Unsolved

This post is more than 5 years old

57 Posts

1917

May 12th, 2007 19:00

Bubble Warnings, Red Desktop, IE Window Opens etc....

I am having the following problems:

1.  Red desktop - despite blue being designated in "display" section of control panel.  Reasserts itself soon after any change by me.
2.  Bubble pop ups on right, just over task bar (usually where "updates are available" comes up).  There are about 5 versions:
   a.  Warning!  your computer is infected
   b.  Your computer is working slowly
   c.  A minimum of 12 spyware entries found
   d.  Your computer is not protected against spyware
   e.  Your security and privacy are at risk
3.  A centrally located pop up window reading, in part:
Windows Security Center - Warning! (upper left hand corner)
Resources(on left)
- How to remove
Win32.TrojanRX
                                                         
 Threat Name    Risk Level (on right)
Win32.TrojanRX    XXXXX
To remove detected spyware pleae click here for MSn search results...(on lower right)
etc...
4.  An IE window opens and tries to locate http://antispysolutions.com
5.  3 DOS-like windows open consecutively, then close the same way.  Have sysrlb in the upper left.  Then a small window with "LoadLibrary Manager had to close" on it comes up.
 
My Hijack Log
---------------------------------------------------------------------------------------------------
 
Logfile of HijackThis v1.99.1
Scan saved at 4:00:11 PM, on 5/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\msorcl32.exe
C:\Program Files\PurgeIE\PurgeIE_Service.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {30000273-8230-4dd4-be4f-6889d1e74167} - (no file)
O2 - BHO: (no name) - {5929cd6e-2062-44a4-b2c5-2c7e78fbab38} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {7C2F2C76-1489-450D-B8FB-0B9692D788F9} - (no file)
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {bb936323-19fa-4521-ba29-eca6a121bc78} - (no file)
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MsgCenterExe] "C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe"  -osboot
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2564B8E6-7D84-11D4-A689-30475BC10000} (Tkweb Control) - http://www.toolkitcma.com/tkweb/tkweb.cab
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01_4.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1148663182501
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.hp.com/ediags/dd/install/guidedsolutions.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.62/code/iPIX-ImageWell-ipix.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CEB197FA-65F5-40DB-907F-263D75C88043}: NameServer = 194.54.90.226
O20 - AppInit_DLLs: C:\WINDOWS\system32\perfc000.dat
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: AFSEGTGF Windows Service - Unknown owner - C:\WINDOWS\system32\dsujs.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PurgeIE XP Service (PurgeIEservice) - Assistance & Resources for Computing, Inc. - C:\Program Files\PurgeIE\PurgeIE_Service.exe
 

4 Apprentice

 • 

20.5K Posts

May 12th, 2007 20:00

Hi, Larrym1232,

We reviewing your log and will reply soon. Thank you for waiting patiently.

2 Intern

 • 

297 Posts

May 13th, 2007 03:00

Hi my name is Hoov and I will be helping you get your system clean
To get your computer clean I must ask that you do a few things to make sure this will happen.
First, do everything I suggest and nothing more.The removal of malware needs to be done in a specific order. That way it will be fully removed when we are done.
  • If you can't follow my instructions because they don't make sense, then ask for clarification.If you can't follow them because what I am asking you to do can't be done, then let me know.
    If for some other reason there is a problem with the instructions, just let me know, and we will deal with them.
Second, work with me until the end. Removing the malware is just the first step. After that we need to make sure you will be able to protect your computer from spyware in the future.
Securing your computer from malware is a process.
  • Getting rid of the malware that already is on your computer.Get the tools and learn how to use them.
    Then there is attitude. You need to make sure you use the tools regularly, and your surfing habits don't leave you open to malware.
I am tearing into your log right now, as soon as I have something for you to do, I will post it up here.

57 Posts

May 13th, 2007 11:00

I await your instructions.

2 Intern

 • 

297 Posts

May 14th, 2007 00:00

First, just to let you know fixing this may take several days, it may seem like we are not going anywhere, but first we have to gather information before we can get to removing the problem. Go to your copy of Hijackthis and rename hijackthis.exe to analyser.exe. There is some malware that can hide from hijackthis.exe. Please download Combofix from here: http://download.bleepingcomputer.com/sUBs/combofix.exe Or http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe ** Take note that the links are case sensitive Save ComboFix to the desktop. 1. Double click on combo.exe & follow the prompts. 2. When finished, it will produce a logfile located at C:\ComboFix.txt. 3. Post the contents of that log in your next reply with all other logs requested. Note: Do not mouseclick combofix's window while it is running. That may cause your system to stall/hang. Do not proceed with the rest of the fix if you fail to run combofix ** ComboFix will not run in Safemode. Please download SmitfraudFix (by S!Ri) to your Desktop.

 _____________________________

Download : Download AVG Anti-Spyware 7.5 and save that file to your desktop. This is a 30 day trial of the program

  1. Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop and double-click it to launch the set up program.
  2. Select Change state" to inactivate 'Resident Shield' and 'Automatic Updates'
  3. Right click on AVG Anti-Spyware in the system tray and uncheck "Start with Windows".
  4. Go to Start > Run and type: services.msc
  5. Press "OK".
  6. In Services, click the "Extended tab" and scroll down the list to find AVG anti-spyware 7.5 guard.
  7. When you find the guard service, double-click on it.
  8. In the Properties Window > General Tab that opens, click the "Stop" button.
  9. From the drop-down menu next to "Startup Type", click on "Manual".
  10. Now click "Apply", then "OK" and close the Services window.
  11. Once the setup is complete you will need run AVG Anti-Spyware and update the definition files.
  12. On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
    • If you are having problems with the updater, manually update with the AVG Anti-Spyware Full database installer from here.
    • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
    • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
    • Under "Reports"
      • Select "Automatically generate report after every scan"
      • Un-Select "Only if threats were found"
      Close AVG Anti-Spyware, Do Not run a scan just yet. We will shortly.

    ______________________________

      Double-click smitfraudfix.exe Select option #1 - Search by typing 1 and press Enter This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply. Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. http://www.beyondlogic.org/consulting/processutil/processutil.htm IMPORTANT: Do NOT run any other options until you are asked to do so! Now give me a new hijackthis log using the renamed analyser.exe. So your next post will have the log from Combofix, Smitfraud and hijackthis.



      Message Edited by ZAGuru_Hoov on 05-13-2007 08:57 PM

      2 Intern

       • 

      297 Posts

      May 14th, 2007 01:00

      Go to the folder C:\Program Files\ HijackThis <-Folder and right click on the filename hijackthis.exe and select rename. Then just type in analyser.exe .

      57 Posts

      May 14th, 2007 01:00

      I think this may take a little longer than you think. :smileyvery-happy:
       
      Just exactly how do I change the name of the hijackthis file?
       
      Meanwhile, I will download all the above programs and be prepared to run them.
       
      Thanks,
       
      L

      57 Posts

      May 14th, 2007 10:00

      Hoov,
       
      I went to Program files and then opened the folder HijackThis and then renamed the file HijackThis (has a clump of dynamite and a plunger icon) "analyser" (I did not add ".exe" because there was no ".exe" to begin with).  I could not see any .exe extension except when I held the cursor over the folder HijackThis.  It seems to have added the .exe to the new name and now indicates that analyser.exe is inside the folder.
       
      I feel this is correct, but want to double check.
       
      Thanks,
       
      L
       
       

      57 Posts

      May 14th, 2007 13:00

      Hoov,
       
      I am pretty sure I did the renaming of HijackThis right so I moved forward.
       
      1.  I set up and ran the ComboFix.exe and the resulting log is below.
       
      2.  I set up the AVG Anti-Spyware but had trouble updating it.  I got a message, "Sorry, the server is not ready to serve, please try again later."  I downloaded the updating software, but when I run it, I get, "ewido anti-malware could not be found on your system."
       
      I won't move forward until I hear something from you.
       
      My ComboFix log
      --------------------------------------------------------------------------------------------------------------------------
       
      "Beth" - 2007-05-14  9:34:41    Service Pack 2 
      ComboFix 07-05.13.V - Running from: "C:\Documents and Settings\Beth\Desktop\Hoov Instructions\"

      ((((((((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))

      C:\WINDOWS\system32\dlh9jkd1q8.exe
      C:\WINDOWS\764.exe
      C:\WINDOWS\system32\smpi1\DealioKit1-stub-0.exe
      C:\Temp\17O7\tmpTF.log
      C:\WINDOWS\system32\bszip.dll
      C:\WINDOWS\system32\perfc000.dat
      C:\WINDOWS\159x.exe
      C:\WINDOWS\system32\helper.sys
      C:\WINDOWS\system32\smpi1
      C:\Temp\17O7
      C:\WINDOWS\system32\perfc000.dat

      (((((((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))

      -------\core

      (((((((((((((((((((((((((((((((   Files Created from 2007-04-05 to 2007-05-14  ))))))))))))))))))))))))))))))))))

      2007-05-12 15:12 0 --a------ C:\WINDOWS\system32\msdn_lib.dll
      2007-05-12 14:06   d-------- C:\Program Files\SUPERAntiSpyware
      2007-05-12 14:06   d-------- C:\DOCUME~1\Beth\APPLIC~1\SUPERAntiSpyware.com
      2007-05-12 14:06   d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
      2007-05-12 14:05   d-------- C:\Program Files\Common Files\Wise Installation Wizard
      2007-05-12 14:00   d-------- C:\Program Files\RogueRemover
      2007-05-11 07:31 4 --a------ C:\WINDOWS\system32\stfv.bin
      2007-05-11 07:04 18,432 --a------ C:\WINDOWS\sysrlb32.exe
      2007-05-11 06:46 12 --a------ C:\WINDOWS\system32\sl.bin
      2007-05-11 06:45 81,927 --a------ C:\WINDOWS\system32\msorcl32.exe
      2007-05-11 06:45 31,744 --a------ C:\WINDOWS\wml.exe
      2007-05-11 06:45 31,488 --a------ C:\WINDOWS\mssvr.exe
      2007-05-11 06:45 30,976 --a------ C:\WINDOWS\Biprep.exe
      2007-05-11 06:45 30,976 --a------ C:\WINDOWS\bi.dll
      2007-05-11 06:45 30,208 --a------ C:\WINDOWS\mspphe.dll
      2007-05-11 06:45 29,696 --a------ C:\WINDOWS\bjam.dll
      2007-05-11 06:45 29,184 --a------ C:\WINDOWS\system32\vxddsk.exe
      2007-05-11 06:45 28,928 --a------ C:\WINDOWS\flt.dll
      2007-05-11 06:45 27,648 --a------ C:\WINDOWS\system32\WER8274.DLL
      2007-05-11 06:45 27,136 --a------ C:\WINDOWS\pbar.dll
      2007-05-11 06:45 26,112 --a------ C:\WINDOWS\updatetc.exe
      2007-05-11 06:45 21,760 --a------ C:\WINDOWS\cdsm32.dll
      2007-05-11 06:45 21,504 --a------ C:\WINDOWS\satmat.exe
      2007-05-11 06:45 19,712 --a------ C:\WINDOWS\swin32.dll
      2007-05-11 06:45 19,456 --a------ C:\WINDOWS\vxddsk.exe
      2007-05-11 06:45 19,200 --a------ C:\WINDOWS\7search.dll
      2007-05-11 06:45 18,688 --a------ C:\WINDOWS\system32\wml.exe
      2007-05-11 06:45 18,176 --a------ C:\WINDOWS\2020search.dll
      2007-05-11 06:45 17,408 --a------ C:\WINDOWS\system32\MSIXU.DLL
      2007-05-11 06:45 15,104 --a------ C:\WINDOWS\voiceip.dll
      2007-05-11 06:45 14,592 --a------ C:\WINDOWS\saiemod.dll
      2007-05-11 06:45 12,800 --a------ C:\WINDOWS\system32\wmvds32.dll
      2007-05-11 06:45 12 --a------ C:\WINDOWS\system32\gtv_sd.bin
      2007-05-11 06:45 11,776 --a------ C:\WINDOWS\salm.exe
      2007-05-11 06:45 11,008 --a------ C:\WINDOWS\180ax.exe
      2007-05-11 06:45 10,759 --a------ C:\WINDOWS\341x.exe
      2007-05-11 06:45 10,496 --a------ C:\WINDOWS\2020search2.dll
      2007-05-10 03:04   d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
      2007-05-07 16:36 27,173 --a------ C:\WINDOWS\233x.exe
      2007-05-04 15:32 13,085 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Music Converter.dat

      ((((((((((((((((((((((((((((((((((((((((((((((((   Find3M Report   )))))))))))))))))))))))))))))))))))))))))))))))))))))

      2007-05-14 01:48:06 -------- d-----w C:\Program Files\Google
      2007-05-14 01:47:46 -------- d-----w C:\DOCUME~1\Beth\APPLIC~1\Google
      2007-05-14 00:15:41 -------- d--h--w C:\Program Files\InstallShield Installation Information
      2007-05-12 19:04:35 -------- d-----w C:\Program Files\PurgeIE
      2007-05-12 19:04:34 -------- d-----w C:\Program Files\Microsoft Works
      2007-05-12 19:04:33 -------- d-----w C:\Program Files\Messenger
      2007-05-04 19:46:03 4,140,920 ----a-w C:\WINDOWS\system32\SpoonUninstall.exe
      2007-04-30 15:46:10 745,600 ----a-w C:\WINDOWS\system32\aswBoot.exe
      2007-04-30 15:41:55 85,952 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
      2007-04-30 15:41:42 94,552 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
      2007-04-30 15:39:41 23,416 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
      2007-04-30 15:38:51 43,176 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
      2007-04-30 15:37:23 26,888 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
      2007-04-30 15:35:28 95,872 ----a-w C:\WINDOWS\system32\AVASTSS.scr
      2007-04-01 23:12:41 240 ----a-w C:\DOCUME~1\Beth\APPLIC~1\wklnhst.dat
      2007-03-28 23:27:27 104,168 ----a-w C:\WINDOWS\hpoins04.dat
      2007-03-28 23:19:00 -------- d-----w C:\Program Files\Common Files\HP
      2007-03-28 23:17:21 -------- d-----w C:\Program Files\HP
      2007-03-28 23:17:21 -------- d-----w C:\Program Files\Hewlett-Packard
      2007-03-24 01:06:02 -------- d-----w C:\DOCUME~1\Beth\APPLIC~1\Template
      2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
      2007-03-15 20:43:49 -------- d-----w C:\DOCUME~1\Beth\APPLIC~1\Roni Music
      2007-03-15 20:43:46 -------- d-----w C:\Program Files\Roni Music
      2007-03-08 15:36:28 577,536 ----a-w C:\WINDOWS\system32\user32.dll
      2007-03-08 15:36:28 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
      2007-03-08 15:36:28 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
      2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys
      2007-02-05 20:17:02 185,344 ----a-w C:\WINDOWS\system32\upnphost.dll

      ((((((((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))
       
       
      *Note* empty entries & legit default entries are not shown
       
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
      {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-01-12 20:38]
      {5CA3D70E-1895-11CF-8E15-001234567890}=C:\WINDOWS\System32\DLA\DLASHX_W.DLL [2005-09-08 06:20]
      {AE7CD045-E861-484f-8273-0445EE161910}=C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [2003-05-15 01:03]
      {CA6319C0-31B7-401E-A518-A07C3DB8F777}=c:\Program Files\BAE\BAE.dll [2006-02-22 20:00]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
      "DLA"="C:\\WINDOWS\\System32\\DLA\\DLACTRLW.EXE"
      "igfxtray"="C:\\WINDOWS\\system32\\igfxtray.exe"
      "igfxhkcmd"="C:\\WINDOWS\\system32\\hkcmd.exe"
      "igfxpers"="C:\\WINDOWS\\system32\\igfxpers.exe"
      "HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe"
      "avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
      "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
      "MsgCenterExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\RealOneMessageCenter.exe\"  -osboot"
      "HP Software Update"="\"c:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe\""
      "HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 06:20]
      "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 09:35]
      "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 09:32]
      "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 09:36]
      "HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-06-22 09:05]
      "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-30 11:42]
      "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-04-04 07:21]
      "MsgCenterExe"="C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" []
      "HP Software Update"="c:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 13:38]
      "HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 15:18]
      [HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
      "RunNarrator"="Narrator.exe"
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
      "NoCDBurning"=dword:00000000
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
      "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 13:55]

      HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon
      HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
         Authentication Packages msv1_0\0\0
         Security Packages kerberos\0msv1_0\0schannel\0wdigest\0\0
         Notification Packages scecli\0\0
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^acrobat assistant.lnk
      C:\PROGRA~1\Adobe\ACROBA~1.0\Distillr\acrotray.exe
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^adobe reader speed launch.lnk
      C:\PROGRA~1\Adobe\ACROBA~2.0\Reader\READER~1.EXE
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^quickbooks update agent.lnk
      C:\PROGRA~1\COMMON~1\Intuit\QUICKB~1\QBUpdate\qbupdate.exe
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\buildbu
      c:\dell\bldbubg.exe
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\corel photo downloader
      C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dellsupport
      "C:\Program Files\Dell Support\DSAgnt.exe" /startup
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\isuspm startup
      "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\isusscheduler
      "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mimboot
      C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mskdetectorexe
      C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\qbreminderflash
      "C:\Program Files\Intuit\QuickBooks 2005\Atom\QBReminder.exe"
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\quicktime task
      "C:\Program Files\QuickTime\qttask.exe" -atboottime
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\realtray
      C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\soundmaxpnp
      C:\Program Files\Analog Devices\Core\smax4pnp.exe
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sunjavaupdatesched
      C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
       
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
      HTTPFilter HTTPFilter\0\0
      LocalService Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
      NetworkService DnsCache\0\0
      DcomLaunch DcomLaunch\0TermService\0\0
      rpcss RpcSs\0\0
      imgsvc StiSvc\0\0
      termsvcs TermService\0\0
      HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost

      Contents of the 'Scheduled Tasks' folder
      C:\WINDOWS\tasks\ISP signup reminder 1.job
      ********************************************************************
      catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
      Rootkit scan 2007-05-14 09:39:26
      Windows 5.1.2600 Service Pack 2 NTFS
      scanning hidden processes ...
      scanning hidden services ...
      scanning hidden autostart entries ...
      scanning hidden files ...
      scan completed successfully
      hidden processes: 0
      hidden services: 0
      hidden files: 0

      ********************************************************************
      Completion time: 2007-05-14  9:40:18 - machine was rebooted
      C:\ComboFix-quarantined-files.txt ... 2007-05-14 09:40
       
       

      57 Posts

      May 14th, 2007 16:00

      Hoov,
       
      I was able to change my Desktop back to its original photo and I am not getting any of the old popup symptoms.:smileytongue:
       
      Is my system already clean?
       
      If not, I am ready to go forward.
       
      Thanks so far!!!!!!!
       
      L

      2 Intern

       • 

      297 Posts

      May 14th, 2007 16:00

      Try using the update in the program again. If that doesn't work use this link to get the file. http://downloads.ewido.net/avgas-signatures-full-current.exe

      2 Intern

       • 

      297 Posts

      May 14th, 2007 17:00

      No you are not clean yet. You are just started on the path. We need to make sure everything is gone.

      57 Posts

      May 14th, 2007 17:00

      Hoov,
       
      The new update file worked (I think).  The AVG program should be ready to go.
       
      I will now post the 2 remaining logs, Smitfraud and HijackThis.
       
      Smitfraud Log
      -------------------------------------------------------------------------------------------------------------
       
      SmitFraudFix v2.181
      Scan done at 14:06:16.65, Mon 05/14/2007
      Run from C:\Documents and Settings\Beth\Desktop\Hoov Instructions\SmitfraudFix
      OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
      The filesystem type is NTFS
      Fix run in normal mode
      »»»»»»»»»»»»»»»»»»»»»»»» Process
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\DLA\DLACTRLW.EXE
      C:\WINDOWS\system32\hkcmd.exe
      C:\WINDOWS\system32\igfxpers.exe
      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\PurgeIE\PurgeIE_Service.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\system32\HPZipm12.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\WINDOWS\system32\cmd.exe
      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      »»»»»»»»»»»»»»»»»»»»»»»» C:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
      C:\WINDOWS\system32\ld????.tmp FOUND !
      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Beth

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Beth\Application Data

      »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Beth\FAVORI~1

      »»»»»»»»»»»»»»»»»»»»»»»» Desktop

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

      »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

      »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
       
      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
      "Source"="About:Home"
      "SubscribedURL"="About:Home"
      "FriendlyName"="My Current Home Page"
       
      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, following keys are not inevitably infected!!!
      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, following keys are not inevitably infected!!!
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=""

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
      !!!Attention, following keys are not inevitably infected!!!
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "System"=""

      »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32
       
      »»»»»»»»»»»»»»»»»»»»»»»» DNS
      Your computer may be victim of a DNS Hijack: 194.54.x.x detected !
      Description: Intel(R) PRO/100 VE Network Connection - Packet Scheduler Miniport
      DNS Server Search Order: 194.54.90.226
      HKLM\SYSTEM\CCS\Services\Tcpip\..\{CEB197FA-65F5-40DB-907F-263D75C88043}: DhcpNameServer=192.168.2.1
      HKLM\SYSTEM\CCS\Services\Tcpip\..\{CEB197FA-65F5-40DB-907F-263D75C88043}: NameServer=194.54.90.226
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{CEB197FA-65F5-40DB-907F-263D75C88043}: DhcpNameServer=192.168.2.1
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{CEB197FA-65F5-40DB-907F-263D75C88043}: NameServer=194.54.90.226
      HKLM\SYSTEM\CS3\Services\Tcpip\..\{CEB197FA-65F5-40DB-907F-263D75C88043}: DhcpNameServer=192.168.2.1
      HKLM\SYSTEM\CS3\Services\Tcpip\..\{CEB197FA-65F5-40DB-907F-263D75C88043}: NameServer=194.54.90.226
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
      HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1

      »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

      »»»»»»»»»»»»»»»»»»»»»»»» End
       
       
       
      HijackThis (aka Analyser) Log
      ---------------------------------------------------------------------------------------------------------
       
      Logfile of HijackThis v1.99.1
      Scan saved at 2:09:11 PM, on 5/14/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\DLA\DLACTRLW.EXE
      C:\WINDOWS\system32\hkcmd.exe
      C:\WINDOWS\system32\igfxpers.exe
      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\PurgeIE\PurgeIE_Service.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\system32\HPZipm12.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\Program Files\HijackThis\analyser.exe
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
      O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
      O2 - BHO: (no name) - {30000273-8230-4dd4-be4f-6889d1e74167} - (no file)
      O2 - BHO: (no name) - {5929cd6e-2062-44a4-b2c5-2c7e78fbab38} - (no file)
      O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
      O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)
      O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
      O2 - BHO: (no name) - {7C2F2C76-1489-450D-B8FB-0B9692D788F9} - (no file)
      O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
      O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
      O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
      O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll
      O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
      O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file)
      O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
      O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
      O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [MsgCenterExe] "C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe"  -osboot
      O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
      O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {2564B8E6-7D84-11D4-A689-30475BC10000} (Tkweb Control) - http://www.toolkitcma.com/tkweb/tkweb.cab
      O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01_4.cab
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1148663182501
      O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.hp.com/ediags/dd/install/guidedsolutions.cab
      O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
      O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
      O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.62/code/iPIX-ImageWell-ipix.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{CEB197FA-65F5-40DB-907F-263D75C88043}: NameServer = 194.54.90.226
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
      O23 - Service: AFSEGTGF Windows Service - Unknown owner - C:\WINDOWS\system32\dsujs.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
      O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: PurgeIE XP Service (PurgeIEservice) - Assistance & Resources for Computing, Inc. - C:\Program Files\PurgeIE\PurgeIE_Service.exe
       

      2 Intern

       • 

      297 Posts

      May 15th, 2007 01:00

      First, the AVG guard didn't get turned off, so..
      • Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop and double-click it to launch the set up program. 
      • Select “Change state" to inactivate 'Resident Shield' and 'Automatic Updates' 
      • Right click on AVG Anti-Spyware in the system tray and uncheck "Start with Windows". 
      • Go to Start > Run and type: services.msc 
      • Press "OK". 
      • In Services, click the "Extended tab" and scroll down the list to find AVG anti-spyware 7.5 guard. 
      • When you find the guard service, double-click on it. 
      • In the Properties Window > General Tab that opens, click the "Stop" button. 
      • From the drop-down menu next to "Startup Type", click on "Manual". 
      • Now click "Apply", then "OK" and close the Services window.

      Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

      Reboot your computer in Safe Mode.


      • If the computer is running, shut down Windows, and then turn off the power.
      • Wait 30 seconds, and then turn the computer on.
      • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
      • Ensure that the Safe Mode option is selected.
      • Press Enter. The computer then begins to start in Safe mode.
      • Login on your usual account.


      _____________________________
      Once in Safe Mode, double-click the SmitfraudFix.exe again.
      Select option #2 - Clean by typing 2 and press Enter.
      Wait for the tool to complete and disk cleanup to finish.
      You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
      The tool will also check if wininet.dll is infected. If it is infected and a clean version is found, you will be prompted to replace the infected wininet.dll with the clean file. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.
      A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.
      The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
      ______________________________
      Clean out your Temporary Internet files. Proceed like this:


      • Quit Internet Explorer and quit any instances of Windows Explorer.
      • Click Start, click Control Panel, and then double-click Internet Options.
      • On the General tab, click Delete Files under Temporary Internet Files.
      • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
      • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
      • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
      • Click OK.


      Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.
      Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin
      _____________________________
      Close ALL open Windows / Programs / Folders. Close ALL open Windows / Programs / Folders.


      • While in Safe Mode, Scan with AVG Anti-Spyware as follows:
        1. Launch AVG Anti-Spyware, click on the "Scanner" button and choose the "Settings" tab.

        • Under "How to act?", click on "Recommended actions" and choose "Quarantine" to set default action for detected malware.
        • Under "How to Scan?" check all (default).
        • Under "Possibly unwanted software" check all (default).
        • Under "What to Scan?" make sure "Scan every file" is selected (default).
        • Under "Reports" select "Automatically generate report after every scan" and UNcheck "Only if threats were found".
        2. Click the "Scan" tab to return to scanning options.
        3. Click "Complete System Scan" to start.
        4. When the scan has finished you will be presented with a list of infected objects found. Click "Apply all actions" to place the files in Quarantine.
        IMPORTANT! Do not save the report before you have clicked the Apply all actions button. If you do, the log that is created will indicate "No action taken", making it more difficult to interpret the report. So be sure you save it only AFTER clicking the "Apply all actions" button?
        5. Click on "Save Report" to view all completed scans. Click on the most recent scan you just performed and select "Save report as" - the default file name will be in date/time format as follows: Report-Scan-20060620-142816.txt. Save to your desktop. A copy of each report will also be saved in C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports\
        6. Exit AVG Anti-Spyware when done, reboot your system back into Normal Mode.

      Also I have a question, did someone else have you run RogueRemover?

      5 Journeyman

       • 

      15.6K Posts

       • 

      45K Points

      May 15th, 2007 11:00

      ZA,
       
      When Larry first posted in the virus/spyware forum, I suggested he could run RogueRemover and/or SuperAntiSpyware.   I also gave him instructions on how to generate/post a HJT log here. 
       
       
       
      I have been keeping an eye on this thread, but have done nothing to interfere with the sequence of help you've been offering since you took on the log.
       

      57 Posts

      May 15th, 2007 12:00

      Hoov,
       
      No, I take full responsibility for running that program.  For some reason, probably since it had been recommended previously, I disassociated it and somehow it never occurred to me that it was even relevant.  It's funny, the technical directions are the "easy" part, the "do only what I tell you" is the really difficult part.  It would probably make a good study in psychology!  I am trying very hard to comply and think of myself as pretty good at taking instructions, but there's the proof!
       
      Anyway, I ran into a roadblock in the last set of directions. I managed to:
       
      1.  fix the AVG (I hope),
       
      2.  run through the Smitfraud exercises in Safe Mode and save a log, which I am posting below (there was no indication that wininet.dll was infected),
       
      3.  clean out my Temporary Internet Files (there was no "Security info" item present),
       
      4.  empty recycle bin.
       
      The problem was that in Safe Mode, the window of the AVG software is too large to fit my screen and I can't see (much less click)  on the right spots.  I tried to restore it down, but it won't budge.
       
      Smitfraud Log
      -----------------------------------------------------------------------------------------------------------
       
      SmitFraudFix v2.181
      Scan done at  8:36:20.28, Tue 05/15/2007
      Run from C:\Documents and Settings\Beth\Desktop\Hoov Instructions\SmitfraudFix
      OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
      The filesystem type is NTFS
      Fix run in safe mode
      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
      !!!Attention, following keys are not inevitably infected!!!
      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll
      »»»»»»»»»»»»»»»»»»»»»»»» Killing process

      »»»»»»»»»»»»»»»»»»»»»»»» hosts
      127.0.0.1       localhost
      »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
      GenericRenosFix by S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
      C:\WINDOWS\system32\ld????.tmp Deleted
      »»»»»»»»»»»»»»»»»»»»»»»» DNS
      HKLM\SYSTEM\CCS\Services\Tcpip\..\{CEB197FA-65F5-40DB-907F-263D75C88043}: DhcpNameServer=192.168.2.1
      HKLM\SYSTEM\CCS\Services\Tcpip\..\{CEB197FA-65F5-40DB-907F-263D75C88043}: NameServer=194.54.90.226
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{CEB197FA-65F5-40DB-907F-263D75C88043}: DhcpNameServer=192.168.2.1
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{CEB197FA-65F5-40DB-907F-263D75C88043}: NameServer=194.54.90.226
      HKLM\SYSTEM\CS3\Services\Tcpip\..\{CEB197FA-65F5-40DB-907F-263D75C88043}: DhcpNameServer=192.168.2.1
      HKLM\SYSTEM\CS3\Services\Tcpip\..\{CEB197FA-65F5-40DB-907F-263D75C88043}: NameServer=194.54.90.226
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
      HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1

      »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
      !!!Attention, following keys are not inevitably infected!!!
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "System"=""

      »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
       
      Registry Cleaning done.
       
      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
      !!!Attention, following keys are not inevitably infected!!!
      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» End
       
       
       
       
      No Events found!

      Top