This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] svschost.exe & Agent AN Trojan

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

On our home PC we have a Trojan called Agent AN Trojan. We are running Xsoftspy.exe which attempts to remove the virus but it always come straight back.. we also have avg free and the same happens.

In the processes tree we also have svschost.exe. BN16.tmp svnshost.exe,

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:52:58, on 06/02/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\hasplms.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\S3trayp.exe
C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\msauc.exe
C:\WINDOWS\services.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\svschost.exe
C:\WINDOWS\system32\svñshost.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\Documents and Settings\Lee\My Documents\My Received Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.tesco.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Tesco.net
R3 - URLSearchHook: (no name) - {DAB46A0D-8939-4056-B80C-028DCE8999EF} - (no file)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [lsass driver] C:\WINDOWS\msauc.exe
O4 - HKLM\..\Run: [Pcejegigus] rundll32.exe "C:\WINDOWS\Rhudamavabowi.dll",e
O4 - HKLM\..\Run: [Uqejugof] rundll32.exe "C:\WINDOWS\igovetidac.dll",e
O4 - HKLM\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKCU\..\Run: [svschost.exe] C:\WINDOWS\system32\svschost.exe -check
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/229?9d0c88cfcc854595972d8f0d413f348a
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/230?9d0c88cfcc854595972d8f0d413f348a
O14 - IERESET.INF: START_PAGE_URL=http://www.tesco.net
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://connect2.pb.com/,DanaInfo=lndancl04…va+iNotes6W.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ClipBook ClipSrvDcomLaunch (ClipSrvDcomLaunch) - Unknown owner - C:\WINDOWS\system32\wpv501233859884.cpx.exe (file missing)
O23 - Service: FCI - Unknown owner - C:\WINDOWS\system32\fci.exe.exe:ext.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HASP License Manager (hasplms) - Aladdin Knowledge Systems Ltd. - C:\WINDOWS\system32\hasplms.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/SHEZ~1.SHE/LOCALS~1/Temp/msohtmlclip1/01/clip_image002.gif
O24 - Desktop Component 1: (no name) - http://www.oksd.wednet.edu/bulldogs.jpg

–
End of file - 6762 bytes


Can you help
hello

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.
shouldn't take that long

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.
Hi

completed this.

here is the log.

I had alot of problems getting the combo program to work.

I'm also getting a runn dll issues with

c:\windows\rhudamavabowi.dll


cheers


ComboFix 09-02-05.04 - Shez 2009-02-06 15:15:39.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.446.92 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
FW: ZoneAlarm Firewall *enabled*
* Created a new restore point
.
ADS - svchost.exe: deleted 25600 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\program files\Microsoft Common
c:\program files\Microsoft Common\svchost.exe
c:\windows\jestertb.dll
c:\windows\msauc.exe
c:\windows\services.exe
c:\windows\system32\a9k.bin
c:\windows\system32\drivers\ati6koxx.sys
c:\windows\system32\drivers\mrxdavv.sys
c:\windows\system32\fci.exe.exe
c:\windows\system32\icf.exe.exe
c:\windows\system32\iokey.dll
c:\windows\system32\kwave.sys
c:\windows\system32\shell31.dll
c:\windows\system32\svschost.exe
c:\windows\system32\wpv241230262534.cpx
c:\windows\system32\wpv341230262430.cpx
c:\windows\system32\wpv501233859884.cpx
c:\windows\system32\wpv751233860660.cpx
c:\windows\system32\zvkbuw.dll
c:\windows\system32\zvkbuw32.dll
c:\windows\wiaserviv.log

—– BITS: Possible infected sites —–

hxxp://supertvist.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_ATI6KOXX
——-\Legacy_CLIPSRVDCOMLAUNCH
——-\Legacy_FCI
——-\Legacy_ICF
——-\Legacy_TCPSR
——-\Service_ati6koxx
——-\Service_ClipSrvDcomLaunch
——-\Service_FCI
——-\Service_ICF
——-\Service_tcpsr


((((((((((((((((((((((((( Files Created from 2009-01-06 to 2009-02-06 )))))))))))))))))))))))))))))))
.

2009-02-06 13:26 . 2009-02-06 13:27 d——– c:\windows\ERUNT
2009-02-06 13:19 . 2009-02-06 13:51 d——– C:\SDFix
2009-02-05 23:59 . 2009-02-06 00:11 d——– c:\program files\RegCure
2009-02-05 23:40 . 2009-02-06 00:12 d——– c:\program files\XoftSpySE
2009-02-05 22:49 . 2009-02-06 14:12 7 –a—— c:\windows\system32\nar.bin
2009-02-05 22:20 . 2009-02-05 22:20 132,096 –a—— c:\windows\igovetidac.dll
2009-02-05 22:16 . 2009-02-05 22:47 d–h—– c:\windows\$hf_mig$
2009-02-05 21:51 . 2009-02-05 21:51 0 –a—— c:\windows\system32\.tmp
2009-02-05 21:28 . 2009-02-05 21:28 132,096 –a—— c:\windows\ipicoyucegaqabih.dll
2009-02-05 21:08 . 2009-02-05 21:08 32 –a-s—- c:\windows\system32\1420803498.dat
2009-02-05 21:07 . 2009-02-06 11:41 92,160 –a—— c:\windows\system32\svñshost.exe
2009-02-05 21:07 . 2009-02-05 21:07 0 –a—— c:\windows\system32\system32xp.exe.tmp
2009-02-05 18:05 . 2004-08-03 22:56 24,576 –a—— c:\windows\system32\stus.exe
2009-02-05 18:04 . 2009-02-05 18:04 8,752 –a—— c:\windows\system32\iokey.sys
2009-02-03 16:18 . 2008-09-19 10:00 3,528,862 –a—— c:\windows\BBeasts_Uninstall.exe
2009-02-03 16:15 . 2009-02-03 17:25 d——– c:\program files\BBeasts
2009-01-31 14:00 . 2009-01-31 14:00 54,156 –ah—– c:\windows\QTFont.qfn
2009-01-31 14:00 . 2009-01-31 14:00 1,409 –a—— c:\windows\QTFont.for
2009-01-13 19:32 . 2009-01-13 19:44 d——– c:\program files\Maxis
2009-01-12 18:05 . 2009-01-12 18:06 d——– c:\program files\Virtual Earth 3D
2009-01-12 15:52 . 2009-01-12 15:54 d——– c:\program files\Walk In Wonderland Papercraft Projects
2009-01-09 14:02 . 2009-01-09 14:02 d——– c:\program files\Infinite Sudoku

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-06 15:27 27,744,288 –sha-w c:\windows\system32\drivers\fidbox.dat
2009-02-06 15:21 325,940 –sha-w c:\windows\system32\drivers\fidbox.idx
2009-02-06 15:20 ——— d—–w c:\documents and settings\All Users\Application Data\Kontiki
2009-02-06 14:28 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-02-06 13:18 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-06 11:56 ——— d—–w c:\program files\Spybot - Search & Destroy
2009-02-06 10:51 1,900,544 —-a-w c:\windows\Internet Logs\xDB8.tmp
2009-02-05 23:26 8,707,094 -c–a-w c:\windows\Internet Logs\tvDebug.zip
2009-02-05 21:10 2,272,768 —-a-w c:\windows\Internet Logs\xDB7.tmp
2009-02-05 21:02 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-02-05 21:02 107,272 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-01-13 20:08 163,644 —-a-w c:\windows\system32\drivers\secdrv.sys
2009-01-13 19:35 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-12 16:02 ——— d—–w c:\program files\My Craft Studio
2008-12-10 12:12 758,784 —-a-w c:\windows\Internet Logs\xDB6.tmp
2008-12-09 17:27 ——— d—–w c:\program files\Decoupage_2
2008-12-08 19:08 ——— d—–w c:\program files\Java
2007-06-06 12:17 0 -c–a-w c:\documents and settings\Shez\^0^DRL^0^.exe
.

——- Sigcheck ——-

2008-06-20 10:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp2gdr\tcpip.sys
2008-06-20 10:44 360960 744e57c99232201ae98c49168b918f48 c:\windows\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp2qfe\tcpip.sys
2008-06-20 11:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp3gdr\tcpip.sys
2008-06-20 11:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp3qfe\tcpip.sys
2004-08-03 21:14 359040 1745b00fc1141404b28f4b94f69a8871 c:\windows\system32\dllcache\tcpip.sys
2004-08-03 21:14 359040 1745b00fc1141404b28f4b94f69a8871 c:\windows\system32\drivers\tcpip.sys

2009-02-05 18:05 22528 050aab32e1117a919dbf650b7c997e48 c:\windows\system32\userinit.exe
2004-08-03 22:56 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\system32\dllcache\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-14 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"kdx"="c:\program files\Kontiki\KHost.exe" [2008-02-27 1032376]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\ASUSTek\ASUSDVD\PDVDServ.exe" [2003-10-31 32768]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-08 136600]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"Uqejugof"="c:\windows\igovetidac.dll" [2009-02-05 132096]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-12 c:\windows\RTHDCPL.exe]
"VTTimer"="VTTimer.exe" [2006-09-21 c:\windows\system32\VTTimer.exe]
"S3Trayp"="S3trayp.exe" [2006-10-10 c:\windows\system32\S3Trayp.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 c:\windows\system32\bthprops.cpl]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-14 68856]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

c:\documents and settings\Leah\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-05 21:02 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati6koxx.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iokey.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
–a—— 2009-02-05 21:02 1601304 c:\progra~1\AVG\AVG8\avgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\ZoneLabs\\avsys\\ScanningProcess.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1947:TCP"= 1947:TCP:HASP SRM
"1947:UDP"= 1947:UDP:HASP SRM

R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [2007-05-04 11264]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-06-10 325128]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-06-10 107272]
R1 iokey;Hardware Interrupt Control Driver;c:\windows\system32\iokey.sys [2009-02-05 8752]
R2 hasplms;HASP License Manager;c:\windows\system32\hasplms.exe -run –> c:\windows\system32\hasplms.exe -run [?]
R3 RTLWUSB;Micronet SP907GK Wireless LAN USB Adapter;c:\windows\system32\drivers\RTL8187.sys [2007-09-09 172416]
R3 S3GIGP;S3GIGP;c:\windows\system32\drivers\S3gIGPm.sys [2007-05-04 634880]
S3 S3G700;S3G700;c:\windows\system32\drivers\VTGKModeDX32.sys [2007-04-18 809984]
S3 SjyPkt;SjyPkt;c:\windows\system32\drivers\SjyPkt.sys [2007-09-09 13532]
S4 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-07-13 903960]
S4 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-13 298264]
.
Contents of the 'Scheduled Tasks' folder

2009-02-06 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-02-12 14:54]

2009-02-06 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 17:58]

2009-02-05 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 17:58]

2009-02-06 c:\windows\Tasks\XoftSpySE 2.job
- c:\program files\XoftSpySE\XoftSpy.exe [2009-02-04 17:16]

2009-02-05 c:\windows\Tasks\XoftSpySE.job
- c:\program files\XoftSpySE\XoftSpy.exe [2009-02-04 17:16]
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
WebBrowser-{2E6F4C13-49FB-4DF3-B601-030D1D470E32} - (no file)
HKCU-Run-svschost.exe - c:\windows\system32\svschost.exe
HKCU-Run-Sonic RecordNow! - (no file)
HKLM-Run-Pcejegigus - c:\windows\Rhudamavabowi.dll
HKLM-Run-lsass driver - c:\windows\msauc.exe
HKLM-Run-services - c:\windows\services.exe
ShellExecuteHooks-{E60A0B68-353A-81DD-ED09-2A8101A6DFBA} - (no file)
Notify-iokey - iokey.dll
Notify-zvkbuw - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.com
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.msn.com
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: Crawler Search - tbr:iemenu
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Open in new background tab - c:\program files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/229?9d0c88cfcc854595972d8f0d413f348a
IE: Open in new foreground tab - c:\program files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/230?9d0c88cfcc854595972d8f0d413f348a
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-06 15:24:14
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\windows\system32\ZoneLabs\vsmon.exe
c:\windows\system32\hasplms.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
.
**************************************************************************
.
Completion time: 2009-02-06 15:32:57 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-06 15:32:52

Pre-Run: 100,894,318,592 bytes free
Post-Run: 101,051,645,952 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

248 — E O F — 2009-02-05 22:16:54

Attachments:

Hi I've posted the txt file. Is there anything else I need to do to my system? Can I turn the virus software/spyware/firewall back on yet? Do I need to worry about the Rhudamavabowi.dll file? I would like to thank you for all your help on this issue Cheers
.Hi

Sorry about that. I re edited my previous thread

I've also attached a new hijack file


Cheers


ComboFix 09-02-05.04 - Shez 2009-02-06 15:15:39.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.446.92 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
FW: ZoneAlarm Firewall *enabled*
* Created a new restore point
.
ADS - svchost.exe: deleted 25600 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\program files\Microsoft Common
c:\program files\Microsoft Common\svchost.exe
c:\windows\jestertb.dll
c:\windows\msauc.exe
c:\windows\services.exe
c:\windows\system32\a9k.bin
c:\windows\system32\drivers\ati6koxx.sys
c:\windows\system32\drivers\mrxdavv.sys
c:\windows\system32\fci.exe.exe
c:\windows\system32\icf.exe.exe
c:\windows\system32\iokey.dll
c:\windows\system32\kwave.sys
c:\windows\system32\shell31.dll
c:\windows\system32\svschost.exe
c:\windows\system32\wpv241230262534.cpx
c:\windows\system32\wpv341230262430.cpx
c:\windows\system32\wpv501233859884.cpx
c:\windows\system32\wpv751233860660.cpx
c:\windows\system32\zvkbuw.dll
c:\windows\system32\zvkbuw32.dll
c:\windows\wiaserviv.log

—– BITS: Possible infected sites —–

hxxp://supertvist.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_ATI6KOXX
——-\Legacy_CLIPSRVDCOMLAUNCH
——-\Legacy_FCI
——-\Legacy_ICF
——-\Legacy_TCPSR
——-\Service_ati6koxx
——-\Service_ClipSrvDcomLaunch
——-\Service_FCI
——-\Service_ICF
——-\Service_tcpsr


((((((((((((((((((((((((( Files Created from 2009-01-06 to 2009-02-06 )))))))))))))))))))))))))))))))
.

2009-02-06 13:26 . 2009-02-06 13:27 d——– c:\windows\ERUNT
2009-02-06 13:19 . 2009-02-06 13:51 d——– C:\SDFix
2009-02-05 23:59 . 2009-02-06 00:11 d——– c:\program files\RegCure
2009-02-05 23:40 . 2009-02-06 00:12 d——– c:\program files\XoftSpySE
2009-02-05 22:49 . 2009-02-06 14:12 7 –a—— c:\windows\system32\nar.bin
2009-02-05 22:20 . 2009-02-05 22:20 132,096 –a—— c:\windows\igovetidac.dll
2009-02-05 22:16 . 2009-02-05 22:47 d–h—– c:\windows\$hf_mig$
2009-02-05 21:51 . 2009-02-05 21:51 0 –a—— c:\windows\system32\.tmp
2009-02-05 21:28 . 2009-02-05 21:28 132,096 –a—— c:\windows\ipicoyucegaqabih.dll
2009-02-05 21:08 . 2009-02-05 21:08 32 –a-s—- c:\windows\system32\1420803498.dat
2009-02-05 21:07 . 2009-02-06 11:41 92,160 –a—— c:\windows\system32\svñshost.exe
2009-02-05 21:07 . 2009-02-05 21:07 0 –a—— c:\windows\system32\system32xp.exe.tmp
2009-02-05 18:05 . 2004-08-03 22:56 24,576 –a—— c:\windows\system32\stus.exe
2009-02-05 18:04 . 2009-02-05 18:04 8,752 –a—— c:\windows\system32\iokey.sys
2009-02-03 16:18 . 2008-09-19 10:00 3,528,862 –a—— c:\windows\BBeasts_Uninstall.exe
2009-02-03 16:15 . 2009-02-03 17:25 d——– c:\program files\BBeasts
2009-01-31 14:00 . 2009-01-31 14:00 54,156 –ah—– c:\windows\QTFont.qfn
2009-01-31 14:00 . 2009-01-31 14:00 1,409 –a—— c:\windows\QTFont.for
2009-01-13 19:32 . 2009-01-13 19:44 d——– c:\program files\Maxis
2009-01-12 18:05 . 2009-01-12 18:06 d——– c:\program files\Virtual Earth 3D
2009-01-12 15:52 . 2009-01-12 15:54 d——– c:\program files\Walk In Wonderland Papercraft Projects
2009-01-09 14:02 . 2009-01-09 14:02 d——– c:\program files\Infinite Sudoku

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-06 15:27 27,744,288 –sha-w c:\windows\system32\drivers\fidbox.dat
2009-02-06 15:21 325,940 –sha-w c:\windows\system32\drivers\fidbox.idx
2009-02-06 15:20 ——— d—–w c:\documents and settings\All Users\Application Data\Kontiki
2009-02-06 14:28 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-02-06 13:18 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-06 11:56 ——— d—–w c:\program files\Spybot - Search & Destroy
2009-02-06 10:51 1,900,544 —-a-w c:\windows\Internet Logs\xDB8.tmp
2009-02-05 23:26 8,707,094 -c–a-w c:\windows\Internet Logs\tvDebug.zip
2009-02-05 21:10 2,272,768 —-a-w c:\windows\Internet Logs\xDB7.tmp
2009-02-05 21:02 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-02-05 21:02 107,272 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-01-13 20:08 163,644 —-a-w c:\windows\system32\drivers\secdrv.sys
2009-01-13 19:35 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-12 16:02 ——— d—–w c:\program files\My Craft Studio
2008-12-10 12:12 758,784 —-a-w c:\windows\Internet Logs\xDB6.tmp
2008-12-09 17:27 ——— d—–w c:\program files\Decoupage_2
2008-12-08 19:08 ——— d—–w c:\program files\Java
2007-06-06 12:17 0 -c–a-w c:\documents and settings\Shez\^0^DRL^0^.exe
.

——- Sigcheck ——-

2008-06-20 10:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp2gdr\tcpip.sys
2008-06-20 10:44 360960 744e57c99232201ae98c49168b918f48 c:\windows\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp2qfe\tcpip.sys
2008-06-20 11:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp3gdr\tcpip.sys
2008-06-20 11:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\sp3qfe\tcpip.sys
2004-08-03 21:14 359040 1745b00fc1141404b28f4b94f69a8871 c:\windows\system32\dllcache\tcpip.sys
2004-08-03 21:14 359040 1745b00fc1141404b28f4b94f69a8871 c:\windows\system32\drivers\tcpip.sys

2009-02-05 18:05 22528 050aab32e1117a919dbf650b7c997e48 c:\windows\system32\userinit.exe
2004-08-03 22:56 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\system32\dllcache\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-14 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"kdx"="c:\program files\Kontiki\KHost.exe" [2008-02-27 1032376]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\ASUSTek\ASUSDVD\PDVDServ.exe" [2003-10-31 32768]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-08 136600]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"Uqejugof"="c:\windows\igovetidac.dll" [2009-02-05 132096]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-12 c:\windows\RTHDCPL.exe]
"VTTimer"="VTTimer.exe" [2006-09-21 c:\windows\system32\VTTimer.exe]
"S3Trayp"="S3trayp.exe" [2006-10-10 c:\windows\system32\S3Trayp.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 c:\windows\system32\bthprops.cpl]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-14 68856]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

c:\documents and settings\Leah\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-05 21:02 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati6koxx.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iokey.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
–a—— 2009-02-05 21:02 1601304 c:\progra~1\AVG\AVG8\avgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\ZoneLabs\\avsys\\ScanningProcess.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1947:TCP"= 1947:TCP:HASP SRM
"1947:UDP"= 1947:UDP:HASP SRM

R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [2007-05-04 11264]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-06-10 325128]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-06-10 107272]
R1 iokey;Hardware Interrupt Control Driver;c:\windows\system32\iokey.sys [2009-02-05 8752]
R2 hasplms;HASP License Manager;c:\windows\system32\hasplms.exe -run –> c:\windows\system32\hasplms.exe -run [?]
R3 RTLWUSB;Micronet SP907GK Wireless LAN USB Adapter;c:\windows\system32\drivers\RTL8187.sys [2007-09-09 172416]
R3 S3GIGP;S3GIGP;c:\windows\system32\drivers\S3gIGPm.sys [2007-05-04 634880]
S3 S3G700;S3G700;c:\windows\system32\drivers\VTGKModeDX32.sys [2007-04-18 809984]
S3 SjyPkt;SjyPkt;c:\windows\system32\drivers\SjyPkt.sys [2007-09-09 13532]
S4 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-07-13 903960]
S4 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-13 298264]
.
Contents of the 'Scheduled Tasks' folder

2009-02-06 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-02-12 14:54]

2009-02-06 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 17:58]

2009-02-05 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 17:58]

2009-02-06 c:\windows\Tasks\XoftSpySE 2.job
- c:\program files\XoftSpySE\XoftSpy.exe [2009-02-04 17:16]

2009-02-05 c:\windows\Tasks\XoftSpySE.job
- c:\program files\XoftSpySE\XoftSpy.exe [2009-02-04 17:16]
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
WebBrowser-{2E6F4C13-49FB-4DF3-B601-030D1D470E32} - (no file)
HKCU-Run-svschost.exe - c:\windows\system32\svschost.exe
HKCU-Run-Sonic RecordNow! - (no file)
HKLM-Run-Pcejegigus - c:\windows\Rhudamavabowi.dll
HKLM-Run-lsass driver - c:\windows\msauc.exe
HKLM-Run-services - c:\windows\services.exe
ShellExecuteHooks-{E60A0B68-353A-81DD-ED09-2A8101A6DFBA} - (no file)
Notify-iokey - iokey.dll
Notify-zvkbuw - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.com
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.msn.com
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: Crawler Search - tbr:iemenu
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Open in new background tab - c:\program files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/229?9d0c88cfcc854595972d8f0d413f348a
IE: Open in new foreground tab - c:\program files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/230?9d0c88cfcc854595972d8f0d413f348a
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-06 15:24:14
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\windows\system32\ZoneLabs\vsmon.exe
c:\windows\system32\hasplms.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
.
**************************************************************************


Completion time: 2009-02-06 15:32:57 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-06 15:32:52

Pre-Run: 100,894,318,592 bytes free
Post-Run: 101,051,645,952 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

248 — E O F — 2009-02-05 22:16:54



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:49:39, on 06/02/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\hasplms.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\S3trayp.exe
C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Documents and Settings\Lee\My Documents\My Received Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://by120w.bay120.mail.live.com/mail/to…mp;n=1583006419
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://by120w.bay120.mail.live.com/mail/to…mp;n=1583006419
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://by120w.bay120.mail.live.com/mail/To…mp;n=1583006419
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Uqejugof] rundll32.exe "C:\WINDOWS\igovetidac.dll",e
O4 - HKLM\..\Run: [Pcejegigus] rundll32.exe "C:\WINDOWS\Rhudamavabowi.dll",e
O4 - HKLM\..\Run: [lsass driver] C:\WINDOWS\msauc.exe
O4 - HKLM\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [svschost.exe] C:\WINDOWS\system32\svschost.exe -check
O4 - HKUS\S-1-5-21-776561741-1637723038-725345543-1004\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Lee')
O4 - HKUS\S-1-5-21-776561741-1637723038-725345543-1004\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" (User 'Lee')
O4 - HKUS\S-1-5-21-776561741-1637723038-725345543-1005\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Leah')
O4 - HKUS\S-1-5-21-776561741-1637723038-725345543-1005\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (User 'Leah')
O4 - HKUS\S-1-5-21-776561741-1637723038-725345543-1006\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Abbey')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-21-776561741-1637723038-725345543-1005 Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Leah')
O4 - S-1-5-21-776561741-1637723038-725345543-1005 User Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Leah')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/229?9d0c88cfcc854595972d8f0d413f348a
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/230?9d0c88cfcc854595972d8f0d413f348a
O14 - IERESET.INF: START_PAGE_URL=http://www.tesco.net
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://connect2.pb.com/,DanaInfo=lndancl04…va+iNotes6W.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: iokey - C:\WINDOWS\
O20 - Winlogon Notify: zvkbuw - C:\WINDOWS\
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HASP License Manager (hasplms) - Aladdin Knowledge Systems Ltd. - C:\WINDOWS\system32\hasplms.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/SHEZ~1.SHE/LOCALS~1/Temp/msohtmlclip1/01/clip_image002.gif
O24 - Desktop Component 1: (no name) - http://www.oksd.wednet.edu/bulldogs.jpg

–
End of file - 8050 bytes
hello

Open notepad and copy/paste the text in the quotebox below into it:

http://forums.whatthetech.com/svschost_exe…jan_t99787.html
Collect::
c:\windows\system32\nar.bin
c:\windows\igovetidac.dll
c:\windows\system32\.tmp
c:\windows\ipicoyucegaqabih.dll
c:\windows\system32\1420803498.dat
c:\windows\system32\svñshost.exe
c:\windows\system32\system32xp.exe.tmp
c:\windows\system32\stus.exe
c:\windows\system32\iokey.sys
c:\documents and settings\Shez\^0^DRL^0^.exe

Registry::
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati6koxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iokey.sys]

Suspect::


Save this as CFScript.txt


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you. Post that log in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
hi Did everything as per previos thread. system shut down on its own, restarted. i entered user log on and its been stood on the desktop for 30 min no start bar or icons. i can get in to task manager but nothing else cheers
hi i'm on my work lap top now. Theres no log at the mo.carn't get into anything the PC will not boot the desk top up Will i be able to get log if i boot in safe mode cheers Lee
Hi logged into sate mode i have the cursor and the words safe mode in each corner but still nothing is hapening. Is there any way i can force the desk top to run. Lee

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI