This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] what is winime and how to remove

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i noticed i have this process called winime running everytime when i start up, but i dont know what it is? how do i find out what it is and how do i remove it?? Here is my hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:31:26 PM, on 10/29/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\System32\rundll32.exe
c:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [RavTimeXP] C:\WINDOWS\Mstray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

–
End of file - 3277 bytes
Hello

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
combofix.txt



((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-31 )))))))))))))))))))))))))))))))
.

2008-10-29 17:30 . 2008-10-29 17:30 d——– C:\Program Files\Trend Micro
2008-10-28 02:55 . 2008-10-28 02:55 d——– C:\WINDOWS\Sun
2008-10-15 17:38 . 2008-10-15 17:38 697 —hs—- C:\comment.htt
2008-10-15 17:38 . 2008-10-15 17:38 72 —hs—- C:\desktop.ini
2008-10-15 11:53 . 2008-10-15 11:53 d——– C:\Documents and Settings\Gabe and Quincy\WINDOWS
2008-10-15 11:53 . 1996-01-09 09:38 283,648 –a—— C:\WINDOWS\uninst.exe
2008-10-15 11:53 . 2008-10-15 11:53 38 –a—— C:\WINDOWS\disney.ini
2008-10-15 11:53 . 2008-10-15 11:53 37 –a—— C:\WINDOWS\disney.old
2008-10-03 15:36 . 2003-02-20 16:39 512,000 –a–c— C:\WINDOWS\system32\dllcache\msado15.dll
2008-10-03 15:35 . 2008-10-03 15:35 d——– C:\Program Files\Common Files\HP
2008-10-03 15:34 . 2008-10-03 15:34 d——– C:\Program Files\Hewlett-Packard
2008-10-03 15:34 . 2008-10-03 15:34 d——– C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-10-03 15:34 . 2004-05-11 09:53 1,230,336 -ra—— C:\WINDOWS\system32\MSXML4.dll
2008-10-03 15:34 . 2004-05-11 09:53 626,960 -ra—— C:\WINDOWS\system32\hpvaut32.dll
2008-10-03 15:34 . 2004-05-11 09:53 487,424 -ra—— C:\WINDOWS\system32\hpvcp70.dll
2008-10-03 15:34 . 2004-05-11 09:53 344,064 -ra—— C:\WINDOWS\system32\hpvcr70.dll
2008-10-03 15:34 . 2004-05-11 09:53 82,432 -ra—— C:\WINDOWS\system32\MSXML4r.dll
2008-10-03 15:34 . 2004-05-11 09:53 44,544 -ra—— C:\WINDOWS\system32\MSXML4a.dll
2008-10-03 15:33 . 2008-10-03 15:33 d——– C:\Program Files\Common Files\Hewlett-Packard
2008-10-03 15:32 . 2008-10-03 15:32 d——– C:\WINDOWS\system32\URTTemp
2008-10-03 15:31 . 2003-08-25 17:06 182,880 –a—— C:\WINDOWS\system32\iuengine.dll
2008-10-03 15:31 . 2003-08-25 17:06 182,880 –a–c— C:\WINDOWS\system32\dllcache\iuengine.dll
2008-10-03 15:31 . 2002-08-29 00:32 28,160 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys
2008-10-03 15:31 . 2002-08-29 00:32 28,160 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-10-03 15:31 . 2002-08-29 00:50 24,960 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2008-10-03 15:31 . 2002-08-29 00:50 24,960 –a–c— C:\WINDOWS\system32\dllcache\usbprint.sys
2008-10-03 15:31 . 2002-08-29 00:48 14,208 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2008-10-03 15:31 . 2002-08-29 00:48 14,208 –a–c— C:\WINDOWS\system32\dllcache\usbscan.sys
2008-10-03 15:29 . 2004-03-18 15:53 278,584 –a—— C:\WINDOWS\system32\HPZidr12.dll
2008-10-03 15:29 . 2004-03-18 15:56 204,800 –a—— C:\WINDOWS\system32\HPZipr12.dll
2008-10-03 15:29 . 2004-03-18 15:39 94,208 –a—— C:\WINDOWS\system32\HPZipt12.dll
2008-10-03 15:29 . 2004-03-18 15:55 65,536 –a—— C:\WINDOWS\system32\HPZipm12.exe
2008-10-03 15:29 . 2004-03-18 15:38 61,440 –a—— C:\WINDOWS\system32\HPZinw12.exe
2008-10-03 15:29 . 2004-03-18 15:39 57,344 –a—— C:\WINDOWS\system32\HPZisn12.dll
2008-10-03 15:28 . 2008-10-03 15:34 d——– C:\Program Files\HP
2008-10-03 15:27 . 2008-10-03 15:40 104,156 –a—— C:\WINDOWS\hpoins04.dat
2008-10-03 15:27 . 2004-06-22 07:04 17,176 ——— C:\WINDOWS\hpomdl04.dat
2008-10-03 15:26 . 2008-10-03 15:27 d——– C:\temp\HP_WebRelease
2008-10-03 15:26 . 2008-10-03 15:26 d——– C:\temp
2008-10-03 02:39 . 2008-10-03 02:39 d—s—- C:\WINDOWS\system32\Microsoft
2008-10-03 01:44 . 2002-12-11 16:34 2,940,928 –a—— C:\WINDOWS\system32\wmploc.dll
2008-10-03 01:44 . 2002-12-11 16:34 225,280 –a—— C:\WINDOWS\system32\wmpdxm.dll
2008-10-03 01:44 . 2002-12-11 16:34 208,896 –a—— C:\WINDOWS\system32\wmpns.dll
2008-10-03 01:44 . 2002-12-11 14:16 167,936 –a—— C:\WINDOWS\system32\wmerror.dll
2008-10-03 01:44 . 2002-12-11 16:34 106,496 –a—— C:\WINDOWS\system32\wmpasf.dll
2008-10-03 01:44 . 2002-12-11 16:34 98,304 –a—— C:\WINDOWS\system32\wmpshell.dll
2008-10-03 01:44 . 2002-12-11 14:09 20,480 –a—— C:\WINDOWS\system32\wmpui.dll
2008-10-03 01:44 . 2002-12-11 14:09 20,480 –a—— C:\WINDOWS\system32\wmpcore.dll
2008-10-03 01:44 . 2002-12-11 14:09 20,480 –a—— C:\WINDOWS\system32\wmpcd.dll
2008-10-03 01:44 . 2002-12-11 14:09 20,480 –a—— C:\WINDOWS\system32\wmp.ocx
2008-10-03 01:44 . 2002-12-11 14:16 7,680 –a—— C:\WINDOWS\system32\asferror.dll
2008-10-03 01:31 . 2002-08-29 01:20 115,200 –a—— C:\WINDOWS\system32\dpcdll.dll
2008-10-03 01:29 . 2002-07-01 20:38 1,325,568 –a—— C:\WINDOWS\system32\webfldrs.msi
2008-10-03 01:28 . 2002-02-18 09:23 945,936 –a—— C:\WINDOWS\system32\msjava.dll
2008-10-03 01:07 . 2002-08-29 02:41 81,804 –a—— C:\WINDOWS\system32\wow32.dkz
2008-10-03 00:40 . 2008-10-03 00:40 d—s—- C:\Documents and Settings\Gabe and Quincy\UserData
2008-10-03 00:35 . 2008-10-29 21:56 d——– C:\Program Files\Steam
2008-10-02 01:05 . 2008-10-02 01:05 d——– C:\Program Files\Common Files\Adobe AIR
2008-10-02 01:04 . 2008-10-02 01:04 d——– C:\Program Files\Common Files\Adobe
2008-10-02 01:02 . 2008-10-02 01:02 d——– C:\Program Files\NOS
2008-10-02 01:02 . 2008-10-02 01:02 d——– C:\Documents and Settings\All Users\Application Data\NOS
2008-10-01 20:15 . 2008-10-01 20:15 d——– C:\Documents and Settings\All Users\Application Data\NVIDIA
2008-10-01 20:00 . 2006-10-22 14:06 208,896 –a—— C:\WINDOWS\system32\NVUNINST.EXE
2008-10-01 20:00 . 2008-10-01 20:00 1,080 –a—— C:\WINDOWS\system32\settingsbkup.sfm
2008-10-01 20:00 . 2008-10-01 20:00 1,080 –a—— C:\WINDOWS\system32\settings.sfm
2008-10-01 19:01 . 2008-10-01 19:01 d——– C:\Program Files\KeyTweak
2008-10-01 17:50 . 2008-10-01 17:50 d——– C:\WINDOWS\system32\NtmsData
2008-10-01 17:35 . 2008-10-01 17:36 d——– C:\Documents and Settings\Gabe and Quincy\Application Data\Ventrilo
2008-10-01 12:14 . 2008-10-03 01:10 d——– C:\Documents and Settings\Gabe and Quincy\Application Data\LimeWire
2008-10-01 12:14 . 2008-06-10 01:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-10-01 12:13 . 2008-10-01 12:14 d——– C:\Program Files\Java
2008-10-01 12:13 . 2008-10-01 12:13 d——– C:\Program Files\Common Files\Java
2008-10-01 12:12 . 2008-10-01 12:12 d——– C:\Program Files\LimeWire
2008-10-01 12:11 . 2008-10-01 12:11 d——– C:\Program Files\7-Zip
2008-10-01 11:51 . 2008-10-01 11:51 d——– C:\WINDOWS\Logs
2008-10-01 11:24 . 2008-10-01 11:24 d——– C:\Program Files\Ventrilo
2008-10-01 11:24 . 2008-10-01 11:24 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-10-01 03:23 . 2008-10-01 03:23 d——– C:\Program Files\Winamp
2008-10-01 03:23 . 2008-10-01 03:24 d——– C:\Documents and Settings\Gabe and Quincy\Application Data\Winamp
2008-10-01 03:23 . 2008-10-01 03:23 316,640 –a—— C:\WINDOWS\WMSysPr9.prx
2008-10-01 03:19 . 2008-10-01 03:19 d——– C:\WINDOWS\system32\Defaults
2008-10-01 03:19 . 2008-10-30 17:03 4,958,588 –a—— C:\WINDOWS\{00000002-00000000-00000001-00001102-00000004-20021102}.CDF
2008-10-01 03:19 . 2008-10-30 17:03 4,958,588 –a—— C:\WINDOWS\{00000002-00000000-00000001-00001102-00000004-20021102}.BAK
2008-10-01 03:19 . 2000-12-05 08:11 4,174,814 ——— C:\WINDOWS\system32\CT4MGM.SF2
2008-10-01 03:19 . 2008-10-30 04:35 32,592 –a—— C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx
2008-10-01 03:19 . 2008-10-30 04:35 32,592 –a—— C:\WINDOWS\system32\BMXState-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx
2008-10-01 03:19 . 2008-10-30 04:35 32,088 –a—— C:\WINDOWS\system32\BMXCtrlState-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx
2008-10-01 03:19 . 2008-10-30 04:35 32,088 –a—— C:\WINDOWS\system32\BMXBkpCtrlState-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx
2008-10-01 03:19 . 2008-10-30 04:35 11,564 –a—— C:\WINDOWS\system32\DVCState-{00000002-00000000-00000001-00001102-00000004-20021102}.rfx
2008-10-01 03:18 . 2008-10-01 03:18 d——– C:\Documents and Settings\Gabe and Quincy\Application Data\Creative
2008-10-01 03:17 . 2008-10-01 03:17 d——– C:\WINDOWS\system32\Data
2008-10-01 03:17 . 2002-08-29 01:01 134,272 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2008-10-01 03:17 . 2002-08-29 00:32 57,856 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2008-10-01 03:17 . 2001-08-17 21:37 22,016 –a—— C:\WINDOWS\system32\wdmaud.drv
2008-10-01 03:17 . 2001-08-17 21:36 4,096 –a–c— C:\WINDOWS\system32\dllcache\ksuser.dll
2008-10-01 03:02 . 2008-10-01 03:02 d——– C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-10-01 02:59 . 2001-08-17 21:36 51,200 –a–c— C:\WINDOWS\system32\dllcache\sfman32.dll
2008-10-01 02:57 . 2008-10-01 03:19 d——– C:\Program Files\Creative
2008-10-01 02:57 . 1998-10-29 15:45 306,688 –a—— C:\WINDOWS\IsUninst.exe
2008-10-01 02:57 . 1999-10-10 17:01 41,984 –a—— C:\WINDOWS\CTREGRUN.EXE
2008-10-01 02:31 . 2008-10-29 18:39 d——– C:\Program Files\PokerStars
2008-10-01 02:15 . 2006-01-12 12:52 1,904 ——— C:\WINDOWS\system32\SetupBD.din
2008-10-01 01:48 . 2008-10-01 03:18 d–h—– C:\Program Files\InstallShield Installation Information
2008-10-01 01:30 . 2008-10-01 01:30 d——– C:\Program Files\Belarc
2008-10-01 01:30 . 2008-02-27 12:49 3,840 –a—— C:\WINDOWS\system32\drivers\BANTExt.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-03 09:28 155,995 —-a-w C:\WINDOWS\java\Packages\XNHJHVJH.ZIP
2008-10-01 11:18 444,952 —-a-w C:\WINDOWS\system32\wrap_oal.dll
2008-10-01 11:18 109,080 —-a-w C:\WINDOWS\system32\OpenAL32.dll
2008-10-01 11:17 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-09-30 12:13 ——— d—–w C:\Program Files\microsoft frontpage
2008-07-31 17:41 68,616 —-a-w C:\WINDOWS\system32\XAPOFX1_1.dll
2008-07-31 17:41 238,088 —-a-w C:\WINDOWS\system32\xactengine3_2.dll
2008-07-31 17:40 509,448 —-a-w C:\WINDOWS\system32\XAudio2_2.dll
2008-07-31 13:16 80,896 —-a-w C:\WINDOWS\system32\dxdllreg.exe
2008-07-12 15:18 467,984 —-a-w C:\WINDOWS\system32\d3dx10_39.dll
2008-07-12 15:18 3,851,784 —-a-w C:\WINDOWS\system32\D3DX9_39.dll
2008-07-12 15:18 1,493,528 —-a-w C:\WINDOWS\system32\D3DCompiler_39.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-10-22 7700480]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2006-10-22 86016]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"HP Software Update"="c:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"nwiz"="nwiz.exe" [2006-10-22 C:\WINDOWS\system32\nwiz.exe]
"CTHelper"="CTHELPER.EXE" [2008-06-27 C:\WINDOWS\system32\CtHelper.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 241664]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 53248]

R3 COMMONFX.SYS;COMMONFX.SYS;C:\WINDOWS\System32\drivers\COMMONFX.SYS [2008-06-27 99352]
R3 CTAUDFX.SYS;CTAUDFX.SYS;C:\WINDOWS\System32\drivers\CTAUDFX.SYS [2008-06-27 555032]
R3 CTSBLFX.SYS;CTSBLFX.SYS;C:\WINDOWS\System32\drivers\CTSBLFX.SYS [2008-06-27 566296]
S3 {DEF85C80-216A-43ab-AF70-1665EDBE2780};{DEF85C80-216A-43ab-AF70-1665EDBE2780};C:\WINDOWS\TEMP\A.tmp [ ]
S3 COMMONFX;COMMONFX;C:\WINDOWS\System32\drivers\COMMONFX.SYS [2008-06-27 99352]
S3 CTAUDFX;CTAUDFX;C:\WINDOWS\System32\drivers\CTAUDFX.SYS [2008-06-27 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;C:\WINDOWS\System32\drivers\CTERFXFX.SYS [2008-06-27 100888]
S3 CTERFXFX;CTERFXFX;C:\WINDOWS\System32\drivers\CTERFXFX.SYS [2008-06-27 100888]
S3 CTSBLFX;CTSBLFX;C:\WINDOWS\System32\drivers\CTSBLFX.SYS [2008-06-27 566296]
S3 getPlus® Helper;getPlus® Helper;C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2008-08-29 33752]

*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-WinampAgent - C:\Program Files\Winamp\winampa.exe


.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com/
O9 -: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
O9 -: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm -

O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-30 17:09:05
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{DEF85C80-216A-43ab-AF70-1665EDBE2780}]
"ImagePath"="\??\C:\WINDOWS\TEMP\A.tmp"
.
Completion time: 2008-10-30 17:10:18
ComboFix-quarantined-files.txt 2008-10-31 01:10:16

Pre-Run: 18,623,098,880 bytes free
Post-Run: 20,655,321,088 bytes free

188
Hello

Please download the OTMoveIt3 by OldTimer or from here.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    {DEF85C80-216A-43ab-AF70-1665EDBE2780}
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== Service {DEF85C80-216A-43ab-AF70-1665EDBE2780} stopped successfully. Service {DEF85C80-216A-43ab-AF70-1665EDBE2780} deleted successfully. ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== File delete failed. C:\DOCUME~1\GABEAN~1\LOCALS~1\Temp\~DFE3D1.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\bca4e2da.$$$ scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\fa56d7ec.$$$ scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.5.0 log created on 10302008_172410 Files moved on Reboot… File C:\DOCUME~1\GABEAN~1\LOCALS~1\Temp\~DFE3D1.tmp not found! C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat moved successfully. File move failed. C:\WINDOWS\temp\bca4e2da.$$$ scheduled to be moved on reboot. File move failed. C:\WINDOWS\temp\fa56d7ec.$$$ scheduled to be moved on reboot.
Malwarebytes' Anti-Malware 1.30 Database version: 1340 Windows 5.1.2600 Service Pack 1 10/30/2008 5:33:08 PM mbam-log-2008-10-30 (17-33-08).txt Scan type: Quick Scan Objects scanned: 41756 Time elapsed: 2 minute(s), 33 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Do this after MBAM, leave Kaspersky till later

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.
SDFix: Version 1.238
Run by [removed] on Thu 10/30/2008 at 06:01 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\Temp\bca4e2da.$$$ - Deleted
C:\WINDOWS\Temp\ed47fa.$ - Deleted
C:\WINDOWS\Temp\fa56d7ec.$$$ - Deleted

Note - Files associated with the MBR Rootkit have been found on this system, to check the PC use the MBR Rootkit Detector by Gmer




Removing Temp Files

ADS Check :
Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
MBR rootkit code detected !
malicious code @ sector 0x4a891c1 size 0x1b3 !
copy of MBR has been found in sector 62 !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.
Hello

Open the Start > run box
type cmd hit the ok button.

At the DOS promt type mbr.exe -f (make sure you have a space before the e and the -f

hit the enter key.

Type exit at the prompt and hit the enter key.

Restart the computer normally.



Run the mbr.exe again.
Let me see the results.
C:\Documents and Settings\Gabe and Quincy>mbr.exe -f 'mbr.exe' is not recognized as an internal or external command, operable program or batch file.
Do this

Hello

Open the Start > run box
type cmd hit the ok button.

At the DOS promt type C:\Documents and Settings\Gabe and Quincy\Desktop\mbr.exe -f

(make sure you have a space before the e and the -f)

hit the enter key.

Type exit at the prompt and hit the enter key.

Restart the computer normally.



Run the mbr.exe again.
Let me see the results.
still no luck C:\Documents and Settings\Gabe and Quincy>mbr.exe -f 'mbr.exe' is not recognized as an internal or external command, operable program or batch file. C:\Documents and Settings\Gabe and Quincy>C:\Documents and Settings\Gabe and Quincy\Desktop\mbr.exe -f 'C:\Documents' is not recognized as an internal or external command, operable program or batch file. C:\Documents and Settings\Gabe and Quincy>

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI