This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Hijacked in "Services" I think

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Every morning following the start up of my computer I get a little message that windows cannot connect to 'such and such' and do I want to connect now. It is not always the same place that it wants to connect to. I click on no and most often I also click on don't ask again. Then, as my AVG runs (it is set to run on startup) I get about six or seven pop-up messages that a trojan is found - and it heals them. I run Malware Bytes, Spybot and they find trojans and then dump them. AdAware doesn't catch anything "critical". Yesterday I ran both Malware Bytes and Spybot in "Safe" mode and they didn't catch anything, but I had already run them in standard mode before I did that. This morning when I started up, I got the same thing. I did a HJT log, and the following is the last entry in the list. I know sometimes a bad file is disguised by somewhat misspelling one of the words and I wonder if this file needs to be deleted. I am also posting the whole HJT file following. Any help would be appreciated.

O23 - Service: Windows Intasll - Unknown owner - C:\WINNT\Windows.exe (file missing)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:23:29 AM, on 2/6/2009
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\system32\msiexec.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\snmp.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe
C:\WINNT\system32\hpha2mon.exe
C:\Program Files\Labtec\Labtec Mouse Software\1.0\lwbwheel.exe
C:\Program Files\FarStone\RestoreIT!\RestoreIT!_2K\VBPTASK.EXE
C:\PROGRA~1\VISION~2\ONETOU~2.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINNT\system32\HPHipm08.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe
O4 - HKLM\..\Run: [HPHA2MON] C:\WINNT\system32\hpha2mon.exe
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Labtec\Labtec Mouse Software\1.0\lwbwheel.exe
O4 - HKLM\..\Run: [RestoreIT!] "C:\Program Files\FarStone\RestoreIT!\RestoreIT!_2K\VBPTASK.EXE" VBStart
O4 - HKLM\..\Run: [OneTouch Monitor] C:\PROGRA~1\VISION~2\ONETOU~2.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6662.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Active Monitor (imonNT) - Intel Corp. - C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Windows Intasll - Unknown owner - C:\WINNT\Windows.exe (file missing)

–
End of file - 5211 bytes
Hi, and Welcome to WhatTheTech :)

Apologies in the delay in a response. We are overwhelmed with logs at the moment and there aren't enough helpers to go around. If you still require help, please do the following:

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Please describe how your computer is behaving at the moment, listing any symptoms and problems that you are experiencing.

Thanks.
Thank you for responding; I knew you guys must be bogged down because it never takes this long for help. Anyway…. Much has happened since I posted, but I still am in need of help. Here is what has transpired. AVG was catching many, many trojans. Everytime I was connected (I'm still on dial up here) they were popping up all over. If I ran Malware Bytes and SpyBot they would catch them and then I wouldn't be bothered until the next start-up. I was running all three programs (SpyBot, AVG, and Malware Bytes) in Safe Mode, but they didn't find anything. I knew the problem was being loaded early, but couldn't find where. When I went into the virus vault of AVG; I dumped what it was finding, it had a list of about a dozen every day. On Tuesday of this week, when I dumped the vault, there was something important in there, because I started getting messages that certain things couldn't run. So I decided to re-install the OS, Windows2000 Pro. I did NOT do a clean install. I thought it would just repair the system, and put in what I was missing. At that point, since it is the orig. disc, I lost all of the service packs, and all of the updates. When things came back up on Tuesday evening, It seemed I had everything except my display graphics drivers. (everything looked like I was running in safe mode). Yesterday morning I put in the Intel Express Installer CD and got the graphics back. Then I spent the whole day downloading and installing the Windows updates. On dial-up it took me from 10:00 a.m. until 4:30 pm before everything was downloaded and installed. Only one security service pack didn't install, but I didn't get any warning about it this morning when I booted up. I did get a pop-up saying the following: (the upper left of the window said svchost) the message was that the file MSWINSCK.OCX is missing. I suspect I have registry issues, I was just about to go to file hippo to see what registry fix programs I could find when I saw your message. The other issues that I'm having all seem to be with the software programs that come on that Intel Express Installer CD. This program was installed by a tech that installed some hardware for me. When I got the tower back, I no longer had the regular Windows Defrag, but "Diskeeper Lite"; I haven't been able to find the regular Windows defrag since. One of the other programs on the disc is RestoreIt Lite which sets a restore point; something that's in my Windows XP system at home, but not in the Windows 2000 system here. All of that being said, I still need some guidence here. Do you still want me to download the two items you suggested, or do you want a new HJT log or some other log. The clean-out/maintenance programs I have are as follows: Hijack This, Malware Bytes, SpyBot S & D, AdAware, AVG (although I lost the updates and have to get them back), CCleaner, and ATF Cleaner.
Hi there, Are you having any more symptoms of Malware? It would be good if you could run DDS for me, then we can make sure all the bad stuff is gone. Once we know that the machine is clean we can start working on the issues that your machine is having. It may be that I have to hand you over to the Tech Team as I am not familiar with Windows 2000 and my area is mainly Malware. Cheers.
Okay DDS is downloaded, but before I run it - I don't want to sound stupid here - how do I disable script blocking? Is that my antivirus?
Well, if you aren't sure what script blocking is then you probably don't have it. Script blocking programs exist to block potentially malicious scripts from running. Symantec Script Blocker is one. Go ahead and run DDS, if you do have any script blocking programs then it will probably popup and notify you about DDS. Thanks.
Here is the DDS: DDS (Ver_09-02-01.01) - NTFSx86 Run by [removed] at 10:53:44.28 on Thu 02/12/2009 Internet Explorer: 6.0.2800.1106 Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.495.207 [GMT -5:00] ============== Running Processes =============== C:\WINNT\system32\spoolsv.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINNT\system32\mabidwe.exe C:\WINNT\system32\perfs.exe C:\WINNT\Explorer.EXE C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\System32\snmp.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINNT\system32\soxpeca.exe C:\WINNT\system32\stisvc.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\mspmspsv.exe C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe C:\WINNT\system32\hpha2mon.exe C:\Program Files\Labtec\Labtec Mouse Software\1.0\lwbwheel.exe C:\PROGRA~1\VISION~2\ONETOU~2.EXE C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\WINNT\system32\HPHipm08.exe C:\WINNT\System32\igfxtray.exe C:\WINNT\system32\hgcheck.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Microsoft Office\Office\1033\msoffice.exe C:\Program Files\Executive Software\DiskeeperLite\DKService.exe C:\WINNT\system32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Doris\Desktop\dds.scr ============== Pseudo HJT Report =============== uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie mDefault_Search_URL = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar5.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\3.1.807.1746\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar5.dll TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\system32\browseui.dll uRun: [Network Connections] c:\winnt\help\internat.exe uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe mRun: [HPDJ Taskbar Utility] c:\winnt\system32\spool\drivers\w32x86\3\hpztsb01.exe mRun: [HPHA2MON] c:\winnt\system32\hpha2mon.exe mRun: [LWBMOUSE] c:\program files\labtec\labtec mouse software\1.0\lwbwheel.exe mRun: [OneTouch Monitor] c:\progra~1\vision~2\ONETOU~2.EXE mRun: [AVG7_CC] c:\progra~1\grisoft\avg7\avgcc.exe /STARTUP mRun: [Synchronization Manager] mobsync.exe /logon mRun: [IgfxTray] c:\winnt\system32\igfxtray.exe mRun: [HotKeysCmds] c:\winnt\system32\hkcmd.exe mRun: [svchost.exe] "c:\winnt\system32\3361\svchost.exe" mRun: [hgcheck] c:\winnt\system32\hgcheck.exe mRun: [farstone] NULL mRunOnce: [svchost.exe] "c:\winnt\system32\3361\svchost.exe" dRun: [AVG7_Run] c:\progra~1\grisoft\avg7\avgw.exe /RUNONCE dRunOnce: [^SetupICWDesktop] c:\program files\internet explorer\connection wizard\icwconn1.exe /desktop StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm Trusted Zone: hgtv.com\boards DPF: DirectAnimation Java Classes - file://c:\winnt\java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab DPF: {0000000A-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/d/4/4/d446e8a9-3a86-4b59-bb19-f5bd11b40367/wmavax.CAB DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} - hxxp://download.microsoft.com/download/PowerPoint2002/Install/10.0.2609/WIN98MeXP/EN-US/msorun.cab DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: {A7207513-03D6-4CA7-9339-36869DC869BD} = 206.231.8.2 206.231.8.3 Notify: igfxcui - igfxsrvc.dll ============= SERVICES / DRIVERS =============== R1 Avg7Core;AVG7 Kernel;c:\winnt\system32\drivers\avg7core.sys [2007-5-14 777984] R1 Avg7RsNT;AVG7 Resident Driver NT;c:\winnt\system32\drivers\avg7rsnt.sys [2007-5-14 26944] R1 Avg7RsW;AVG7 Wrap Driver;c:\winnt\system32\drivers\avg7rsw.sys [2007-5-14 4224] R1 AvgClean;AVG7 Clean Driver;c:\winnt\system32\drivers\avgclean.sys [2007-5-14 3968] R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-7-7 611664] R2 afisicx;afisicx Service;c:\winnt\system32\afisicx.exe [2003-7-14 185856] R2 Avg7Alrt;AVG7 Alert Manager Server;c:\progra~1\grisoft\avg7\avgamsvr.exe [2007-5-14 353280] R2 Avg7UpdSvc;AVG7 Update Service;c:\progra~1\grisoft\avg7\avgupsvc.exe [2007-5-14 49664] R2 AVGEMS;AVG E-mail Scanner;c:\progra~1\grisoft\avg7\avgemc.exe [2007-5-14 351744] R2 AvgTdi;AVG Network Redirector;c:\winnt\system32\drivers\avgtdi.sys [2007-5-14 4960] R2 Gatewaysver;Gateway Service;c:\winnt\system32\waysver.exe [2009-2-12 374984] R2 mabidwe;mabidwe Service;c:\winnt\system32\mabidwe.exe [2003-7-14 184832] R2 Netlogs;Network Connections Logs;c:\winnt\system32\perfs.exe [2003-7-14 120320] R2 noytcyr;noytcyr Service;c:\winnt\system32\noytcyr.exe [2003-7-14 185856] R2 ppsio2;PPDevice;c:\winnt\system32\drivers\ppsio2.sys [2006-6-22 23200] R2 roytctm;roytctm Service;c:\winnt\system32\roytctm.exe [2003-7-14 185856] R2 soxpeca;soxpeca Service;c:\winnt\system32\soxpeca.exe [2003-7-14 182784] R2 tdydowkc;tdydowkc Service;c:\winnt\system32\tdydowkc.exe [2003-7-14 185344] R2 wsldoekd;wsldoekd Service;c:\winnt\system32\wsldoekd.exe [2003-7-14 184832] R3 pmxscan;Visioneer USB Kernel;c:\winnt\system32\drivers\usbscan.sys [2007-4-24 12592] R3 usbhub20;USB 2.0 Root Hub Support;c:\winnt\system32\drivers\usbhub20.sys [2003-7-14 49776] R3 Winacpci;Winacpci;c:\winnt\system32\drivers\winacpci.sys [2005-9-8 602128] RUnknown VVBackd5;VVBackd5; [x] S2 Windows Intasll;Windows Intasll;c:\winnt\Windows Intasll [2009-2-10 559104] S3 WMP11;Instant Wireless PCI Card Driver;c:\winnt\system32\drivers\WMP11NDS.sys [2005-9-8 54083] =============== Created Last 30 ================ 2009-02-12 10:53 16,384 a——t c:\winnt\system32\Perflib_Perfdata_480.dat 2009-02-12 10:06 100 a——- c:\winnt\Delete.bat 2009-02-12 10:06 374,984 —shr– c:\winnt\system32\waysver.exe 2009-02-12 09:39 –d—– c:\program files\Executive Software 2009-02-12 08:40 16,384 a——t c:\winnt\system32\Perflib_Perfdata_6a0.dat 2009-02-12 08:39 16,384 a——t c:\winnt\system32\Perflib_Perfdata_3b8.dat 2009-02-12 08:39 16,384 a——t c:\winnt\system32\Perflib_Perfdata_260.dat 2009-02-12 08:38 16,384 a——t c:\winnt\system32\Perflib_Perfdata_330.dat 2009-02-12 08:37 16,384 a——t c:\winnt\system32\Perflib_Perfdata_264.dat 2009-02-12 08:28 16,384 a——t c:\winnt\system32\Perflib_Perfdata_37c.dat 2009-02-11 16:57 16,384 a——t c:\winnt\system32\Perflib_Perfdata_3a8.dat 2009-02-11 16:54 16,384 a——t c:\winnt\system32\Perflib_Perfdata_3b0.dat 2009-02-11 16:51 118 a——- c:\winnt\system32\MRT.INI 2009-02-11 16:50 0 a——- c:\winnt\Down(0)x.ex 2009-02-11 16:40 129,536 a——- c:\winnt\Down(1).exe 2009-02-11 16:11 309,712 a——- c:\winnt\system32\hguest.exe 2009-02-11 16:11 198 a——- c:\winnt\system32\delme.bat 2009-02-11 16:10 107,745 a——- c:\winnt\system32\hgcheck.exe 2009-02-11 16:04 374,984 a——- c:\winnt\FireFoxUpdater.exe 2009-02-11 15:53 587,776 a——- c:\winnt\system32\WININET.DLL 2009-02-11 15:17 16,384 a——t c:\winnt\system32\Perflib_Perfdata_3b4.dat 2009-02-11 14:26 16,384 a——t c:\winnt\system32\Perflib_Perfdata_378.dat 2009-02-11 14:23 20,534 a——- c:\winnt\system32\snmp.sys 2009-02-11 14:18 478,720 a——- c:\winnt\system32\mstask.sys 2009-02-11 14:16 102,400 a——- c:\winnt\system32\IPHOST.dll 2009-02-11 14:16 102,400 a——- c:\winnt\system32\_proxy.dll 2009-02-11 14:15 151,552 a——- C:\aa.exe 2009-02-11 13:03 222,384 -c—— c:\winnt\system32\dllcache\nscm.exe 2009-02-11 13:03 16,784 -c—— c:\winnt\system32\dllcache\nsiislog.dll 2009-02-11 13:03 44,032 -c—— c:\winnt\system32\dllcache\msxml3r.dll 2009-02-11 13:03 22,800 -c—— c:\winnt\system32\dllcache\fltmc.exe 2009-02-11 13:03 18,192 -c—— c:\winnt\system32\dllcache\fltlib.dll 2009-02-11 13:03 55,568 -c—— c:\winnt\system32\dllcache\authz.dll 2009-02-11 12:24 1,735,808 -c—— c:\winnt\system32\dllcache\NTKRPAMP.EXE 2009-02-11 12:24 1,714,496 -c—— c:\winnt\system32\dllcache\NTKRNLMP.EXE 2009-02-11 12:24 1,713,536 -c—— c:\winnt\system32\dllcache\ntkrnlpa.exe 2009-02-11 12:24 1,690,880 -c—— c:\winnt\system32\dllcache\ntoskrnl.exe 2009-02-11 11:24 21,264 -c—— c:\winnt\system32\dllcache\verclsid.exe 2009-02-11 10:48 0 a—-r– c:\winnt\system32\TFTP460 2009-02-11 09:24 155,648 a—-r– c:\winnt\system32\igfxres.dll 2009-02-11 08:35 a-d—– C:\WUTemp 2009-02-11 08:35 182,880 a——- c:\winnt\system32\iuengine.dll 2009-02-11 08:35 213,528 ac—— c:\winnt\system32\dllcache\wuaucpl.cpl 2009-02-11 08:35 213,528 a——- c:\winnt\system32\wuaucpl.cpl 2009-02-10 17:24 16,384 a——t c:\winnt\system32\Perflib_Perfdata_320.dat 2009-02-10 17:21 32,827 ac—— c:\winnt\system32\dllcache\tcptest.exe 2009-02-10 17:20 7,440 ac—— c:\winnt\system32\dllcache\kbdycl.dll 2009-02-10 17:17 185,616 ac—— c:\winnt\system32\dllcache\wordpad.exe 2009-02-10 17:17 576,784 a——- c:\winnt\system32\hypertrm.dll 2009-02-10 17:04 4,624 a——- c:\winnt\system32\drivers\intelide.sys 2009-02-10 16:58 1,429 a——- c:\winnt\imsins.BAK 2009-02-10 16:58 148,992 ac—— c:\winnt\system32\dllcache\spxcoins.dll 2009-02-10 16:58 148,992 a——- c:\winnt\system32\spxcoins.dll 2009-02-10 16:58 1,167,584 a—-r– c:\winnt\SET53.tmp 2009-02-10 16:58 13,785 a—-r– c:\winnt\SET2B.tmp 2009-02-10 16:49 0 a——- c:\winnt\SET2.tmp 2009-02-10 16:41 0 a——- c:\winnt\SET1.tmp 2009-02-10 16:26 16,384 a——t c:\winnt\system32\Perflib_Perfdata_384.dat 2009-02-10 16:23 466,088 —-h— c:\winnt\ShellIconCache 2009-02-10 15:32 110 a——- c:\winnt\FireFoxUpdater.bat 2009-02-10 14:13 16,384 a——t c:\winnt\system32\Perflib_Perfdata_374.dat 2009-02-10 14:12 16,384 a——t c:\winnt\system32\Perflib_Perfdata_278.dat 2009-02-10 13:53 559,104 —shr– c:\winnt\Windows Intasll 2009-02-10 11:20 3 a——- c:\winnt\system32\version-lead 2009-02-10 11:09 221,184 a——- c:\winnt\system32\tapi.exe 2009-02-10 11:06 221,184 a——- c:\winnt\Down(0).exe 2009-02-09 15:48 16,384 a——t c:\winnt\system32\Perflib_Perfdata_33c.dat 2009-02-09 15:13 16,384 a——t c:\winnt\system32\Perflib_Perfdata_340.dat 2009-02-09 15:08 151,552 a——- c:\winnt\lee.exe 2009-02-09 08:26 16,384 a——t c:\winnt\system32\Perflib_Perfdata_4c8.dat 2009-02-05 15:00 16,384 a——t c:\winnt\system32\Perflib_Perfdata_2ec.dat 2009-02-05 11:06 a-d—– c:\winnt\system32\3361 2009-02-05 11:06 104,457 a——- c:\winnt\Down(2).exe 2009-02-02 15:30 125 a——- c:\winnt\vis.bat 2009-02-02 15:30 62 a——- c:\winnt\home.sys 2009-02-02 08:20 16,384 a——t c:\winnt\system32\Perflib_Perfdata_328.dat 2009-01-30 14:18 16,384 a——t c:\winnt\system32\Perflib_Perfdata_32c.dat 2009-01-30 14:17 1,536 a——- c:\winnt\system32\AUTMGR.EXE 2009-01-30 14:17 712,704 a——- c:\winnt\system32\kernel32_check.dll 2009-01-30 14:17 10,240 a——- c:\winnt\system32\Packer.dll 2009-01-30 14:17 5 a——- c:\winnt\system32\riphy.dll 2009-01-30 14:17 5 a——- c:\winnt\system32\iphy.dll 2009-01-30 14:17 3 a——- c:\winnt\system32\fhpatch.dll 2009-01-30 14:17 0 a——- c:\winnt\system32\fiplock.dll 2009-01-14 08:19 16,384 a——t c:\winnt\system32\Perflib_Perfdata_318.dat ==================== Find3M ==================== 2009-02-12 08:40 159,744 a——- c:\winnt\system32\Bsmtp.dll 2009-02-12 08:40 114,688 a——- c:\winnt\help\rundll32.exe 2009-02-10 17:18 21,952 -c–h— c:\program files\folder.htt 2009-02-10 17:18 271 —-h— c:\program files\desktop.ini 2009-02-10 17:18 15,004 ac—— c:\winnt\system32\emptyregdb.dat 2009-02-10 16:27 73,728 a——- c:\winnt\help\svchost32.exe 2009-01-14 16:11 38,496 a——- c:\winnt\system32\drivers\mbamswissarmy.sys 2009-01-14 16:11 15,504 a——- c:\winnt\system32\drivers\mbam.sys 2009-01-12 09:08 16,384 a——t c:\winnt\system32\Perflib_Perfdata_2fc.dat 2009-01-09 13:13 4,695 a——- c:\winnt\system32\mywfhit.ini.tmp 2009-01-07 08:21 16,384 a——t c:\winnt\system32\Perflib_Perfdata_314.dat 2009-01-05 08:23 16,384 a——t c:\winnt\system32\Perflib_Perfdata_304.dat 2008-12-31 12:01 0 a——- c:\documents and settings\doris\iphist.dat 2008-12-31 08:31 16,384 a——t c:\winnt\system32\Perflib_Perfdata_30c.dat 2008-12-30 16:56 413,696 a——- c:\winnt\help\internat.exe 2008-12-30 13:31 226,639 a——- c:\winnt\system32\pcguardmon.exe 2003-07-14 07:00 32,528 a——- c:\winnt\inf\wbfirdma.sys ============= FINISH: 10:54:03.59 ===============

Attachments:

Hi,

I am working through that log, but I'm afraid its not looking good.

Identity Theft

It looks like you have been infected by a few Backdoor Trojans.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

Its very possible that anything could have been installed on your computer by the remote attacker, including opening other backdoors and installing rootkits. While we can attempt to clean what we see in your logs, we cannot guarantee that your computer will be completely in the clear since we have no way of knowing that has been done to the computer. Your computer could be completely compromised at this moment. It may be prudent to backup your information, reformat, and reinstall.

More information on Remote Access Trojans can be found here.

I suggest you do the following immediately:
  • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.

If, however, you decide that the computer is not used for any sensitive work, or if you do not wish to reformat at this time, I can help you clean your computer to the best of my abilities. I must remind you that i cannot guarantee that your computer will be completely clean afterwards since we have no way of knowing what has been done to it.

To help you make your decision, here are a few related articles that i suggest you read:

  • Danger: Remote Access Trojans.
  • When should I re-format? How should I reinstall?
  • How Do I Handle Possible Identify Theft, Internet Fraud and Credit Card Fraud?

Should you have any questions, please feel free to ask.

Please let me know what you decide to do in your next post.

Thanks.
HoooBoy. You've really got my heart pumping now. Here's the scoop. This is a business computer. We don't do any online banking, however I do have quickbooks installed and use it mainly for check writing purposes. I do not use it to run the business. There are no account numbers stored in it. I also have our ledgers on Excell spread sheets, and of course a whole slew of word, and publisher documents - no account numbers. Also have our outlook addresses, which has phone numbers, but no account numbers. Coincidently, we have someone that has offered to do a clean install of an upgrade OS for us as payment for some work we did. I'm thinking that now is the time to do that. Do you agree? I will do the password changes that you mentioned for our e-mail, and the various places that I visit. I don't save passwords in my computer, and I haven't visited some of them since any of this started. I am not connected to the internet the whole 9 hours that I am here at the office either, because the fax and the computer share the same phone line. But being connected all day yesterday downloading those updates probably didn't do me any good either. Can these backdoor trojans 'read' my software programs and documents? What about if I'm not connected to the internet - I usually only connect when I need to read the e-mail or need to look something up. If I'm disconnected am I any safer?
Hi,

Coincidently, we have someone that has offered to do a clean install of an upgrade OS for us as payment for some work we did. I'm thinking that now is the time to do that. Do you agree?

I think that would be a great idea, especially in this situation. You can of course back up all your data files (but no programs, .exe or anything else that can be "run" in any way).

Can these backdoor trojans 'read' my software programs and documents? What about if I'm not connected to the internet - I usually only connect when I need to read the e-mail or need to look something up. If I'm disconnected am I any safer?

I am afraid that is where the uncertainty with backdoor Trojans lies. There is no way of telling what was done to your system, and how it operates. It could work only when connected. However, it could collect what it wants all the time and only send out periodic reports to wherever it wants.

We can't tell how serious it is and what it does, but I can tell you that the machine is heavily infected - I personally wouldn't take any chances. That clean install sounds like your best option in my honest opinion.

If you have any more questions, feel free to ask.

I am sorry it has come to this, its always a shame when we get a machine that we can't get 100% clean.

Thanks.
I'm was very surprised at what you said, because I had just had things cleaned out with LDTate about a month or so ago - maybe less. So I did another Malware Bytes scan and sure enough it found 40+ items. So I took care of what it found. Nothing like that was there before I did the Windows updates yesterday - when the computer was connected without updated antivirus for 8 hours. My SpyBot was clean too, and so was the AVG before the meltdown on Tuesday. Is it possible that everything that you are seeing came in yesterday? I just ran Malware Bytes again and it is clean again. I am going to run the others again too. Any chance that we will be able to take care of things after that??
Hi,

Is it possible that everything that you are seeing came in yesterday?

It looks like a large proportion of it had arrived in the last day or two. However, there are some components that seem to have been on your machine longer, since around the end of December. Since we are dealing with sneaky backdoor stuff here, it is possible that it effectively "laid low" until a couple of days a go.

I just ran Malware Bytes again and it is clean again. I am going to run the others again too. Any chance that we will be able to take care of things after that??

Do you wish to attempt to clean this machine then? Or are you performing this clean install?

Let me know,

Thanks.
Well, I would like to clean up as much as I can, and then do another back-up of the files in "My Documents". I made a back-up disc, but it was before we started conversing today. As I said, Malware Bytes found 40+ and it said it cleaned them. I just finished running SpyBot and it found 38, and said it cleaned them also. AdAwareSE is running right now. I can't run my AVG Antivirus because when I re-installed the OS on Tuesday, it lost the updates. The updates over my dial-up connection will take over an hour, and I am nervous to leave myself connected that long. I will make a copy of an updated version of the AVG from a different computer with high-speed connection, and then install it from a disc in this one. Would it be alright if I posted updated versions of those two notepads from DDS after I'm done running the AdAware in a few minutes? Then we can see if things look any better?
Okay, thank you. I am doing the AVG updates right now. As soon as I'm done I will run the AVG scan, and will again run the Malware Bytes and SpyBot S & D. As soon as that is finished I will do the DDS and post. We are on opposite time zones, I think, but I will post as soon as I can.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI