This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Help I'm infected!

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So I definitely have some kind of virus. First of all, I am un able to access my programs. Second, while navigating online, i will sporadically encounter a warning that says "In Secure Internet Activity. Threat of Virus Attack." Also, the clock on my desktop has been switched to military time and to the right of it reads: "Virus Alert!" I have run AVG scans with results of infection. A good friend of mine reffered me to you guys praising your expedience and expertise. Any help that you could spare me would be immensely appreciated. Thank you!

Logfile of HijackThis v1.99.1
Scan saved at 20:44: VIRUS ALERT!, on 7/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\LEXPPS.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINNT\system32\hkcmd.exe
C:\WINNT\system32\igfxpers.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\PC Tools AntiVirus\PCTAV.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINNT\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\M-Audio\JamLab\JamLabInst.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\tcpsvcs.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINNT\System32\mspmspsv.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINNT\system32\wscntfy.exe
C:\WINNT\system32\WgaTray.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINNT\system32\igfxsrvc.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {625B6070-80A8-48BF-B8F5-E2C0FCDEEEB7} - C:\WINNT\system32\urqNEXno.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: (no name) - {A631B418-708F-2505-FD35-7FA2919B429D} - C:\WINNT\system32\lme.dll (file missing)
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll (file missing)
O2 - BHO: QXK Olive - {BDF21582-F109-4BAB-A660-437476CF0D2A} - C:\WINNT\gfetqaxsbfk.dll
O2 - BHO: (no name) - {D2EEB637-A4A5-4BBB-8C0C-96AF821110C2} - C:\WINNT\system32\ssqoopND.dll (file missing)
O3 - Toolbar: OIN Search - {B9F6E8EB-A4E3-478E-88A4-D3995B5C45C8} - C:\Program Files\OIN Search\OINSearch.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll
O3 - Toolbar: gxvpsafm - {63733480-2CC8-4334-8627-35651AAF74F4} - C:\WINNT\gxvpsafm.dll (file missing)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINNT\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [M-Audio Taskbar Icon] C:\WINNT\System32\M-AudioTaskBarIcon.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [789:;<=>?@ABCDEFGHIJexe] ,-./0123456789:;<=>?@ABCDEFGHIJexe
O4 - HKLM\..\Run: [3456789:;<=>?@ABCDEFexe] ()*+,-./0123456789:;<=>?@ABCDEFexe
O4 - HKLM\..\Run: [3456789:;<=>?@ABCDEFGexe] ()*+,-./0123456789:;<=>?@ABCDEFGexe
O4 - HKLM\..\Run: [580345f7] rundll32.exe "C:\WINNT\system32\glfiaols.dll",b
O4 - HKLM\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Oncc] "C:\WINNT\system32\SSTEM3~1\rundll32.exe" -vt yazb
O4 - HKCU\..\Run: [Vixljaww] C:\WINNT\system32\?asks\w?nword.exe
O4 - HKCU\..\Run: [Bzfdwacs] "C:\Documents and Settings\Administrator\Application Data\F?nts\w?wexec.exe"
O4 - HKCU\..\Run: [Atcma] "C:\Program Files\??mantec\m?iexec.exe"
O4 - HKCU\..\Run: [Ubd] "C:\Documents and Settings\Administrator\Application Data\s?mbols\??oolsv.exe"
O4 - HKCU\..\Run: [Psik] "C:\Program Files\Common Files\F?nts\??chost.exe"
O4 - HKCU\..\Run: [Ynbdk] "C:\Program Files\??crosoft\n?lookup.exe"
O4 - HKCU\..\Run: [Ctqmviwc] "C:\Documents and Settings\Administrator\Application Data\??stem\s?anregw.exe"
O4 - HKCU\..\Run: [Sct] C:\WINNT\system32\s?stem32\m?hta.exe
O4 - HKCU\..\Run: [Eyoayfs] "C:\Documents and Settings\Administrator\Application Data\W?nSxS\m?config.exe"
O4 - HKCU\..\Run: [Vyuns] "C:\Program Files\F?nts\r?gsvr32.exe"
O4 - HKCU\..\Run: [Uwn] "C:\Program Files\Common Files\F?nts\t?skmgr.exe"
O4 - HKCU\..\Run: [Vqdlwa] C:\WINNT\??sks\?vchost.exe
O4 - HKCU\..\Run: [Pnlkoaa] "C:\Program Files\??mantec\?xplorer.exe"
O4 - HKCU\..\Run: [Wnua] "C:\Program Files\Common Files\??pPatch\t?skmgr.exe"
O4 - HKCU\..\Run: [Dmwxaay] "C:\Documents and Settings\Administrator\Application Data\s?curity\l?gonui.exe"
O4 - HKCU\..\Run: [Zjrpenci] "C:\Documents and Settings\Administrator\Application Data\W?nSxS\l?gonui.exe"
O4 - HKCU\..\Run: [Kmbzc] "C:\Documents and Settings\Administrator\My Documents\?racle\j?vaw.exe"
O4 - HKCU\..\Run: [Lthmk] "C:\Documents and Settings\Administrator\My Documents\s?curity\d?dplay.exe"
O4 - HKCU\..\Run: [Lrmdrxl] "C:\Program Files\??mbols\n?tepad.exe"
O4 - HKCU\..\Run: [Xhi] "C:\Documents and Settings\Administrator\My Documents\?dobe\m?dtc.exe"
O4 - HKCU\..\Run: [Mcnt] C:\WINNT\F?nts\w?wexec.exe
O4 - HKCU\..\Run: [Hffki] "C:\Program Files\Common Files\?ppPatch\s?anregw.exe"
O4 - HKCU\..\Run: [Qbci] "C:\Documents and Settings\Administrator\My Documents\??mantec\??ool32.exe"
O4 - HKCU\..\Run: [Kss] C:\WINNT\system32\??mantec\w?crtupd.exe
O4 - HKCU\..\Run: [Ewmikx] "C:\Program Files\Common Files\T?sks\n?lookup.exe"
O4 - HKCU\..\Run: [Kfuoovrf] C:\WINNT\?ppPatch\s?ool32.exe
O4 - HKCU\..\Run: [Lpjtigtn] "C:\Documents and Settings\Administrator\My Documents\a?sembly\?vchost.exe"
O4 - HKCU\..\Run: [Fqsecwqo] "C:\Program Files\?ystem\w?auboot.exe"
O4 - HKCU\..\Run: [Owucfid] "C:\Program Files\?icrosoft.NET\??plorer.exe"
O4 - HKCU\..\Run: [Dlopgswc] C:\WINNT\system32\?ymbols\r?gsvr32.exe
O4 - HKCU\..\Run: [789:;<=>?@ABCDEFGHIJexe] ,-./0123456789:;<=>?@ABCDEFGHIJexe
O4 - HKCU\..\Run: [3456789:;<=>?@ABCDEFexe] ()*+,-./0123456789:;<=>?@ABCDEFexe
O4 - HKCU\..\Run: [3456789:;<=>?@ABCDEFGexe] ()*+,-./0123456789:;<=>?@ABCDEFGexe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1162247318156
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: ssqoopND - ssqoopND.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINNT\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINNT\system32\WPDShServiceObj.dll
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: JamLab Installer (JamLabInstallerService) - M-Audio - C:\Program Files\M-Audio\JamLab\JamLabInst.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Hi! Welcome to the forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.
32 Bit HP CIO Components Installer Adobe Flash Player 9 ActiveX Adobe Flash Player ActiveX Adobe Reader 6.0.1 AIM 6.0 AVG 8.0 Dell Photo Printer 720 Dell ResourceCD Hijackthis 1.99.1 HijackThis 1.99.1 Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) HP Customer Participation Program 8.0 HP Imaging Device Functions 8.0 HP OCR Software 8.0 HP Photosmart All-In-One Software 8.0 HP Photosmart Essential HP Solution Center 8.0 HP Update HPSSupply Intel® Extreme Graphics 2 Driver Intel® PRO Network Adapters and Drivers J2SE Runtime Environment 5.0 Update 8 JamLab Jasc Paint Shop Photo Album Jasc Paint Shop Pro 8 Dell Edition Lexmark Printer Software Uninstall Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Encarta Encyclopedia Standard 2002 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Standard Edition 2003 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Works 2002 Setup Launcher Microsoft Works 6.0 Microsoft Works Suite Add-in for Microsoft Word MSXML 4.0 SP2 (KB936181) OIN Search Outerinfo Outerinfo PC Tools AntiVirus4.0 Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB917734) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB923810) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937894) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB941644) Security Update for Windows XP (KB941693) Security Update for Windows XP (KB943055) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB943485) Security Update for Windows XP (KB944653) Security Update for Windows XP (KB945553) Security Update for Windows XP (KB946026) Security Update for Windows XP (KB948590) Security Update for Windows XP (KB948881) Security Update for Windows XP (KB950749) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Shockwave SoundMAX Spybot - Search & Destroy 1.4 Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB932823-v3) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Viewpoint Manager (Remove Only) Viewpoint Media Player Viewpoint Toolbar WebVideo Support Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player 11 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885884 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781
Hi

If you already have Combofix, please delete this copy and download it again as it's being updated regularly.

Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix


Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once Recovery Console is installed, you should see a blue screen prompt like the one below:

[external image: Posted Image]

Click Yes to allow Combofix to continue scanning for malware.

When done, a log will be produced. Please post that log and a new HijackThis log in your next reply.


1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.



In your next reply post:
ComboFix.txt
New HijackThis log taken after the above scan has run
ComboFix 08-07-31.06 - Administrator 2008-08-02 13:23:05.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.192 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\WinXP_EN_PRO_BF.EXE
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Administrator\Application Data\ASEMBL~1
C:\Documents and Settings\Administrator\Application Data\ASKS~1
C:\Documents and Settings\Administrator\Application Data\ASKS~2
C:\Documents and Settings\Administrator\Application Data\CROSOF~1
C:\Documents and Settings\Administrator\Application Data\DOBE~1
C:\Documents and Settings\Administrator\Application Data\ECURIT~1
C:\Documents and Settings\Administrator\Application Data\FNTS~1
C:\Documents and Settings\Administrator\Application Data\FNTS~2
C:\Documents and Settings\Administrator\Application Data\ICROSO~1
C:\Documents and Settings\Administrator\Application Data\ICROSO~2
C:\Documents and Settings\Administrator\Application Data\MANTEC~1
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus-2008pro.lnk
C:\Documents and Settings\Administrator\Application Data\PPPATC~1
C:\Documents and Settings\Administrator\Application Data\RACLE~1
C:\Documents and Settings\Administrator\Application Data\SCURIT~1
C:\Documents and Settings\Administrator\Application Data\SEMBLY~1
C:\Documents and Settings\Administrator\Application Data\SKS~1
C:\Documents and Settings\Administrator\Application Data\SMANTE~1
C:\Documents and Settings\Administrator\Application Data\SMBOLS~1
C:\Documents and Settings\Administrator\Application Data\SSEMBL~1
C:\Documents and Settings\Administrator\Application Data\STEM~1
C:\Documents and Settings\Administrator\Application Data\TSKS~1
C:\Documents and Settings\Administrator\Application Data\WNSXS~1
C:\Documents and Settings\Administrator\Application Data\YMBOLS~1
C:\Documents and Settings\Administrator\Desktop\antivirus-2008pro.lnk
C:\Documents and Settings\Administrator\Desktop\Error Cleaner.url
C:\Documents and Settings\Administrator\Desktop\Privacy Protector.url
C:\Documents and Settings\Administrator\Desktop\Spyware&Malware Protection.url
C:\Documents and Settings\Administrator\Favorites\Error Cleaner.url
C:\Documents and Settings\Administrator\Favorites\Privacy Protector.url
C:\Documents and Settings\Administrator\Favorites\Spyware&Malware Protection.url
C:\Documents and Settings\Administrator\My Documents\ASEMBL~1
C:\Documents and Settings\Administrator\My Documents\ASKS~1
C:\Documents and Settings\Administrator\My Documents\CROSOF~1
C:\Documents and Settings\Administrator\My Documents\CROSOF~1.NET
C:\Documents and Settings\Administrator\My Documents\DOBE~1
C:\Documents and Settings\Administrator\My Documents\DOBE~1\s?curity\
C:\Documents and Settings\Administrator\My Documents\FNTS~1
C:\Documents and Settings\Administrator\My Documents\FNTS~2
C:\Documents and Settings\Administrator\My Documents\ICROSO~1.NET
C:\Documents and Settings\Administrator\My Documents\MANTEC~1
C:\Documents and Settings\Administrator\My Documents\MCROSO~1
C:\Documents and Settings\Administrator\My Documents\RACLE~1
C:\Documents and Settings\Administrator\My Documents\SKS~1
C:\Documents and Settings\Administrator\My Documents\SMBOLS~1
C:\Documents and Settings\Administrator\My Documents\SSEMBL~1
C:\Documents and Settings\Administrator\My Documents\TSKS~1
C:\Documents and Settings\Administrator\My Documents\WNSXS~1
C:\Documents and Settings\Administrator\My Documents\YSTEM~1
C:\Documents and Settings\Administrator\Start Menu\Programs\Antivirus 2008 PRO
C:\Documents and Settings\Administrator\Start Menu\Programs\Antivirus 2008 PRO\antivirus-2008pro.lnk
C:\Documents and Settings\Administrator\Start Menu\Programs\Outerinfo
C:\Documents and Settings\Administrator\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\Administrator\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Program Files\Antivirus 2008 PRO
C:\Program Files\Antivirus 2008 PRO\vscan.tsi
C:\Program Files\Antivirus 2008 PRO\zlib.dll
C:\Program Files\appatc~1
C:\Program Files\asks~1
C:\Program Files\Common Files\asembl~1
C:\Program Files\Common Files\crosof~1
C:\Program Files\Common Files\crosof~1.net
C:\Program Files\Common Files\ecurit~1
C:\Program Files\Common Files\fnts~1
C:\Program Files\Common Files\fnts~2
C:\Program Files\Common Files\icroso~1.net
C:\Program Files\Common Files\mbols~1
C:\Program Files\Common Files\mcroso~1
C:\Program Files\Common Files\mcroso~1.net
C:\Program Files\Common Files\ppatch~1
C:\Program Files\Common Files\pppatc~1
C:\Program Files\Common Files\racle~1
C:\Program Files\Common Files\scurit~1
C:\Program Files\Common Files\smante~1
C:\Program Files\Common Files\smbols~1
C:\Program Files\Common Files\ssembl~1
C:\Program Files\Common Files\sstem~1
C:\Program Files\Common Files\tsks~1
C:\Program Files\Common Files\wnsxs~1
C:\Program Files\Common Files\ymante~1
C:\Program Files\crosof~1
C:\Program Files\dobe~1
C:\Program Files\ecurit~1
C:\Program Files\fnts~1
C:\Program Files\icroso~1
C:\Program Files\icroso~1.net
C:\Program Files\mantec~1
C:\Program Files\mbols~1
C:\Program Files\mcroso~1.net
C:\Program Files\oin search
C:\Program Files\oin search\OINSearch.dll
C:\Program Files\oin search\Uninstall.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\PCHealthCenter
C:\Program Files\PCHealthCenter\0.gif
C:\Program Files\PCHealthCenter\2.gif
C:\Program Files\PCHealthCenter\3.gif
C:\Program Files\pppatc~1
C:\Program Files\racle~1
C:\Program Files\sembly~1
C:\Program Files\sks~1
C:\Program Files\smante~1
C:\Program Files\smbols~1
C:\Program Files\ssembl~1
C:\Program Files\sstem~1
C:\Program Files\tsks~1
C:\Program Files\VAV
C:\Program Files\VAV\vav0.dat
C:\Program Files\VAV\vav1.dat
C:\Program Files\ymbols~1
C:\Program Files\ystem~1
C:\WINNT\cookies.ini
C:\WINNT\crosof~1
C:\WINNT\dobe~1
C:\WINNT\fnts~1
C:\WINNT\fnts~2
C:\WINNT\gfetqaxsbfk.dll
C:\WINNT\ppatch~1
C:\WINNT\pppatc~1
C:\WINNT\privacy_danger
C:\WINNT\privacy_danger\images\danger.jpg
C:\WINNT\privacy_danger\images\spacer.gif
C:\WINNT\racle~1
C:\WINNT\scurit~1
C:\WINNT\sembly~1
C:\WINNT\sks~1
C:\WINNT\smante~1
C:\WINNT\smbols~1
C:\WINNT\sstem3~1
C:\WINNT\stem~1
C:\WINNT\system32\appatc~1
C:\WINNT\system32\asembl~1
C:\WINNT\system32\asks~1
C:\WINNT\system32\crosof~1
C:\WINNT\system32\curity~1
C:\WINNT\system32\fnts~1
C:\WINNT\system32\icroso~1
C:\WINNT\system32\icroso~1.net
C:\WINNT\system32\mantec~1
C:\WINNT\system32\mbols~1
C:\WINNT\system32\mcrh.tmp
C:\WINNT\system32\onXENqru.ini
C:\WINNT\system32\onXENqru.ini2
C:\WINNT\system32\pppatc~1
C:\WINNT\system32\pppatc~2
C:\WINNT\system32\racle~1
C:\WINNT\system32\racle~2
C:\WINNT\system32\scurit~1
C:\WINNT\system32\sembly~1
C:\WINNT\system32\sloaiflg.ini
C:\WINNT\system32\smbols~1
C:\WINNT\system32\sstem3~1
C:\WINNT\system32\sstem3~1\s?stem32\
C:\WINNT\system32\stem~1
C:\WINNT\system32\stem32~1
C:\WINNT\system32\wnscpit.exe
C:\WINNT\system32\wnscpsv.exe
C:\WINNT\system32\xchllrlx.ini
C:\WINNT\system32\ymbols~1
C:\WINNT\system32\ystem~1
C:\WINNT\Web\default.htt
C:\WINNT\ystem~1

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_IPRIP
——-\Service_Iprip


((((((((((((((((((((((((( Files Created from 2008-07-02 to 2008-08-02 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-02 20:28 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-02 20:28 ——— d—–w C:\Program Files\PC Tools AntiVirus
2008-07-25 15:41 97,928 —-a-w C:\WINNT\system32\drivers\avgldx86.sys
2008-07-07 15:45 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg8
2008-07-07 15:43 10,520 —-a-w C:\WINNT\system32\avgrsstx.dll
2008-06-29 22:30 76,040 —-a-w C:\WINNT\system32\drivers\avgtdix.sys
2008-06-29 22:29 45,568 —-a-w C:\WINNT\system32\avgfwdx.dll
2008-06-29 22:29 23,296 —-a-w C:\WINNT\system32\drivers\avgfwdx.sys
2008-06-29 21:45 ——— d—–w C:\Documents and Settings\Administrator\Application Data\AdobeUM
2008-06-29 18:41 ——— d—–w C:\Program Files\AVG
2008-06-29 17:54 ——— d—–w C:\Documents and Settings\All Users\Application Data\PC Tools
2008-06-29 17:54 ——— d—–w C:\Documents and Settings\Administrator\Application Data\PC Tools
2008-06-29 17:52 ——— d—–w C:\Program Files\Common Files\PC Tools
2008-06-16 10:09 ——— d—–w C:\Program Files\LimeWire
2008-06-13 13:10 272,128 ——w C:\WINNT\system32\drivers\bthport.sys
2008-05-07 05:18 1,287,680 —-a-w C:\WINNT\system32\quartz.dll
2006-10-13 15:21 271 –sh–w C:\Program Files\desktop.ini
2006-10-13 15:21 21,952 —ha-w C:\Program Files\folder.htt
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Vixljaww"="C:\WINNT\system32\?asks\w?nword.exe" [?]
"Bzfdwacs"="C:\Documents and Settings\Administrator\Application Data\F?nts\w?wexec.exe" [?]
"Atcma"="C:\Program Files\??mantec\m?iexec.exe" [?]
"Ubd"="C:\Documents and Settings\Administrator\Application Data\s?mbols\??oolsv.exe" [?]
"Psik"="C:\Program Files\Common Files\F?nts\??chost.exe" [?]
"Ynbdk"="C:\Program Files\??crosoft\n?lookup.exe" [?]
"Ctqmviwc"="C:\Documents and Settings\Administrator\Application Data\??stem\s?anregw.exe" [?]
"Sct"="C:\WINNT\system32\s?stem32\m?hta.exe" [?]
"Eyoayfs"="C:\Documents and Settings\Administrator\Application Data\W?nSxS\m?config.exe" [?]
"Vyuns"="C:\Program Files\F?nts\r?gsvr32.exe" [?]
"Uwn"="C:\Program Files\Common Files\F?nts\t?skmgr.exe" [?]
"Vqdlwa"="C:\WINNT\??sks\?vchost.exe" [?]
"Pnlkoaa"="C:\Program Files\??mantec\?xplorer.exe" [?]
"Wnua"="C:\Program Files\Common Files\??pPatch\t?skmgr.exe" [?]
"Dmwxaay"="C:\Documents and Settings\Administrator\Application Data\s?curity\l?gonui.exe" [?]
"Zjrpenci"="C:\Documents and Settings\Administrator\Application Data\W?nSxS\l?gonui.exe" [?]
"Kmbzc"="C:\Documents and Settings\Administrator\My Documents\?racle\j?vaw.exe" [?]
"Lthmk"="C:\Documents and Settings\Administrator\My Documents\s?curity\d?dplay.exe" [?]
"Lrmdrxl"="C:\Program Files\??mbols\n?tepad.exe" [?]
"Xhi"="C:\Documents and Settings\Administrator\My Documents\?dobe\m?dtc.exe" [?]
"Mcnt"="C:\WINNT\F?nts\w?wexec.exe" [?]
"Hffki"="C:\Program Files\Common Files\?ppPatch\s?anregw.exe" [?]
"Qbci"="C:\Documents and Settings\Administrator\My Documents\??mantec\??ool32.exe" [?]
"Kss"="C:\WINNT\system32\??mantec\w?crtupd.exe" [?]
"Ewmikx"="C:\Program Files\Common Files\T?sks\n?lookup.exe" [?]
"Kfuoovrf"="C:\WINNT\?ppPatch\s?ool32.exe" [?]
"Lpjtigtn"="C:\Documents and Settings\Administrator\My Documents\a?sembly\?vchost.exe" [?]
"Fqsecwqo"="C:\Program Files\?ystem\w?auboot.exe" [?]
"Owucfid"="C:\Program Files\?icrosoft.NET\??plorer.exe" [?]
"Dlopgswc"="C:\WINNT\system32\?ymbols\r?gsvr32.exe" [?]
"789:;<=>?@ABCDEFGHIJexe"="" [?]
"3456789:;<=>?@ABCDEFexe"="()*+" [?]
"3456789:;<=>?@ABCDEFGexe"="()*+" [?]
"ctfmon.exe"="C:\WINNT\system32\ctfmon.exe" [2006-02-28 05:00 15360]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2006-11-07 08:29 50736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"789:;<=>?@ABCDEFGHIJexe"="" [?]
"3456789:;<=>?@ABCDEFexe"="()*+" [?]
"3456789:;<=>?@ABCDEFGexe"="()*+" [?]
"WorksFUD"="C:\Program Files\Microsoft Works\wkfud.exe" [2001-10-05 17:34 24576]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2001-08-23 14:52 331830]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-16 21:41 28738]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 15:42 1404928]
"igfxtray"="C:\WINNT\system32\igfxtray.exe" [2005-09-20 10:35 94208]
"igfxhkcmd"="C:\WINNT\system32\hkcmd.exe" [2005-09-20 10:32 77824]
"igfxpers"="C:\WINNT\system32\igfxpers.exe" [2005-09-20 10:36 114688]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" [2006-07-26 04:03 49263]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 21:52 49152]
"PCTAVApp"="C:\Program Files\PC Tools AntiVirus\PCTAV.exe" [2008-03-05 09:37 1238928]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-25 08:41 1235736]
"Synchronization Manager"="mobsync.exe" [2006-02-28 05:00 143360 C:\WINNT\system32\mobsync.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [2006-02-28 05:00 214528]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 21:40:10 210520]
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2001-08-07 16:06:54 24633]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft Office\\OFFICE11\\POWERPNT.EXE"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINNT\system32\Drivers\avgldx86.sys [2008-07-25 08:41]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-25 08:41]
R2 avgfws8;AVG8 Firewall;C:\PROGRA~1\AVG\AVG8\avgfws8.exe [2008-07-25 08:41]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINNT\system32\Drivers\avgtdix.sys [2008-06-29 15:30]
R2 JamLabInstallerService;JamLab Installer;C:\Program Files\M-Audio\JamLab\JamLabInst.exe [2006-01-09 17:39]
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 14:38]
R3 Avgfwdx;Avgfwdx;C:\WINNT\system32\DRIVERS\avgfwdx.sys [2008-06-29 15:29]
S3 Avgfwfd;AVG network filter service;C:\WINNT\system32\DRIVERS\avgfwdx.sys [2008-06-29 15:29]
S3 MAUSBJL;Service for M-Audio JamLab Driver (WDM);C:\WINNT\system32\DRIVERS\mausbjl.sys []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{413051aa-8b56-11dc-8a7e-00111197dc8e}]
\Shell\1\Command - E:\autorun.pif
\Shell\2\Command - E:\autorun.pif
\Shell\AutoRun\command - C:\WINNT\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.pif
.
- - - - ORPHANS REMOVED - - - -

BHO-{625B6070-80A8-48BF-B8F5-E2C0FCDEEEB7} - C:\WINNT\system32\urqNEXno.dll
BHO-{A631B418-708F-2505-FD35-7FA2919B429D} - C:\WINNT\system32\lme.dll
HKCU-Run-Oncc - C:\WINNT\system32\SSTEM3~1\rundll32.exe
HKLM-Run-M-Audio Taskbar Icon - C:\WINNT\System32\M-AudioTaskBarIcon.exe
HKLM-Run-580345f7 - C:\WINNT\system32\glfiaols.dll
Notify-ssqoopND - ssqoopND.dll


.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000

O16 -: DirectAnimation Java Classes - file://C:\WINNT\Java\classes\dajava.cab
C:\WINNT\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - file://C:\WINNT\Java\classes\xmldso.cab
C:\WINNT\Downloaded Program Files\Microsoft XML Parser for Java.osd


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-02 13:27:49
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\LEXPPS.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\WINNT\system32\tcpsvcs.exe
C:\WINNT\system32\mspmspsv.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINNT\system32\wscntfy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-08-02 13:33:12 - machine was rebooted [Administrator]
ComboFix-quarantined-files.txt 2008-08-02 20:32:56

Pre-Run: 25,411,629,056 bytes free
Post-Run: 25,581,547,520 bytes free

WinXP_EN_PRO_BF.EXE
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINNT
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINNT="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

361 — E O F — 2008-06-21 10:01:03



……………………………………………………………………..
………………………………………………………………………
………………………………………………………………………
……………………………………………………….

Logfile of HijackThis v1.99.1
Scan saved at 13:47, on 8/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\LEXPPS.EXE
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\M-Audio\JamLab\JamLabInst.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\tcpsvcs.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINNT\System32\mspmspsv.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINNT\system32\hkcmd.exe
C:\WINNT\system32\igfxpers.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\PC Tools AntiVirus\PCTAV.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINNT\system32\wscntfy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\explorer.exe
C:\WINNT\system32\notepad.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll (file missing)
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINNT\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [789:;<=>?@ABCDEFGHIJexe] ,-./0123456789:;<=>?@ABCDEFGHIJexe
O4 - HKLM\..\Run: [3456789:;<=>?@ABCDEFexe] ()*+,-./0123456789:;<=>?@ABCDEFexe
O4 - HKLM\..\Run: [3456789:;<=>?@ABCDEFGexe] ()*+,-./0123456789:;<=>?@ABCDEFGexe
O4 - HKLM\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Vixljaww] C:\WINNT\system32\?asks\w?nword.exe
O4 - HKCU\..\Run: [Bzfdwacs] "C:\Documents and Settings\Administrator\Application Data\F?nts\w?wexec.exe"
O4 - HKCU\..\Run: [Atcma] "C:\Program Files\??mantec\m?iexec.exe"
O4 - HKCU\..\Run: [Ubd] "C:\Documents and Settings\Administrator\Application Data\s?mbols\??oolsv.exe"
O4 - HKCU\..\Run: [Psik] "C:\Program Files\Common Files\F?nts\??chost.exe"
O4 - HKCU\..\Run: [Ynbdk] "C:\Program Files\??crosoft\n?lookup.exe"
O4 - HKCU\..\Run: [Ctqmviwc] "C:\Documents and Settings\Administrator\Application Data\??stem\s?anregw.exe"
O4 - HKCU\..\Run: [Sct] C:\WINNT\system32\s?stem32\m?hta.exe
O4 - HKCU\..\Run: [Eyoayfs] "C:\Documents and Settings\Administrator\Application Data\W?nSxS\m?config.exe"
O4 - HKCU\..\Run: [Vyuns] "C:\Program Files\F?nts\r?gsvr32.exe"
O4 - HKCU\..\Run: [Uwn] "C:\Program Files\Common Files\F?nts\t?skmgr.exe"
O4 - HKCU\..\Run: [Vqdlwa] C:\WINNT\??sks\?vchost.exe
O4 - HKCU\..\Run: [Pnlkoaa] "C:\Program Files\??mantec\?xplorer.exe"
O4 - HKCU\..\Run: [Wnua] "C:\Program Files\Common Files\??pPatch\t?skmgr.exe"
O4 - HKCU\..\Run: [Dmwxaay] "C:\Documents and Settings\Administrator\Application Data\s?curity\l?gonui.exe"
O4 - HKCU\..\Run: [Zjrpenci] "C:\Documents and Settings\Administrator\Application Data\W?nSxS\l?gonui.exe"
O4 - HKCU\..\Run: [Kmbzc] "C:\Documents and Settings\Administrator\My Documents\?racle\j?vaw.exe"
O4 - HKCU\..\Run: [Lthmk] "C:\Documents and Settings\Administrator\My Documents\s?curity\d?dplay.exe"
O4 - HKCU\..\Run: [Lrmdrxl] "C:\Program Files\??mbols\n?tepad.exe"
O4 - HKCU\..\Run: [Xhi] "C:\Documents and Settings\Administrator\My Documents\?dobe\m?dtc.exe"
O4 - HKCU\..\Run: [Mcnt] C:\WINNT\F?nts\w?wexec.exe
O4 - HKCU\..\Run: [Hffki] "C:\Program Files\Common Files\?ppPatch\s?anregw.exe"
O4 - HKCU\..\Run: [Qbci] "C:\Documents and Settings\Administrator\My Documents\??mantec\??ool32.exe"
O4 - HKCU\..\Run: [Kss] C:\WINNT\system32\??mantec\w?crtupd.exe
O4 - HKCU\..\Run: [Ewmikx] "C:\Program Files\Common Files\T?sks\n?lookup.exe"
O4 - HKCU\..\Run: [Kfuoovrf] C:\WINNT\?ppPatch\s?ool32.exe
O4 - HKCU\..\Run: [Lpjtigtn] "C:\Documents and Settings\Administrator\My Documents\a?sembly\?vchost.exe"
O4 - HKCU\..\Run: [Fqsecwqo] "C:\Program Files\?ystem\w?auboot.exe"
O4 - HKCU\..\Run: [Owucfid] "C:\Program Files\?icrosoft.NET\??plorer.exe"
O4 - HKCU\..\Run: [Dlopgswc] C:\WINNT\system32\?ymbols\r?gsvr32.exe
O4 - HKCU\..\Run: [789:;<=>?@ABCDEFGHIJexe] ,-./0123456789:;<=>?@ABCDEFGHIJexe
O4 - HKCU\..\Run: [3456789:;<=>?@ABCDEFexe] ()*+,-./0123456789:;<=>?@ABCDEFexe
O4 - HKCU\..\Run: [3456789:;<=>?@ABCDEFGexe] ()*+,-./0123456789:;<=>?@ABCDEFGexe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1162247318156
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINNT\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINNT\system32\WPDShServiceObj.dll
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: JamLab Installer (JamLabInstallerService) - M-Audio - C:\Program Files\M-Audio\JamLab\JamLabInst.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Hi

Download Flash_Disinfector from here and save it to your desktop.
Doubleclick on Flash_Disinfector.exe to run it and follow the prompts.
Wait until it has finished scanning and then exit the program.
The utility may ask you to insert your flash drive and/or other removable drives. This may include your mobile phone.
Please do so and allow the utility to clean up those drives as well.


Remember to disconnect from the Internet before carrying out the next instruction, and to save the following script before you do.You must
also manually disable your anti-virus and anti-spyware programs. See the link below for instructions on doing this.

http://www.bleepingcomputer.com/forums/topic114351.html

Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
E:\autorun.pif

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Vixljaww"=-
"Bzfdwacs"=-
"Atcma"=-
"Ubd"=-
"Psik"=-
"Ynbdk"=-
"Ctqmviwc"=-
"Sct"=-
"Eyoayfs"=-
"Vyuns"=-
"Uwn"=-
"Vqdlwa"=-
"Pnlkoaa"=-
"Wnua"=-
"Dmwxaay"=-
"Zjrpenci"=-
"Kmbzc"=-
"Lthmk"=-
"Lrmdrxl"=-
"Xhi"=-
"Mcnt"=-
"Hffki"=-
"Qbci"=-
"Kss"=-
"Ewmikx"=-
"Kfuoovrf"=-
"Lpjtigtn"=-
"Fqsecwqo"=-
"Owucfid"=-
"Dlopgswc"=-
"789:;<=>?@ABCDEFGHIJexe"=-
"3456789:;<=>?@ABCDEFexe"=-
"3456789:;<=>?@ABCDEFGexe"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"789:;<=>?@ABCDEFGHIJexe"=-
"3456789:;<=>?@ABCDEFexe"=-
"3456789:;<=>?@ABCDEFGexe"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{413051aa-8b56-11dc-8a7e-00111197dc8e}]

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe


Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Post that log back here.

In your next reply post:
ComboFix.txt
MBAM log
New HijackThis log taken after the above scan has run

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI