Spyware / Malware / Virus Removal
[Resolved] Hijacked in "Services" I think
25 min read
gtbase
Okay, before I proceed to Jotti and SystemLook, I wanted to let you know that one of the files you told me to delete would not delete. c:\winnt\system32\drivers\etc\mergIPAy.dll It said it was being used by Windows. Please advise.
gtbase
Here are the results of the first two items you requested - from Jotti. I will now got to System Look.
File: AUTMGR.EXE
Status: POSSIBLY INFECTED/MALWARE (Note: this file was only flagged as malware by heuristic detection(s). This might be a false positive. Therefore, results of this scan will not be stored in the database)
MD5: 1cc14e80efd217f49b1dfe17411ffdcc
Packers detected: -
Scanner results
Scan taken on 18 Feb 2009 18:11:19 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
G DATA Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Sophos Antivirus Found Sus/UnkPacker (probable variant)
VirusBuster Found nothing
VBA32 Found nothing
Service load: 0% 100%
File: Packer.dll
Status: OK
MD5: d94cfc45e010a8ef31b313050486c2e8
Packers detected: -
Scanner results
Scan taken on 18 Feb 2009 18:17:52 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
G DATA Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing
gtbase
Here is the rest of what you asked for - the System Look and the two DDS files. I will try to attach them rather than take up space; hopefully I do this correctly!
jpshortstuff
Hi,
OK, one more run of ComboFix, let's see if we can kill this thing for once and for all.
1. Please open Notepad
3. Save the above as CFScript.txt
4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.
[external image: Posted Image]
5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
Thanks.
OK, one more run of ComboFix, let's see if we can kill this thing for once and for all.
1. Please open Notepad
- Click Start , then Run
- Type notepad.exe in the Run Box.
File::
c:\winnt\system32\V8lp4VtEv8.klg
c:\documents and settings\doris\iphist.dat
c:\winnt\system32\drivers\etc\mergIPAy.dll
Driver::
SSDPR
NetSvc::
SSDPR
DDS::
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD}
3. Save the above as CFScript.txt
4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.
[external image: Posted Image]
5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
- Combofix.txt
- A new HijackThis log.
Thanks.
gtbase
These two logs (combo Fix and HJT) were run before I just got that message.
okay, sorry, I didn't save the HJT on my desktop so I ran another one - this one (below) is after the AVG notice. The combofix log is attached. I will be leaving in a few minutes, so I will either check your instructions from my home computer or wait until tomorrow morning. Thank you for sticking it out with me.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:55:18 PM, on 2/18/2009
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe
C:\WINNT\system32\hpha2mon.exe
C:\Program Files\Labtec\Labtec Mouse Software\1.0\lwbwheel.exe
C:\PROGRA~1\VISION~2\ONETOU~2.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINNT\system32\HPHipm08.exe
C:\WINNT\System32\igfxtray.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\WINNT\explorer.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\system32\perfs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe
O4 - HKLM\..\Run: [HPHA2MON] C:\WINNT\system32\hpha2mon.exe
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Labtec\Labtec Mouse Software\1.0\lwbwheel.exe
O4 - HKLM\..\Run: [OneTouch Monitor] C:\PROGRA~1\VISION~2\ONETOU~2.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6662.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A7207513-03D6-4CA7-9339-36869DC869BD}: NameServer = 206.231.8.2 206.231.8.3
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Active Monitor (imonNT) - Intel Corp. - C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Network Connections Logs (Netlogs) - Unknown owner - C:\WINNT\system32\perfs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
–
End of file - 6234 bytes
gtbase
These two logs (combo Fix and HJT) were run before I just got that message.
okay, sorry, I didn't save the HJT on my desktop so I ran another one - this one (below) is after the AVG notice. The combofix log is attached. I will be leaving in a few minutes, so I will either check your instructions from my home computer or wait until tomorrow morning. Thank you for sticking it out with me.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:55:18 PM, on 2/18/2009
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe
C:\WINNT\system32\hpha2mon.exe
C:\Program Files\Labtec\Labtec Mouse Software\1.0\lwbwheel.exe
C:\PROGRA~1\VISION~2\ONETOU~2.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINNT\system32\HPHipm08.exe
C:\WINNT\System32\igfxtray.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\WINNT\explorer.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\system32\perfs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe
O4 - HKLM\..\Run: [HPHA2MON] C:\WINNT\system32\hpha2mon.exe
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Labtec\Labtec Mouse Software\1.0\lwbwheel.exe
O4 - HKLM\..\Run: [OneTouch Monitor] C:\PROGRA~1\VISION~2\ONETOU~2.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6662.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A7207513-03D6-4CA7-9339-36869DC869BD}: NameServer = 206.231.8.2 206.231.8.3
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Active Monitor (imonNT) - Intel Corp. - C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Network Connections Logs (Netlogs) - Unknown owner - C:\WINNT\system32\perfs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
–
End of file - 6234 bytes
jpshortstuff
Hi,
Let's do this in a way that we can keep AVG on. Next time AVG finds a threat, please note down where it finds it.
Please download OTMoveIt3 by OldTimer.
Please post a new DDS log as well (just the DDS.txt please).
Thanks.
Let's do this in a way that we can keep AVG on. Next time AVG finds a threat, please note down where it finds it.
Please download OTMoveIt3 by OldTimer.
- Save it to your desktop.
- Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
- Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
:processes
explorer.exe
perfs.exe
:services
Netlogs
:files
C:\WINNT\system32\perfs.exe
c:\winnt\system32\drivers\etc\murgIPAy.dll
:Commands
[emptytemp]
[Reboot] - Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
- Click the red Moveit! button.
- Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
- Close OTMoveIt3
Please post a new DDS log as well (just the DDS.txt please).
Thanks.
gtbase
Good morning.
Well, I don't know if it's me or what - it seems that nothing goes the way it's supposed to!!
I will give you the morning's events in order of what happened.
Turned on the computer; Boot up when fine.
AVG started running a scan since it is scheduled to run on start-up. Within the first few minutes of the scan, on the scan window - not a pop-up window - it listed two threats found. I wrote them down so I could give them to you when I connected to the internet and checked in with you. Here they are:
File: snmp[1].bin Result/Infection: Trojan horse Back Door.lrcbot.HEF Path: C:Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\09JPZM4D\snmp[1].bin
File: mstask[1].bin Result/Infection: Trojan horse Clicker.WCZ Path: C:Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\2R9ST08Z\mstask[1].bin
The scan continued for 30 minutes without any other changes, so I put it in the background and connected to the internet to check my e-mail for your response. As soon as I connected, an AVG pop-up window came up that said "Threat Detected" and it was the same as the first one I listed above. Then a minute or two later, another pop-up from AVG and it was the same as the second windoe I listed above.
I checked your response and proceeded to download the OTMoveIt3. Since you said we would do things in a way to keep AVG on, I left the scan running; opened the OTMoveIt3, and followed your instructions for pasteing the codebox you gave me.
When the results came in the right side, I tried to copy and paste, but it wouldn't allow it. So I had wrote the results:
PROCESSES
Process explorer.exe killed successfully.
Unable to kil process: perfs.exe
I then realized that everything was frozen. I couldn't "X" out of OTMoveIt3, and AVG was no longer in the background - only a black screen. I pressed CtlAltDel and was able to End the processes, then I waited to see if anything would come back. Nothing did, so I pressed CtlAltDel again and shut down the computer. When I restarted, everything loaded fine. I opened AVG to finish the scan (it allows you to continue from the stop point). This time, in the scan window, both of the previous infections (above) were gone. I let the scan complete so I could report to you. At the end, there were two items found, but the window doesn't stay open long enough to write them down. I went to the virus vault to write down the two from the scan. One was listed as from the second part of the scan (after the restart). They were slightly different than the two that were in the first scan window. C:\WINNT\system32\snmp.sys and C:\WINNT\system32\mstask.sys it also says at the bottom of the AVG window C:\WINNT\system32\snmp.sys C:\WINNT\system32\,stask.sys
Backup copy Backup copy
Infected Infected
Following this, I connected up to the internet to post to you. Before going back to your e-mail I decided to run MalwareBytes. I did a "Quick Scan" . Towards the end of the scan the AVG pop-up window came up saying that a threat was detected in C:Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\2R9ST08Z\mstask[1].bin
As I was writing it down for you, the window blinked twice and the part in the [] changed to [2] and then [3]. It gives the option to heal so I clicked that for all three windows.
When they closed, the MalwareBytes window was open saying it found 7 infections. I kept the log to post here; and then followed the directions to delete them. Then one window remained that said that some files could not be healed (or removed) until restart. The listed file was C:\WINNT\System32\perfs.exe It asked if I wanted to restart so I did.
Since there wasn't any log generated for the OTMoveIt3, below is the DDS
The Malware Bytes is also below.
DDS (Ver_09-02-01.01) - NTFSx86
Run by [removed] at 10:43:24.50 on Thu 02/19/2009
Internet Explorer: 6.0.2800.1106
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.495.219 [GMT -5:00]
============== Running Processes ===============
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\snmp.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe
C:\WINNT\system32\hpha2mon.exe
C:\Program Files\Labtec\Labtec Mouse Software\1.0\lwbwheel.exe
C:\PROGRA~1\VISION~2\ONETOU~2.EXE
C:\WINNT\system32\HPHipm08.exe
C:\WINNT\System32\igfxtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Documents and Settings\Doris\Desktop\dds.scr
============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar5.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\3.1.807.1746\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Google;: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar5.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: &Yahoo;! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\system32\browseui.dll
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe
mRun: [HPDJ Taskbar Utility] c:\winnt\system32\spool\drivers\w32x86\3\hpztsb01.exe
mRun: [HPHA2MON] c:\winnt\system32\hpha2mon.exe
mRun: [LWBMOUSE] c:\program files\labtec\labtec mouse software\1.0\lwbwheel.exe
mRun: [OneTouch Monitor] c:\progra~1\vision~2\ONETOU~2.EXE
mRun: [AVG7_CC] c:\progra~1\grisoft\avg7\avgcc.exe /STARTUP
mRun: [Synchronization Manager] mobsync.exe /logon
mRun: [IgfxTray] c:\winnt\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\winnt\system32\hkcmd.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [AVG7_Run] c:\progra~1\grisoft\avg7\avgw.exe /RUNONCE
dRunOnce: [^SetupICWDesktop] c:\program files\internet explorer\connection wizard\icwconn1.exe /desktop
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
Trusted Zone: hgtv.com\boards
DPF: DirectAnimation Java Classes - file://c:\winnt\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab
DPF: {0000000A-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/d/4/4/d446e8a9-3a86-4b59-bb19-f5bd11b40367/wmavax.CAB
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} - hxxp://download.microsoft.com/download/PowerPoint2002/Install/10.0.2609/WIN98MeXP/EN-US/msorun.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: {A7207513-03D6-4CA7-9339-36869DC869BD} = 206.231.8.2 206.231.8.3
Notify: igfxcui - igfxsrvc.dll
============= SERVICES / DRIVERS ===============
R1 Avg7Core;AVG7 Kernel;c:\winnt\system32\drivers\avg7core.sys [2007-5-14 821856]
R1 Avg7RsNT;AVG7 Resident Driver NT;c:\winnt\system32\drivers\avg7rsnt.sys [2007-5-14 26944]
R1 Avg7RsW;AVG7 Wrap Driver;c:\winnt\system32\drivers\avg7rsw.sys [2007-5-14 4224]
R1 AvgClean;AVG7 Clean Driver;c:\winnt\system32\drivers\avgclean.sys [2007-5-14 10760]
R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-7-7 611664]
R2 Avg7Alrt;AVG7 Alert Manager Server;c:\progra~1\grisoft\avg7\avgamsvr.exe [2007-5-14 418816]
R2 Avg7UpdSvc;AVG7 Update Service;c:\progra~1\grisoft\avg7\avgupsvc.exe [2007-5-14 49664]
R2 AVGEMS;AVG E-mail Scanner;c:\progra~1\grisoft\avg7\avgemc.exe [2007-5-14 406528]
R2 AvgTdi;AVG Network Redirector;c:\winnt\system32\drivers\avgtdi.sys [2007-5-14 4960]
R2 ppsio2;PPDevice;c:\winnt\system32\drivers\ppsio2.sys [2006-6-22 23200]
R3 pmxscan;Visioneer USB Kernel;c:\winnt\system32\drivers\usbscan.sys [2007-4-24 12592]
R3 usbhub20;USB 2.0 Root Hub Support;c:\winnt\system32\drivers\usbhub20.sys [2003-7-14 49776]
R3 Winacpci;Winacpci;c:\winnt\system32\drivers\winacpci.sys [2005-9-8 602128]
S3 WMP11;Instant Wireless PCI Card Driver;c:\winnt\system32\drivers\WMP11NDS.sys [2005-9-8 54083]
=============== Created Last 30 ================
2009-02-19 10:43 16,384 a——t c:\winnt\system32\Perflib_Perfdata_144.dat
2009-02-19 09:58 16,384 a——t c:\winnt\system32\Perflib_Perfdata_544.dat
2009-02-19 09:58 16,384 a——t c:\winnt\system32\Perflib_Perfdata_2dc.dat
2009-02-19 09:58 16,384 a——t c:\winnt\system32\Perflib_Perfdata_280.dat
2009-02-19 09:56 19,215 a——- c:\winnt\system32\tmp0_750613184288.bk
2009-02-19 09:52 414,613 a——- c:\winnt\system32\mstask.sys
2009-02-19 09:32 16,384 a——t c:\winnt\system32\Perflib_Perfdata_328.dat
2009-02-19 09:25 –d—– C:\_OTMoveIt
2009-02-19 08:26 16,384 a——t c:\winnt\system32\Perflib_Perfdata_31c.dat
2009-02-18 17:01 49,640 a——- c:\winnt\FireFoxUpdater.exe
2009-02-18 17:01 133 a——- c:\winnt\WinF.bat
2009-02-18 17:01 97 a——- c:\winnt\WindowsGard
2009-02-18 17:01 23 a——- c:\winnt\WinA.bat
2009-02-18 16:47 59,392 a——- c:\winnt\lee.exe
2009-02-17 12:00 73,728 a——- c:\winnt\system32\javacpl.cpl
2009-02-16 14:38 250 a——- c:\winnt\gmer.ini
2009-02-16 09:04 161,792 a——- c:\winnt\SWREG.exe
2009-02-16 09:04 98,816 a——- c:\winnt\sed.exe
2009-02-12 09:39 –d—– c:\program files\Executive Software
2009-02-11 16:51 118 a——- c:\winnt\system32\MRT.INI
2009-02-11 15:53 587,776 a——- c:\winnt\system32\WININET.DLL
2009-02-11 13:03 222,384 -c—— c:\winnt\system32\dllcache\nscm.exe
2009-02-11 13:03 16,784 -c—— c:\winnt\system32\dllcache\nsiislog.dll
2009-02-11 13:03 44,032 -c—— c:\winnt\system32\dllcache\msxml3r.dll
2009-02-11 13:03 22,800 -c—— c:\winnt\system32\dllcache\fltmc.exe
2009-02-11 13:03 18,192 -c—— c:\winnt\system32\dllcache\fltlib.dll
2009-02-11 13:03 55,568 -c—— c:\winnt\system32\dllcache\authz.dll
2009-02-11 12:24 1,735,808 -c—— c:\winnt\system32\dllcache\NTKRPAMP.EXE
2009-02-11 12:24 1,714,496 -c—— c:\winnt\system32\dllcache\NTKRNLMP.EXE
2009-02-11 12:24 1,713,536 -c—— c:\winnt\system32\dllcache\ntkrnlpa.exe
2009-02-11 12:24 1,690,880 -c—— c:\winnt\system32\dllcache\ntoskrnl.exe
2009-02-11 11:24 21,264 -c—— c:\winnt\system32\dllcache\verclsid.exe
2009-02-11 09:24 155,648 a—-r– c:\winnt\system32\igfxres.dll
2009-02-11 08:35 a-d—– C:\WUTemp
2009-02-11 08:35 182,880 a——- c:\winnt\system32\iuengine.dll
2009-02-11 08:35 213,528 ac—— c:\winnt\system32\dllcache\wuaucpl.cpl
2009-02-11 08:35 213,528 a——- c:\winnt\system32\wuaucpl.cpl
2009-02-10 17:21 32,827 ac—— c:\winnt\system32\dllcache\tcptest.exe
2009-02-10 17:20 7,440 ac—— c:\winnt\system32\dllcache\kbdycl.dll
2009-02-10 17:17 185,616 ac—— c:\winnt\system32\dllcache\wordpad.exe
2009-02-10 17:17 576,784 a——- c:\winnt\system32\hypertrm.dll
2009-02-10 17:04 4,624 a——- c:\winnt\system32\drivers\intelide.sys
2009-02-10 16:58 148,992 ac—— c:\winnt\system32\dllcache\spxcoins.dll
2009-02-10 16:58 148,992 a——- c:\winnt\system32\spxcoins.dll
2009-02-10 16:23 1,108,710 —-h— c:\winnt\ShellIconCache
2009-01-30 14:17 1,536 a——- c:\winnt\system32\AUTMGR.EXE
2009-01-30 14:17 10,240 a——- c:\winnt\system32\Packer.dll
==================== Find3M ====================
2009-02-17 12:00 410,984 a——- c:\winnt\system32\deploytk.dll
2009-02-16 09:08 159,744 a——- c:\winnt\system32\Bsmtp.dll
2009-02-11 10:19 38,496 a——- c:\winnt\system32\drivers\mbamswissarmy.sys
2009-02-11 10:19 15,504 a——- c:\winnt\system32\drivers\mbam.sys
2009-02-10 17:18 21,952 -c–h— c:\program files\folder.htt
2009-02-10 17:18 271 —-h— c:\program files\desktop.ini
2009-02-10 17:18 15,004 ac—— c:\winnt\system32\emptyregdb.dat
2003-07-14 07:00 32,528 a——- c:\winnt\inf\wbfirdma.sys
============= FINISH: 10:43:45.18 ===============
Malwarebytes' Anti-Malware 1.34
Database version: 1773
Windows 5.0.2195 Service Pack 4
2/19/2009 9:56:14 AM
mbam-log-2009-02-19 (09-56-04).txt
Scan type: Quick Scan
Objects scanned: 51080
Time elapsed: 2 minute(s), 30 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
C:\WINNT\system32\perfs.exe (Trojan.Downloader) -> No action taken.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\netlogs (Trojan.Downloader) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\netlogs (Trojan.Downloader) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\netlogs (Trojan.Downloader) -> No action taken.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINNT\system32\comsa32.sys (Trojan.Agent) -> No action taken.
C:\WINNT\system32\drmgs.sys (Rootkit.Agent) -> No action taken.
C:\WINNT\system32\perfs.exe (Trojan.Downloader) -> No action taken.
jpshortstuff
Hi,
OK, perhaps the AVG scan interfered. OTMI should have rebooted your computer, which AVG probably didn't like. Make sure AVG isn't scanning (it can be active, just not scanning), and that no Windows are open. Then run OTMI3 again with this script:
When MalwareBytes' runs, do you click Remove Selected to allow it to remove what it finds?
If you get OTMI to run successfully, post a DDS log from after it runs.
Thanks.
OK, perhaps the AVG scan interfered. OTMI should have rebooted your computer, which AVG probably didn't like. Make sure AVG isn't scanning (it can be active, just not scanning), and that no Windows are open. Then run OTMI3 again with this script:
:processes explorer.exe perfs.exe :services Netlogs :files C:\WINNT\system32\perfs.exe c:\winnt\system32\drivers\etc\murgIPAy.dll c:\winnt\system32\tmp0_750613184288.bk c:\winnt\system32\mstask.sys c:\winnt\FireFoxUpdater.exe c:\winnt\WinF.bat c:\winnt\WindowsGard c:\winnt\WinA.bat c:\winnt\lee.exe :Commands [emptytemp] [Reboot]
When MalwareBytes' runs, do you click Remove Selected to allow it to remove what it finds?
If you get OTMI to run successfully, post a DDS log from after it runs.
Thanks.
gtbase
Yes, I do allow it to remove what it finds - however sometimes it doesn't say remove, sometimes it just quarantines them.
Okay- Here is the OTMoveIt3 log
========== PROCESSES ==========
Process explorer.exe killed successfully.
Unable to kill process: perfs.exe
========== SERVICES/DRIVERS ==========
Unable to stop service Netlogs .
========== FILES ==========
File/Folder C:\WINNT\system32\perfs.exe not found.
DllUnregisterServer procedure not found in c:\winnt\system32\drivers\etc\murgIPAy.dll
c:\winnt\system32\drivers\etc\murgIPAy.dll NOT unregistered.
c:\winnt\system32\drivers\etc\murgIPAy.dll moved successfully.
c:\winnt\system32\tmp0_750613184288.bk moved successfully.
c:\winnt\system32\mstask.sys moved successfully.
c:\winnt\FireFoxUpdater.exe moved successfully.
c:\winnt\WinF.bat moved successfully.
c:\winnt\WindowsGard moved successfully.
c:\winnt\WinA.bat moved successfully.
c:\winnt\lee.exe moved successfully.
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINNT\temp\JET17B4.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINNT\temp\JET1A35.tmp scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02192009_115818
Files moved on Reboot…
File C:\WINNT\temp\JET17B4.tmp not found!
File C:\WINNT\temp\JET1A35.tmp not found!
DDS text:
DDS (Ver_09-02-01.01) - NTFSx86
Run by [removed] at 12:06:39.89 on Thu 02/19/2009
Internet Explorer: 6.0.2800.1106
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.495.211 [GMT -5:00]
============== Running Processes ===============
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\snmp.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe
C:\WINNT\system32\hpha2mon.exe
C:\Program Files\Labtec\Labtec Mouse Software\1.0\lwbwheel.exe
C:\PROGRA~1\VISION~2\ONETOU~2.EXE
C:\WINNT\system32\HPHipm08.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINNT\System32\igfxtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Doris\Desktop\dds.scr
============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar5.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\3.1.807.1746\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar5.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\system32\browseui.dll
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe
mRun: [HPDJ Taskbar Utility] c:\winnt\system32\spool\drivers\w32x86\3\hpztsb01.exe
mRun: [HPHA2MON] c:\winnt\system32\hpha2mon.exe
mRun: [LWBMOUSE] c:\program files\labtec\labtec mouse software\1.0\lwbwheel.exe
mRun: [OneTouch Monitor] c:\progra~1\vision~2\ONETOU~2.EXE
mRun: [AVG7_CC] c:\progra~1\grisoft\avg7\avgcc.exe /STARTUP
mRun: [Synchronization Manager] mobsync.exe /logon
mRun: [IgfxTray] c:\winnt\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\winnt\system32\hkcmd.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [AVG7_Run] c:\progra~1\grisoft\avg7\avgw.exe /RUNONCE
dRunOnce: [^SetupICWDesktop] c:\program files\internet explorer\connection wizard\icwconn1.exe /desktop
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
Trusted Zone: hgtv.com\boards
DPF: DirectAnimation Java Classes - file://c:\winnt\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab
DPF: {0000000A-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/d/4/4/d446e8a9-3a86-4b59-bb19-f5bd11b40367/wmavax.CAB
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} - hxxp://download.microsoft.com/download/PowerPoint2002/Install/10.0.2609/WIN98MeXP/EN-US/msorun.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: {A7207513-03D6-4CA7-9339-36869DC869BD} = 206.231.8.2 206.231.8.3
Notify: igfxcui - igfxsrvc.dll
============= SERVICES / DRIVERS ===============
R1 Avg7Core;AVG7 Kernel;c:\winnt\system32\drivers\avg7core.sys [2007-5-14 821856]
R1 Avg7RsNT;AVG7 Resident Driver NT;c:\winnt\system32\drivers\avg7rsnt.sys [2007-5-14 26944]
R1 Avg7RsW;AVG7 Wrap Driver;c:\winnt\system32\drivers\avg7rsw.sys [2007-5-14 4224]
R1 AvgClean;AVG7 Clean Driver;c:\winnt\system32\drivers\avgclean.sys [2007-5-14 10760]
R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-7-7 611664]
R2 Avg7Alrt;AVG7 Alert Manager Server;c:\progra~1\grisoft\avg7\avgamsvr.exe [2007-5-14 418816]
R2 Avg7UpdSvc;AVG7 Update Service;c:\progra~1\grisoft\avg7\avgupsvc.exe [2007-5-14 49664]
R2 AVGEMS;AVG E-mail Scanner;c:\progra~1\grisoft\avg7\avgemc.exe [2007-5-14 406528]
R2 AvgTdi;AVG Network Redirector;c:\winnt\system32\drivers\avgtdi.sys [2007-5-14 4960]
R2 ppsio2;PPDevice;c:\winnt\system32\drivers\ppsio2.sys [2006-6-22 23200]
R3 pmxscan;Visioneer USB Kernel;c:\winnt\system32\drivers\usbscan.sys [2007-4-24 12592]
R3 usbhub20;USB 2.0 Root Hub Support;c:\winnt\system32\drivers\usbhub20.sys [2003-7-14 49776]
R3 Winacpci;Winacpci;c:\winnt\system32\drivers\winacpci.sys [2005-9-8 602128]
S3 WMP11;Instant Wireless PCI Card Driver;c:\winnt\system32\drivers\WMP11NDS.sys [2005-9-8 54083]
=============== Created Last 30 ================
2009-02-19 12:06 16,384 a——t c:\winnt\system32\Perflib_Perfdata_364.dat
2009-02-19 12:02 16,384 a——t c:\winnt\system32\Perflib_Perfdata_5c0.dat
2009-02-19 12:00 16,384 a——t c:\winnt\system32\Perflib_Perfdata_2d4.dat
2009-02-19 12:00 16,384 a——t c:\winnt\system32\Perflib_Perfdata_278.dat
2009-02-19 09:58 16,384 a——t c:\winnt\system32\Perflib_Perfdata_2dc.dat
2009-02-19 09:32 16,384 a——t c:\winnt\system32\Perflib_Perfdata_328.dat
2009-02-19 09:25 –d—– C:\_OTMoveIt
2009-02-19 08:26 16,384 a——t c:\winnt\system32\Perflib_Perfdata_31c.dat
2009-02-17 12:00 73,728 a——- c:\winnt\system32\javacpl.cpl
2009-02-16 14:38 250 a——- c:\winnt\gmer.ini
2009-02-16 09:04 161,792 a——- c:\winnt\SWREG.exe
2009-02-16 09:04 98,816 a——- c:\winnt\sed.exe
2009-02-12 09:39 –d—– c:\program files\Executive Software
2009-02-11 16:51 118 a——- c:\winnt\system32\MRT.INI
2009-02-11 15:53 587,776 a——- c:\winnt\system32\WININET.DLL
2009-02-11 13:03 222,384 -c—— c:\winnt\system32\dllcache\nscm.exe
2009-02-11 13:03 16,784 -c—— c:\winnt\system32\dllcache\nsiislog.dll
2009-02-11 13:03 44,032 -c—— c:\winnt\system32\dllcache\msxml3r.dll
2009-02-11 13:03 22,800 -c—— c:\winnt\system32\dllcache\fltmc.exe
2009-02-11 13:03 18,192 -c—— c:\winnt\system32\dllcache\fltlib.dll
2009-02-11 13:03 55,568 -c—— c:\winnt\system32\dllcache\authz.dll
2009-02-11 12:24 1,735,808 -c—— c:\winnt\system32\dllcache\NTKRPAMP.EXE
2009-02-11 12:24 1,714,496 -c—— c:\winnt\system32\dllcache\NTKRNLMP.EXE
2009-02-11 12:24 1,713,536 -c—— c:\winnt\system32\dllcache\ntkrnlpa.exe
2009-02-11 12:24 1,690,880 -c—— c:\winnt\system32\dllcache\ntoskrnl.exe
2009-02-11 11:24 21,264 -c—— c:\winnt\system32\dllcache\verclsid.exe
2009-02-11 09:24 155,648 a—-r– c:\winnt\system32\igfxres.dll
2009-02-11 08:35 a-d—– C:\WUTemp
2009-02-11 08:35 182,880 a——- c:\winnt\system32\iuengine.dll
2009-02-11 08:35 213,528 ac—— c:\winnt\system32\dllcache\wuaucpl.cpl
2009-02-11 08:35 213,528 a——- c:\winnt\system32\wuaucpl.cpl
2009-02-10 17:21 32,827 ac—— c:\winnt\system32\dllcache\tcptest.exe
2009-02-10 17:20 7,440 ac—— c:\winnt\system32\dllcache\kbdycl.dll
2009-02-10 17:17 185,616 ac—— c:\winnt\system32\dllcache\wordpad.exe
2009-02-10 17:17 576,784 a——- c:\winnt\system32\hypertrm.dll
2009-02-10 17:04 4,624 a——- c:\winnt\system32\drivers\intelide.sys
2009-02-10 16:58 148,992 ac—— c:\winnt\system32\dllcache\spxcoins.dll
2009-02-10 16:58 148,992 a——- c:\winnt\system32\spxcoins.dll
2009-02-10 16:23 1,108,710 —-h— c:\winnt\ShellIconCache
2009-01-30 14:17 1,536 a——- c:\winnt\system32\AUTMGR.EXE
2009-01-30 14:17 10,240 a——- c:\winnt\system32\Packer.dll
==================== Find3M ====================
2009-02-17 12:00 410,984 a——- c:\winnt\system32\deploytk.dll
2009-02-16 09:08 159,744 a——- c:\winnt\system32\Bsmtp.dll
2009-02-11 10:19 38,496 a——- c:\winnt\system32\drivers\mbamswissarmy.sys
2009-02-11 10:19 15,504 a——- c:\winnt\system32\drivers\mbam.sys
2009-02-10 17:18 21,952 -c–h— c:\program files\folder.htt
2009-02-10 17:18 271 —-h— c:\program files\desktop.ini
2009-02-10 17:18 15,004 ac—— c:\winnt\system32\emptyregdb.dat
2003-07-14 07:00 32,528 a——- c:\winnt\inf\wbfirdma.sys
============= FINISH: 12:07:00.76 ===============
jpshortstuff
That log looks pretty good - how are things running?
Can I see a fresh HijackThis log please?
gtbase
jp–
I am writing to you from my home computer, NOT the one at the office with the problem. I tried to get a PM to you via my phone web, but I don't think that it worked.
I can no longer connect to the internet. When I started up this morning, AVG started to run, as usual. within the first three minutes, it found three problems. The first two were the same as yesterdays, as in the mstask, but today there were two listings for the same file the only difference being the number in the []. One had a [1] the other had a [2]. The third problem it found was a different spot, but had to do with the perfs. I shut the scan down so I could connect to get your advice for today, but then I could not connect - it kept telling me my username and password were incorrect. I called my internet provider and we checked everything, and even reinstalled the connection from start. That did not work. We checked the modem via the computer, and it said that it was working properly. We even uninstalled and reinstalled the modem. The computer System said that the modem was working properly. I'm not sure what we did yesterday, but I don't think that anything we did could have done this. I then let the AVG run a complete scan and it only reported the original three problems. When I went to the log, it said it deleted the three files. Then a very strange thing happened. Someone tried to fax our office. Our fax machine shares the internet dial-up line. When the fax line rang, it rang through the computer - which it is not set up to do. So I checked my settings and they were still set to not allow incoming faxes through the computer, but to allow outgoing - these are the same settings I have always had. I completely took away all fax functions from the computer. Then I had someone send me a test fax to see if our regular fax machine would pick it up, to verify if there was a problem on the phone line. The fax machine received the fax correctly. Then computer would still not connect to the internet. My internet provider said the only other conclusion was that the System test of the modem was a false positive and that the modem needs to be replaced.
Therefore, I cannot communicate with you at all today until I get home again tonight - 5:30 EST. Obviously whatever was causing me problems starts itself before windows starts up or somewhere where it hasn't been killed yet. And it is somewhere in IE because I don't have problems until I connect to the internet. All of my other programs seem to be working fine.
I have spoken with my employer and we have decided that we are going to do a clean install of an upgraded operating system. That seems to be the concensis of the only way to get rid of what is troubling our computer.
I can check for whatever response you give me when I get home tonight, but by tomorrow, I will have disconnected my PC and gotten it down to the person that is going to install the XP OS. I will check in with you later, or tomorrow to give you an update from my home computer and, of course, to thank you for all of your hard work. If you want, you can put a message in my message box, I think I can get to that from my phone, but I can't get to the forum board, because the page is too large for my phone browser.
jpshortstuff
Hi,
I am sorry we couldn't "win" this one. I hope you have more luck in the future.
Let me know if I can be of any more help.
Thanks.
I would agree with that. It looks like the infections had taken too much of a hold. It could be that the Malware finally nuked your internet, it could be that the Malware was so deeply integrated into the system that when AVG and the tools we were running tried to remove it new issues were being caused. At the end of the day, I think this choice is the right choice.I have spoken with my employer and we have decided that we are going to do a clean install of an upgraded operating system. That seems to be the concensis of the only way to get rid of what is troubling our computer.
I am sorry we couldn't "win" this one. I hope you have more luck in the future.
Let me know if I can be of any more help.
Thanks.
jpshortstuff
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI