This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Badly infected PC

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When I called on a friend to help with his infected PC, I found that his son's PC had not been used for over 12 months because of infections. It is running Win XP sp2. When I turned it on it went to the login screen and I logged into Bob's account. The first thing I saw was a box with a yellow top half and the words: "Warning! Spyware detecetd on your computer" and a blue bottom half with the words: "Install an antivirus or spyware remover to clean your computer". This stayed there as the wallpaper. Then an Red X Windows Script Host alert appeared saying that tt2.tmp.vbs failed. Then a series of BSODs with: BOGUS DRIVER stop error #: 0x00000099 and file update.sys IRQ_NOT_LESS_OR_EQUAL 0x000000?? and file ??? (missed the ?? on this one) NO_MORE_IRQ_STACK_LOCATIONS 0x000000354 splitter.sys NO_MORE_IRQ_STACK_LOCATIONS 0x000000354 sysaudio.sys UNEXPECTED_KERNEL_MOD_TRAY 0x0000007F ntkrnlpa.exe UNEXPECTED_KERNEL_MOD_TRAY 0x0000007F HIDCLASS>SYS PAGE_FAULT_IN_NONPAGE_AREA 0x00000050 splitter.sys At this point I powered down and then powered up again. This time I got the yellow/blue message (as wallpaper) the Windows Script Host error and then an application window: Antivirus XP 2008 which looks like a genuine AV scan window and reported finding 2707 threats. This PC had AVG installed and this Antivirus XP 2008 was not installed by the users (it looks similar to the av2009 we found on Bob's PC in a separate thread). I exited from the Antivirus XP 2008 window and closed the Windows Script Host alert. I then tried to run Word, IE, Windows Search and all seemd to operate noramally. I then left it displaying the desktop for about 15 minutes while I did some work on Bob's PC. I then noticed that this PC went to the first of the BSODs reported above and started that restart-BSOD cycle again. I was able to run a HiJackThis on this PC: here is the log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:07:46 AM, on 1/21/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\sm56hlpr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe C:\WINDOWS\system32\lphc1fkj0egc1.exe C:\Program Files\rhc5fkj0egc1\rhc5fkj0egc1.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\WINDOWS\system32\pphc1fkj0egc1.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Bob\Desktop\HiJackThis_v2-02.exe O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: XML module - {500BCA15-57A7-4eaf-8143-8C619470B13D} - C:\WINDOWS\system32\msxml71.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe O4 - HKLM\..\Run: [FlashIcon] C:\Program Files\Generic\USB Card Reader Driver v2.3\FlashIcon.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" O4 - HKLM\..\Run: [ToolBoxFX] "C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /systrayIcon:on /fl:on /fr:on /appData:on O4 - HKLM\..\Run: [lphc1fkj0egc1] C:\WINDOWS\system32\lphc1fkj0egc1.exe O4 - HKLM\..\Run: [SMrhc5fkj0egc1] C:\Program Files\rhc5fkj0egc1\rhc5fkj0egc1.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [activeds] C:\WINDOWS\system32\activeds.exe O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user') O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe – End of file - 4160 bytes ====================================== Your help would be appreciated.
Hi , welcome to the forum.

Please be advised, as I'm still in training, all my replies will have to be approved by a teacher or expert before I can post them. This may cause some delays, but I will do my best to keep them as short as possible.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
I will post back soon with additional instructions.


Thanks
Hi Kangaroo,

I need some information on some unidentified files. We will use Virustotal Please submit these files for analysis

To submit a file to virustotal, please click on this link

Http://www.virustotal.com

copy and paste the following into the upload a file box (one at a time if more than one file is listed)

C:\WINDOWS\system32\lphc1fkj0egc1.exe
C:\Program Files\rhc5fkj0egc1\rhc5fkj0egc1.exe
C:\WINDOWS\system32\pphc1fkj0egc1.exe


scroll down a bit and click "send file", wait for the results and post them in your next reply.

Please note that sometimes the scans take a few minutes. Please ensure that the scan has completed and the results are complete before submitting the next sample. Also please make sure each result is clearly identified as to which sample they belong to.

Please download DDS and save it to your desktop. Do not run it yet, you will use it at the end.

You may want to print out or copy and paste the rest of these instruction into a notepad and save it to your desktop for easy reference. When you run this next tool you will be in safe mode with no access to this thread.

Next Download SDFix and save it to your Desktop.

Double click SDFix.exe and choose Install to extract it to its own folder on the Desktop. Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
  • In Safe Mode, right click the SDFix.zip folder and choose Extract All,
  • Open the extracted folder and double click RunThis.bat to start the script.
  • Type Y to begin the script.
  • It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • Your system will take longer that normal to restart as the fixtool will be running and removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
  • Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt back onto the forum with a new HijackThis log

Next
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please include the contents of the following in your next reply:

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post

Please post back with both DDS logs, the Virustotal results and the SDFix report.

Thanks
Hi oldman960,

Have followed your instructions and the Antivirus XP 2008 icon in the System Tray has gone as has the "Spyware detected" wallpaper and so far no more warnings from AV XP 2008.

Here are the results:

Virustotal scan of lphc1fkj0egc1.exe (when I saw the results of the next two, I decided to do a resubmit and re-analysis as indicated in this report and got additional information):
This was for file 1: lphc1fkj0egc1.exe

File unknown received on 09.18.2008 08:50:19 (CET)
Current status: finished
Result: 32/36 (88.89%)
Compact
Print results
Antivirus Version Last Update Result
AhnLab-V3 - - Win-Trojan/Pakes.109056.K
AntiVir - - TR/Crypt.XPACK.Gen
Authentium - - W32/AV2008.B
Avast - - Win32:Trojan-gen {Other}
AVG - - I-Worm/Nuwar.S
BitDefender - - Trojan.Peed.JOA
CAT-QuickHeal - - Trojan.Pakes.jtt
ClamAV - - Trojan.Pakes-2309
DrWeb - - Trojan.Packed.512
eSafe - - Suspicious File
eTrust-Vet - - Win32/Tibs.B
Ewido - - Trojan.Pakes.jtt
F-Prot - - W32/Zhelatin.O.gen!Eldorado
F-Secure - - Trojan.Win32.Pakes.jtt
Fortinet - - PossibleThreat
GData - - Trojan.Win32.Pakes.jtt
Ikarus - - Trojan.Peed.JOA
K7AntiVirus - - Trojan.Win32.Peed.JOA
Kaspersky - - Trojan.Win32.Pakes.jtt
McAfee - - Generic.dx
Microsoft - - Trojan:Win32/Tibs.J
NOD32v2 - - Win32/TrojanDownloader.FakeAlert.EH
Norman - - W32/Tibs.CKTY
Panda - - Adware/AntivirusXP2008
PCTools - - -
Prevx1 - - Malicious Software
Rising - - -
Sophos - - Mal/Generic-A
Sunbelt - - Antivirus XP 2008 (Winifixer)
Symantec - - Packed.Generic.174
TheHacker - - -
TrendMicro - - TROJ_TIBS.BUL
VBA32 - - Trojan.Packed.512
ViRobot - - -
VirusBuster - - Trojan.Pakes.DBL
Webwasher-Gateway - - Trojan.Crypt.XPACK.Gen
Additional information
MD5: 3de20d6a87f7a73dfd2a3ac03086b99d
SHA1: 0ebfd32a79b1b0e1bafb378cdc0bbb5513a49c3d
SHA256: b0e0c873471e6845cc2e732c56653177d33d61319aa49c6c96f1b40ef0de2a6a



I did a re-submit and re-analyse and got this report:

File lphc1fkj0egc1.exe received on 01.23.2009 23:41:56 (CET)
Current status: finished
Result: 32/36 (88.89%)
Compact
Print results
Email:



Antivirus Version Last Update Result
a-squared 4.0.0.73 2009.01.23 Trojan.Peed.JOA!IK
AhnLab-V3 5.0.0.2 2009.01.23 Win-Trojan/Pakes.109056.K
AntiVir 7.9.0.60 2009.01.23 TR/Crypt.XPACK.Gen
Authentium 5.1.0.4 2009.01.23 W32/AV2008.B
Avast 4.8.1281.0 2009.01.23 Win32:Trojan-gen {Other}
AVG 8.0.0.229 2009.01.23 I-Worm/Nuwar.S
BitDefender 7.2 2009.01.23 Trojan.Packed.Gen.1
CAT-QuickHeal 10.00 2009.01.23 Trojan.Tibs.J
ClamAV 0.94.1 2009.01.23 Trojan.Pakes-2309
Comodo 943 2009.01.23 TrojWare.Win32.TrojanDownloader.FakeAlert.EE
DrWeb 4.44.0.09170 2009.01.23 Trojan.Packed.512
eSafe 7.0.17.0 2009.01.22 Suspicious File
eTrust-Vet 31.6.6323 2009.01.23 Win32/Tibs.B
F-Prot 4.4.4.56 2009.01.23 W32/Zhelatin.O.gen!Eldorado
Fortinet 3.117.0.0 2009.01.23 W32/Agent.TRC!tr
GData 19 2009.01.23 Trojan.Packed.Gen.1
Ikarus T3.1.1.45.0 2009.01.23 Trojan.Peed.JOA
K7AntiVirus 7.10.602 2009.01.23 Trojan.Win32.Peed.JOA
Kaspersky 7.0.0.125 2009.01.23 Trojan.Win32.Pakes.jtt
McAfee 5504 2009.01.23 Generic.dx
McAfee+Artemis 5504 2009.01.23 Generic.dx
Microsoft 1.4205 2009.01.23 Trojan:Win32/Tibs.J
NOD32 3795 2009.01.23 Win32/TrojanDownloader.FakeAlert.EH
nProtect 2009.1.8.0 2009.01.23 Trojan.Packed.Gen.1
Panda 9.5.1.2 2009.01.23 Adware/AntivirusXP2008
PCTools 4.4.2.0 2009.01.23 -
Rising 21.13.42.00 2009.01.23 -
SecureWeb-Gateway 6.7.6 2009.01.23 Trojan.Crypt.XPACK.Gen
Sophos 4.37.0 2009.01.23 Mal/Generic-A
Sunbelt 3.2.1835.2 2009.01.16 Antivirus XP 2008 (Winifixer)
Symantec 10 2009.01.23 Packed.Generic.174
TheHacker 6.3.1.5.226 2009.01.22 -
TrendMicro 8.700.0.1004 2009.01.23 TROJ_TIBS.BUL
VBA32 3.12.8.11 2009.01.23 Malware-Cryptor.Win32.Zherlo
ViRobot 2009.1.23.1576 2009.01.23 -
VirusBuster 4.5.11.0 2009.01.23 Trojan.Pakes.DBL
Additional information
File size: 109056 bytes
MD5…: 3de20d6a87f7a73dfd2a3ac03086b99d
SHA1..: 0ebfd32a79b1b0e1bafb378cdc0bbb5513a49c3d
SHA256: b0e0c873471e6845cc2e732c56653177d33d61319aa49c6c96f1b40ef0de2a6a
SHA512: ca1273cee12d4650f8745ebacefc2a9dbc0e6c31ac2782f5b6f8e94ade979366
504eabf262189541f789945948f96fbc9ae9e101f1b687804144ecba152eae7b
ssdeep: 1536:gt+7v01OawqC7gNKfDX+JbsM02/9uaX+7XNJvbr1dd0vRkhtC78vJtCtQxt
f:4+Va87gIfDXKwM0msn9dQkhY8kQt
PEiD..: -
TrID..: File type identification
Win32 Dynamic Link Library (generic) (55.5%)
Clipper DOS Executable (14.7%)
Generic Win/DOS Executable (14.6%)
DOS Executable Generic (14.6%)
VXD Driver (0.2%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x406d40
timedatestamp…..: 0x485d33e9 (Sat Jun 21 17:01:29 2008)
machinetype…….: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x8e49 0x6000 7.99 6e286db3aab08fe1336e4ddf3dc7f2e4
.rdata 0xa000 0x2f95 0x1400 7.96 79a94081d62c712de0560dd1548b2179
.data 0xd000 0x25c9f 0x11200 8.00 f94dde69cbf17a276959e6501006d80b
.rsrc 0x33000 0x2000 0x2000 5.37 22fbd89f431d2d8e2e5eee67d093bc7c

( 3 imports )
> shell32.dll: DAD_DragLeave, StrStrIA, DuplicateIcon
> msvcrt.dll: _mbccpy, _mbctombb, _mbsdec, _pctype, _snprintf, _snwprintf
> kernel32.dll: CompareFileTime, CopyFileW, CreateThread, DefineDosDeviceW, EnumResourceTypesW, GetCommConfig, GetConsoleWindow, GetDateFormatW

( 0 exports )
ThreatExpert info: http://www.threatexpert.com/report.aspx?md5=3de20d6a87f7a73dfd2a3ac03086b99d' target='_blank'>http://www.threatexpert.com/report.aspx?md5=3de20d6a87f7a73dfd2a3ac03086b99d


Here is the report on rhc5fkj0egc1.exe:
This one produced an exception error first but re-analyse produced a report:
Exception
Please report failure as: ErrorTime= "Jan 23 23:16:31"


2nd attempt:

File has already been analysed:
MD5: 21e04c74b41191139ff5728e7f94029f
First received: 07.06.2008 11:31:46 (CET)
Date: 07.18.2008 23:58:17 (CET) [>188D]
Results: 20/32
Permalink: analisis/06e86e0d91f0df30d8623ea702785599



File rhc5fkj0egc1.exe received on 07.18.2008 23:58:17 (CET)
Current status: finished
Result: 20/32 (62.50%)
Compact
Print results
Antivirus Version Last Update Result
AhnLab-V3 - - -
AntiVir - - TR/Drop.Age.1642496
Authentium - - -
Avast - - Win32:Trojan-gen {Other}
AVG - - Agent.XZM
BitDefender - - Trojan.Peed.JOP
CAT-QuickHeal - - FraudTool.AntivirusXP2008 (Not a Virus)
ClamAV - - -
DrWeb - - Trojan.Packed.566
eSafe - - Suspicious File
eTrust-Vet - - -
Ewido - - -
F-Prot - - -
F-Secure - - FraudTool.Win32.AntivirusXP2008.a
Fortinet - - FakeAlert.B!tr
GData - - Win32:Trojan-gen
Ikarus - - Trojan.Peed.JOA
Kaspersky - - not-a-virus:FraudTool.Win32.AntivirusXP2008.a
McAfee - - Generic FakeAlert.b
NOD32v2 - - -
Norman - - W32/Renos.YT
Panda - - -
Prevx1 - - Malicious Software
Rising - - -
Sophos - - Troj/FakeVir-DF
Sunbelt - - CWS.DesktopHijack
Symantec - - -
TheHacker - - Aplicacion/AntivirusXP2008.a
TrendMicro - - TROJ_NUWAR.AEI
VBA32 - - -
VirusBuster - - -
Webwasher-Gateway - - Trojan.Drop.Age.1642496
Additional information
MD5: 21e04c74b41191139ff5728e7f94029f
SHA1: 6a9656271eddb12c6f7483445f4a78e8805c074a
SHA256: a9f00105a50acc28354aa8430e14d0e5246430d52a2612ef5480e37931cd97c3
SHA512: b5becf40ca04ba330af75ca9


Here is report for pphc1fjk0egc1.exe:
This one also seemed brief and a re-analysis produced more information:
File has already been analysed:
MD5: 45684e238403d720ead129a0fb2e2258
First received: 06.22.2008 18:21:12 (CET)
Date: 09.26.2008 17:39:02 (CET) [>119D]
Results: 34/36
Permalink: analisis/ba60f85133b080c2faea6dc30ef532f5



This was the last report:
File pphc1fkj0egc1.exe received on 09.26.2008 17:39:02 (CET)
Current status: finished
Result: 34/36 (94.44%)
Compact
Print results
Antivirus Version Last Update Result
AhnLab-V3 - - Win-Trojan/Fackav.94208
AntiVir - - TR/Fakealert.AG
Authentium - - W32/Backdoor2.CCHB
Avast - - Win32:FraudTool-GI
AVG - - WinFixer.ATW
BitDefender - - Trojan.FakeAlert.TR
CAT-QuickHeal - - FraudTool.MalwareProtector.d (Not a Virus)
ClamAV - - BAT.AutoDelete.A
DrWeb - - Trojan.Fakealert.949
eSafe - - -
eTrust-Vet - - Win32/FakeAlert.N
Ewido - - Not-A-Virus.PUP.MalwareProtector.d
F-Prot - - W32/Backdoor2.CCHB
F-Secure - - Trojan:W32/Renos.DC
Fortinet - - Misc/FakAlert
GData - - Trojan.FakeAlert.TR
Ikarus - - BAT.AutoDelete.A
K7AntiVirus - - not-a-virus:FraudTool.Win32.MalwareProtector.d
Kaspersky - - not-a-virus:FraudTool.Win32.MalwareProtector.d
McAfee - - FakeAlert-AQ
Microsoft - - Trojan:Win32/Renos.BAH
NOD32 - - Win32/Adware.WinFixer
Norman - - W32/Renos.XN
Panda - - Adware/MalwareProtector2008
PCTools - - -
Prevx1 - - Cloaked Malware
Rising - - Trojan.Win32.Undef.ive
SecureWeb-Gateway - - Trojan.Dldr.FraudLoa.NC
Sophos - - Troj/FakeAV-AQ
Sunbelt - - CWS.DesktopHijack
Symantec - - MalwareProtector2008
TheHacker - - Aplicacion/MalwareProtector.d
TrendMicro - - TROJ_RENOS.AAM
VBA32 - - Win32.Adware.WinFixer
ViRobot - - Adware.MalwareProtector.94208
VirusBuster - - Trojan.Renos.AQO
Additional information
MD5: 45684e238403d720ead129a0fb2e2258
SHA1: 1adab6088f394487d6e57c73931da3d471c30b72
SHA256: daed5971ade8ea2fa88cd4341e467aafef826b3bb620226031161d0aa9395d16
SHA512: b93e937f31758e3e579e5bc33e206f87e97fbde2794b538a16a147b8be516f2e952096208cf41ff2
b139c8765921aa7b9dee79eb66f7899505fde0b04403a418


Did a re-anlyse and got this:

File pphc1fkj0egc1.exe received on 01.23.2009 23:26:18 (CET)
Current status: scanning

Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact
Print results
Email:



Antivirus Version Last Update Result
BitDefender 7.2 2009.01.23 Trojan.FakeAlert.TR
ClamAV 0.94.1 2009.01.23 BAT.AutoDelete.A
DrWeb 4.44.0.09170 2009.01.23 Trojan.Fakealert.949
eSafe 7.0.17.0 2009.01.22 -
F-Secure 8.0.14470.0 2009.01.23 Rogue:W32/XPAntivirus.gen
GData 19 2009.01.23 Trojan.FakeAlert.TR
Kaspersky 7.0.0.125 2009.01.23 not-a-virus:FraudTool.Win32.MalwareProtector.d
Microsoft 1.4205 2009.01.23 Trojan:Win32/Renos.BAH
NOD32 3795 2009.01.23 Win32/Adware.WinFixer
nProtect 2009.1.8.0 2009.01.23 Trojan-Clicker/W32.Fakealert.94208
Rising 21.13.42.00 2009.01.23 Trojan.Win32.Undef.ive
SecureWeb-Gateway 6.7.6 2009.01.23 Trojan.Dldr.FraudLoa.NC
VBA32 3.12.8.11 2009.01.23 Win32.Adware.WinFixer
Additional information
File size: 94208 bytes
MD5…: 45684e238403d720ead129a0fb2e2258
SHA1..: 1adab6088f394487d6e57c73931da3d471c30b72
SHA256: daed5971ade8ea2fa88cd4341e467aafef826b3bb620226031161d0aa9395d16
SHA512: b93e937f31758e3e579e5bc33e206f87e97fbde2794b538a16a147b8be516f2e
952096208cf41ff2b139c8765921aa7b9dee79eb66f7899505fde0b04403a418
ssdeep: 1536:mgB2tR9M994bdg3r+a56dsAB3qvbUq/qCKkqUCZKOlwXy9:589M994iD6aS
3tslqUCZKOlwX
PEiD..: -
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x406df5
timedatestamp…..: 0x485c5bc8 (Sat Jun 21 01:39:20 2008)
machinetype…….: 0x14c (I386)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0xda92 0xe000 6.56 04167fd1d49bf06b808aede3e9373fd9
.rdata 0xf000 0x2df4 0x3000 4.87 755a9a883fbaed9e59bd1678dc543db8
.data 0x12000 0x2ac0 0x2000 2.17 9a5b1b0544a0ba83777a36cb94f62677
.tls 0x15000 0x7 0x1000 0.00 620f0b67a91f7f74151bc5be745b7110
.rsrc 0x16000 0x1e20 0x2000 5.42 c257661d6c95eb7c3b5231af545a237d

( 5 imports )
> KERNEL32.dll: WaitForSingleObject, CreateMutexA, Sleep, TerminateProcess, GetTickCount, FindFirstFileA, FindClose, GetTempPathA, lstrcpyA, CreateFileA, WriteFile, CloseHandle, lstrcatA, GetModuleFileNameA, GetEnvironmentVariableA, GetDriveTypeA, GetVolumeInformationA, HeapAlloc, HeapFree, UnmapViewOfFile, OpenFileMappingA, MapViewOfFile, GetModuleHandleA, FindResourceA, GetLastError, LoadLibraryA, GetProcAddress, SetStdHandle, GetOEMCP, IsBadCodePtr, IsBadReadPtr, GetCurrentProcess, SizeofResource, LockResource, LoadResource, DeleteCriticalSection, InitializeCriticalSection, RaiseException, lstrlenW, WideCharToMultiByte, MultiByteToWideChar, GetVersionExA, GetACP, GetLocaleInfoA, GetThreadLocale, InterlockedExchange, InterlockedDecrement, lstrlenA, GetStringTypeW, GetStringTypeA, GetSystemInfo, VirtualProtect, GetCurrentProcessId, QueryPerformanceCounter, SetUnhandledExceptionFilter, VirtualQuery, GetFileType, SetHandleCount, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, UnhandledExceptionFilter, LocalFree, EnterCriticalSection, LeaveCriticalSection, InterlockedIncrement, GetSystemTimeAsFileTime, GetStartupInfoA, GetCommandLineA, RtlUnwind, ExitProcess, HeapReAlloc, LCMapStringA, LCMapStringW, GetCPInfo, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, IsBadWritePtr, HeapSize, TlsAlloc, SetLastError, GetCurrentThreadId, TlsFree, TlsSetValue, TlsGetValue, SetFilePointer, FlushFileBuffers, GetStdHandle
> ADVAPI32.dll: RegSetValueExA, RegQueryValueExA, RegOpenKeyExA, RegCloseKey
> SHELL32.dll: ShellExecuteA
> ole32.dll: OleRun, CoInitialize, CoCreateInstance
> OLEAUT32.dll: -, -, -, -, -, -, -, -

( 0 exports )

The above was after a “Waiting” status; it then continued scanning and gave:


File pphc1fkj0egc1.exe received on 01.23.2009 23:26:18 (CET)
Current status: finished
Result: 27/29 (93.11%)
Compact
Print results
Email:



Antivirus Version Last Update Result
a-squared 4.0.0.73 2009.01.23 BAT.AutoDelete.A!IK
AhnLab-V3 5.0.0.2 2009.01.23 Win-Trojan/Fackav.94208



Here is the SDFix report:

SDFix: Version 1.240
Run by [removed] on Sat 01/24/2009 at 08:24 AM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\Documents and Settings\[removed]\Desktop\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File
Restoring Default Desktop Wallpaper
Restoring Default ScreenSaver value

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\system32\lphc1fkj0egc1.exe - Deleted
C:\WINDOWS\system32\pphc1fkj0egc1.exe - Deleted
C:\Program Files\rhc5fkj0egc1\database.dat - Deleted
C:\Program Files\rhc5fkj0egc1\license.txt - Deleted
C:\Program Files\rhc5fkj0egc1\MFC71.dll - Deleted
C:\Program Files\rhc5fkj0egc1\MFC71ENU.DLL - Deleted
C:\Program Files\rhc5fkj0egc1\msvcp71.dll - Deleted
C:\Program Files\rhc5fkj0egc1\msvcr71.dll - Deleted
C:\Program Files\rhc5fkj0egc1\rhc5fkj0egc1.exe - Deleted
C:\Program Files\rhc5fkj0egc1\rhc5fkj0egc1.exe.local - Deleted
C:\Program Files\rhc5fkj0egc1\rhc5fkj0egc1Skin.dll - Deleted
C:\Program Files\rhc5fkj0egc1\Uninstall.exe - Deleted
C:\WINDOWS\SYSTEM32\PPHC1F~1.EXE - Deleted
C:\WINDOWS\system32\phc1fkj0egc1.bmp - Deleted
C:\WINDOWS\system32\blphc1fkj0egc1.scr - Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk - Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk - Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk - Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk - Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt1.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt11.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt12.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt13.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt15.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt16.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt1A.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt2.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt3.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt4.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt5.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt6.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt7.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.ttF.tmp - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt4.tmp.vbs - Deleted
C:\DOCUME~1\Bob\LOCALS~1\Temp\.tt5.tmp.vbs - Deleted
C:\Documents and Settings\All Users\Desktop\Antivirus XP 2008.lnk - Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk - Deleted
C:\WINDOWS\system32\msxml71.dll - Deleted



Folder C:\Program Files\rhc5fkj0egc1 - Removed
Folder C:\Documents and Settings\Bob\Application Data\rhc5fkj0egc1 - Removed


Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-24 08:28:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe:*:Enabled:avgamsvr.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

Remaining Files :


File Backups: - C:\DOCUME~1\Bob\Desktop\SDFix\backups\backups.zip

Files with Hidden Attributes :

Sun 25 Feb 2007 1,562 A..H. — "C:\Program Files\InterActual\InterActual Player\iti9.tmp"
Tue 9 Oct 2007 5,916 …H. — "C:\Documents and Settings\Chris\Local Settings\Temp\[removed]"
Tue 9 Oct 2007 1,409 …H. — "C:\Documents and Settings\Chris\Local Settings\Temp\[removed]"
Sat 24 Jan 2009 113,491,064 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\ab59ac72525ea90a47679441587835c9\BIT33.tmp"

Finished!



Here is the HiJackThis log I ran after completing the SDFix:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:32:04 AM, on 1/24/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\sm56hlpr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Bob\Desktop\HiJackThis_v2-02.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [FlashIcon] C:\Program Files\Generic\USB Card Reader Driver v2.3\FlashIcon.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [ToolBoxFX] "C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /systrayIcon:on /fl:on /fr:on /appData:on
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 3718 bytes



I then ran the DDS script and here are the reports, first DS.txt:

DDS (Ver_09-01-19.01) - NTFSx86
Run by [removed] at 8:34:07.28 on Sat 01/24/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.503.184 [GMT -8:00]

AV: AVG 7.5.524 *On-access scanning enabled* (Outdated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\sm56hlpr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Bob\Desktop\dds.scr

============== Pseudo HJT Report ===============

BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [SMSERIAL] sm56hlpr.exe
mRun: [FlashIcon] c:\program files\generic\usb card reader driver v2.3\FlashIcon.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [AVG7_CC] c:\progra~1\grisoft\avgfre~1\avgcc.exe /STARTUP
mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"
mRun: [ToolBoxFX] "c:\program files\hp\toolboxfx\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /systrayIcon:on /fl:on /fr:on /appData:on
dRun: [AVG7_Run] c:\progra~1\grisoft\avgfre~1\avgw.exe /RUNONCE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: igfxcui - igfxsrvc.dll

============= SERVICES / DRIVERS ===============

R1 Avg7Core;AVG7 Kernel;c:\windows\system32\drivers\avg7core.sys [2006-10-17 821856]
R1 Avg7RsW;AVG7 Wrap Driver;c:\windows\system32\drivers\avg7rsw.sys [2006-10-17 4224]
R1 Avg7RsXP;AVG7 Resident Driver XP;c:\windows\system32\drivers\avg7rsxp.sys [2006-10-17 27776]
R1 AvgClean;AVG7 Clean Driver;c:\windows\system32\drivers\avgclean.sys [2006-12-20 10760]
R4 Avg7Alrt;AVG7 Alert Manager Server;c:\progra~1\grisoft\avgfre~1\avgamsvr.exe [2006-10-17 418816]
R4 Avg7UpdSvc;AVG7 Update Service;c:\progra~1\grisoft\avgfre~1\avgupsvc.exe [2006-10-17 49664]
R4 AVGEMS;AVG E-mail Scanner;c:\progra~1\grisoft\avgfre~1\avgemc.exe [2006-10-17 406528]
R4 AvgTdi;AVG Network Redirector;c:\windows\system32\drivers\avgtdi.sys [2006-10-17 4960]
S3 cpuz;cpuz;\??\c:\docume~1\owner\locals~1\temp\cpuz.sys –> c:\docume~1\owner\locals~1\temp\cpuz.sys [?]
S3 filter;filter;c:\windows\system32\drivers\filter.sys [2004-7-4 8832]

=============== Created Last 30 ================

2009-01-24 08:22 –d—– c:\windows\ERUNT

==================== Find3M ====================

2008-07-07 19:25 62,910 a——- c:\program files\Uninstall.exe
2008-07-07 19:25 0 a——- c:\program files\uninstall.dat

============= FINISH: 8:34:18.53 ===============


And here is the Attach.txt:
📎Attach.txt



Finally, I did another HiJackThis and here is the log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:38:36 AM, on 1/24/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\sm56hlpr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Bob\Desktop\HiJackThis_v2-02.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [FlashIcon] C:\Program Files\Generic\USB Card Reader Driver v2.3\FlashIcon.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [ToolBoxFX] "C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /systrayIcon:on /fl:on /fr:on /appData:on
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 3628 bytes


I trust all this helps you progress this clean-up.
Hi Kangaroo,

Go to add/remove programs and uninstall, if present

NoAdware v3.0

Please download and save to your desktop, Malwarebytes Anti-Malware

please double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Launch Malwarebytes' Anti-Malware, uncheck Update Malwarebytes' Anti-Malware, if checked, then click Finish.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with the MBAM log and a new HJT log. Tell us how the computer is now.

Thanks
Hi oldman 960, Uninstalled Noadware v3. Ran MBAM, here is the log: Malwarebytes' Anti-Malware 1.32 Database version: 1616 Windows 5.1.2600 Service Pack 2 1/25/2009 11:46:14 AM mbam-log-2009-01-25 (11-46-14).txt Scan type: Quick Scan Objects scanned: 65664 Time elapsed: 6 minute(s), 39 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 3 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 17 Files Infected: 20 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\Typelib\{9233c3c0-1472-4091-a505-5580a23bb4ac} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7c4bcd17-bdba-4078-9d8c-8ca8b7eabe77} (Rogue.Multiple) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Documents and Settings\All Users\Application Data\ADSL Software Ltd (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\ADSL Software Ltd\WinSpywareProtect (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\ADSL Software Ltd\WinSpywareProtect\BASE (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\ADSL Software Ltd\WinSpywareProtect\DELETED (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\ADSL Software Ltd\WinSpywareProtect\LOG (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\ADSL Software Ltd\WinSpywareProtect\SAVED (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Application Data\rhc5fkj0egc1 (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Application Data\rhc5fkj0egc1\Quarantine (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Application Data\rhc5fkj0egc1\Quarantine\Autorun (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Application Data\rhc5fkj0egc1\Quarantine\Autorun\HKCU (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Application Data\rhc5fkj0egc1\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Application Data\rhc5fkj0egc1\Quarantine\Autorun\HKLM (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Application Data\rhc5fkj0egc1\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Application Data\rhc5fkj0egc1\Quarantine\Autorun\StartMenuAllUsers (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Application Data\rhc5fkj0egc1\Quarantine\Autorun\StartMenuCurrentUser (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Application Data\rhc5fkj0egc1\Quarantine\BrowserObjects (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Application Data\rhc5fkj0egc1\Quarantine\Packages (Rogue.Multiple) -> Quarantined and deleted successfully. Files Infected: C:\Documents and Settings\Chris\Local Settings\Temp\11.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Local Settings\Temp\F.tmp (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\0FEXUVAN\Install_242_509_[1].exe (Rogue.Installer) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\MF0BUZ65\setup_242_509_[1].exe (Rogue.Installer) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\ADSL Software Ltd\WinSpywareProtect\Winspywareprotect.exe (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\ADSL Software Ltd\WinSpywareProtect\LOG\20080707202402359.log (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\ADSL Software Ltd\WinSpywareProtect\LOG\20080707223304828.log (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\ADSL Software Ltd\WinSpywareProtect\LOG\20080722122030359.log (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk (Rogue.Antivirus2008) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Local Settings\Temp\.tt15.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Local Settings\Temp\.tt1.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Local Settings\Temp\.tt2.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Local Settings\Temp\.tt3.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Local Settings\Temp\.tt4.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Local Settings\Temp\.tt5.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Local Settings\Temp\.tt6.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Local Settings\Temp\.tt8.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Local Settings\Temp\.ttC.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Local Settings\Temp\.ttE.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Chris\Local Settings\Temp\.ttF.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. ========================================== Ran HiJackThis and here is the log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:51:08 AM, on 1/25/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\sm56hlpr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\NOTEPAD.EXE \?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE C:\Documents and Settings\Bob\Desktop\Repairs Chris\HiJackThis_v2-02.exe O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe O4 - HKLM\..\Run: [FlashIcon] C:\Program Files\Generic\USB Card Reader Driver v2.3\FlashIcon.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" O4 - HKLM\..\Run: [ToolBoxFX] "C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /systrayIcon:on /fl:on /fr:on /appData:on O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user') O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe – End of file - 3842 bytes ========================================== MBAM removed about 40 items. Where to next?
Hi Kangaroo,

How's the computer running?

Please download ATF Cleaner by Atribune.

Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.

Note your computer may boot a little slower the first couple of times.

Go here to run an online scannner from ESET:
http://www.eset.eu/online-scanner

(Note: You must use Internet Explorer for this scan.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • Re-enable your Antivirus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. We will need this later.
Please post back with the ESET log and a new HJT log. Please let us know how the computer is. You are our eyes.

Thanks
Hi Oldman960,
Pardon the delay but I was an organiser of our community lunch for Australia Day and have only just got all that out of the way.

The ATF and ESET scans went fine. infections were still found; here is the ESET log:

# version=4
# OnlineScanner.ocx=[removed]
# OnlineScannerDLLA.dll=1, 0, 0, 51
# OnlineScannerDLLW.dll=1, 0, 0, 51
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3799 (20090125)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=8fa273aa88adf24591d8a01d0708e268
# end=finished
# remove_checked=false
# unwanted_checked=true
# utc_time=2009-01-26 07:45:20
# local_time=2009-01-26 11:45:20 (-0800, Pacific Standard Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 2
# scanned=131630
# found=8
# scan_time=889
C:\Documents and Settings\Bob\Desktop\Repairs Chris\SDFix\backups\backups.zip multiple infiltrations 75FEA2BCB47238BC1EB475DB7A3F442A
C:\Documents and Settings\Bob\Desktop\Repairs Chris\SDFix\backups\backups.zip »ZIP »backups/.tt4.tmp.vbs Win32/Adware.XPAntivirus application 00000000000000000000000000000000
C:\Documents and Settings\Bob\Desktop\Repairs Chris\SDFix\backups\backups.zip »ZIP »backups/.tt5.tmp.vbs Win32/Adware.XPAntivirus application 00000000000000000000000000000000
C:\Documents and Settings\Bob\Desktop\Repairs Chris\SDFix\backups\backups.zip »ZIP »backups/lphc1fkj0egc1.exe Win32/TrojanDownloader.FakeAlert.EH trojan 00000000000000000000000000000000
C:\Documents and Settings\Bob\Desktop\Repairs Chris\SDFix\backups\backups.zip »ZIP »backups/msxml71.dll Win32/Adware.BHO.NCX application 00000000000000000000000000000000
C:\Documents and Settings\Bob\Desktop\Repairs Chris\SDFix\backups\backups.zip »ZIP »backups/phc1fkj0egc1.bmp Win32/TrojanDownloader.FakeAlert.DJ trojan 00000000000000000000000000000000
C:\Documents and Settings\Bob\Desktop\Repairs Chris\SDFix\backups\backups.zip »ZIP »backups/pphc1fkj0egc1.exe Win32/Adware.WinFixer application 00000000000000000000000000000000
C:\Documents and Settings\Chris\My Documents\My Downloads\Utilities\setup_242_509_.exe Win32/Adware.WinSpywareProtect application C7C5F70F4526D84EAECDE7E2548A1155

======================================

Here is the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:53:47 AM, on 1/26/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\sm56hlpr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Bob\Desktop\Repairs Chris\HiJackThis_v2-02.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [FlashIcon] C:\Program Files\Generic\USB Card Reader Driver v2.3\FlashIcon.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [ToolBoxFX] "C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /systrayIcon:on /fl:on /fr:on /appData:on
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/OnlineScanner.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 3876 bytes

===========================================

The PC seems to be running fine at the moment. We were able to browse; running Disk Defragmenter went normally. Also ran Word and Solitaire without any problems evident.
Hi Kangaroo,

Looking better. 7 of the infections are all ready quarantined. We'll remove the other one and have a look at a folder.

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Do not copy the word CODE

    :Files
    C:\Documents and Settings\Chris\My Documents\My Downloads\Utilities\setup_242_509_.exe 
    
    :Commands
    [EmptyTemp]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. After the reboot, OTMoveIt3 will start automatically to finish the move process. Highlight everything in the Results pane (underneath the green bar) by right-clicking in it and choosing Select All and then right-clicking again and choosing Copy. Return to this topic and click the Reply button, right-click in the Reply window and choose paste to copy all of the results back here.

Please download DirLook by jpshortstuff from here.
  • Double-click DirLook.exe to run it.
  • Ensure that Show Hidden Files/Folders and BBCode Ouput are both checked.
  • Copy the content of the following codebox into the textfield labeled "Directory:":

    C:\Documents and Settings\Chris\My Documents\My Downloads\Utilities
  • Click the DirLook button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply. (Note: The log can also be found at C:\dl_log.txt)
Note: Scanning may take longer for large folders.

Please post back with the OTMOVEIT3 results, the DirLook log and a new HJT log.

Thanks
Oops!, sorry oldman960; I got distracted working with the other PC in this household.

When we ran OTMoveIt it did not restart after the reboot; I hope we did the right thing and ran it a second time. Here is teh first OTMI log:

========== FILES ==========
C:\Documents and Settings\Chris\My Documents\My Downloads\Utilities\setup_242_509_.exe moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Bob\LOCALS~1\Temp\~DF5702.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Bob\LOCALS~1\Temp\~DFE15E.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Bob\LOCALS~1\Temp\~DFF1CD.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Temp folders emptied.

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01272009_141446

Files moved on Reboot…
File C:\DOCUME~1\Bob\LOCALS~1\Temp\~DF5702.tmp not found!
File C:\DOCUME~1\Bob\LOCALS~1\Temp\~DFE15E.tmp not found!
File C:\DOCUME~1\Bob\LOCALS~1\Temp\~DFF1CD.tmp not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.

===========================================

Here is the second OTMI log:

========== FILES ==========
File/Folder C:\Documents and Settings\Chris\My Documents\My Downloads\Utilities\setup_242_509_.exe not found.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Bob\LOCALS~1\Temp\~DFA439.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Bob\LOCALS~1\Temp\~DFC845.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Temp folders emptied.

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01272009_143734

Files moved on Reboot…
File C:\DOCUME~1\Bob\LOCALS~1\Temp\~DFA439.tmp not found!
File C:\DOCUME~1\Bob\LOCALS~1\Temp\~DFC845.tmp not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.

==============================================

Here is the DirLook log:

DirLook.exe v2.0 by jpshortstuff
Log created at 14:44 on 27/01/2009
==================================
Contents of "C:\Documents and Settings\Chris\My Documents\My Downloads\Utilities"

—FOLDERS—

avg update 1 (Created on 17/10/2006 at 22:57) d—–
avg update 2 (Created on 17/10/2006 at 22:56) d—–
avg update 3 (Created on 17/10/2006 at 22:56) d—–

—FILES—

AdbeRdr708_en_US.exe (21290704 bytes - created on 17/10/2006 at 22:24, modified on 12/06/2006 at 01:02) –a—
avg71free_405a782.exe (17676960 bytes - created on 17/10/2006 at 22:24, modified on 09/08/2006 at 00:15) –a—
avg75free_430a828.exe (17383608 bytes - created on 21/12/2006 at 00:25, modified on 03/11/2006 at 00:22) –a—
iview385.exe (837120 bytes - created on 17/10/2006 at 22:27, modified on 24/09/2003 at 06:12) –a—
iview_all_plugins.exe (3497984 bytes - created on 17/10/2006 at 22:29, modified on 01/09/2003 at 04:04) –a—
noadwarefullv3.exe (875413 bytes - created on 26/10/2006 at 15:55, modified on 25/08/2005 at 06:45) –a—
WindowsDefender.msi (5763072 bytes - created on 17/10/2006 at 22:36, modified on 10/08/2006 at 02:54) –a—
winzip100.exe (5834344 bytes - created on 17/10/2006 at 22:24, modified on 05/12/2005 at 03:17) –a—

==================================
=EOF=

================================================

And here is the new HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:47:44 PM, on 1/27/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\sm56hlpr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\Bob\Desktop\Repairs Chris\HiJackThis_v2-02.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [FlashIcon] C:\Program Files\Generic\USB Card Reader Driver v2.3\FlashIcon.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [ToolBoxFX] "C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /systrayIcon:on /fl:on /fr:on /appData:on
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/OnlineScanner.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 3931 bytes

========================================

This PC seems to be normal now. Where to now?
Hi Kangaroo,

A couple of things left to do then we'll clean up.

Use OTMOVEIT3 again with this fix.
:Files
C:\Documents and Settings\Chris\My Documents\My Downloads\Utilities\noadwarefullv3.exe
C:\noadwar* /s

Please post the OTMOVEIT3 results and 1 more HJT log.

Thanks
Hi oldman960.

Here are the OTMoveIt results:

========== FILES ==========
C:\Documents and Settings\Chris\My Documents\My Downloads\Utilities\noadwarefullv3.exe moved successfully.
C:\_OTMoveIt\MovedFiles\01292009_135715\Documents and Settings\Chris\My Documents\My Downloads\Utilities\noadwarefullv3.exe moved successfully.

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01292009_135715

==========================================

And here is the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:01:36 PM, on 1/29/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\sm56hlpr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Bob\Desktop\Repairs Chris\HiJackThis_v2-02.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [FlashIcon] C:\Program Files\Generic\USB Card Reader Driver v2.3\FlashIcon.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [ToolBoxFX] "C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /systrayIcon:on /fl:on /fr:on /appData:on
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/OnlineScanner.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 3875 bytes

===================================

To check the computer's behaviour after this we did the following:
1. a reboot and checked how long it took to shutdown and restart back to the desktop; about 30 secs.

2. started a scan with AVG (Just started a quick scan and when it seemed to be going OK stopped it.)

3. Disk Defragmenter | Analyse button worked (didn't try to defrag).

4. updated AVG.

5. Used IE to browse to http://forums.whatthetech.com.

6. Used IE to browse to the ESET online scan address <http://www.eset.eu/online-scanner>. (Didn't start a scan.)

All seems to be good.

Are we ready to clean-up now?
Hi Kangaroo,

Time to clean up the tools. :thumbup:

From your desktop please delete
  • DDS.txt
  • Attach.txt
  • DirLook.exe
Also any notepads/logs that may have been saved there.

In Windows Explorer, please delete C:\dl_log.txt

Eset online scan can be uninstalled via add/remove if you wish.

I suggest you keep ATF and MBAM. Keep MBAM updated and use it as an on demand scanner.

Open OTMOVEIT3 then click the Clean Up button. You may get prompted by your firewall that OTMoveIt wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

*We'll reset your restore points

Create a new restore point

You must be logged on to an administrator account
  • Go to Start - All Programs - Accessories - System Tools - System Restore.
  • Click Create a restore point, and then click Next.
  • In the text box labeled Restore Point Description, type a name for this restore point
  • click create
* Remove old restore points

  • Go to Start - All Programs - Accessories - system tools.
  • Launch the Disk Cleanup tool and let it run.
  • When it finishes a box with tabs will appear, select the more options tab.
  • On this tab you will find a section for System Restore.
  • If you press the Clean Up button for that section, Windows will delete all restore points except for the most recent one.

Updates and upgrade

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 7 first. Be sure to move any PDF documents to another folder first though.

* If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the cirtical updates installed (Free) Microsoft Office Update

Some Recommendations and prevention tips

I suggest you use an antispyware program with real time scanning. These are 2 free ones
Winpatrol OR
Windows Defender

You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.

* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for tips, reviews and links to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware)

-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.

- Keep your antivirus program updated, as well as any other security programs you have.

- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post when you have finished.

Take care :adios:
Hi oldman960, Thanks for all your help on this. We'll apply your clean-up steps and your prevention steps will hopefully keep us safe in future.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI