\v1.1.4322\Updates\M886903\M886903Uninstall.msp"
Microsoft Age of Empires Gold –> "C:\Program Files\Microsoft Games\Age of Empires\UNINSTAL.EXE" /runtemp
Microsoft Age of Empires II –> "C:\Program Files\Microsoft Games\Age of Empires II\UNINSTAL.EXE" /runtemp /uninstall
Microsoft Broadband Networking –> MsiExec.exe /I{06B2B442-19FE-4398-BD4B-F5C00928DD8E}
Microsoft Halo –> "C:\Program Files\Microsoft Games\Halo\UNINSTAL.EXE" /runtemp /addremove
Microsoft IntelliPoint –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ABEA93FA-8D65-11D2-98AB-00C04F79C5D1}\setup.exe" Uninstall
Microsoft Office 2000 SR-1 Premium –> MsiExec.exe /I{00000409-78E1-11D2-B60F-006097C998E7}
Microsoft Speech SDK 5.1 –> MsiExec.exe /I{A403D88E-ED7D-48E3-91FD-B8C8A720EDA1}
Microsoft Windows Journal Viewer –> MsiExec.exe /X{43DCF766-6838-4F9A-8C91-D92DA586DFA7}
mIRC –> "C:\Program Files\mIRC\mirc.exe" -uninstall
Mozilla Firefox (1.0.5) –> C:\WINNT\UninstallFirefox.exe /ua "1.0.5 (en-US)"
MSXML 4.0 SP2 Parser and SDK –> MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
Natural Selection 3.2 –> c:\valve\steam\steamapps\ixkillxforxrice\half-life\unins000.exe
Nero 6 Enterprise Edition –> C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
NS pack –> "C:\WINNT\NS pack\uninstall.exe" "/U:c:\valve\steam\steamapps\ixkillxforxrice\half-life\Uninstall\uninstall.xml"
NVIDIA Drivers –> C:\WINNT\system32\nvudisp.exe UninstallGUI
Ragnarok Sakray –> "C:\WINNT\IFinst27.exe" -UC:\Program Files\Gravity\RO\IFU146.inf
RealPlayer –> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Resident Evil, The Awakening Part 1 1.2 –> c:\valve\steam\steamapps\ixkillxforxrice\half-life\Uninstal RE1.exe
RTP for RM2K (Png, Wav, Midi, Fonts) –> C:\WINNT\UnGins.exe "C:\Program Files\ASCII\RPG2000\RTP\install.log"
Secure Delivery –> RunDll32 advpack.dll,LaunchINFSection C:\WINNT\kdx\kdx.inf,DefaultUninstall,5
Security Update for Windows 2000 (KB904706) –> "C:\WINNT\$NtUninstallKB904706$\spuninst\spuninst.exe"
Security Update for Windows 2000 (KB923689) –> "C:\WINNT\$NtUninstallKB923689$\spuninst\spuninst.exe"
SoundMAX –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\Setup.exe"
Starcraft –> C:\WINNT\SCunin.exe C:\WINNT\SCunin.dat
Sven Co-op 3.0 –> C:\WINNT\unvise32.exe c:\valve\steam\steamapps\ixkillxforxrice\half-life\SvenCoop\uninstal.log
User's Guides –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}\setup.exe"
Ventrilo Client –> MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}
VideoLAN VLC media player 0.8.5 –> C:\Program Files\VideoLAN\VLC\uninstall.exe
Warcraft III: All Products –> C:\WINNT\War3Unin.exe C:\WINNT\War3Unin.dat
WC3Banlist –> "C:\Program Files\WC3Banlist\unins000.exe"
Winamp –> "C:\Program Files\Winamp\UninstWA.exe"
Windows 2000 Service Pack 4 –> C:\WINNT\$NtServicePackUninstall$\spuninst\spuninst.exe
Windows Defender Signatures –> MsiExec.exe /I{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}
Windows Genuine Advantage v1.3.0254.0 –> MsiExec.exe /I{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}
Windows Media Player 9 Hotfix [See KB885492 for more information] –> C:\WINNT\$NtUninstallKB885492$\spuninst\spuninst.exe
Windows Media Player system update (9 Series) –> C:\PROGRA~1\WINDOW~2\setup_wm.exe /Uninstall
WinPcap 3.1 –> C:\Program Files\WinPcap\uninstall.exe
WinRAR archiver –> C:\Program Files\WinRAR\uninstall.exe
YAMAHA SoftSynthesizer S-YXG50 –> C:\WINNT\IsUninst.exe -fC:\WINNT\DeIsL1.isu -c"C:\WINNT\System32\sxgunins.dll


– Application Event Log ——————————————————-

Event Record #/Type31469 / Error
Event Submitted/Written: 07/23/2008 10:08:50 PM
Event ID/Source: 1000 / Userenv
Event Description:
Windows cannot unload your registry file. If you have a roaming profile, your settings are not replicated. Contact your administrator.

DETAIL - Access is denied. , Build number ((2195)).

Event Record #/Type31464 / Error
Event Submitted/Written: 07/23/2008 09:21:04 PM
Event ID/Source: 1000 / Userenv
Event Description:
Windows cannot unload your registry file. If you have a roaming profile, your settings are not replicated. Contact your administrator.

DETAIL - Access is denied. , Build number ((2195)).

Event Record #/Type31446 / Error
Event Submitted/Written: 07/23/2008 06:23:01 PM
Event ID/Source: 1000 / Userenv
Event Description:
Windows cannot unload your registry file. If you have a roaming profile, your settings are not replicated. Contact your administrator.

DETAIL - Access is denied. , Build number ((2195)).

Event Record #/Type31365 / Warning
Event Submitted/Written: 07/21/2008 10:49:27 AM
Event ID/Source: 101 / Automatic LiveUpdate Scheduler
Event Description:
warningAutomatic LiveUpdate produced an unexpected exit code: 0; advancing schedule…

Event Record #/Type31358 / Error
Event Submitted/Written: 07/21/2008 07:12:32 AM
Event ID/Source: 101 / Automatic LiveUpdate Scheduler
Event Description:
errorInternet connection not detected.



– Security Event Log ———————————————————-

No Errors/Warnings found.


– System Event Log ————————————————————

Event Record #/Type21103 / Error
Event Submitted/Written: 07/24/2008 08:46:44 AM
Event ID/Source: 7000 / Service Control Manager
Event Description:
The Task Scheduler service failed to start due to the following error:
%%1083

Event Record #/Type21100 / Error
Event Submitted/Written: 07/24/2008 08:46:37 AM
Event ID/Source: 7000 / Service Control Manager
Event Description:
The LINKSYS WAP11 USB Device Driver service failed to start due to the following error:
%%1058

Event Record #/Type21097 / Error
Event Submitted/Written: 07/23/2008 11:01:37 PM
Event ID/Source: 7000 / Service Control Manager
Event Description:
The Task Scheduler service failed to start due to the following error:
%%1083

Event Record #/Type21096 / Error
Event Submitted/Written: 07/23/2008 11:01:29 PM
Event ID/Source: 7000 / Service Control Manager
Event Description:
The LINKSYS WAP11 USB Device Driver service failed to start due to the following error:
%%1058

Event Record #/Type21090 / Error
Event Submitted/Written: 07/23/2008 10:48:26 PM / 07/23/2008 10:48:56 PM
Event ID/Source: 4307 / NetBT
Event Description:
Initialization failed because the transport refused to open initial Addresses.



– End of Deckard's System Scanner: finished at 2008-07-24 10:19:59 ————

Dave_63,

To repair the faulty file associations, please do the following:
  • Make sure that DSS.exe is located on your Desktop.
  • Click on your START button, then choose Run. A little box will appear.
  • Now copy and paste all the following in bold (including the "" marks into the run box and click OK.

    "%userprofile%\desktop\dss.exe" /daft


  • This will start DSS in a different way. A small window will appear.
  • Click on the Scan button.
  • If it finds faulty file associations, they will appear in red beside a checkbox. If this occurs, just place a tick in the boxes in question.
  • Click the Fix button.
  • Re-scan and save a logfile. By default, it will save as daft.txt.

Post the contents of that logfile with your next post
.

Please either print out these instructions for reference or copy/paste them in notepad and save to your desktop for access when in safe mode

Make all files and folders visible
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.



  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • O4 - HKLM\..\Run: [intdctrr] C:\WINNT\system32\idctup20.exe
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.

We Now Need To Boot Into Safemode

Restart your computer.
When the machine first starts again it will generally list some equipment that is installed in your machine,
amount of memory, hard drives installed etc (BOOT SCREEEN).
At this point you should gently tap the F8 key repeatedly until you are presented with a Options menu.
Select the option for Safe Mode using the arrow keys.
Then press enter on your keyboard to boot into Safe Mode.

Using Windows Explorer (Windows Key + E), locate the following files and DELETE it:
C:\WINNT\system32\idctup20.exe <–This file


Restart your computer normally.
Please provide a new HijackThis log
I followed your instructions and when I restarted my computer in safe mode to look for the file you specified, it wasn't there. I think it was deleted when you told me to use Hijack This to "fix" it. Anyways here are my two logs.

daft:

DAFT Log saved on 2008-07-24 13:58:58
———————————————————————–
All associations okay!


and Hijack This:

Logfile of HijackThis v1.99.1
Scan saved at 14:18, on 2008-07-24
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINNT\system32\cisvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\msdtc.exe
C:\WINNT\system32\mqsvc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\SxgTkBar.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\Wireless LAN\WlanUtil.exe
C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\WINNT\system32\wuauclt.exe
C:\Valve\Steam\Steam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [SxgTkBar] SxgTkBar.exe
O4 - HKLM\..\Run: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtray.exe SetReg
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: IEEE 802.11g USB Wireless LAN Utility.lnk = C:\Program Files\Wireless LAN\WlanUtil.exe
O4 - Global Startup: Microsoft Broadband Networking.lnk = C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{1E0A612D-E7DA-448E-A7BD-665A904BCCCB}: NameServer = 192.168.254.254
O17 - HKLM\System\CCS\Services\Tcpip\..\{95EFE720-4E19-4D5E-A91A-9815B45BAB71}: Domain = frontiernet.net
O17 - HKLM\System\CCS\Services\Tcpip\..\{D111BF2D-EC5C-4063-AF53-46D3782FF089}: NameServer = 192.168.1.1,192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{1E0A612D-E7DA-448E-A7BD-665A904BCCCB}: NameServer = 192.168.254.254
O17 - HKLM\System\CS2\Services\Tcpip\..\{1E0A612D-E7DA-448E-A7BD-665A904BCCCB}: NameServer = 192.168.254.254
O20 - Winlogon Notify: klogon - C:\WINNT\system32\klogon.dll
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

Nope still not working, I crash right when it finishes updating. It says that klif.sys and ntoskrnl.exe may be to blame. What should I do now?
klif.sys is part of your Kaspersky Anti-Virus and ntoskrnl.exe is part of windows. There has been known problems associated with klif.sys in the past but it was my understanding the Kaspersky fixed this problem long ago. Lets try this:

  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • O4 - HKLM\..\Run: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtray.exe SetReg
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.

Using Windows Explorer (Windows Key + E), locate the following files/folders, and DELETE them (if still present):
C:\Program Files\Common Files\Symantec Shared <–This folder

Then

I need you to run the following scan: Eset Online Scanner

  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply along with a new HijackThis log.
Here's my scanner log:

# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3296 (20080724)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.064 (20070717)
# EOSSerial=28a796d0fac7414ca424cdf9ceb4dc8d
# end=finished
# remove_checked=false
# unwanted_checked=false
# utc_time=2008-07-25 07:22:12
# local_time=2008-07-25 12:22:12 (-0800, Pacific Daylight Time)
# country="United States"
# osver=5.0.2195 NT Service Pack 4
# scanned=231102
# found=8
# scan_time=10167
C:\QooBox\Quarantine\C\WINNT\SYSTEM32\gipiyhel.dll.vir Win32/Adware.Virtumonde application AB76CAC1DDC402CD48AD461FDB577C89
C:\QooBox\Quarantine\C\WINNT\SYSTEM32\ihlcqh.dll.vir Win32/Adware.Virtumonde application AB76CAC1DDC402CD48AD461FDB577C89
C:\QooBox\Quarantine\C\WINNT\SYSTEM32\lpwareld.dll.vir Win32/Adware.Virtumonde application B5267DF35A4E9DA772BD2D224112E1D7
C:\QooBox\Quarantine\C\WINNT\SYSTEM32\mstneawn.dll.vir Win32/Adware.BHO.NDA application 51CBBBFE632D90EBD8A873F5338CD3B4
C:\QooBox\Quarantine\C\WINNT\SYSTEM32\ugdigybq.dll.vir Win32/BHO.NFH trojan 053E95ADB29A1CE6CE3335EE04562790
C:\QooBox\Quarantine\C\WINNT\SYSTEM32\vahxgiqt.dll.vir Win32/Adware.Virtumonde application 542F232FC77C6C6E648355522191ACB0
C:\QooBox\Quarantine\C\WINNT\SYSTEM32\xdpjmg.dll.vir Win32/BHO.NFH trojan 053E95ADB29A1CE6CE3335EE04562790
C:\QooBox\Quarantine\C\WINNT\SYSTEM32\xfsnxuqu.dll.vir Win32/Adware.Virtumonde application B5267DF35A4E9DA772BD2D224112E1D7


And here's my new Hijack This log:

Logfile of HijackThis v1.99.1
Scan saved at 01:27, on 2008-07-25
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\cisvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\msdtc.exe
C:\WINNT\system32\mqsvc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\SxgTkBar.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Wireless LAN\WlanUtil.exe
C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Valve\Steam\Steam.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [SxgTkBar] SxgTkBar.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: IEEE 802.11g USB Wireless LAN Utility.lnk = C:\Program Files\Wireless LAN\WlanUtil.exe
O4 - Global Startup: Microsoft Broadband Networking.lnk = C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1E0A612D-E7DA-448E-A7BD-665A904BCCCB}: NameServer = 192.168.254.254
O17 - HKLM\System\CCS\Services\Tcpip\..\{95EFE720-4E19-4D5E-A91A-9815B45BAB71}: Domain = frontiernet.net
O17 - HKLM\System\CCS\Services\Tcpip\..\{D111BF2D-EC5C-4063-AF53-46D3782FF089}: NameServer = 192.168.1.1,192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{1E0A612D-E7DA-448E-A7BD-665A904BCCCB}: NameServer = 192.168.254.254
O17 - HKLM\System\CS2\Services\Tcpip\..\{1E0A612D-E7DA-448E-A7BD-665A904BCCCB}: NameServer = 192.168.254.254
O20 - Winlogon Notify: klogon - C:\WINNT\system32\klogon.dll
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI