This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Virus - csrssc.exe

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello ,

found out i had this virus this morning - csrssc.exe i think i also have others, It's disabled my registry and stop me looking for hidden files and folders , i have included a hijack this from before underneath ! Please someone help me
Thanks :wacko: :wacko: :wacko: :wacko: :wacko:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:30:11, on 15/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\csrss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\WINDOWS\Explorer.EXE
H:\Program Files\XpertVision\TBPanel.exe
H:\WINDOWS\RTHDCPL.EXE
H:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
H:\Program Files\btbb_wcm\McciTrayApp.exe
H:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
H:\PROGRA~1\Grisoft\AVG7\avgcc.exe
H:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
H:\WINDOWS\system32\RUNDLL32.EXE
H:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
H:\Program Files\Bonjour\mDNSResponder.exe
H:\WINDOWS\system32\LVCOMSX.EXE
H:\Program Files\Logitech\Video\LogiTray.exe
H:\WINDOWS\system32\nvsvc32.exe
H:\DOCUME~1\Adam\LOCALS~1\Temp\winloggn.exe
H:\PROGRA~1\Yahoo!\browser\ycommon.exe
H:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
H:\program files\steam\steam.exe
H:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBZE.EXE
H:\Program Files\Windows Live\Messenger\msnmsgr.exe
H:\WINDOWS\System32\svchost.exe
H:\Program Files\Logitech\Video\FxSvr2.exe
H:\WINDOWS\system32\SearchIndexer.exe
H:\WINDOWS\system32\wscntfy.exe
H:\WINDOWS\System32\alg.exe
H:\Program Files\Windows Live\Messenger\usnsvc.exe
H:\PROGRA~1\Yahoo!\browser\ybrowser.exe
H:\PROGRA~1\Yahoo!\browser\ybrowser.exe
H:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
H:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
H:\DOCUME~1\Adam\LOCALS~1\Temp\csrssc.exe
H:\WINDOWS\system32\SearchProtocolHost.exe
H:\WINDOWS\system32\SearchFilterHost.exe
H:\Program Files\Trend Micro\HijackThis\HijackThis.exe
H:\Program Files\Trend Micro\HijackThis\HijackThis.exe
H:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
O2 - BHO: {ef4e30da-e94e-c059-c3a4-da77a6275102} - {2015726a-77ad-4a3c-950c-e49ead03e4fe} - H:\WINDOWS\system32\tspjnr.dll (file missing)
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - H:\WINDOWS\system32\iiffFXrq.dll
O2 - BHO: (no name) - {99B6046A-1B4A-466A-8299-44FDF6D32668} - H:\WINDOWS\system32\nnnlmKba.dll (file missing)
O2 - BHO: (no name) - {D5BF49A2-94F1-42BD-F434-3604812C807D} - (no file)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - H:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - H:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - H:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [Gainward] H:\Program Files\XpertVision\TBPanel.exe /A
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE H:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [btbb_wcm_McciTrayApp] H:\Program Files\btbb_wcm\McciTrayApp.exe
O4 - HKLM\..\Run: [YBrowser] H:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [AVG7_CC] H:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE H:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "H:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "H:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [LVCOMSX] H:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] H:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] H:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [xsgds4fgffght] H:\DOCUME~1\Adam\LOCALS~1\Temp\winloggn.exe
O4 - HKLM\..\Run: [000000af] rundll32.exe "H:\WINDOWS\system32\cftabpcv.dll",b
O4 - HKLM\..\Run: [SpyHunter Security Suite] H:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKCU\..\Run: [Steam] "h:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "H:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [EPSON Stylus D92 Series] H:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBZE.EXE /FU "H:\WINDOWS\TEMP\E_SB6.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [xsgds4fgffght] H:\DOCUME~1\Adam\LOCALS~1\Temp\winloggn.exe
O4 - HKCU\..\Run: [msnmsgr] "H:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] H:\DOCUME~1\Adam\LOCALS~1\Temp\csrssc.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] H:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] H:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] H:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] H:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] H:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - H:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - H:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Hog Heaven Slots by pogo - http://game3.pogo.com/v/9.1.4.5/applet/fancy/fancy-en_US.cab
O16 - DPF: Lottso by pogo - http://game3.pogo.com/v/9.1.3.19/applet/lo…ottso-en_US.cab
O16 - DPF: Yahoo! Pool 2 - http://download2.games.yahoo.com/games/clients/y/poti_x.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - http://www.bebo.com/files/BeboUploader.5.1.4.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1229082500593
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1229082463015
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: tspjnr.dll
O20 - Winlogon Notify: iiffFXrq - H:\WINDOWS\SYSTEM32\iiffFXrq.dll
O22 - SharedTaskScheduler: KJhaiufhw3nrih7wefywjfsdfd - {D5BF49A2-94F1-42BD-F434-3604812C807D} - (no file)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - H:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - H:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - H:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - H:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - H:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - H:\Program Files\WinPcap\rpcapd.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - H:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - H:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: YPCService - Yahoo! Inc. - H:\WINDOWS\system32\YPCSER~1.EXE

–
End of file - 10096 bytes
Hello

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.
Hello As Requested :

ComboFix Log Below :

ComboFix 08-12-15.08 - Adam 2008-12-16 21:25:28.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3071.2348 [GMT 0:00]
Running from: h:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

h:\windows\system32\_000007_.tmp.dll
h:\windows\system32\_000008_.tmp.dll
h:\windows\system32\abKmlnnn.ini
h:\windows\system32\abKmlnnn.ini2
h:\windows\system32\uqdfwrlo.dll
h:\windows\system32\vcpbatfc.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_TDSSSERV.SYS
——-\Service_TDSSserv.sys


((((((((((((((((((((((((( Files Created from 2008-11-16 to 2008-12-16 )))))))))))))))))))))))))))))))
.

2008-12-15 13:55 . 2008-12-15 13:55 d——– h:\documents and settings\Adam\Application Data\Malwarebytes
2008-12-15 13:54 . 2008-12-15 13:54 d——– h:\program files\Malwarebytes' Anti-Malware
2008-12-15 13:54 . 2008-12-15 13:54 d——– h:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-15 13:54 . 2008-12-03 19:59 38,496 –a—— h:\windows\system32\drivers\mbamswissarmy.sys
2008-12-15 13:54 . 2008-12-03 19:59 15,504 –a—— h:\windows\system32\drivers\mbam.sys
2008-12-15 13:46 . 2008-12-15 13:46 d——– h:\windows\Sun
2008-12-15 13:46 . 2008-12-15 13:47 d——– h:\documents and settings\Adam\.housecall6.6
2008-12-15 13:46 . 2008-12-15 13:46 102,664 –a—— h:\windows\system32\drivers\tmcomm.sys
2008-12-15 13:29 . 2008-12-15 13:29 d——– h:\program files\Trend Micro
2008-12-15 13:14 . 2008-12-15 13:14 d——– h:\program files\Lavasoft
2008-12-15 13:14 . 2008-12-15 13:15 d——– h:\documents and settings\All Users\Application Data\Lavasoft
2008-12-15 13:03 . 2008-12-15 13:08 d-a—— h:\documents and settings\All Users\Application Data\TEMP
2008-12-15 13:02 . 2008-12-15 13:04 d——– h:\program files\Spyware Doctor
2008-12-15 13:02 . 2008-12-15 13:02 d——– h:\program files\Common Files\Download Manager
2008-12-15 13:02 . 2008-12-15 13:02 d——– h:\documents and settings\Adam\Application Data\PC Tools
2008-12-15 13:02 . 2008-06-10 21:22 81,288 –a—— h:\windows\system32\drivers\iksyssec.sys
2008-12-15 13:02 . 2008-06-02 15:19 66,952 –a—— h:\windows\system32\drivers\iksysflt.sys
2008-12-15 13:02 . 2008-06-02 15:19 42,376 –a—— h:\windows\system32\drivers\ikfilesec.sys
2008-12-15 13:02 . 2008-06-02 15:19 29,576 –a—— h:\windows\system32\drivers\kcom.sys
2008-12-15 09:54 . 2008-12-15 09:54 d——– h:\program files\CCleaner
2008-12-15 09:28 . 2008-12-15 12:13 d——– h:\program files\Enigma Software Group
2008-12-15 08:57 . 2008-12-15 13:21 dr-h—– H:\$VAULT$.AVG
2008-12-13 10:20 . 2008-12-13 10:53 23 –a—— h:\windows\popcinfot.dat
2008-12-12 19:43 . 2008-12-12 19:43 d——– h:\program files\Ventrilo
2008-12-12 19:43 . 2008-12-15 13:14 d——– h:\program files\Common Files\Wise Installation Wizard
2008-12-12 19:43 . 2008-12-12 19:44 d——– h:\documents and settings\Adam\Application Data\Ventrilo
2008-12-12 19:43 . 2008-12-12 19:43 262 –a—— h:\windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
2008-12-12 12:15 . 2008-12-12 12:15 d——– h:\documents and settings\Adam\Application Data\Windows Search
2008-12-12 12:00 . 2008-12-12 12:00 d——– h:\program files\Microsoft Silverlight
2008-12-12 11:56 . 2008-12-12 11:56 d——– h:\windows\system32\GroupPolicy
2008-12-12 11:56 . 2008-12-12 11:56 d——– h:\program files\Windows Desktop Search
2008-12-12 11:56 . 2008-12-12 11:56 d——– h:\documents and settings\Adam\Application Data\Windows Desktop Search
2008-12-12 11:56 . 2008-03-07 17:02 192,000 —–c— h:\windows\system32\dllcache\offfilt.dll
2008-12-12 11:56 . 2008-03-07 17:02 98,304 —–c— h:\windows\system32\dllcache\nlhtml.dll
2008-12-12 11:56 . 2008-03-07 17:02 29,696 —–c— h:\windows\system32\dllcache\mimefilt.dll
2008-12-12 11:55 . 2008-12-12 11:55 d——– h:\program files\Microsoft CAPICOM 2.1.0.2
2008-12-12 11:54 . 2008-10-24 11:21 455,296 —–c— h:\windows\system32\dllcache\mrxsmb.sys
2008-12-12 11:53 . 2008-08-14 10:11 2,189,184 —–c— h:\windows\system32\dllcache\ntoskrnl.exe
2008-12-12 11:53 . 2008-08-14 10:09 2,145,280 —–c— h:\windows\system32\dllcache\ntkrnlmp.exe
2008-12-12 11:53 . 2008-08-14 09:33 2,066,048 —–c— h:\windows\system32\dllcache\ntkrnlpa.exe
2008-12-12 11:53 . 2008-08-14 09:33 2,023,936 —–c— h:\windows\system32\dllcache\ntkrpamp.exe
2008-12-12 11:53 . 2008-09-15 12:12 1,846,400 —–c— h:\windows\system32\dllcache\win32k.sys
2008-12-12 11:53 . 2008-09-04 17:15 1,106,944 —–c— h:\windows\system32\dllcache\msxml3.dll
2008-12-12 11:53 . 2008-10-15 16:34 337,408 —–c— h:\windows\system32\dllcache\netapi32.dll
2008-12-12 11:53 . 2008-09-08 10:41 333,824 —–c— h:\windows\system32\dllcache\srv.sys
2008-12-12 11:53 . 2008-08-14 10:04 138,496 —–c— h:\windows\system32\dllcache\afd.sys
2008-12-12 11:51 . 2008-04-11 19:04 691,712 —–c— h:\windows\system32\dllcache\inetcomm.dll
2008-12-12 11:51 . 2008-05-01 14:33 331,776 —–c— h:\windows\system32\dllcache\msadce.dll
2008-12-12 11:50 . 2008-06-13 11:05 272,128 —–c— h:\windows\system32\dllcache\bthport.sys
2008-12-12 11:50 . 2008-05-08 14:02 203,136 —–c— h:\windows\system32\dllcache\rmcast.sys
2008-12-12 11:49 . 2008-10-16 14:07 23,576 –a—— h:\windows\system32\wuapi.dll.mui
2008-12-11 18:16 . 2008-12-15 09:39 d——– h:\program files\Football Superstars
2008-12-06 14:59 . 2008-12-06 14:59 d——– h:\program files\GoldWave

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-16 21:28 ——— d—–w h:\program files\Steam
2008-12-16 20:04 ——— d—–w h:\documents and settings\Adam\Application Data\AVG7
2008-12-15 09:58 ——— d—–w h:\program files\Windows Live
2008-12-15 09:58 ——— d—–w h:\program files\Sports Interactive
2008-12-15 09:48 ——— d—–w h:\program files\LimeWire
2008-12-15 09:38 ——— d—–w h:\program files\Spybot - Search & Destroy
2008-12-15 09:38 ——— d—–w h:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-15 09:37 ——— d—–w h:\documents and settings\All Users\Application Data\avg7
2008-12-15 09:36 ——— d—–w h:\documents and settings\Adam\Application Data\OpenOffice.org2
2008-12-12 11:48 ——— d–h–w h:\program files\InstallShield Installation Information
2008-11-19 17:57 ——— d—–w h:\documents and settings\Adam\Application Data\Sports Interactive
2008-11-06 21:48 ——— d—–w h:\documents and settings\Adam\Application Data\BitTorrent
2008-11-04 18:45 ——— d—–w h:\documents and settings\Adam\Application Data\LimeWire
2008-10-24 11:21 455,296 —-a-w h:\windows\system32\drivers\mrxsmb.sys
2008-10-19 20:41 3,132,860 —-a-w h:\windows\java\Packages\OEEDJBXV.ZIP
2008-10-19 19:33 2,879,279 —-a-w h:\windows\java\Packages\JDBJJ9F1.ZIP
2008-01-29 14:12 32 —-a-w h:\documents and settings\All Users\Application Data\ezsid.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="h:\program files\steam\steam.exe" [2008-10-08 1410296]
"LogitechSoftwareUpdate"="h:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
"EPSON Stylus D92 Series"="h:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIBZE.EXE" [2006-09-27 139264]
"msnmsgr"="h:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"MSMSGS"="h:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gainward"="h:\program files\XpertVision\TBPanel.exe" [2007-11-01 2165256]
"NvCplDaemon"="h:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
"btbb_wcm_McciTrayApp"="h:\program files\btbb_wcm\McciTrayApp.exe" [2005-12-29 543232]
"YBrowser"="h:\progra~1\Yahoo!\browser\ybrwicon.exe" [2003-12-09 57344]
"AVG7_CC"="h:\progra~1\Grisoft\AVG7\avgcc.exe" [2008-10-16 590848]
"NvMediaCenter"="h:\windows\system32\NvMcTray.dll" [2007-12-05 81920]
"QuickTime Task"="h:\program files\QuickTime\qttask.exe" [2008-01-10 385024]
"SunJavaUpdateSched"="h:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"LVCOMSX"="h:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="h:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="h:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"SpyHunter Security Suite"="h:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2008-10-08 864256]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-10 h:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2007-04-04 h:\windows\SkyTel.exe]
"nwiz"="nwiz.exe" [2007-12-05 h:\windows\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="h:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"AVG7_Run"="h:\progra~1\Grisoft\AVG7\avgw.exe" [2008-01-08 219136]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "h:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=tspjnr.dll

[HKLM\~\startupfolder\H:^Documents and Settings^Adam^Start Menu^Programs^Startup^OpenOffice.org 2.4.lnk]
path=h:\documents and settings\Adam\Start Menu\Programs\Startup\OpenOffice.org 2.4.lnk
backup=h:\windows\pss\OpenOffice.org 2.4.lnkStartup

[HKLM\~\startupfolder\H:^Documents and Settings^All Users^Start Menu^Programs^Startup^BT Broadband Desktop Help.lnk]
path=h:\documents and settings\All Users\Start Menu\Programs\Startup\BT Broadband Desktop Help.lnk
backup=h:\windows\pss\BT Broadband Desktop Help.lnkCommon Startup

[HKLM\~\startupfolder\H:^Documents and Settings^All Users^Start Menu^Programs^Startup^Printkey2000.lnk]
path=h:\documents and settings\All Users\Start Menu\Programs\Startup\Printkey2000.lnk
backup=h:\windows\pss\Printkey2000.lnkCommon Startup

[HKLM\~\startupfolder\H:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=h:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=h:\windows\pss\Windows Search.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2007-10-10 19:51 39792 h:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eyeBeam SIP Client]
–a—— 2006-07-31 20:00 19857408 h:\program files\BT Broadband Talk Softphone\BTSoftphone.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
–a—— 2006-02-06 18:52 462935 h:\progra~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2008-04-14 00:12 1695232 h:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
–a—— 2007-10-18 11:34 5724184 h:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra—— 2008-02-01 17:22 21898024 h:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ThePrivacyGuard]
–a—— 2007-05-15 13:02 2127360 h:\progra~1\THEPRI~1\THEPRI~1.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2005-08-31 17:11 2478080 h:\progra~1\Yahoo!\MESSEN~1\ypager.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"h:\\Program Files\\Steam\\steamapps\\shawzinhio\\team fortress 2\\hl2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"h:\\Program Files\\mIRC\\mirc.exe"=
"h:\\Program Files\\Steam\\Steam.exe"=
"h:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"h:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"h:\\Program Files\\12Sky\\TwelveSky.exe"=
"h:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
"h:\\Program Files\\Skype\\Phone\\Skype.exe"=
"h:\\Program Files\\uTorrent\\uTorrent.exe"=
"h:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"h:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"h:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"h:\\Program Files\\Yahoo!\\browser\\ybrowser.exe"=
"h:\\WINDOWS\\system32\\dpvsetup.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

S3 NPF;NetGroup Packet Filter Driver;h:\windows\system32\drivers\npf.sys [2007-11-06 34064]
S3 sdAuxService;PC Tools Auxiliary Service;h:\program files\Spyware Doctor\pctsAuxs.exe [2008-12-15 356920]
S3 XDva062;XDva062;\??\h:\windows\system32\XDva062.sys []
.
- - - - ORPHANS REMOVED - - - -

BHO-{99B6046A-1B4A-466A-8299-44FDF6D32668} - h:\windows\system32\nnnlmKba.dll


.
——- Supplementary Scan ——-
.
uStart Page = www.google.co.uk/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/

O16 -: Hog Heaven Slots by pogo - hxxp://game3.pogo.com/v/9.1.4.5/applet/fancy/fancy-en_US.cab
h:\windows\Downloaded Program Files\Hog Heaven Slots by pogo.osd

O16 -: Lottso by pogo - hxxp://game3.pogo.com/v/9.1.3.19/applet/lottso/lottso-en_US.cab
h:\windows\Downloaded Program Files\Lottso by pogo.osd

O16 -: Microsoft XML Parser for Java - file://h:\windows\Java\classes\xmldso.cab
h:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-16 21:28:24
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
h:\program files\Lavasoft\Ad-Aware\aawservice.exe
h:\progra~1\Grisoft\AVG7\avgamsvr.exe
h:\progra~1\Grisoft\AVG7\avgupsvc.exe
h:\program files\Bonjour\mDNSResponder.exe
h:\windows\system32\nvsvc32.exe
h:\windows\system32\rundll32.exe
h:\progra~1\Yahoo!\browser\ycommon.exe
h:\windows\system32\searchindexer.exe
h:\program files\Logitech\Video\FxSvr2.exe
h:\windows\system32\wscntfy.exe
h:\windows\system32\searchprotocolhost.exe
h:\windows\system32\searchfilterhost.exe
.
**************************************************************************
.
Completion time: 2008-12-16 21:31:15 - machine was rebooted [Adam]
ComboFix-quarantined-files.txt 2008-12-16 21:31:12

Pre-Run: 213,931,393,024 bytes free
Post-Run: 214,394,806,272 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
h:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

235
Hello

Please download the OTMoveIt3 by OldTimer or from here.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    h:\windows\java\Packages\OEEDJBXV.ZIP
    h:\windows\java\Packages\JDBJJ9F1.ZIP
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
Hello , Please Find OTMoveIT report below: ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== h:\windows\java\Packages\OEEDJBXV.ZIP moved successfully. h:\windows\java\Packages\JDBJJ9F1.ZIP moved successfully. ========== COMMANDS ========== File delete failed. H:\DOCUME~1\Adam\LOCALS~1\Temp\~DF5063.tmp scheduled to be deleted on reboot. File delete failed. H:\DOCUME~1\Adam\LOCALS~1\Temp\~DF5070.tmp scheduled to be deleted on reboot. File delete failed. H:\DOCUME~1\Adam\LOCALS~1\Temp\~DF5A96.tmp scheduled to be deleted on reboot. File delete failed. H:\DOCUME~1\Adam\LOCALS~1\Temp\~DF5AA1.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. H:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12172008_175746 Files moved on Reboot… File H:\DOCUME~1\Adam\LOCALS~1\Temp\~DF5063.tmp not found! File H:\DOCUME~1\Adam\LOCALS~1\Temp\~DF5070.tmp not found! File H:\DOCUME~1\Adam\LOCALS~1\Temp\~DF5A96.tmp not found! File H:\DOCUME~1\Adam\LOCALS~1\Temp\~DF5AA1.tmp not found! File move failed. H:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
Malwarebytes report below : Malwarebytes' Anti-Malware 1.31 Database version: 1456 Windows 5.1.2600 Service Pack 3 17/12/2008 18:12:42 mbam-log-2008-12-17 (18-12-42).txt Scan type: Quick Scan Objects scanned: 47373 Time elapsed: 2 minute(s), 48 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
The Kasparsky Online scanner will not update so i give up on that , do i have to do it ? Let me know Thanks I thank you for all your help!
Try this instead

Please click here to download AVP Tool by Kaspersky.
  • Save it to your desktop.
  • Reboot your computer into SafeMode.

    You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
    Use your up arrow key to highlight SafeMode then hit enter
    .

  • Double click the setup file to run it.
  • Click Next to continue.
  • It will by default install it to your desktop folder.Click Next.
  • Hit ok at the prompt for scanning in Safe Mode.
  • It will then open a box There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.

  • System Memory
  • Startup Objects
  • Disk Boot Sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)


  • Then click on Scan at the to right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left unneutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then chooose The delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file name it Kas.
  • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI