This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Hijacked in "Services" I think

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Okay, before I proceed to Jotti and SystemLook, I wanted to let you know that one of the files you told me to delete would not delete. c:\winnt\system32\drivers\etc\mergIPAy.dll It said it was being used by Windows. Please advise.
Here are the results of the first two items you requested - from Jotti. I will now got to System Look. File: AUTMGR.EXE Status: POSSIBLY INFECTED/MALWARE (Note: this file was only flagged as malware by heuristic detection(s). This might be a false positive. Therefore, results of this scan will not be stored in the database) MD5: 1cc14e80efd217f49b1dfe17411ffdcc Packers detected: - Scanner results Scan taken on 18 Feb 2009 18:11:19 (GMT) A-Squared Found nothing AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing CPsecure Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing G DATA Found nothing Ikarus Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing Panda Antivirus Found nothing Sophos Antivirus Found Sus/UnkPacker (probable variant) VirusBuster Found nothing VBA32 Found nothing Service load: 0% 100% File: Packer.dll Status: OK MD5: d94cfc45e010a8ef31b313050486c2e8 Packers detected: - Scanner results Scan taken on 18 Feb 2009 18:17:52 (GMT) A-Squared Found nothing AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing CPsecure Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing G DATA Found nothing Ikarus Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing Panda Antivirus Found nothing Sophos Antivirus Found nothing VirusBuster Found nothing VBA32 Found nothing
Hi,

OK, one more run of ComboFix, let's see if we can kill this thing for once and for all.

1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
c:\winnt\system32\V8lp4VtEv8.klg
c:\documents and settings\doris\iphist.dat
c:\winnt\system32\drivers\etc\mergIPAy.dll

Driver::
SSDPR

NetSvc::
SSDPR

DDS::
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD}

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
Let me know how things are running after this.

Thanks.
:wacko: whoo boy, these updates are killing me!! :blush: When I dragged the notepad into combofix, it started, but then gave me a notice that there was an updated version and did I want to update. So I clicked yes. That only took a few minutes, but then when it was done it automatically started the program. I had noticed that the notepad file had not 'dropped' into the combofix, so I was unsure if it was running a FULL scan or just that part you wanted me to drag and drop. So when I saved it I titled it 'full scan' just in case I had to still drag and drop the notepad. In the end when it restarted, the notepad file was gone. I hope I've gotten you the correct log. Oh no….I had turned AVG off while ComboFix was updating and did not turn it on again when I just connected. I just got a pop-up that said a threat was detected - but AVG said it healed it. ARRGGGHH :pullhair:
These two logs (combo Fix and HJT) were run before I just got that message.

okay, sorry, I didn't save the HJT on my desktop so I ran another one - this one (below) is after the AVG notice. The combofix log is attached. I will be leaving in a few minutes, so I will either check your instructions from my home computer or wait until tomorrow morning. Thank you for sticking it out with me.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:55:18 PM, on 2/18/2009
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe
C:\WINNT\system32\hpha2mon.exe
C:\Program Files\Labtec\Labtec Mouse Software\1.0\lwbwheel.exe
C:\PROGRA~1\VISION~2\ONETOU~2.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINNT\system32\HPHipm08.exe
C:\WINNT\System32\igfxtray.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\WINNT\explorer.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\system32\perfs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe
O4 - HKLM\..\Run: [HPHA2MON] C:\WINNT\system32\hpha2mon.exe
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Labtec\Labtec Mouse Software\1.0\lwbwheel.exe
O4 - HKLM\..\Run: [OneTouch Monitor] C:\PROGRA~1\VISION~2\ONETOU~2.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6662.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A7207513-03D6-4CA7-9339-36869DC869BD}: NameServer = 206.231.8.2 206.231.8.3
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Active Monitor (imonNT) - Intel Corp. - C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Network Connections Logs (Netlogs) - Unknown owner - C:\WINNT\system32\perfs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

–
End of file - 6234 bytes
:wacko: whoo boy, these updates are killing me!! :blush: When I dragged the notepad into combofix, it started, but then gave me a notice that there was an updated version and did I want to update. So I clicked yes. That only took a few minutes, but then when it was done it automatically started the program. I had noticed that the notepad file had not 'dropped' into the combofix, so I was unsure if it was running a FULL scan or just that part you wanted me to drag and drop. So when I saved it I titled it 'full scan' just in case I had to still drag and drop the notepad. In the end when it restarted, the notepad file was gone. I hope I've gotten you the correct log. Oh no….I had turned AVG off while ComboFix was updating and did not turn it on again when I just connected. I just got a pop-up that said a threat was detected - but AVG said it healed it. ARRGGGHH :pullhair:
These two logs (combo Fix and HJT) were run before I just got that message.

okay, sorry, I didn't save the HJT on my desktop so I ran another one - this one (below) is after the AVG notice. The combofix log is attached. I will be leaving in a few minutes, so I will either check your instructions from my home computer or wait until tomorrow morning. Thank you for sticking it out with me.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:55:18 PM, on 2/18/2009
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe
C:\WINNT\system32\hpha2mon.exe
C:\Program Files\Labtec\Labtec Mouse Software\1.0\lwbwheel.exe
C:\PROGRA~1\VISION~2\ONETOU~2.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINNT\system32\HPHipm08.exe
C:\WINNT\System32\igfxtray.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\WINNT\explorer.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\system32\perfs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe
O4 - HKLM\..\Run: [HPHA2MON] C:\WINNT\system32\hpha2mon.exe
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Labtec\Labtec Mouse Software\1.0\lwbwheel.exe
O4 - HKLM\..\Run: [OneTouch Monitor] C:\PROGRA~1\VISION~2\ONETOU~2.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6662.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A7207513-03D6-4CA7-9339-36869DC869BD}: NameServer = 206.231.8.2 206.231.8.3
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Active Monitor (imonNT) - Intel Corp. - C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Network Connections Logs (Netlogs) - Unknown owner - C:\WINNT\system32\perfs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

–
End of file - 6234 bytes

Attachments:

Hi,

Let's do this in a way that we can keep AVG on. Next time AVG finds a threat, please note down where it finds it.

Please download OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :processes
    explorer.exe
    perfs.exe

    :services
    Netlogs

    :files
    C:\WINNT\system32\perfs.exe
    c:\winnt\system32\drivers\etc\murgIPAy.dll

    :Commands
    [emptytemp]
    [Reboot]

  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


Please post a new DDS log as well (just the DDS.txt please).

Thanks.
Good morning. Well, I don't know if it's me or what - it seems that nothing goes the way it's supposed to!! I will give you the morning's events in order of what happened. Turned on the computer; Boot up when fine. AVG started running a scan since it is scheduled to run on start-up. Within the first few minutes of the scan, on the scan window - not a pop-up window - it listed two threats found. I wrote them down so I could give them to you when I connected to the internet and checked in with you. Here they are: File: snmp[1].bin Result/Infection: Trojan horse Back Door.lrcbot.HEF Path: C:Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\09JPZM4D\snmp[1].bin File: mstask[1].bin Result/Infection: Trojan horse Clicker.WCZ Path: C:Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\2R9ST08Z\mstask[1].bin The scan continued for 30 minutes without any other changes, so I put it in the background and connected to the internet to check my e-mail for your response. As soon as I connected, an AVG pop-up window came up that said "Threat Detected" and it was the same as the first one I listed above. Then a minute or two later, another pop-up from AVG and it was the same as the second windoe I listed above. I checked your response and proceeded to download the OTMoveIt3. Since you said we would do things in a way to keep AVG on, I left the scan running; opened the OTMoveIt3, and followed your instructions for pasteing the codebox you gave me. When the results came in the right side, I tried to copy and paste, but it wouldn't allow it. So I had wrote the results: PROCESSES Process explorer.exe killed successfully. Unable to kil process: perfs.exe I then realized that everything was frozen. I couldn't "X" out of OTMoveIt3, and AVG was no longer in the background - only a black screen. I pressed CtlAltDel and was able to End the processes, then I waited to see if anything would come back. Nothing did, so I pressed CtlAltDel again and shut down the computer. When I restarted, everything loaded fine. I opened AVG to finish the scan (it allows you to continue from the stop point). This time, in the scan window, both of the previous infections (above) were gone. I let the scan complete so I could report to you. At the end, there were two items found, but the window doesn't stay open long enough to write them down. I went to the virus vault to write down the two from the scan. One was listed as from the second part of the scan (after the restart). They were slightly different than the two that were in the first scan window. C:\WINNT\system32\snmp.sys and C:\WINNT\system32\mstask.sys it also says at the bottom of the AVG window C:\WINNT\system32\snmp.sys C:\WINNT\system32\,stask.sys Backup copy Backup copy Infected Infected Following this, I connected up to the internet to post to you. Before going back to your e-mail I decided to run MalwareBytes. I did a "Quick Scan" . Towards the end of the scan the AVG pop-up window came up saying that a threat was detected in C:Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\2R9ST08Z\mstask[1].bin As I was writing it down for you, the window blinked twice and the part in the [] changed to [2] and then [3]. It gives the option to heal so I clicked that for all three windows. When they closed, the MalwareBytes window was open saying it found 7 infections. I kept the log to post here; and then followed the directions to delete them. Then one window remained that said that some files could not be healed (or removed) until restart. The listed file was C:\WINNT\System32\perfs.exe It asked if I wanted to restart so I did. Since there wasn't any log generated for the OTMoveIt3, below is the DDS The Malware Bytes is also below. DDS (Ver_09-02-01.01) - NTFSx86 Run by [removed] at 10:43:24.50 on Thu 02/19/2009 Internet Explorer: 6.0.2800.1106 Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.495.219 [GMT -5:00] ============== Running Processes =============== C:\WINNT\system32\spoolsv.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\Program Files\Executive Software\DiskeeperLite\DKService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINNT\system32\regsvc.exe C:\WINNT\System32\snmp.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINNT\system32\stisvc.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\mspmspsv.exe C:\WINNT\Explorer.EXE C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe C:\WINNT\system32\hpha2mon.exe C:\Program Files\Labtec\Labtec Mouse Software\1.0\lwbwheel.exe C:\PROGRA~1\VISION~2\ONETOU~2.EXE C:\WINNT\system32\HPHipm08.exe C:\WINNT\System32\igfxtray.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Microsoft Office\Office\1033\msoffice.exe C:\Program Files\Internet Explorer\iexplore.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\Documents and Settings\Doris\Desktop\dds.scr ============== Pseudo HJT Report =============== uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie mDefault_Search_URL = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar5.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\3.1.807.1746\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: &Google;: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar5.dll TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File TB: &Yahoo;! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\system32\browseui.dll uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe mRun: [HPDJ Taskbar Utility] c:\winnt\system32\spool\drivers\w32x86\3\hpztsb01.exe mRun: [HPHA2MON] c:\winnt\system32\hpha2mon.exe mRun: [LWBMOUSE] c:\program files\labtec\labtec mouse software\1.0\lwbwheel.exe mRun: [OneTouch Monitor] c:\progra~1\vision~2\ONETOU~2.EXE mRun: [AVG7_CC] c:\progra~1\grisoft\avg7\avgcc.exe /STARTUP mRun: [Synchronization Manager] mobsync.exe /logon mRun: [IgfxTray] c:\winnt\system32\igfxtray.exe mRun: [HotKeysCmds] c:\winnt\system32\hkcmd.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" dRun: [AVG7_Run] c:\progra~1\grisoft\avg7\avgw.exe /RUNONCE dRunOnce: [^SetupICWDesktop] c:\program files\internet explorer\connection wizard\icwconn1.exe /desktop StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm Trusted Zone: hgtv.com\boards DPF: DirectAnimation Java Classes - file://c:\winnt\java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab DPF: {0000000A-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/d/4/4/d446e8a9-3a86-4b59-bb19-f5bd11b40367/wmavax.CAB DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} - hxxp://download.microsoft.com/download/PowerPoint2002/Install/10.0.2609/WIN98MeXP/EN-US/msorun.cab DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: {A7207513-03D6-4CA7-9339-36869DC869BD} = 206.231.8.2 206.231.8.3 Notify: igfxcui - igfxsrvc.dll ============= SERVICES / DRIVERS =============== R1 Avg7Core;AVG7 Kernel;c:\winnt\system32\drivers\avg7core.sys [2007-5-14 821856] R1 Avg7RsNT;AVG7 Resident Driver NT;c:\winnt\system32\drivers\avg7rsnt.sys [2007-5-14 26944] R1 Avg7RsW;AVG7 Wrap Driver;c:\winnt\system32\drivers\avg7rsw.sys [2007-5-14 4224] R1 AvgClean;AVG7 Clean Driver;c:\winnt\system32\drivers\avgclean.sys [2007-5-14 10760] R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-7-7 611664] R2 Avg7Alrt;AVG7 Alert Manager Server;c:\progra~1\grisoft\avg7\avgamsvr.exe [2007-5-14 418816] R2 Avg7UpdSvc;AVG7 Update Service;c:\progra~1\grisoft\avg7\avgupsvc.exe [2007-5-14 49664] R2 AVGEMS;AVG E-mail Scanner;c:\progra~1\grisoft\avg7\avgemc.exe [2007-5-14 406528] R2 AvgTdi;AVG Network Redirector;c:\winnt\system32\drivers\avgtdi.sys [2007-5-14 4960] R2 ppsio2;PPDevice;c:\winnt\system32\drivers\ppsio2.sys [2006-6-22 23200] R3 pmxscan;Visioneer USB Kernel;c:\winnt\system32\drivers\usbscan.sys [2007-4-24 12592] R3 usbhub20;USB 2.0 Root Hub Support;c:\winnt\system32\drivers\usbhub20.sys [2003-7-14 49776] R3 Winacpci;Winacpci;c:\winnt\system32\drivers\winacpci.sys [2005-9-8 602128] S3 WMP11;Instant Wireless PCI Card Driver;c:\winnt\system32\drivers\WMP11NDS.sys [2005-9-8 54083] =============== Created Last 30 ================ 2009-02-19 10:43 16,384 a——t c:\winnt\system32\Perflib_Perfdata_144.dat 2009-02-19 09:58 16,384 a——t c:\winnt\system32\Perflib_Perfdata_544.dat 2009-02-19 09:58 16,384 a——t c:\winnt\system32\Perflib_Perfdata_2dc.dat 2009-02-19 09:58 16,384 a——t c:\winnt\system32\Perflib_Perfdata_280.dat 2009-02-19 09:56 19,215 a——- c:\winnt\system32\tmp0_750613184288.bk 2009-02-19 09:52 414,613 a——- c:\winnt\system32\mstask.sys 2009-02-19 09:32 16,384 a——t c:\winnt\system32\Perflib_Perfdata_328.dat 2009-02-19 09:25 –d—– C:\_OTMoveIt 2009-02-19 08:26 16,384 a——t c:\winnt\system32\Perflib_Perfdata_31c.dat 2009-02-18 17:01 49,640 a——- c:\winnt\FireFoxUpdater.exe 2009-02-18 17:01 133 a——- c:\winnt\WinF.bat 2009-02-18 17:01 97 a——- c:\winnt\WindowsGard 2009-02-18 17:01 23 a——- c:\winnt\WinA.bat 2009-02-18 16:47 59,392 a——- c:\winnt\lee.exe 2009-02-17 12:00 73,728 a——- c:\winnt\system32\javacpl.cpl 2009-02-16 14:38 250 a——- c:\winnt\gmer.ini 2009-02-16 09:04 161,792 a——- c:\winnt\SWREG.exe 2009-02-16 09:04 98,816 a——- c:\winnt\sed.exe 2009-02-12 09:39 –d—– c:\program files\Executive Software 2009-02-11 16:51 118 a——- c:\winnt\system32\MRT.INI 2009-02-11 15:53 587,776 a——- c:\winnt\system32\WININET.DLL 2009-02-11 13:03 222,384 -c—— c:\winnt\system32\dllcache\nscm.exe 2009-02-11 13:03 16,784 -c—— c:\winnt\system32\dllcache\nsiislog.dll 2009-02-11 13:03 44,032 -c—— c:\winnt\system32\dllcache\msxml3r.dll 2009-02-11 13:03 22,800 -c—— c:\winnt\system32\dllcache\fltmc.exe 2009-02-11 13:03 18,192 -c—— c:\winnt\system32\dllcache\fltlib.dll 2009-02-11 13:03 55,568 -c—— c:\winnt\system32\dllcache\authz.dll 2009-02-11 12:24 1,735,808 -c—— c:\winnt\system32\dllcache\NTKRPAMP.EXE 2009-02-11 12:24 1,714,496 -c—— c:\winnt\system32\dllcache\NTKRNLMP.EXE 2009-02-11 12:24 1,713,536 -c—— c:\winnt\system32\dllcache\ntkrnlpa.exe 2009-02-11 12:24 1,690,880 -c—— c:\winnt\system32\dllcache\ntoskrnl.exe 2009-02-11 11:24 21,264 -c—— c:\winnt\system32\dllcache\verclsid.exe 2009-02-11 09:24 155,648 a—-r– c:\winnt\system32\igfxres.dll 2009-02-11 08:35 a-d—– C:\WUTemp 2009-02-11 08:35 182,880 a——- c:\winnt\system32\iuengine.dll 2009-02-11 08:35 213,528 ac—— c:\winnt\system32\dllcache\wuaucpl.cpl 2009-02-11 08:35 213,528 a——- c:\winnt\system32\wuaucpl.cpl 2009-02-10 17:21 32,827 ac—— c:\winnt\system32\dllcache\tcptest.exe 2009-02-10 17:20 7,440 ac—— c:\winnt\system32\dllcache\kbdycl.dll 2009-02-10 17:17 185,616 ac—— c:\winnt\system32\dllcache\wordpad.exe 2009-02-10 17:17 576,784 a——- c:\winnt\system32\hypertrm.dll 2009-02-10 17:04 4,624 a——- c:\winnt\system32\drivers\intelide.sys 2009-02-10 16:58 148,992 ac—— c:\winnt\system32\dllcache\spxcoins.dll 2009-02-10 16:58 148,992 a——- c:\winnt\system32\spxcoins.dll 2009-02-10 16:23 1,108,710 —-h— c:\winnt\ShellIconCache 2009-01-30 14:17 1,536 a——- c:\winnt\system32\AUTMGR.EXE 2009-01-30 14:17 10,240 a——- c:\winnt\system32\Packer.dll ==================== Find3M ==================== 2009-02-17 12:00 410,984 a——- c:\winnt\system32\deploytk.dll 2009-02-16 09:08 159,744 a——- c:\winnt\system32\Bsmtp.dll 2009-02-11 10:19 38,496 a——- c:\winnt\system32\drivers\mbamswissarmy.sys 2009-02-11 10:19 15,504 a——- c:\winnt\system32\drivers\mbam.sys 2009-02-10 17:18 21,952 -c–h— c:\program files\folder.htt 2009-02-10 17:18 271 —-h— c:\program files\desktop.ini 2009-02-10 17:18 15,004 ac—— c:\winnt\system32\emptyregdb.dat 2003-07-14 07:00 32,528 a——- c:\winnt\inf\wbfirdma.sys ============= FINISH: 10:43:45.18 =============== Malwarebytes' Anti-Malware 1.34 Database version: 1773 Windows 5.0.2195 Service Pack 4 2/19/2009 9:56:14 AM mbam-log-2009-02-19 (09-56-04).txt Scan type: Quick Scan Objects scanned: 51080 Time elapsed: 2 minute(s), 30 second(s) Memory Processes Infected: 1 Memory Modules Infected: 0 Registry Keys Infected: 3 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 3 Memory Processes Infected: C:\WINNT\system32\perfs.exe (Trojan.Downloader) -> No action taken. Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\netlogs (Trojan.Downloader) -> No action taken. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\netlogs (Trojan.Downloader) -> No action taken. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\netlogs (Trojan.Downloader) -> No action taken. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINNT\system32\comsa32.sys (Trojan.Agent) -> No action taken. C:\WINNT\system32\drmgs.sys (Rootkit.Agent) -> No action taken. C:\WINNT\system32\perfs.exe (Trojan.Downloader) -> No action taken.
Hi,

OK, perhaps the AVG scan interfered. OTMI should have rebooted your computer, which AVG probably didn't like. Make sure AVG isn't scanning (it can be active, just not scanning), and that no Windows are open. Then run OTMI3 again with this script:
:processes
explorer.exe
perfs.exe

:services
Netlogs

:files
C:\WINNT\system32\perfs.exe
c:\winnt\system32\drivers\etc\murgIPAy.dll
c:\winnt\system32\tmp0_750613184288.bk
c:\winnt\system32\mstask.sys
c:\winnt\FireFoxUpdater.exe
c:\winnt\WinF.bat
c:\winnt\WindowsGard
c:\winnt\WinA.bat
c:\winnt\lee.exe

:Commands
[emptytemp]
[Reboot]

When MalwareBytes' runs, do you click Remove Selected to allow it to remove what it finds?

If you get OTMI to run successfully, post a DDS log from after it runs.

Thanks.
Yes, I do allow it to remove what it finds - however sometimes it doesn't say remove, sometimes it just quarantines them. Okay- Here is the OTMoveIt3 log ========== PROCESSES ========== Process explorer.exe killed successfully. Unable to kill process: perfs.exe ========== SERVICES/DRIVERS ========== Unable to stop service Netlogs . ========== FILES ========== File/Folder C:\WINNT\system32\perfs.exe not found. DllUnregisterServer procedure not found in c:\winnt\system32\drivers\etc\murgIPAy.dll c:\winnt\system32\drivers\etc\murgIPAy.dll NOT unregistered. c:\winnt\system32\drivers\etc\murgIPAy.dll moved successfully. c:\winnt\system32\tmp0_750613184288.bk moved successfully. c:\winnt\system32\mstask.sys moved successfully. c:\winnt\FireFoxUpdater.exe moved successfully. c:\winnt\WinF.bat moved successfully. c:\winnt\WindowsGard moved successfully. c:\winnt\WinA.bat moved successfully. c:\winnt\lee.exe moved successfully. ========== COMMANDS ========== User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINNT\temp\JET17B4.tmp scheduled to be deleted on reboot. File delete failed. C:\WINNT\temp\JET1A35.tmp scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02192009_115818 Files moved on Reboot… File C:\WINNT\temp\JET17B4.tmp not found! File C:\WINNT\temp\JET1A35.tmp not found! DDS text: DDS (Ver_09-02-01.01) - NTFSx86 Run by [removed] at 12:06:39.89 on Thu 02/19/2009 Internet Explorer: 6.0.2800.1106 Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.495.211 [GMT -5:00] ============== Running Processes =============== C:\WINNT\system32\spoolsv.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\Program Files\Executive Software\DiskeeperLite\DKService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINNT\system32\regsvc.exe C:\WINNT\System32\snmp.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINNT\system32\stisvc.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\mspmspsv.exe C:\WINNT\Explorer.EXE C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe C:\WINNT\system32\hpha2mon.exe C:\Program Files\Labtec\Labtec Mouse Software\1.0\lwbwheel.exe C:\PROGRA~1\VISION~2\ONETOU~2.EXE C:\WINNT\system32\HPHipm08.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\WINNT\System32\igfxtray.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Microsoft Office\Office\1033\msoffice.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Doris\Desktop\dds.scr ============== Pseudo HJT Report =============== uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie mDefault_Search_URL = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar5.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\3.1.807.1746\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar5.dll TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\system32\browseui.dll uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe mRun: [HPDJ Taskbar Utility] c:\winnt\system32\spool\drivers\w32x86\3\hpztsb01.exe mRun: [HPHA2MON] c:\winnt\system32\hpha2mon.exe mRun: [LWBMOUSE] c:\program files\labtec\labtec mouse software\1.0\lwbwheel.exe mRun: [OneTouch Monitor] c:\progra~1\vision~2\ONETOU~2.EXE mRun: [AVG7_CC] c:\progra~1\grisoft\avg7\avgcc.exe /STARTUP mRun: [Synchronization Manager] mobsync.exe /logon mRun: [IgfxTray] c:\winnt\system32\igfxtray.exe mRun: [HotKeysCmds] c:\winnt\system32\hkcmd.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" dRun: [AVG7_Run] c:\progra~1\grisoft\avg7\avgw.exe /RUNONCE dRunOnce: [^SetupICWDesktop] c:\program files\internet explorer\connection wizard\icwconn1.exe /desktop StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm Trusted Zone: hgtv.com\boards DPF: DirectAnimation Java Classes - file://c:\winnt\java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab DPF: {0000000A-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/d/4/4/d446e8a9-3a86-4b59-bb19-f5bd11b40367/wmavax.CAB DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} - hxxp://download.microsoft.com/download/PowerPoint2002/Install/10.0.2609/WIN98MeXP/EN-US/msorun.cab DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: {A7207513-03D6-4CA7-9339-36869DC869BD} = 206.231.8.2 206.231.8.3 Notify: igfxcui - igfxsrvc.dll ============= SERVICES / DRIVERS =============== R1 Avg7Core;AVG7 Kernel;c:\winnt\system32\drivers\avg7core.sys [2007-5-14 821856] R1 Avg7RsNT;AVG7 Resident Driver NT;c:\winnt\system32\drivers\avg7rsnt.sys [2007-5-14 26944] R1 Avg7RsW;AVG7 Wrap Driver;c:\winnt\system32\drivers\avg7rsw.sys [2007-5-14 4224] R1 AvgClean;AVG7 Clean Driver;c:\winnt\system32\drivers\avgclean.sys [2007-5-14 10760] R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-7-7 611664] R2 Avg7Alrt;AVG7 Alert Manager Server;c:\progra~1\grisoft\avg7\avgamsvr.exe [2007-5-14 418816] R2 Avg7UpdSvc;AVG7 Update Service;c:\progra~1\grisoft\avg7\avgupsvc.exe [2007-5-14 49664] R2 AVGEMS;AVG E-mail Scanner;c:\progra~1\grisoft\avg7\avgemc.exe [2007-5-14 406528] R2 AvgTdi;AVG Network Redirector;c:\winnt\system32\drivers\avgtdi.sys [2007-5-14 4960] R2 ppsio2;PPDevice;c:\winnt\system32\drivers\ppsio2.sys [2006-6-22 23200] R3 pmxscan;Visioneer USB Kernel;c:\winnt\system32\drivers\usbscan.sys [2007-4-24 12592] R3 usbhub20;USB 2.0 Root Hub Support;c:\winnt\system32\drivers\usbhub20.sys [2003-7-14 49776] R3 Winacpci;Winacpci;c:\winnt\system32\drivers\winacpci.sys [2005-9-8 602128] S3 WMP11;Instant Wireless PCI Card Driver;c:\winnt\system32\drivers\WMP11NDS.sys [2005-9-8 54083] =============== Created Last 30 ================ 2009-02-19 12:06 16,384 a——t c:\winnt\system32\Perflib_Perfdata_364.dat 2009-02-19 12:02 16,384 a——t c:\winnt\system32\Perflib_Perfdata_5c0.dat 2009-02-19 12:00 16,384 a——t c:\winnt\system32\Perflib_Perfdata_2d4.dat 2009-02-19 12:00 16,384 a——t c:\winnt\system32\Perflib_Perfdata_278.dat 2009-02-19 09:58 16,384 a——t c:\winnt\system32\Perflib_Perfdata_2dc.dat 2009-02-19 09:32 16,384 a——t c:\winnt\system32\Perflib_Perfdata_328.dat 2009-02-19 09:25 –d—– C:\_OTMoveIt 2009-02-19 08:26 16,384 a——t c:\winnt\system32\Perflib_Perfdata_31c.dat 2009-02-17 12:00 73,728 a——- c:\winnt\system32\javacpl.cpl 2009-02-16 14:38 250 a——- c:\winnt\gmer.ini 2009-02-16 09:04 161,792 a——- c:\winnt\SWREG.exe 2009-02-16 09:04 98,816 a——- c:\winnt\sed.exe 2009-02-12 09:39 –d—– c:\program files\Executive Software 2009-02-11 16:51 118 a——- c:\winnt\system32\MRT.INI 2009-02-11 15:53 587,776 a——- c:\winnt\system32\WININET.DLL 2009-02-11 13:03 222,384 -c—— c:\winnt\system32\dllcache\nscm.exe 2009-02-11 13:03 16,784 -c—— c:\winnt\system32\dllcache\nsiislog.dll 2009-02-11 13:03 44,032 -c—— c:\winnt\system32\dllcache\msxml3r.dll 2009-02-11 13:03 22,800 -c—— c:\winnt\system32\dllcache\fltmc.exe 2009-02-11 13:03 18,192 -c—— c:\winnt\system32\dllcache\fltlib.dll 2009-02-11 13:03 55,568 -c—— c:\winnt\system32\dllcache\authz.dll 2009-02-11 12:24 1,735,808 -c—— c:\winnt\system32\dllcache\NTKRPAMP.EXE 2009-02-11 12:24 1,714,496 -c—— c:\winnt\system32\dllcache\NTKRNLMP.EXE 2009-02-11 12:24 1,713,536 -c—— c:\winnt\system32\dllcache\ntkrnlpa.exe 2009-02-11 12:24 1,690,880 -c—— c:\winnt\system32\dllcache\ntoskrnl.exe 2009-02-11 11:24 21,264 -c—— c:\winnt\system32\dllcache\verclsid.exe 2009-02-11 09:24 155,648 a—-r– c:\winnt\system32\igfxres.dll 2009-02-11 08:35 a-d—– C:\WUTemp 2009-02-11 08:35 182,880 a——- c:\winnt\system32\iuengine.dll 2009-02-11 08:35 213,528 ac—— c:\winnt\system32\dllcache\wuaucpl.cpl 2009-02-11 08:35 213,528 a——- c:\winnt\system32\wuaucpl.cpl 2009-02-10 17:21 32,827 ac—— c:\winnt\system32\dllcache\tcptest.exe 2009-02-10 17:20 7,440 ac—— c:\winnt\system32\dllcache\kbdycl.dll 2009-02-10 17:17 185,616 ac—— c:\winnt\system32\dllcache\wordpad.exe 2009-02-10 17:17 576,784 a——- c:\winnt\system32\hypertrm.dll 2009-02-10 17:04 4,624 a——- c:\winnt\system32\drivers\intelide.sys 2009-02-10 16:58 148,992 ac—— c:\winnt\system32\dllcache\spxcoins.dll 2009-02-10 16:58 148,992 a——- c:\winnt\system32\spxcoins.dll 2009-02-10 16:23 1,108,710 —-h— c:\winnt\ShellIconCache 2009-01-30 14:17 1,536 a——- c:\winnt\system32\AUTMGR.EXE 2009-01-30 14:17 10,240 a——- c:\winnt\system32\Packer.dll ==================== Find3M ==================== 2009-02-17 12:00 410,984 a——- c:\winnt\system32\deploytk.dll 2009-02-16 09:08 159,744 a——- c:\winnt\system32\Bsmtp.dll 2009-02-11 10:19 38,496 a——- c:\winnt\system32\drivers\mbamswissarmy.sys 2009-02-11 10:19 15,504 a——- c:\winnt\system32\drivers\mbam.sys 2009-02-10 17:18 21,952 -c–h— c:\program files\folder.htt 2009-02-10 17:18 271 —-h— c:\program files\desktop.ini 2009-02-10 17:18 15,004 ac—— c:\winnt\system32\emptyregdb.dat 2003-07-14 07:00 32,528 a——- c:\winnt\inf\wbfirdma.sys ============= FINISH: 12:07:00.76 ===============
jp– I am writing to you from my home computer, NOT the one at the office with the problem. I tried to get a PM to you via my phone web, but I don't think that it worked. I can no longer connect to the internet. When I started up this morning, AVG started to run, as usual. within the first three minutes, it found three problems. The first two were the same as yesterdays, as in the mstask, but today there were two listings for the same file the only difference being the number in the []. One had a [1] the other had a [2]. The third problem it found was a different spot, but had to do with the perfs. I shut the scan down so I could connect to get your advice for today, but then I could not connect - it kept telling me my username and password were incorrect. I called my internet provider and we checked everything, and even reinstalled the connection from start. That did not work. We checked the modem via the computer, and it said that it was working properly. We even uninstalled and reinstalled the modem. The computer System said that the modem was working properly. I'm not sure what we did yesterday, but I don't think that anything we did could have done this. I then let the AVG run a complete scan and it only reported the original three problems. When I went to the log, it said it deleted the three files. Then a very strange thing happened. Someone tried to fax our office. Our fax machine shares the internet dial-up line. When the fax line rang, it rang through the computer - which it is not set up to do. So I checked my settings and they were still set to not allow incoming faxes through the computer, but to allow outgoing - these are the same settings I have always had. I completely took away all fax functions from the computer. Then I had someone send me a test fax to see if our regular fax machine would pick it up, to verify if there was a problem on the phone line. The fax machine received the fax correctly. Then computer would still not connect to the internet. My internet provider said the only other conclusion was that the System test of the modem was a false positive and that the modem needs to be replaced. Therefore, I cannot communicate with you at all today until I get home again tonight - 5:30 EST. Obviously whatever was causing me problems starts itself before windows starts up or somewhere where it hasn't been killed yet. And it is somewhere in IE because I don't have problems until I connect to the internet. All of my other programs seem to be working fine. I have spoken with my employer and we have decided that we are going to do a clean install of an upgraded operating system. That seems to be the concensis of the only way to get rid of what is troubling our computer. I can check for whatever response you give me when I get home tonight, but by tomorrow, I will have disconnected my PC and gotten it down to the person that is going to install the XP OS. I will check in with you later, or tomorrow to give you an update from my home computer and, of course, to thank you for all of your hard work. If you want, you can put a message in my message box, I think I can get to that from my phone, but I can't get to the forum board, because the page is too large for my phone browser.
Hi,

I have spoken with my employer and we have decided that we are going to do a clean install of an upgraded operating system. That seems to be the concensis of the only way to get rid of what is troubling our computer.

I would agree with that. It looks like the infections had taken too much of a hold. It could be that the Malware finally nuked your internet, it could be that the Malware was so deeply integrated into the system that when AVG and the tools we were running tried to remove it new issues were being caused. At the end of the day, I think this choice is the right choice.

I am sorry we couldn't "win" this one. I hope you have more luck in the future.

Let me know if I can be of any more help.

Thanks.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI