Hi oldman960,
Have followed your instructions and the Antivirus XP 2008 icon in the System Tray has gone as has the "Spyware detected" wallpaper and so far no more warnings from AV XP 2008.
Here are the results:
Virustotal scan of lphc1fkj0egc1.exe (when I saw the results of the next two, I decided to do a resubmit and re-analysis as indicated in this report and got additional information):
This was for file 1: lphc1fkj0egc1.exe
File unknown received on 09.18.2008 08:50:19 (CET)
Current status: finished
Result: 32/36 (88.89%)
Compact
Print results
Antivirus Version Last Update Result
AhnLab-V3 - - Win-Trojan/Pakes.109056.K
AntiVir - - TR/Crypt.XPACK.Gen
Authentium - - W32/AV2008.B
Avast - - Win32:Trojan-gen {Other}
AVG - - I-Worm/Nuwar.S
BitDefender - - Trojan.Peed.JOA
CAT-QuickHeal - - Trojan.Pakes.jtt
ClamAV - - Trojan.Pakes-2309
DrWeb - - Trojan.Packed.512
eSafe - - Suspicious File
eTrust-Vet - - Win32/Tibs.B
Ewido - - Trojan.Pakes.jtt
F-Prot - - W32/Zhelatin.O.gen!Eldorado
F-Secure - - Trojan.Win32.Pakes.jtt
Fortinet - - PossibleThreat
GData - - Trojan.Win32.Pakes.jtt
Ikarus - - Trojan.Peed.JOA
K7AntiVirus - - Trojan.Win32.Peed.JOA
Kaspersky - - Trojan.Win32.Pakes.jtt
McAfee - - Generic.dx
Microsoft - - Trojan:Win32/Tibs.J
NOD32v2 - - Win32/TrojanDownloader.FakeAlert.EH
Norman - - W32/Tibs.CKTY
Panda - - Adware/AntivirusXP2008
PCTools - - -
Prevx1 - - Malicious Software
Rising - - -
Sophos - - Mal/Generic-A
Sunbelt - - Antivirus XP 2008 (Winifixer)
Symantec - - Packed.Generic.174
TheHacker - - -
TrendMicro - - TROJ_TIBS.BUL
VBA32 - - Trojan.Packed.512
ViRobot - - -
VirusBuster - - Trojan.Pakes.DBL
Webwasher-Gateway - - Trojan.Crypt.XPACK.Gen
Additional information
MD5: 3de20d6a87f7a73dfd2a3ac03086b99d
SHA1: 0ebfd32a79b1b0e1bafb378cdc0bbb5513a49c3d
SHA256: b0e0c873471e6845cc2e732c56653177d33d61319aa49c6c96f1b40ef0de2a6a
I did a re-submit and re-analyse and got this report:
File lphc1fkj0egc1.exe received on 01.23.2009 23:41:56 (CET)
Current status: finished
Result: 32/36 (88.89%)
Compact
Print results
Email:
Antivirus Version Last Update Result
a-squared 4.0.0.73 2009.01.23 Trojan.Peed.JOA!IK
AhnLab-V3 5.0.0.2 2009.01.23 Win-Trojan/Pakes.109056.K
AntiVir 7.9.0.60 2009.01.23 TR/Crypt.XPACK.Gen
Authentium 5.1.0.4 2009.01.23 W32/AV2008.B
Avast 4.8.1281.0 2009.01.23 Win32:Trojan-gen {Other}
AVG 8.0.0.229 2009.01.23 I-Worm/Nuwar.S
BitDefender 7.2 2009.01.23 Trojan.Packed.Gen.1
CAT-QuickHeal 10.00 2009.01.23 Trojan.Tibs.J
ClamAV 0.94.1 2009.01.23 Trojan.Pakes-2309
Comodo 943 2009.01.23 TrojWare.Win32.TrojanDownloader.FakeAlert.EE
DrWeb 4.44.0.09170 2009.01.23 Trojan.Packed.512
eSafe 7.0.17.0 2009.01.22 Suspicious File
eTrust-Vet 31.6.6323 2009.01.23 Win32/Tibs.B
F-Prot 4.4.4.56 2009.01.23 W32/Zhelatin.O.gen!Eldorado
Fortinet 3.117.0.0 2009.01.23 W32/Agent.TRC!tr
GData 19 2009.01.23 Trojan.Packed.Gen.1
Ikarus T3.1.1.45.0 2009.01.23 Trojan.Peed.JOA
K7AntiVirus 7.10.602 2009.01.23 Trojan.Win32.Peed.JOA
Kaspersky 7.0.0.125 2009.01.23 Trojan.Win32.Pakes.jtt
McAfee 5504 2009.01.23 Generic.dx
McAfee+Artemis 5504 2009.01.23 Generic.dx
Microsoft 1.4205 2009.01.23 Trojan:Win32/Tibs.J
NOD32 3795 2009.01.23 Win32/TrojanDownloader.FakeAlert.EH
nProtect 2009.1.8.0 2009.01.23 Trojan.Packed.Gen.1
Panda 9.5.1.2 2009.01.23 Adware/AntivirusXP2008
PCTools 4.4.2.0 2009.01.23 -
Rising 21.13.42.00 2009.01.23 -
SecureWeb-Gateway 6.7.6 2009.01.23 Trojan.Crypt.XPACK.Gen
Sophos 4.37.0 2009.01.23 Mal/Generic-A
Sunbelt 3.2.1835.2 2009.01.16 Antivirus XP 2008 (Winifixer)
Symantec 10 2009.01.23 Packed.Generic.174
TheHacker 6.3.1.5.226 2009.01.22 -
TrendMicro 8.700.0.1004 2009.01.23 TROJ_TIBS.BUL
VBA32 3.12.8.11 2009.01.23 Malware-Cryptor.Win32.Zherlo
ViRobot 2009.1.23.1576 2009.01.23 -
VirusBuster 4.5.11.0 2009.01.23 Trojan.Pakes.DBL
Additional information
File size: 109056 bytes
MD5…: 3de20d6a87f7a73dfd2a3ac03086b99d
SHA1..: 0ebfd32a79b1b0e1bafb378cdc0bbb5513a49c3d
SHA256: b0e0c873471e6845cc2e732c56653177d33d61319aa49c6c96f1b40ef0de2a6a
SHA512: ca1273cee12d4650f8745ebacefc2a9dbc0e6c31ac2782f5b6f8e94ade979366
504eabf262189541f789945948f96fbc9ae9e101f1b687804144ecba152eae7b
ssdeep: 1536:gt+7v01OawqC7gNKfDX+JbsM02/9uaX+7XNJvbr1dd0vRkhtC78vJtCtQxt
f:4+Va87gIfDXKwM0msn9dQkhY8kQt
PEiD..: -
TrID..: File type identification
Win32 Dynamic Link Library (generic) (55.5%)
Clipper DOS Executable (14.7%)
Generic Win/DOS Executable (14.6%)
DOS Executable Generic (14.6%)
VXD Driver (0.2%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x406d40
timedatestamp…..: 0x485d33e9 (Sat Jun 21 17:01:29 2008)
machinetype…….: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x8e49 0x6000 7.99 6e286db3aab08fe1336e4ddf3dc7f2e4
.rdata 0xa000 0x2f95 0x1400 7.96 79a94081d62c712de0560dd1548b2179
.data 0xd000 0x25c9f 0x11200 8.00 f94dde69cbf17a276959e6501006d80b
.rsrc 0x33000 0x2000 0x2000 5.37 22fbd89f431d2d8e2e5eee67d093bc7c
( 3 imports )
> shell32.dll: DAD_DragLeave, StrStrIA, DuplicateIcon
> msvcrt.dll: _mbccpy, _mbctombb, _mbsdec, _pctype, _snprintf, _snwprintf
> kernel32.dll: CompareFileTime, CopyFileW, CreateThread, DefineDosDeviceW, EnumResourceTypesW, GetCommConfig, GetConsoleWindow, GetDateFormatW
( 0 exports )
ThreatExpert info:
http://www.threatexpert.com/report.aspx?md5=3de20d6a87f7a73dfd2a3ac03086b99d' target='_blank'>
http://www.threatexpert.com/report.aspx?md5=3de20d6a87f7a73dfd2a3ac03086b99d
Here is the report on rhc5fkj0egc1.exe:
This one produced an exception error first but re-analyse produced a report:
Exception
Please report failure as: ErrorTime= "Jan 23 23:16:31"
2nd attempt:
File has already been analysed:
MD5: 21e04c74b41191139ff5728e7f94029f
First received: 07.06.2008 11:31:46 (CET)
Date: 07.18.2008 23:58:17 (CET) [>188D]
Results: 20/32
Permalink: analisis/06e86e0d91f0df30d8623ea702785599
File rhc5fkj0egc1.exe received on 07.18.2008 23:58:17 (CET)
Current status: finished
Result: 20/32 (62.50%)
Compact
Print results
Antivirus Version Last Update Result
AhnLab-V3 - - -
AntiVir - - TR/Drop.Age.1642496
Authentium - - -
Avast - - Win32:Trojan-gen {Other}
AVG - - Agent.XZM
BitDefender - - Trojan.Peed.JOP
CAT-QuickHeal - - FraudTool.AntivirusXP2008 (Not a Virus)
ClamAV - - -
DrWeb - - Trojan.Packed.566
eSafe - - Suspicious File
eTrust-Vet - - -
Ewido - - -
F-Prot - - -
F-Secure - - FraudTool.Win32.AntivirusXP2008.a
Fortinet - - FakeAlert.B!tr
GData - - Win32:Trojan-gen
Ikarus - - Trojan.Peed.JOA
Kaspersky - - not-a-virus:FraudTool.Win32.AntivirusXP2008.a
McAfee - - Generic FakeAlert.b
NOD32v2 - - -
Norman - - W32/Renos.YT
Panda - - -
Prevx1 - - Malicious Software
Rising - - -
Sophos - - Troj/FakeVir-DF
Sunbelt - - CWS.DesktopHijack
Symantec - - -
TheHacker - - Aplicacion/AntivirusXP2008.a
TrendMicro - - TROJ_NUWAR.AEI
VBA32 - - -
VirusBuster - - -
Webwasher-Gateway - - Trojan.Drop.Age.1642496
Additional information
MD5: 21e04c74b41191139ff5728e7f94029f
SHA1: 6a9656271eddb12c6f7483445f4a78e8805c074a
SHA256: a9f00105a50acc28354aa8430e14d0e5246430d52a2612ef5480e37931cd97c3
SHA512: b5becf40ca04ba330af75ca9
Here is report for pphc1fjk0egc1.exe:
This one also seemed brief and a re-analysis produced more information:
File has already been analysed:
MD5: 45684e238403d720ead129a0fb2e2258
First received: 06.22.2008 18:21:12 (CET)
Date: 09.26.2008 17:39:02 (CET) [>119D]
Results: 34/36
Permalink: analisis/ba60f85133b080c2faea6dc30ef532f5
This was the last report:
File pphc1fkj0egc1.exe received on 09.26.2008 17:39:02 (CET)
Current status: finished
Result: 34/36 (94.44%)
Compact
Print results
Antivirus Version Last Update Result
AhnLab-V3 - - Win-Trojan/Fackav.94208
AntiVir - - TR/Fakealert.AG
Authentium - - W32/Backdoor2.CCHB
Avast - - Win32:FraudTool-GI
AVG - - WinFixer.ATW
BitDefender - - Trojan.FakeAlert.TR
CAT-QuickHeal - - FraudTool.MalwareProtector.d (Not a Virus)
ClamAV - - BAT.AutoDelete.A
DrWeb - - Trojan.Fakealert.949
eSafe - - -
eTrust-Vet - - Win32/FakeAlert.N
Ewido - - Not-A-Virus.PUP.MalwareProtector.d
F-Prot - - W32/Backdoor2.CCHB
F-Secure - - Trojan:W32/Renos.DC
Fortinet - - Misc/FakAlert
GData - - Trojan.FakeAlert.TR
Ikarus - - BAT.AutoDelete.A
K7AntiVirus - - not-a-virus:FraudTool.Win32.MalwareProtector.d
Kaspersky - - not-a-virus:FraudTool.Win32.MalwareProtector.d
McAfee - - FakeAlert-AQ
Microsoft - - Trojan:Win32/Renos.BAH
NOD32 - - Win32/Adware.WinFixer
Norman - - W32/Renos.XN
Panda - - Adware/MalwareProtector2008
PCTools - - -
Prevx1 - - Cloaked Malware
Rising - - Trojan.Win32.Undef.ive
SecureWeb-Gateway - - Trojan.Dldr.FraudLoa.NC
Sophos - - Troj/FakeAV-AQ
Sunbelt - - CWS.DesktopHijack
Symantec - - MalwareProtector2008
TheHacker - - Aplicacion/MalwareProtector.d
TrendMicro - - TROJ_RENOS.AAM
VBA32 - - Win32.Adware.WinFixer
ViRobot - - Adware.MalwareProtector.94208
VirusBuster - - Trojan.Renos.AQO
Additional information
MD5: 45684e238403d720ead129a0fb2e2258
SHA1: 1adab6088f394487d6e57c73931da3d471c30b72
SHA256: daed5971ade8ea2fa88cd4341e467aafef826b3bb620226031161d0aa9395d16
SHA512: b93e937f31758e3e579e5bc33e206f87e97fbde2794b538a16a147b8be516f2e952096208cf41ff2
b139c8765921aa7b9dee79eb66f7899505fde0b04403a418
Did a re-anlyse and got this:
File pphc1fkj0egc1.exe received on 01.23.2009 23:26:18 (CET)
Current status: scanning
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact
Print results
Email:
Antivirus Version Last Update Result
BitDefender 7.2 2009.01.23 Trojan.FakeAlert.TR
ClamAV 0.94.1 2009.01.23 BAT.AutoDelete.A
DrWeb 4.44.0.09170 2009.01.23 Trojan.Fakealert.949
eSafe 7.0.17.0 2009.01.22 -
F-Secure 8.0.14470.0 2009.01.23 Rogue:W32/XPAntivirus.gen
GData 19 2009.01.23 Trojan.FakeAlert.TR
Kaspersky 7.0.0.125 2009.01.23 not-a-virus:FraudTool.Win32.MalwareProtector.d
Microsoft 1.4205 2009.01.23 Trojan:Win32/Renos.BAH
NOD32 3795 2009.01.23 Win32/Adware.WinFixer
nProtect 2009.1.8.0 2009.01.23 Trojan-Clicker/W32.Fakealert.94208
Rising 21.13.42.00 2009.01.23 Trojan.Win32.Undef.ive
SecureWeb-Gateway 6.7.6 2009.01.23 Trojan.Dldr.FraudLoa.NC
VBA32 3.12.8.11 2009.01.23 Win32.Adware.WinFixer
Additional information
File size: 94208 bytes
MD5…: 45684e238403d720ead129a0fb2e2258
SHA1..: 1adab6088f394487d6e57c73931da3d471c30b72
SHA256: daed5971ade8ea2fa88cd4341e467aafef826b3bb620226031161d0aa9395d16
SHA512: b93e937f31758e3e579e5bc33e206f87e97fbde2794b538a16a147b8be516f2e
952096208cf41ff2b139c8765921aa7b9dee79eb66f7899505fde0b04403a418
ssdeep: 1536:mgB2tR9M994bdg3r+a56dsAB3qvbUq/qCKkqUCZKOlwXy9:589M994iD6aS
3tslqUCZKOlwX
PEiD..: -
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x406df5
timedatestamp…..: 0x485c5bc8 (Sat Jun 21 01:39:20 2008)
machinetype…….: 0x14c (I386)
( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0xda92 0xe000 6.56 04167fd1d49bf06b808aede3e9373fd9
.rdata 0xf000 0x2df4 0x3000 4.87 755a9a883fbaed9e59bd1678dc543db8
.data 0x12000 0x2ac0 0x2000 2.17 9a5b1b0544a0ba83777a36cb94f62677
.tls 0x15000 0x7 0x1000 0.00 620f0b67a91f7f74151bc5be745b7110
.rsrc 0x16000 0x1e20 0x2000 5.42 c257661d6c95eb7c3b5231af545a237d
( 5 imports )
> KERNEL32.dll: WaitForSingleObject, CreateMutexA, Sleep, TerminateProcess, GetTickCount, FindFirstFileA, FindClose, GetTempPathA, lstrcpyA, CreateFileA, WriteFile, CloseHandle, lstrcatA, GetModuleFileNameA, GetEnvironmentVariableA, GetDriveTypeA, GetVolumeInformationA, HeapAlloc, HeapFree, UnmapViewOfFile, OpenFileMappingA, MapViewOfFile, GetModuleHandleA, FindResourceA, GetLastError, LoadLibraryA, GetProcAddress, SetStdHandle, GetOEMCP, IsBadCodePtr, IsBadReadPtr, GetCurrentProcess, SizeofResource, LockResource, LoadResource, DeleteCriticalSection, InitializeCriticalSection, RaiseException, lstrlenW, WideCharToMultiByte, MultiByteToWideChar, GetVersionExA, GetACP, GetLocaleInfoA, GetThreadLocale, InterlockedExchange, InterlockedDecrement, lstrlenA, GetStringTypeW, GetStringTypeA, GetSystemInfo, VirtualProtect, GetCurrentProcessId, QueryPerformanceCounter, SetUnhandledExceptionFilter, VirtualQuery, GetFileType, SetHandleCount, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, UnhandledExceptionFilter, LocalFree, EnterCriticalSection, LeaveCriticalSection, InterlockedIncrement, GetSystemTimeAsFileTime, GetStartupInfoA, GetCommandLineA, RtlUnwind, ExitProcess, HeapReAlloc, LCMapStringA, LCMapStringW, GetCPInfo, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, IsBadWritePtr, HeapSize, TlsAlloc, SetLastError, GetCurrentThreadId, TlsFree, TlsSetValue, TlsGetValue, SetFilePointer, FlushFileBuffers, GetStdHandle
> ADVAPI32.dll: RegSetValueExA, RegQueryValueExA, RegOpenKeyExA, RegCloseKey
> SHELL32.dll: ShellExecuteA
> ole32.dll: OleRun, CoInitialize, CoCreateInstance
> OLEAUT32.dll: -, -, -, -, -, -, -, -
( 0 exports )
The above was after a “Waiting” status; it then continued scanning and gave:
File pphc1fkj0egc1.exe received on 01.23.2009 23:26:18 (CET)
Current status: finished
Result: 27/29 (93.11%)
Compact
Print results
Email:
Antivirus Version Last Update Result
a-squared 4.0.0.73 2009.01.23 BAT.AutoDelete.A!IK
AhnLab-V3 5.0.0.2 2009.01.23 Win-Trojan/Fackav.94208
Here is the SDFix report:
SDFix: Version 1.240
Run by [removed] on Sat 01/24/2009 at 08:24 AM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\Documents and Settings\[removed]\Desktop\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Restoring Default Desktop Wallpaper
Restoring Default ScreenSaver value
Rebooting
Checking Files :
Trojan Files Found:
C:\WINDOWS\system32\lphc1fkj0egc1.exe - Deleted
C:\WINDOWS\system32\pphc1fkj0egc1.exe - Deleted
C:\Program Files\rhc5fkj0egc1\database.dat - Deleted
C:\Program Files\rhc5fkj0egc1\license.txt - Deleted
C:\Program Files\rhc5fkj0egc1\MFC71.dll - Deleted
C:\Program Files\rhc5fkj0egc1\MFC71ENU.DLL - Deleted
C:\Program Files\rhc5fkj0egc1\msvcp71.dll - Deleted
C:\Program Files\rhc5fkj0egc1\msvcr71.dll - Deleted
C:\Program Files\rhc5fkj0egc1\rhc5fkj0egc1.exe - Deleted
C:\Program Files\rhc5fkj0egc1\rhc5fkj0egc1.exe.local - Deleted
C:\Program Files\rhc5fkj0egc1\rhc5fkj0egc1Skin.dll - Deleted
C:\Program Files\rhc5fkj0egc1\Uninstall.exe - Deleted
C:\WINDOWS\SYSTEM32\PPHC1F~1.EXE - Deleted
C:\WINDOWS\system32\phc1fkj0egc1.bmp - Deleted
C:\WINDOWS\system32\blphc1fkj0egc1.scr - Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk - Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk - Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk - Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk - Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt1.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt11.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt12.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt13.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt15.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt16.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt1A.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt2.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt3.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt4.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt5.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt6.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt7.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.ttF.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt4.tmp.vbs - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt5.tmp.vbs - Deleted
C:\Documents and Settings\All Users\Desktop\Antivirus XP 2008.lnk - Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk - Deleted
C:\WINDOWS\system32\msxml71.dll - Deleted
Folder C:\Program Files\rhc5fkj0egc1 - Removed
Folder C:\Documents and Settings\Bob\Application Data\rhc5fkj0egc1 - Removed
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-24 08:28:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden services & system hive …
scanning hidden registry entries …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files :
File Backups: - C:\DOCUME~1\Bob\Desktop\SDFix\backups\backups.zip
Files with Hidden Attributes :
Sun 25 Feb 2007 1,562 A..H. — "C:\Program Files\InterActual\InterActual Player\iti9.tmp"
Tue 9 Oct 2007 5,916 …H. — "C:\Documents and Settings\Chris\Local Settings\Temp\[removed]"
Tue 9 Oct 2007 1,409 …H. — "C:\Documents and Settings\Chris\Local Settings\Temp\[removed]"
Sat 24 Jan 2009 113,491,064 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\ab59ac72525ea90a47679441587835c9\BIT33.tmp"
Finished!
Here is the HiJackThis log I ran after completing the SDFix:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:32:04 AM, on 1/24/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\sm56hlpr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Bob\Desktop\HiJackThis_v2-02.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [FlashIcon] C:\Program Files\Generic\USB Card Reader Driver v2.3\FlashIcon.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [ToolBoxFX] "C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /systrayIcon:on /fl:on /fr:on /appData:on
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
–
End of file - 3718 bytes
I then ran the DDS script and here are the reports, first DS.txt:
DDS (Ver_09-01-19.01) - NTFSx86
Run by [removed] at 8:34:07.28 on Sat 01/24/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.503.184 [GMT -8:00]
AV: AVG 7.5.524 *On-access scanning enabled* (Outdated)
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\sm56hlpr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Bob\Desktop\dds.scr
============== Pseudo HJT Report ===============
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [SMSERIAL] sm56hlpr.exe
mRun: [FlashIcon] c:\program files\generic\usb card reader driver v2.3\FlashIcon.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [AVG7_CC] c:\progra~1\grisoft\avgfre~1\avgcc.exe /STARTUP
mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"
mRun: [ToolBoxFX] "c:\program files\hp\toolboxfx\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /systrayIcon:on /fl:on /fr:on /appData:on
dRun: [AVG7_Run] c:\progra~1\grisoft\avgfre~1\avgw.exe /RUNONCE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: igfxcui - igfxsrvc.dll
============= SERVICES / DRIVERS ===============
R1 Avg7Core;AVG7 Kernel;c:\windows\system32\drivers\avg7core.sys [2006-10-17 821856]
R1 Avg7RsW;AVG7 Wrap Driver;c:\windows\system32\drivers\avg7rsw.sys [2006-10-17 4224]
R1 Avg7RsXP;AVG7 Resident Driver XP;c:\windows\system32\drivers\avg7rsxp.sys [2006-10-17 27776]
R1 AvgClean;AVG7 Clean Driver;c:\windows\system32\drivers\avgclean.sys [2006-12-20 10760]
R4 Avg7Alrt;AVG7 Alert Manager Server;c:\progra~1\grisoft\avgfre~1\avgamsvr.exe [2006-10-17 418816]
R4 Avg7UpdSvc;AVG7 Update Service;c:\progra~1\grisoft\avgfre~1\avgupsvc.exe [2006-10-17 49664]
R4 AVGEMS;AVG E-mail Scanner;c:\progra~1\grisoft\avgfre~1\avgemc.exe [2006-10-17 406528]
R4 AvgTdi;AVG Network Redirector;c:\windows\system32\drivers\avgtdi.sys [2006-10-17 4960]
S3 cpuz;cpuz;\??\c:\docume~1\owner\locals~1\temp\cpuz.sys –> c:\docume~1\owner\locals~1\temp\cpuz.sys [?]
S3 filter;filter;c:\windows\system32\drivers\filter.sys [2004-7-4 8832]
=============== Created Last 30 ================
2009-01-24 08:22 –d—– c:\windows\ERUNT
==================== Find3M ====================
2008-07-07 19:25 62,910 a——- c:\program files\Uninstall.exe
2008-07-07 19:25 0 a——- c:\program files\uninstall.dat
============= FINISH: 8:34:18.53 ===============
And here is the Attach.txt:
📎Attach.txt
Finally, I did another HiJackThis and here is the log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:38:36 AM, on 1/24/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\sm56hlpr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Bob\Desktop\HiJackThis_v2-02.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [FlashIcon] C:\Program Files\Generic\USB Card Reader Driver v2.3\FlashIcon.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [ToolBoxFX] "C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /systrayIcon:on /fl:on /fr:on /appData:on
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
–
End of file - 3628 bytes
I trust all this helps you progress this clean-up.