Unsolved

This post is more than 5 years old

44 Posts

4031

April 4th, 2007 00:00

HijackThis log - web redirects & windows security alerts

Logfile of HijackThis v1.99.1
Scan saved at 9:52:27 PM, on 4/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
C:\WINDOWS\system32\Rundll32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\adirss.exe
C:\WINDOWS\system32\adirka.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\fix my computer!\Feb 8 2007 spyware removers et al\Hijackthis\HijackThis.exe
O1 - Hosts: 127.0.0.2 www.mpeghunter.com
O1 - Hosts: 127.0.0.3 www.passdb.com127.0.0.1 www.trendmicro.com
O2 - BHO: Shell Event Object Class - {00534B55-3155-CA4F-B41D-0E922121D03C} - C:\WINDOWS\system32\cscentfy.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - C:\WINDOWS\system32\tmpCD.tmp.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {db89d043-3bdd-4882-9043-58f1b1d75b0c} - C:\WINDOWS\system32\dsddro.dll
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
O4 - HKLM\..\Run: [sysinter] C:\WINDOWS\system32\adirss.exe
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\effcbx.dll",setvm
O4 - HKLM\..\Run: [winctl] winctl.exe /install
O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\system32\rpcc.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [adirka] C:\WINDOWS\system32\adirka.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Broken Internet access because of LSP provider 'rsvp32_2.dll' missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{ABDC76CF-6624-4DE0-8812-22FFA71CEF46}: NameServer = 192.168.1.1
O20 - AppInit_DLLs: C:\WINDOWS\system32\win_w6.dll
O20 - Winlogon Notify: dsddro - C:\WINDOWS\SYSTEM32\dsddro.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: DCOM Server 20509 - {2C1CD3D7-86AC-4068-93BC-A02304B20509} - C:\WINDOWS\system32\khsafn.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Unknown owner - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ieupdater22 (Microsoft IEUpdater22) - Unknown owner - C:\Documents and Settings\Mr. Troy Russell\ie_updater.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
 
 
Hi, been getting website redirects and then after leaving my computer on today I come back about 8 hours later and see the blue screen of death. after reboot i got two message popups "Windows File Protection: Files that are required for Windows to run properly have been replaced by unrecognized versions. To maintain system stability, Windows must restore the original versions of these files. Insert your Windows XP Professional Service Pack 2 CD now" and "Windows Security Alert:  To help protect your computer, Windows Firewall has blocked some features of this program. Do you want to keep blocking this program? Name: Windows Explorer. Publisher: Microsoft Corporation."
 
sounds pretty serious. and I don't have the service pack cd. don't know if I ever had it.
 
Ive run AVG and search & destroy antispywares but not in safe mode. I'm not sure what to do about the 2 alert popups so I've just left them up for now. I'm a little worried to restart my computer without addressing these first.
 
Thanks a lot if anyone can help out.
 

10.4K Posts

April 4th, 2007 01:00


TJGRS

Your log is heavily infected. It will take a few runs at this to completely remove the infections, so please be patient

1. Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :

  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.

  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
bamajim   Graduate of MRU
CastleCops  Instructor

44 Posts

April 4th, 2007 10:00



SDFix: Version 1.76
Run by Mr. Troy Russell - Wed 04/04/2007 -  7:32:16.21
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
EXAMPLE
Runtime
wincom32
ImagePath:
\??\C:\WINDOWS\system32\main.sys
\??\C:\WINDOWS\System32\drivers\runtime.sys
\??\C:\WINDOWS\system32\wincom32.sys
EXAMPLE Deleted
Runtime Deleted
wincom32 Deleted

Restoring Windows Registry Entries
Restoring Default Hosts File
Reset AppInit_DLLs value

Rebooting...
Normal Mode:
Checking Files:
Below files will be copied to Backups folder then removed:
C:\WINDOWS\SYSTEM32\WIN_W6.DLL - Deleted
C:\WINDOWS\SYSTEM32\SFXZMT~1.DLL  - Deleted
C:\WINDOWS\SYSTEM32\SFXZMT~2.DLL  - Deleted
C:\WINDOWS\SYSTEM32\SFXZMT~3.DLL  - Deleted
C:\WINDOWS\SYSTEM32\SFXZMT~4.DLL  - Deleted
C:\WINDOWS\system32\ma.exe.exe - Deleted
C:\WINDOWS\system32\pep.exe.exe - Deleted
C:\WINDOWS\system32\zoom.exe.exe - Deleted
C:\DOCUME~1\MR476D~1.TRO\LOCALS~1\Temp\tmp50.tmp.exe - Deleted
C:\DOCUME~1\MR476D~1.TRO\LOCALS~1\Temp\tmpAD3.tmp.exe - Deleted
C:\DOCUME~1\MR476D~1.TRO\LOCALS~1\Temp\tmpAD4.tmp.exe - Deleted
C:\DOCUME~1\MR476D~1.TRO\LOCALS~1\Temp\tmpBF.tmp.exe - Deleted
C:\DOCUME~1\MR476D~1.TRO\LOCALS~1\Temp\tmpC6.tmp.exe - Deleted
C:\DOCUME~1\MR476D~1.TRO\LOCALS~1\Temp\tmpCD.tmp.exe - Deleted
C:\Documents and Settings\Mr. Troy Russell\ie_updater.exe - Deleted
C:\DOCUME~1\MR476D~1.TRO\LOCALS~1\Temp\abc123.pid - Deleted
C:\WINDOWS\system32\adirka.dll - Deleted
C:\WINDOWS\system32\adirka.exe - Deleted
C:\WINDOWS\system32\adirss.exe - Deleted
C:\WINDOWS\system32\rpcc.exe - Deleted
C:\WINDOWS\system32\svcp.csv - Deleted
C:\WINDOWS\system32\wincom32.ini - Deleted
C:\WINDOWS\system32\wincom32.sys - Deleted
C:\WINDOWS\system32\winsub.xml - Deleted
C:\WINDOWS\Temp\kaw - Deleted
 
ADS Check:
C:\WINDOWS\system32
No streams found.

                                 Final Check:
Remaining Services:
------------------
EXAMPLE
Runtime
Rootkit PE386 maybe active, Use a Rootkit scanner!
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"
"C:\\Program Files\\Java\\j2re1.4.2_03\\bin\\javaw.exe"="C:\\Program Files\\Java\\j2re1.4.2_03\\bin\\javaw.exe:*:Enabled:javaw"
"C:\\Program Files\\Soulseek\\slsk.exe"="C:\\Program Files\\Soulseek\\slsk.exe:*:Enabled:SoulSeek"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Disabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Disabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Disabled:AOL"
"C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"="C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe:*:Disabled:Sid Meier's Civilization 4"
"C:\\Documents and Settings\\Mr. Troy Russell\\Desktop\\slsk.exe"="C:\\Documents and Settings\\Mr. Troy Russell\\Desktop\\slsk.exe:*:Enabled:SoulSeek"
"C:\\Documents and Settings\\Mr. Troy Russell\\Desktop\\utorrent.exe"="C:\\Documents and Settings\\Mr. Troy Russell\\Desktop\\utorrent.exe:*:Enabled:µTorrent"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Documents and Settings\\Mr. Troy Russell\\Desktop\\RatioMaster-1.7.5\\RatioMaster.exe"="C:\\Documents and Settings\\Mr. Troy Russell\\Desktop\\RatioMaster-1.7.5\\RatioMaster.exe:*:Enabled:Ratio Master"
"C:\\WINDOWS\\system32\\smt.exe"="C:\\WINDOWS\\system32\\smt.exe:*:Enabled:enable"
"C:\\WINDOWS\\system32\\adirss.exe"="C:\\WINDOWS\\system32\\adirss.exe:*:Enabled:enable"
"C:\\WINDOWS\\Explorer.EXE"="C:\\WINDOWS\\Explorer.EXE:*:Enabled:enable"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"

Remaining Files:
---------------
C:\WINDOWS\system32\rsvp32_2.dll Found - LSP!
Backups Folder: - C:\SDFix\backups\backups.zip
Checking For Files with Hidden Attributes :
C:\Program Files\Microsoft Works Suite 2005\Setup\MNYINSTA.DLL
C:\Program Files\Microsoft Works Suite 2005\Setup\SETUPLNG.DLL
C:\Program Files\Microsoft Works Suite 2005\Setup\LAUNCHER.EXE
C:\Program Files\Microsoft Works Suite 2005\Setup\RMVSUITE.EXE
C:\Program Files\Microsoft Works Suite 2005\Setup\UNREGWTR.EXE
C:\WINDOWS\system32\svchb.exe
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch3\lock.tmp
C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp
C:\Documents and Settings\Mr. Troy Russell\Desktop\~WRL0724.tmp
C:\Documents and Settings\Mr. Troy Russell\Desktop\~WRL1887.tmp
C:\Documents and Settings\Mr. Troy Russell\Desktop\~WRL2722.tmp
C:\Documents and Settings\Mr. Troy Russell\Desktop\~WRL3067.tmp
C:\Documents and Settings\Mr. Troy Russell\Desktop\~WRL3784.tmp
                                 Finished
 
Logfile of HijackThis v1.99.1
Scan saved at 7:41:00 AM, on 4/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\fix my computer!\Feb 8 2007 spyware removers et al\Hijackthis\HijackThis.exe
O2 - BHO: Shell Event Object Class - {00534B55-3155-CA4F-B41D-0E922121D03C} - C:\WINDOWS\system32\cscentfy.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - C:\WINDOWS\system32\tmpCD.tmp.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {db89d043-3bdd-4882-9043-58f1b1d75b0c} - C:\WINDOWS\system32\dsddro.dll
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\effcbx.dll",setvm
O4 - HKLM\..\Run: [winctl] winctl.exe /install
O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\system32\rpcc.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Broken Internet access because of LSP provider 'rsvp32_2.dll' missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{ABDC76CF-6624-4DE0-8812-22FFA71CEF46}: NameServer = 192.168.1.1
O20 - Winlogon Notify: dsddro - C:\WINDOWS\SYSTEM32\dsddro.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: DCOM Server 20509 - {2C1CD3D7-86AC-4068-93BC-A02304B20509} - C:\WINDOWS\system32\khsafn.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Unknown owner - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ieupdater22 (Microsoft IEUpdater22) - Unknown owner - C:\Documents and Settings\Mr. Troy Russell\ie_updater.exe (file missing)
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
 
 
Thanks a lot

10.4K Posts

April 4th, 2007 13:00

TJGRS

Your Welcome

You may want to print out these instructions for reference

1. Copy and paste the following into NotePad (Not Wordpad)
  • sc stop ieupdater22
    sc delete ieupdater22

Click File ->> Save as ->>type in cmd.bat
  • Under "Save as type" Select " all files" ->>Save it to your Desktop
    Close Notepad
    The cmd.bat file should now appear on your Desktop
    Double Click that file (It will appear that nothing has happened, but that's o.k.)

2. We need to make sure we can see hidden files and folders

To enable the viewing of Hidden and System files follow these steps:
  • Right click on Start and select Explore.
    Select the Tools menu and click Folder Options.
    After the new window appears select the View tab.
    Put a checkmark in the checkbox labeled Display the contents of system folders.
    Under the Hidden files and folders section select the radio button labeled Show hidden files and folders. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
    Remove the checkmark from the checkbox labeled Hide protected operating system files.
    Click Yes To confirm
    Press the Apply button and then the OK button.

3. I need you to help us out with some research

Please go HERE

Put Your Name, and Dell HJT forum

and In the file to submit box, click Browse. Using Windows Explorer
  • (Right click on "Start," select "Explore," and you will see the "tree' of file folders in the left side of the window. Click on the "+" next to any folder name to expand its contents)
Locate the file

  • C:\WINDOWS\SYSTEM32\dsddro.dll

In the comments tell them that I asked you to upload the file
Then Select Send File.

Thanks

4. Please download the Killbox.
  • 1)Save it to the desktop and run it.
    2) Select " Delete on Reboot", and then select "All files".
    3) Copy the file names below to the clipboard by highlighting them and pressing Control-C:

    • C:\WINDOWS\system32\cscentfy.dll
      C:\WINDOWS\system32\tmpCD.tmp.dll
      C:\WINDOWS\system32\dsddro.dll
      C:\WINDOWS\system32\lsasss.exe
      C:\WINDOWS\system32\rpcc.exe
      C:\WINDOWS\system32\khsafn.dll


    4) Return to Killbox, go to the File menu, and choose " Paste from Clipboard".
    5) Click the red-and-white " Delete File" button.  Click " Yes" at the Delete on Reboot prompt.  Click " No" at the Pending Operations prompt.
Reboot your PC->>Rerun Hijackthis->> and post a fresh Hijackthis log
 
bamajim   Graduate of MRU
CastleCops Instructor

44 Posts

April 4th, 2007 22:00

Logfile of HijackThis v1.99.1
Scan saved at 7:26:21 PM, on 4/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\fix my computer!\Feb 8 2007 spyware removers et al\Hijackthis\HijackThis.exe
O2 - BHO: Shell Event Object Class - {00534B55-3155-CA4F-B41D-0E922121D03C} - C:\WINDOWS\system32\cscentfy.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - C:\WINDOWS\system32\tmpCD.tmp.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {db89d043-3bdd-4882-9043-58f1b1d75b0c} - C:\WINDOWS\system32\dsddro.dll (file missing)
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\effcbx.dll",setvm
O4 - HKLM\..\Run: [winctl] winctl.exe /install
O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\system32\rpcc.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Broken Internet access because of LSP provider 'rsvp32_2.dll' missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{ABDC76CF-6624-4DE0-8812-22FFA71CEF46}: NameServer = 192.168.1.1
O20 - Winlogon Notify: dsddro - dsddro.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: DCOM Server 20509 - {2C1CD3D7-86AC-4068-93BC-A02304B20509} - C:\WINDOWS\system32\khsafn.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Unknown owner - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ieupdater22 (Microsoft IEUpdater22) - Unknown owner - C:\Documents and Settings\Mr. Troy Russell\ie_updater.exe (file missing)
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
 
 
A couple things I thought I should mention. When I first rebooted, I got a automatic shutdown window having to do with the "lsasss.exe" file. Then after it rebooted again there was a window saying something about the "LSA Shell (Export Version)" not functioning. Still seeing the same Windows File Protection window pop up.
 
Bamajim - I uploaded the dsddro file but the website didn't give any indication that the upload was successful. I tried it twice and both times it said "uploading..." and Done at the bottom of the window, but that's it. Hopefully it worked, thanks again.

10.4K Posts

April 4th, 2007 23:00

TJGRS

Thanks for the upload, I'll check later and see what turned up. As far as the shell error message. It's the infection trying to protect itself. But we are getting there.

1. Rerun Hija]ckthis (scan only) and place checks beside the following entries
  • O2 - BHO: Shell Event Object Class - {00534B55-3155-CA4F-B41D-0E922121D03C} - C:\WINDOWS\system32\cscentfy.dll (file missing)
    O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - C:\WINDOWS\system32\tmpCD.tmp.dll (file missing)
    O2 - BHO: (no name) - {db89d043-3bdd-4882-9043-58f1b1d75b0c} - C:\WINDOWS\system32\dsddro.dll (file missing)
    O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
    O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\effcbx.dll",setvm
    O4 - HKLM\..\Run: [winctl] winctl.exe /install
    O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\system32\rpcc.exe
    O20 - Winlogon Notify: dsddro - dsddro.dll (file missing)
    O21 - SSODL: DCOM Server 20509 - {2C1CD3D7-86AC-4068-93BC-A02304B20509} - C:\WINDOWS\system32\khsafn.dll (file missing)
    O23 - Service: ieupdater22 (Microsoft IEUpdater22) - Unknown owner - C:\Documents and Settings\Mr. Troy Russell\ie_updater.exe (file missing)

Close all other open windows except Hijackthis and Select " Fix checked"

Close Hijackthis->>Reboot your PC->>Rerun Hijackthis and post a fresh log
 
bamajim   Graduate of MRU
CastleCops  Instructor

44 Posts

April 5th, 2007 02:00

Logfile of HijackThis v1.99.1
Scan saved at 10:55:57 PM, on 4/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\Rundll32.exe
c:\program files\internet explorer\iexplore.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\fix my computer!\Feb 8 2007 spyware removers et al\Hijackthis\HijackThis.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [winctl] winctl.exe /install
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Broken Internet access because of LSP provider 'rsvp32_2.dll' missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{ABDC76CF-6624-4DE0-8812-22FFA71CEF46}: NameServer = 192.168.1.1
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Unknown owner - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ieupdater22 (Microsoft IEUpdater22) - Unknown owner - C:\Documents and Settings\Mr. Troy Russell\ie_updater.exe (file missing)
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
 
Hi. Looks like things are improving. Still getting the "Windows File Protection . . . insert service pack" window though.
 
Thanks!

10.4K Posts

April 5th, 2007 11:00

TJGRS

We are making some progress. You at one time had AVG Anti-Spyware. We need to get it and use it again

1. Please download ATF Cleaner by Atribune.
  • Double-click ATF-Cleaner.exe to run the program.
    Under Main choose: Select All
    Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.
This will remove all files from the items that are checked so if you have some cookies you'd like to save. please move them to a different directory first.

2. Go here and Download AVG Anti-Spyware
( 30 day free trial version) Save it to Your Desktop
 
Double Click AVG Anti-Spyware-setup
(It will create its own folder)
Once the program starts You will be at the Status menu
  • Under "Your computers Security"
    Click Update now (next to last update)
    After the update loads
    Under Automatic updates Uncheck download and install updates automatically(recommended)
    (you can always select maual updates the next day)
At the top toolbar Click Scanner Then the settings tab
  • Under How to act? Set default action for detected malwareTo Quarantine
    Under how to scan All boxes should be checked
    Under Possibly unwanted software All boxes should be checked
    Under reports Select Automatically generate report after every scan
    Uncheck Only if threats were found
    Under what to scan Scan every file should be highlited
Exit AVG (But do not run it yet)
 
Reboot into Safe Mode
This can be done by
  • Restart your PC, and after it starts, but before you see the Windows Splash screen
    Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)
    Use your arrow keys and select Safe Mode and then Enter
Run AVG Anti-Spyware
  • Click scanner
    Select Complete system scan
Once the scan finishes
  • Select Apply all actions (The items found will be quarantined)
    Click save report as (Another window will open)
    Save it to your desktop
    (By default It will be saved in the AVG folder as)
    C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports
  • Exit AVG
     
    Reboot your PC in Normal Mode->>Re run Hijackthis and post a fresh Hijackthis log.
    Double click the report-scan txt. you saved to your desktop
    It will open in Notepad
    Copy and paste that report as a reply to this thread
Your reply should include
  • a fresh Hijackthis log
    your report_scan.txt log from AVG
    bamajim   Graduate of MRU
    CastleCops  Instructor


    44 Posts

    April 5th, 2007 23:00

    ---------------------------------------------------------
    AVG Anti-Spyware - Scan Report
    ---------------------------------------------------------
     + Created at: 8:09:16 PM 4/5/2007
     + Scan result: 
     
    C:\!KillBox\cscentfy.dll -> Adware.Cscentfy : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0009210.dll -> Adware.Cscentfy : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP67\A0008147.sys -> Backdoor.Bulknet : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0008180.sys -> Backdoor.Bulknet : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0008201.sys -> Backdoor.Bulknet : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0009204.sys -> Backdoor.Bulknet : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0009224.sys -> Backdoor.Bulknet : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0009236.sys -> Backdoor.Bulknet : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP69\A0009249.sys -> Backdoor.Bulknet : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP69\A0010252.sys -> Backdoor.Bulknet : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP69\A0010268.sys -> Backdoor.Bulknet : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\drivers\ip6fw.sys -> Backdoor.Bulknet : Cleaned with backup (quarantined).
    C:\SDFix\backups\backups.zip/backups/tmpAD3.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
    C:\SDFix\backups\backups.zip/backups/tmpBF.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0008217.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0008219.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\update28125911.exe -> Downloader.Small : Cleaned with backup (quarantined).
    C:\SDFix\backups\backups.zip/backups/win_w6.dll -> Downloader.Small.cyn : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0008202.dll -> Downloader.Small.cyn : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0008203.dll -> Downloader.Small.cyn : Cleaned with backup (quarantined).
    C:\!KillBox\lsasss.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
    C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
    C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
    C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
    C:\Program Files\DAEMON Tools\daemon.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
    C:\Program Files\Java\jre1.6.0\bin\jusched.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
    C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
    C:\Program Files\PowerISO\PWRISOVM.EXE -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
    C:\Program Files\QuickTime\qttask.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
    C:\Program Files\iTunes\iTunesHelper.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0009213.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\rsvp32_2.dll -> Proxy.Horst : Cleaned with backup (quarantined).
    [608] C:\WINDOWS\system32\rsvp32_2.dll -> Proxy.Horst : Cleaned with backup (quarantined).
    C:\SDFix\backups\backups.zip/backups/wincom32.sys -> Rootkit.Agent.dh : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0008194.sys -> Rootkit.Agent.dh : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0008223.sys -> Rootkit.Agent.dh : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP67\A0008146.sys -> Rootkit.Agent.el : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0008179.sys -> Rootkit.Agent.el : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0009203.sys -> Rootkit.Agent.el : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0009223.sys -> Rootkit.Agent.el : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0009235.sys -> Rootkit.Agent.el : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP69\A0009248.sys -> Rootkit.Agent.el : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP69\A0010251.sys -> Rootkit.Agent.el : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP69\A0010267.sys -> Rootkit.Agent.el : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP69\A0010277.sys -> Rootkit.Agent.el : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP67\A0008141.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
    C:\WINDOWS\effcbx.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP67\A0008150.exe -> Trojan.Agent.aie : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\winctl.exe -> Trojan.Agent.aie : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0009208.dll -> Trojan.Pakes : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0009225.dll:fork2 -> Trojan.Pakes : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP69\A0009242.dll:fork2 -> Trojan.Pakes : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP69\A0010242.dll:fork2 -> Trojan.Pakes : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP69\A0010262.dll:fork2 -> Trojan.Pakes : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\ws2_32.dll:fork2 -> Trojan.Pakes : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\wsys.dll -> Trojan.Pakes : Cleaned with backup (quarantined).
    [324] C:\WINDOWS\system32\ole2.dll -> Trojan.Pakes : Cleaned with backup (quarantined).
    C:\SDFix\backups\backups.zip/backups/tmp50.tmp.exe -> Trojan.Small : Cleaned with backup (quarantined).
    C:\SDFix\backups\backups.zip/backups/tmpAD4.tmp.exe -> Trojan.Small : Cleaned with backup (quarantined).
    C:\SDFix\backups\backups.zip/backups/tmpC6.tmp.exe -> Trojan.Small : Cleaned with backup (quarantined).
    C:\SDFix\backups\backups.zip/backups/tmpCD.tmp.exe -> Trojan.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0008216.exe -> Trojan.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0008218.exe -> Trojan.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0008220.exe -> Trojan.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0008221.exe -> Trojan.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\update15050767.exe -> Trojan.Spambot : Cleaned with backup (quarantined).
    C:\SDFix\backups\backups.zip/backups/adirka.dll -> Worm.Banwarum.f : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP67\A0008153.dll -> Worm.Banwarum.f : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0008189.dll -> Worm.Banwarum.f : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP68\A0008205.dll -> Worm.Banwarum.f : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\rsvp32_2.dllr55675et -> Worm.Zhelatin.al : Cleaned with backup (quarantined).
    C:\WINDOWS\duo.exe -> Worm.Zhelatin.cl : Cleaned with backup (quarantined).
    C:\WINDOWS\pep.exe -> Worm.Zhelatin.cl : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\duo.exe -> Worm.Zhelatin.cl : Cleaned with backup (quarantined).

    ::Report end
     
     
    Logfile of HijackThis v1.99.1
    Scan saved at 8:27:28 PM, on 4/5/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\fix my computer!\Feb 8 2007 spyware removers et al\Hijackthis\HijackThis.exe
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
    O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16
    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O10 - Broken Internet access because of LSP provider 'rsvp32_2.dll' missing
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
    O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{ABDC76CF-6624-4DE0-8812-22FFA71CEF46}: NameServer = 192.168.1.1
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: ieupdater22 (Microsoft IEUpdater22) - Unknown owner - C:\Documents and Settings\Mr. Troy Russell\ie_updater.exe (file missing)
    O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
    O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
     
     
    I can no longer access the internet since running the AVG quarantine. Not sure if this is due to trojan or something I shouldnt have quarantined. My computer seems to be getting a strong wireless signal but I cannot view pages in IE or Opera. Whatever malware was in the SDFix that you can see in the avg log seemed to have a little problem, I received a message stating AVG could not quarantine because it was also in another sdfix folder and asked me if I wanted to quarantine the entire folder. I clicked 'yes'. Maybe that was a mistake though. Sorry I don't have the exact details on the message, took a screencap but forgot to save it before reboot.
     
    Thanks

    10.4K Posts

    April 6th, 2007 00:00

    TJGRS

    We can fix that

    Go HERE and download LSPfix and save it to your Desktop
    • Rt click->>Extract(unzip) it to its own folder on your Desktop
      Disconnect from the internet, and close all browser windows.
      Open the LSPFix folder
      Run LSPFix. Click the " I know what I'm doing" button.
      In the left hand pane, hilite all instances of rsvp32_2.dll ( and nothing else),
      move them to the "Remove" pane and by clicking the >> button.
      Click Finish. Reboot to complete the process.

    A tutorial for using LSPfix can be found HERE

    You should be able to get back on now.

    2. Download catchme.exe from Here to your desktop.
    • Double click the catchme.exe to run it.
      Press Scan
      When it finishes, if there are any files listed in the window, press zip to make a copy of any files to submit if we ask for it
      It shall produce a log for you.
      Open catchme.log and post its contents in a reply.
        bamajim   Graduate of MRU
          CastleCops  Instructor

        44 Posts

        April 6th, 2007 02:00

        catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
        http://www.gmer.net
        scanning hidden processes ...
        scanning hidden services ...
        HKLM\SYSTEM\CurrentControlSet\Services\PerfNetk
        HKLM\SYSTEM\CurrentControlSet\Services\PerfOSt
        HKLM\SYSTEM\CurrentControlSet\Services\PSchedtedStorage
        HKLM\SYSTEM\CurrentControlSet\Services\ql108020
        HKLM\SYSTEM\CurrentControlSet\Services\ql12400
        HKLM\SYSTEM\CurrentControlSet\Services\RasManp
        HKLM\SYSTEM\CurrentControlSet\Services\Rasptioe
        HKLM\SYSTEM\CurrentControlSet\Services\Rdbssi
        HKLM\SYSTEM\CurrentControlSet\Services\RDPDDD
        HKLM\SYSTEM\CurrentControlSet\Services\redbookgr
        HKLM\SYSTEM\CurrentControlSet\Services\RpcLocatorstry
        HKLM\SYSTEM\CurrentControlSet\Services\RpcSscator
        HKLM\SYSTEM\CurrentControlSet\Services\RSVPs
        HKLM\SYSTEM\CurrentControlSet\Services\SamSsme
        HKLM\SYSTEM\CurrentControlSet\Services\SCDEmuvr
        HKLM\SYSTEM\CurrentControlSet\Services\Secdrvle
        HKLM\SYSTEM\CurrentControlSet\Services\SENSogon
        HKLM\SYSTEM\CurrentControlSet\Services\Serialm
        HKLM\SYSTEM\CurrentControlSet\Services\SimbadWDetection
        HKLM\SYSTEM\CurrentControlSet\Services\Spoolerr
        HKLM\SYSTEM\CurrentControlSet\Services\sptdler
        HKLM\SYSTEM\CurrentControlSet\Services\srtd
        HKLM\SYSTEM\CurrentControlSet\Services\Srvervice
        HKLM\SYSTEM\CurrentControlSet\Services\SSDPSRV5
        HKLM\SYSTEM\CurrentControlSet\Services\ssrtlnV
        HKLM\SYSTEM\CurrentControlSet\Services\SwPrvi
        HKLM\SYSTEM\CurrentControlSet\Services\sym_hix
        HKLM\SYSTEM\CurrentControlSet\Services\TapiSrvog
        HKLM\SYSTEM\CurrentControlSet\Services\Tcpiprv
        HKLM\SYSTEM\CurrentControlSet\Services\TDTCPE
        HKLM\SYSTEM\CurrentControlSet\Services\tfsnboioice
        HKLM\SYSTEM\CurrentControlSet\Services\tfsnifss
        HKLM\SYSTEM\CurrentControlSet\Services\tfsnudfl
        HKLM\SYSTEM\CurrentControlSet\Services\Themesfa
        HKLM\SYSTEM\CurrentControlSet\Services\tmcommr
        HKLM\SYSTEM\CurrentControlSet\Services\Tmntsrvr
        HKLM\SYSTEM\CurrentControlSet\Services\TmPfwrv
        HKLM\SYSTEM\CurrentControlSet\Services\tmproxyt
        HKLM\SYSTEM\CurrentControlSet\Services\tmtdixy
        HKLM\SYSTEM\CurrentControlSet\Services\TSDDDs
        HKLM\SYSTEM\CurrentControlSet\Services\UdfsD
        HKLM\SYSTEM\CurrentControlSet\Services\UPSphost
        HKLM\SYSTEM\CurrentControlSet\Services\usbccgpo
        HKLM\SYSTEM\CurrentControlSet\Services\usbhubi
        HKLM\SYSTEM\CurrentControlSet\Services\usbscant
        HKLM\SYSTEM\CurrentControlSet\Services\viaagpe
        HKLM\SYSTEM\CurrentControlSet\Services\VSSpint
        HKLM\SYSTEM\CurrentControlSet\Services\W3SVCme
        HKLM\SYSTEM\CurrentControlSet\Services\WDICAw
        HKLM\SYSTEM\CurrentControlSet\Services\winachsft
        HKLM\SYSTEM\CurrentControlSet\Services\winmgmtf
        HKLM\SYSTEM\CurrentControlSet\Services\WmdmPmSNP Service
        HKLM\SYSTEM\CurrentControlSet\Services\WmimPmSN
        HKLM\SYSTEM\CurrentControlSet\Services\WS2IFSLorkSvc
        HKLM\SYSTEM\CurrentControlSet\Services\wscsvcL
        HKLM\SYSTEM\CurrentControlSet\Services\WudfPfrv
        HKLM\SYSTEM\CurrentControlSet\Services\WZCSVCc
        HKLM\SYSTEM\CurrentControlSet\Services\aa64e8inF-6624-4DE0-8812-22FFA71CEF46}
        scanning hidden autostart entries ...
        HKLM\Software\Microsoft\Windows\CurrentVersion\Run
          DLBUCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
        scanning hidden files ...

        scan completed successfully
        hidden processes: 0
        hidden services: 58
        hidden files: 0
         
        Thanks! Internet is working again. Please let me know if there's anything else I should do.

        10.4K Posts

        April 6th, 2007 13:00

        TJGRS

        Looking better

        1. Run an online virus scan called Kaspersky from HERE.
        • 1. Click on " Kaspersky Online Scanner"
          2. A new smaller window will pop up. Press on " Accept". After reading the contents.
          3. Now Kaspersky will update the anti-virus database. Let it run.
          4. Click on " Next"->>" Scan Settings", and make sure the database is set to " extended". And check both the scan options. Then click OK.
          5. Then click on " My Computer". And the scan will start.
          6. Once finished, save a log as ". txt" to the desktop.

        Copy and post the results of the Kaspersky Online scan

        Note: You may have to make sure Trend AV and Firewall are set to allow the Scan
         
        bamajim   Graduate of MRU
        CastleCops  Instructor

        44 Posts

        April 6th, 2007 16:00

        Hi,
         
        Kaspersky website seems to be down. Is there somewhere else I can get it or anything else I can do?
         
        Thank you.

        10.4K Posts

        April 6th, 2007 18:00

        TJGRS
         
        It seems to work for me. What happens when you try the link?
         
        bamajim   Graduate of MRU
        CastleCops  Instructor


        Message Edited by bamajim on 04-06-2007 02:45 PM

        44 Posts

        April 6th, 2007 19:00

        Hi,
         
        It seems to be my computer. My internet at this point is no longer working properly. Not sure why. I'm using another computer, same wireless connection. The computer with the problems is getting an excellent signal but is working intermittently. Kaspersky website does work on the computer I'm using now but I'd imagine it won't do me much good because it's an online scan.
         
        Please let me know if there's anything else I can do to fix this.
         
        Thanks again.

        10.4K Posts

        April 6th, 2007 19:00

        TJGRS

        1. Download this file - combofix.exe
        2. Double click combofix.exe & follow the prompts.
        3. When finished, it shall produce a log for you. Post that log in your next reply

        Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
         
        bamajim   Graduate of MRU
        CastleCops  Instructor

        No Events found!

        Top