Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

That &^$##@ Antivirusxp 2008


  • This topic is locked This topic is locked
5 replies to this topic

#1 doctec50

doctec50

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Ohio
  • Local time:04:51 AM

Posted 05 August 2008 - 05:50 PM

Greetings ,

MY sad story is much the same as many others on this forum, though i was downloading an Adobe plugin and ended up with a most valuable

bit of software that keeps informing me " that AntivirusXP 2008 has detected 1606 viruses on your computer............"

Even a computer dumbass like yours truly found this a little suspect, that and endless pop-ups, a big blue screen with a warning plastered across the center

informing me that i have nasty viruses all over the place and i better deal with it right now. All i need to do is................. send money.

Since I am not a big fan of cyber-extortion , here I am.
:thumbsup:



While plowing through data received on date and time when this whackness all started keep running into these clowns, rhc7osj0et9e.exe, lphc3osj0et9e.exe
can`t help but think they are involved somehow.




Deckard's System Scanner v20071014.68
Run by the old doctor on 2008-08-05 17:24:40
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as the old doctor.exe) --------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:24:49 PM, on 8/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\All Users\Application Data\ivkfodmp\epkvyrax.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
c:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\lphc3osj0et9e.exe
C:\Program Files\rhc7osj0et9e\rhc7osj0et9e.exe
C:\WINDOWS\system32\xgngtkhi.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\pphc3osj0et9e.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Documents and Settings\the old doctor\Desktop\dss.exe
C:\DOCUME~1\THEOLD~1\MYDOCU~1\TOM`ST~1\THEOLD~1.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/mywaybiz
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [DwlClient] c:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [lphc3osj0et9e] C:\WINDOWS\system32\lphc3osj0et9e.exe
O4 - HKLM\..\Run: [SMrhc7osj0et9e] C:\Program Files\rhc7osj0et9e\rhc7osj0et9e.exe
O4 - HKCU\..\Run: [setdb] C:\WINDOWS\system32\qjspidwx.exe
O4 - HKCU\..\Run: [uiadm] C:\WINDOWS\system32\xgngtkhi.exe
O4 - HKCU\..\Run: [apimsgapp] C:\WINDOWS\system32\cjedudmd.exe
O4 - HKLM\..\Policies\Explorer\Run: [GaVceWvq5q] C:\Documents and Settings\All Users\Application Data\ivkfodmp\epkvyrax.exe
O4 - Global Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O21 - SSODL: UiShEn - {0D420F0A-4B18-376E-410E-05B0C2E50618} - C:\Program Files\qmhuwbg\UiShEn.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 5992 bytes

-- Files created between 2008-07-05 and 2008-08-05 -----------------------------

2008-08-05 05:23:31 94208 --a------ C:\WINDOWS\system32\pphc3osj0et9e.exe
2008-08-05 05:23:30 0 d-------- C:\Documents and Settings\the old doctor\Application Data\rhc7osj0et9e
2008-08-05 05:23:12 0 d-------- C:\Program Files\rhc7osj0et9e
2008-08-05 05:23:03 60928 --a------ C:\WINDOWS\system32\blphc3osj0et9e.scr <Not Verified; Sysinternals; Sysinternals Blue Screen>
2008-08-05 05:23:02 133632 --a------ C:\WINDOWS\system32\lphc3osj0et9e.exe
2008-08-04 21:46:58 90112 --a------ C:\WINDOWS\system32\xgngtkhi.exe
2008-08-04 21:07:12 336 --a------ C:\Program Files\temp995.bat
2008-08-04 20:29:37 0 d-------- C:\Documents and Settings\the old doctor\Application Data\pdf995
2008-08-04 20:11:44 81920 --a------ C:\WINDOWS\system32\apsrarqt.exe
2008-08-04 19:00:49 81920 --a------ C:\WINDOWS\system32\rcpaxwnu.exe
2008-08-04 18:35:57 90112 --a------ C:\WINDOWS\system32\cjedudmd.exe
2008-08-04 18:08:29 0 d-------- C:\Documents and Settings\the old doctor\Application Data\Malwarebytes
2008-08-04 18:08:24 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-04 18:08:23 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-04 10:33:00 77824 --a------ C:\WINDOWS\system32\pehuzovw.exe
2008-08-04 10:33:00 114176 --a------ C:\WINDOWS\system32\hohszong.exe
2008-08-04 09:28:31 77824 --a------ C:\WINDOWS\system32\ryrolatk.exe
2008-08-03 10:16:18 0 d-------- C:\Program Files\RogueRemover FREE
2008-07-28 04:58:13 90112 --a------ C:\WINDOWS\system32\rcdmlexs.exe
2008-07-26 07:27:06 77824 --a------ C:\WINDOWS\system32\slubsxsh.exe
2008-07-25 05:19:10 81920 --a------ C:\WINDOWS\system32\nolatcxm.exe
2008-07-25 05:19:09 110080 --a------ C:\WINDOWS\system32\rehynkzo.exe
2008-07-24 21:37:52 0 d-------- C:\Program Files\MSXML 4.0
2008-07-24 18:57:03 98304 --a------ C:\WINDOWS\system32\zalkpilw.exe
2008-07-24 18:54:55 0 d-------- C:\WINDOWS\system32\PreInstall
2008-07-24 18:06:06 0 d-------- C:\Program Files\Enigma Software Group
2008-07-24 05:41:02 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-07-22 19:46:50 0 d-------- C:\Program Files\qmhuwbg
2008-07-22 19:16:38 0 d-------- C:\Documents and Settings\All Users\Application Data\ivkfodmp


-- Find3M Report ---------------------------------------------------------------

2008-08-04 21:07:56 105048 --a----c- C:\WINDOWS\HPFins09.dat
2008-08-04 21:07:12 0 d-------- C:\Program Files\PDF995
2008-08-04 13:03:40 0 d-------- C:\Program Files\Common Files
2008-08-04 13:00:02 0 d-------- C:\Program Files\TurboTax
2008-08-04 12:59:58 0 d-------- C:\Program Files\Common Files\Intuit
2008-08-04 12:58:54 0 d-------- C:\Program Files\ItsDeductible2005
2008-08-04 12:56:50 0 d-------- C:\Program Files\Jasc Software Inc
2008-08-04 12:52:40 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-08-04 12:49:18 0 d-------- C:\Program Files\BitLord
2008-08-04 12:20:07 0 d-------- C:\Program Files\Java
2008-08-03 20:06:46 0 d-------- C:\Documents and Settings\the old doctor\Application Data\Help
2008-07-24 21:05:43 0 d-------- C:\Program Files\Lavasoft
2008-07-24 21:04:50 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-05 10:50:38 0 d-------- C:\Documents and Settings\the old doctor\Application Data\Mozilla
2008-06-15 13:38:19 0 d-------- C:\Program Files\Audacity


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [02/10/2004 12:55 PM]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [02/10/2004 12:51 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [02/01/2008 12:13 AM]
"DwlClient"="c:\Program Files\Common Files\Dell\EUSW\Support.exe" [05/27/2004 09:05 PM]
"CARPService"="carpserv.exe" [06/11/2003 11:54 AM C:\WINDOWS\SYSTEM32\carpserv.exe]
"NeroCheck"="C:\WINDOWS\System32\\NeroCheck.exe" [07/09/2001 06:50 AM]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [01/02/2006 06:41 PM]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [09/24/2005 12:08 AM]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" []
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [03/09/2007 11:09 AM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 11:16 PM]
"lphc3osj0et9e"="C:\WINDOWS\system32\lphc3osj0et9e.exe" [08/05/2008 05:23 AM]
"SMrhc7osj0et9e"="C:\Program Files\rhc7osj0et9e\rhc7osj0et9e.exe" [08/03/2008 02:14 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"setdb"="C:\WINDOWS\system32\qjspidwx.exe" []
"uiadm"="C:\WINDOWS\system32\xgngtkhi.exe" [08/04/2008 09:46 PM]
"apimsgapp"="C:\WINDOWS\system32\cjedudmd.exe" [08/05/2008 05:23 AM]

C:\Documents and Settings\the old doctor\Start Menu\Programs\Startup\
DESKTOP.INI [9/3/2002 10:00:00 AM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DESKTOP.INI [9/3/2002 10:00:00 AM]
DING!.lnk - C:\Program Files\Southwest Airlines\Ding\Ding.exe [5/17/2005 3:22:42 PM]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [9/24/2005 12:28:44 AM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispBackgroundPage"=1 (0x1)
"NoDispScrSavPage"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
"GaVceWvq5q"=C:\Documents and Settings\All Users\Application Data\ivkfodmp\epkvyrax.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"UiShEn"= {0D420F0A-4B18-376E-410E-05B0C2E50618} - C:\Program Files\qmhuwbg\UiShEn.dll [07/22/2008 07:46 PM 114688]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"




-- End of Deckard's System Scanner: finished at 2008-08-05 17:25:03 ------------



For some reason hijack this is not kicking out an extra.txt for this session, so will inclued last one I have, hope that helps



Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Home Edition (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel® Pentium® 4 CPU 3.00GHz
CPU 1: Intel® Pentium® 4 CPU 3.00GHz
Percentage of Memory in Use: 62%
Physical Memory (total/avail): 766.98 MiB / 288.38 MiB
Pagefile Memory (total/avail): 1108.55 MiB / 574.95 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1929.05 MiB

C: is Fixed (NTFS) - 71.46 GiB total, 56.79 GiB free.
D: is CDROM (No Media)
E: is CDROM (No Media)

\\.\PHYSICALDRIVE0 - WDC WD800BB-75FJA1 - 74.5 GiB - 3 partitions
\PARTITION0 - Unknown - 39.19 MiB
\PARTITION1 (bootable) - Installable File System - 71.46 GiB - C:
\PARTITION2 - Unknown - 3 GiB



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.


[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"
"C:\\Program Files\\Phantom EFX\\OnlineCasino\\Bin\\Prelauncher.exe"="C:\\Program Files\\Phantom EFX\\OnlineCasino\\Bin\\Prelauncher.exe:*:Disabled:Prelauncher"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\BitLord\\BitLord.exe"="C:\\Program Files\\BitLord\\BitLord.exe:*:Disabled:BitLord"
"C:\\Program Files\\Phantom EFX\\OnlineCasino\\Launcher\\OLCLauncher.exe"="C:\\Program Files\\Phantom EFX\\OnlineCasino\\Launcher\\OLCLauncher.exe:*:Enabled:OLCLauncher"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\the old doctor\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=MOJOBLASTER
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\the old doctor
LOGONSERVER=\\MOJOBLASTER
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\;C:\Program Files\QuickTime\QTSystem\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 3 Stepping 4, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0304
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\THEOLD~1\LOCALS~1\Temp
TMP=C:\DOCUME~1\THEOLD~1\LOCALS~1\Temp
USERDOMAIN=MOJOBLASTER
USERNAME=the old doctor
USERPROFILE=C:\Documents and Settings\the old doctor
windir=C:\WINDOWS


-- User Profiles ---------------------------------------------------------------

the old doctor (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
123 Free Solitaire --> C:\PROGRA~1\123FRE~1\UNWISE.EXE C:\PROGRA~1\123FRE~1\INSTALL.LOG
Ad-Aware --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742) --> MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Adobe Reader 8.1.2 Security Update 1 (KB403742) -->
Adobe® Photoshop® Album Starter Edition 3.2 --> MsiExec.exe /I{A654A805-41D9-40C7-AA46-4AF04F044D61}
AntivirXP08 --> "C:\Program Files\rhc7osj0et9e\uninstall.exe"
Apple Mobile Device Support --> MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
ATI - Software Uninstall Utility --> C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Catalyst Control Center --> MsiExec.exe /I{CB2D95C7-189C-4596-B071-CE99C309573D}
ATI Display Driver --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
Audacity 1.2.6 --> "C:\Program Files\Audacity\unins000.exe"
BitLord 1.1 --> C:\Program Files\BitLord\uninst.exe
Bonjour --> MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
Dell Solution Center --> MsiExec.exe /X{11F1920A-56A2-4642-B6E0-3B31A12C9288}
Dell Support --> MsiExec.exe /X{43FCA273-9534-40DB-B7C5-D7758875616A}
DING! --> MsiExec.exe /X{84031A18-BA9A-4156-A74F-E05B52DDFCE2}
Fallout --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{941F9BA8-06F6-42FD-AB91-CFB99B5E13BF}\Setup.exe" -l0x9 -removeonly
Fallout2 --> C:\WINDOWS\ipuninst.exe -fC:\Program Files\BlackIsle\Fallout2\uninst.log
HijackThis 2.0.2 --> "C:\Documents and Settings\the old doctor\My Documents\tom`s temps\HijackThis.exe" /uninstall
HP Deskjet 6900 series --> C:\Program Files\HP\Digital Imaging\{7ADE9F27-A175-447F-A4B4-B05FA82735E1}\setup\hpzscr01.exe -datfile hpfscr09.dat
HP Imaging Device Functions 6.0 --> C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
HP Photosmart Essential --> MsiExec.exe /X{D7CAE58E-26DE-49B7-A75D-EAEDF76726BE}
HP Software Update --> MsiExec.exe /X{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}
HP Solution Center and Imaging Support Tools 6.0 --> C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
Intel® Extreme Graphics 2 Driver --> RUNDLL32.EXE C:\WINDOWS\System32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2572
Intel® PRO Network Adapters and Drivers --> Prounstl.exe
Intel® PROSet --> MsiExec.exe /I{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}
IntelliFlash --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\VIKING COMPONENTS\IntelliFlash\Uninst.isu"
Internet Explorer Default Page --> MsiExec.exe /I{35BDEFF1-A610-4956-A00D-15453C116395}
Jasc Paint Shop Photo Album --> MsiExec.exe /I{CC000127-5E5D-4A1C-90CB-EEAAAC1E3AC0}
Jasc Paint Shop Pro 8 Dell Edition --> MsiExec.exe /I{81A34902-9D0B-4920-A25C-4CDC5D14B328}
Java 2 Runtime Environment, SE v1.4.2_03 --> MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030}
Java™ 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java™ 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java™ 6 Update 7 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
JetShell PRO --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1826E565-D493-4B93-9031-D3667B340E80}\setup.exe" -l0x9
Kyodai Mahjongg --> "C:\Program Files\Kyodai Mahjongg\unins000.exe"
Logitech SetPoint --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}\setup.exe" -l0x9 -removeonly
Macromedia Shockwave Player --> C:\WINDOWS\SYSTEM32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\SYSTEM32\Macromed\SHOCKW~1\Install.log
Malwarebytes' RogueRemover --> "C:\Program Files\RogueRemover FREE\unins000.exe"
Masque Slots --> C:\Masque\Slots\UNWISE.EXE C:\Masque\Slots\INSTALL.LOG
Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{91E30409-6000-11D3-8CFE-0150048383C9}
Mozilla (1.7.2) --> C:\WINDOWS\MozillaUninstall.exe /ua "1.7.2 (en)"
Mozilla Firefox (3.0) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MysticForest --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C743D506-6CD5-4C50-838F-52FC0EA80369}\setup.exe" -l0x9 -removeonly
Nero - Burning Rom --> MsiExec.exe /X{A4D7B764-4140-11D4-88EB-0050DA3579C0}
NetWaiting --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\Setup.exe" -l0x9 ControlPanelAnyText
NickelsAndMore --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5721000D-6D4F-45E7-AA18-AF0D990666C0}\setup.exe" -l0x9
Pdf995 (installed by TaxCut) --> C:\Program Files\pdf995\setup.exe uninstall
PdfEdit995 (installed by TaxCut) --> C:\Program Files\pdf995\res\utilities\thinsetup.exe - uninstall
QuickTime --> MsiExec.exe /I{BFD96B89-B769-4CD6-B11E-E79FFD46F067}
RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Reel Deal Casino - Championship Edition --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0579D184-8A11-4983-8AAF-89D7B27AA117}\setup.exe" -l0x9
Reel Deal Slots 2nd Volume --> "c:\Program Files\Phantom\Reel Deal Slots 2nd Volume\unins000.exe"
Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins001.exe"
Spybot - Search & Destroy 1.2 --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
SpyHunter --> "C:\Program Files\Enigma Software Group\SpyHunter\Uninstall.exe" "C:\Program Files\Enigma Software Group\SpyHunter\install.log" -u
System Requirements Lab --> C:\Program Files\Common Files\SystemRequirementsLab\Uninstall.exe
TaxCut Ohio 2007 --> MsiExec.exe /X{D4C005F8-44C9-4EF3-A1ED-061BB4802E21}
TaxCut Premium + State 2007 --> MsiExec.exe /X{663E217E-FC26-4249-9E8E-F190CD63E737}
TaxCut Premium 2006 --> C:\PROGRA~1\TaxCut06\Program\removetc.exe
TurboTax Deluxe 2005 --> C:\Program Files\TurboTax\Deluxe 2005\TaxUnst.EXE "C:\Program Files\TurboTax\Deluxe 2005\Uninstall.log" -NoGui
TurboTax ItsDeductible 2005 --> MsiExec.exe /X{2E7595EC-4FB1-4E29-93D4-9083C8A9B107}
V92 PCI Voice Faxmodem --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FF04A828-ABA4-11D7-A021-0060979CE4D3}\setup.exe" -l0x9
WexTech AnswerWorks --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}\SETUP.EXE" -l0x9 -eliminate
WordPerfect Office 12 --> MsiExec.exe /I{AF19F291-F22F-4798-9662-525305AE9E48}
X5 User's Guide --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{21CB7553-5A17-441E-B208-29690EB99F66}\setup.exe" -l0x9


-- Application Event Log -------------------------------------------------------

Event Record #/Type30169 / Error
Event Submitted/Written: 08/04/2008 09:28:15 AM
Event ID/Source: 2004 / PerfNet
Event Description:
Unable to open the Server service. Server performance data
will not be returned. Error code returned is in data DWORD 0.

Event Record #/Type30168 / Error
Event Submitted/Written: 08/04/2008 09:28:08 AM
Event ID/Source: 2004 / PerfNet
Event Description:
Unable to open the Server service. Server performance data
will not be returned. Error code returned is in data DWORD 0.

Event Record #/Type30163 / Error
Event Submitted/Written: 08/04/2008 09:10:31 AM
Event ID/Source: 2004 / PerfNet
Event Description:
Unable to open the Server service. Server performance data
will not be returned. Error code returned is in data DWORD 0.

Event Record #/Type30157 / Error
Event Submitted/Written: 08/03/2008 10:04:02 AM
Event ID/Source: 2004 / PerfNet
Event Description:
Unable to open the Server service. Server performance data
will not be returned. Error code returned is in data DWORD 0.

Event Record #/Type30153 / Error
Event Submitted/Written: 07/28/2008 04:57:40 AM
Event ID/Source: 2004 / PerfNet
Event Description:
Unable to open the Server service. Server performance data
will not be returned. Error code returned is in data DWORD 0.



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type68997 / Error
Event Submitted/Written: 08/04/2008 00:15:02 PM
Event ID/Source: 12294 / ati2mtag
Event Description:
CRT invalid display type

Event Record #/Type68996 / Error
Event Submitted/Written: 08/04/2008 00:13:27 PM
Event ID/Source: 12294 / ati2mtag
Event Description:
CRT invalid display type

Event Record #/Type68992 / Error
Event Submitted/Written: 08/04/2008 10:53:35 AM
Event ID/Source: 12294 / ati2mtag
Event Description:
CRT invalid display type

Event Record #/Type68991 / Error
Event Submitted/Written: 08/04/2008 10:52:28 AM
Event ID/Source: 12294 / ati2mtag
Event Description:
CRT invalid display type

Event Record #/Type68990 / Warning
Event Submitted/Written: 08/04/2008 10:39:32 AM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.



-- End of Deckard's System Scanner: finished at 2008-08-04 12:45:23 ------------

BC AdBot (Login to Remove)

 


#2 kahdah

kahdah

  • Security Colleague
  • 11,138 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:05:51 AM

Posted 05 August 2008 - 07:38 PM

Hello doctec50

Welcome to BleepingComputer :thumbsup:
========================
The first thing I will need you to do is to Download ONE of these anti-virus programs and install it.
These are free.
AVG free 8.0
Note this is free antispyware protection and Antivirus protection.
or
Antivir
==============================================
Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\WINDOWS\system32\lphc3osj0et9e.exe
    C:\Program Files\rhc7osj0et9e
    C:\WINDOWS\system32\qjspidwx.exe
    C:\WINDOWS\system32\xgngtkhi.exe
    C:\WINDOWS\system32\cjedudmd.exe
    C:\Documents and Settings\All Users\Application Data\ivkfodmp
    C:\Program Files\qmhuwbg
    C:\WINDOWS\system32\pphc3osj0et9e.exe
    C:\Documents and Settings\the old doctor\Application Data\rhc7osj0et9e
    C:\WINDOWS\system32\blphc3osj0et9e.scr 
    C:\Program Files\temp995.bat
    C:\WINDOWS\system32\apsrarqt.exe
    C:\WINDOWS\system32\rcpaxwnu.exe
    C:\WINDOWS\system32\cjedudmd.exe
    C:\WINDOWS\system32\pehuzovw.exe
    C:\WINDOWS\system32\hohszong.exe
    C:\WINDOWS\system32\ryrolatk.exe
    C:\WINDOWS\system32\rcdmlexs.exe
    C:\WINDOWS\system32\slubsxsh.exe
    C:\WINDOWS\system32\nolatcxm.exe
    C:\WINDOWS\system32\rehynkzo.exe
    C:\WINDOWS\system32\zalkpilw.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\lphc3osj0et9e
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\SMrhc7osj0et9e
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\setdb
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\uiadm
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\apimsgapp
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system\\NoDispBackgroundPage
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system\\NoDispScrSavPage
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run\\GaVceWvq5q
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\UiShEn
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • OTMoveit2 will create a log of moved files in the C:\_OTMoveIt\MovedFiles folder. The log's name will appear as the date and time it was created, with the format mmddyyyy_hhmmss.log. Open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
==================
Then update Malware BYtes ANtimalware and run a full scan with it.
It will say remove selected when Items are found click that button and it will remoove the infections it finds.
It may ask for a reboot if so do it.
=========================
Then post these logs in your next reply:
OtMove itlog
Mbam log
New dss log

Please do not pm for help, post it in the forums instead.

If I am helping you and have not responded for 48 hours please send me a pm as I don't always get notifications.

My help is always free, however, if you would like to make a donation to me for the help I have provided please click here Posted Image

#3 doctec50

doctec50
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Ohio
  • Local time:04:51 AM

Posted 06 August 2008 - 05:22 PM

Hey kahdah,

Thanks for the quick response !!

Can imagine that the team gets a little tired of dealing with the same problems over and over and over....................... again.

But I got`a tell you man , it is much appreciated by us with meager computer skills.

As instructed :

AVG installed

As requested:

Malwarebytes' Anti-Malware 1.24
Database version: 1030
Windows 5.1.2600 Service Pack 2

6:19:47 PM 8/6/2008
mbam-log-8-6-2008 (18-19-47).txt

Scan type: Full Scan (C:\|)
Objects scanned: 127532
Time elapsed: 54 minute(s), 55 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)







OTMoveit log


File/Folder C:\WINDOWS\system32\lphc3osj0et9e.exe not found.
File/Folder C:\Program Files\rhc7osj0et9e not found.
File/Folder C:\WINDOWS\system32\qjspidwx.exe not found.
File/Folder C:\WINDOWS\system32\xgngtkhi.exe not found.
File/Folder C:\WINDOWS\system32\cjedudmd.exe not found.
C:\Documents and Settings\All Users\Application Data\ivkfodmp moved successfully.
C:\Program Files\qmhuwbg moved successfully.
File/Folder C:\WINDOWS\system32\pphc3osj0et9e.exe not found.
File/Folder C:\Documents and Settings\the old doctor\Application Data\rhc7osj0et9e not found.
File/Folder C:\WINDOWS\system32\blphc3osj0et9e.scr not found.
C:\Program Files\temp995.bat moved successfully.
File/Folder C:\WINDOWS\system32\apsrarqt.exe not found.
File/Folder C:\WINDOWS\system32\rcpaxwnu.exe not found.
File/Folder C:\WINDOWS\system32\cjedudmd.exe not found.
File/Folder C:\WINDOWS\system32\pehuzovw.exe not found.
File/Folder C:\WINDOWS\system32\hohszong.exe not found.
File/Folder C:\WINDOWS\system32\ryrolatk.exe not found.
File/Folder C:\WINDOWS\system32\rcdmlexs.exe not found.
File/Folder C:\WINDOWS\system32\slubsxsh.exe not found.
File/Folder C:\WINDOWS\system32\nolatcxm.exe not found.
File/Folder C:\WINDOWS\system32\rehynkzo.exe not found.
File/Folder C:\WINDOWS\system32\zalkpilw.exe not found.
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\lphc3osj0et9e >
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\lphc3osj0et9e not found.
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\SMrhc7osj0et9e >
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\SMrhc7osj0et9e not found.
< HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\setdb >
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\setdb deleted successfully.
< HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\uiadm >
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\uiadm deleted successfully.
< HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\apimsgapp >
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\apimsgapp deleted successfully.
< HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system\\NoDispBackgroundPage >
Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system\\NoDispBackgroundPage deleted successfully.
< HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system\\NoDispScrSavPage >
Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system\\NoDispScrSavPage deleted successfully.
< HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run\\GaVceWvq5q >
Registry value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run\\GaVceWvq5q deleted successfully.
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\UiShEn >
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\UiShEn deleted successfully.

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08062008_163617





And lastly

Deckard's System Scanner v20071014.68
Run by the old doctor on 2008-08-06 16:56:11
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as the old doctor.exe) --------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:56:23 PM, on 8/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
c:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\the old doctor\Desktop\dss.exe
C:\DOCUME~1\THEOLD~1\MYDOCU~1\TOM`ST~1\THEOLD~1.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/mywaybiz
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [DwlClient] c:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - Global Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 6052 bytes

-- Files created between 2008-07-06 and 2008-08-06 -----------------------------

2008-08-05 23:25:04 0 d--h----- C:\$AVG8.VAULT$
2008-08-05 23:19:15 0 d-------- C:\WINDOWS\system32\drivers\Avg
2008-08-05 23:19:15 0 d-------- C:\Documents and Settings\the old doctor\Application Data\AVGTOOLBAR
2008-08-05 23:19:04 0 d-------- C:\Program Files\AVG
2008-08-05 23:19:04 0 d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-08-04 20:29:37 0 d-------- C:\Documents and Settings\the old doctor\Application Data\pdf995
2008-08-04 18:08:29 0 d-------- C:\Documents and Settings\the old doctor\Application Data\Malwarebytes
2008-08-04 18:08:24 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-04 18:08:23 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-03 10:16:18 0 d-------- C:\Program Files\RogueRemover FREE
2008-07-24 21:37:52 0 d-------- C:\Program Files\MSXML 4.0
2008-07-24 18:54:55 0 d-------- C:\WINDOWS\system32\PreInstall
2008-07-24 18:06:06 0 d-------- C:\Program Files\Enigma Software Group
2008-07-24 05:41:02 0 d-------- C:\WINDOWS\system32\SoftwareDistribution


-- Find3M Report ---------------------------------------------------------------

2008-08-04 21:07:56 105048 --a----c- C:\WINDOWS\HPFins09.dat
2008-08-04 21:07:12 0 d-------- C:\Program Files\PDF995
2008-08-04 13:03:40 0 d-------- C:\Program Files\Common Files
2008-08-04 13:00:02 0 d-------- C:\Program Files\TurboTax
2008-08-04 12:59:58 0 d-------- C:\Program Files\Common Files\Intuit
2008-08-04 12:58:54 0 d-------- C:\Program Files\ItsDeductible2005
2008-08-04 12:56:50 0 d-------- C:\Program Files\Jasc Software Inc
2008-08-04 12:52:40 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-08-04 12:49:18 0 d-------- C:\Program Files\BitLord
2008-08-04 12:20:07 0 d-------- C:\Program Files\Java
2008-08-03 20:06:46 0 d-------- C:\Documents and Settings\the old doctor\Application Data\Help
2008-07-24 21:05:43 0 d-------- C:\Program Files\Lavasoft
2008-07-24 21:04:50 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-05 10:50:38 0 d-------- C:\Documents and Settings\the old doctor\Application Data\Mozilla
2008-06-15 13:38:19 0 d-------- C:\Program Files\Audacity


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
08/05/2008 11:19 PM 2055960 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [08/05/2008 11:19 PM 2055960]

[-HKEY_CLASSES_ROOT\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [02/10/2004 12:55 PM]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [02/10/2004 12:51 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [02/01/2008 12:13 AM]
"DwlClient"="c:\Program Files\Common Files\Dell\EUSW\Support.exe" [05/27/2004 09:05 PM]
"CARPService"="carpserv.exe" [06/11/2003 11:54 AM C:\WINDOWS\SYSTEM32\carpserv.exe]
"NeroCheck"="C:\WINDOWS\System32\\NeroCheck.exe" [07/09/2001 06:50 AM]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [01/02/2006 06:41 PM]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [09/24/2005 12:08 AM]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [03/09/2007 11:09 AM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 11:16 PM]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [08/05/2008 11:19 PM]

C:\Documents and Settings\the old doctor\Start Menu\Programs\Startup\
DESKTOP.INI [9/3/2002 10:00:00 AM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DESKTOP.INI [9/3/2002 10:00:00 AM]
DING!.lnk - C:\Program Files\Southwest Airlines\Ding\Ding.exe [5/17/2005 3:22:42 PM]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [9/24/2005 12:28:44 AM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"




-- End of Deckard's System Scanner: finished at 2008-08-06 16:56:43 ------------

Well Hot Damn, to the untrained eye it looks like the greasy weasel has been tracked down and dealt with.

#4 kahdah

kahdah

  • Security Colleague
  • 11,138 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:05:51 AM

Posted 06 August 2008 - 07:49 PM

You are welcome :)
==============
Please re-open Hijackthis and click on "Do a system scan only"
Then place a check mark next to these entries below:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/mywaybiz



Now click on Fix Checked and then close Hijackthis.
====================================
Cleanup::
  • Make sure you have an Internet Connection.
  • Double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Click on the CleanUp! button
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OtMoveit2 to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.
===============
Upgrading Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 7.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 7 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u6-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.
======================
Use a Firewall:

Install and use a firewall with outbound protection
While the firewall built into Windows XP is adequate to protect you from incoming attacks, it will not be much help in alerting you to programs already on your PC attempting to connect to remote servers
I therefore strongly recommend that you install one of the following free firewalls: Comodo Firewall or Zonealarm
See Bleepingcomputer's excellent tutorial to help using and understanding a firewall here
Note: You should only have one firewall installed at a time. Having more than one antivirus program installed at once is likely to cause conflicts and may well decrease your overall protection as well as seriously impairing the performance of your PC.


=============================
Delete\uninstall anything else that we have used.

System Restore
Then I will need you to reset your System Restore points.
The link below shows how to create a clean restore point.
How to Turn On and Turn Off System Restore in Windows XP
http://support.microsoft.com/kb/310405/en-us

If you are using Vista then see this link > http://www.bleepingcomputer.com/tutorials/...143.html#manual
=====================================
After that your log is clean. :thumbsup:

The following is a list of tools and utilities that I like to suggest to people.
You do not have to have all or any of them they are only suggestions.
This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.

Spybot Search & Destroy-Uber powerful tool which can search and annhilate nasties that make it onto your system. Now with an Immunize section that will help prevent future infections.

Spyware Blaster - Great prevention tool to keep nasties from installing on your system.

Spywareguard-Works as a Spyware "Shield" to protect your computer from getting malware in the first place.

IE-SPYAD- puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.

Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.

Tony Klein article To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein.
Please do not pm for help, post it in the forums instead.

If I am helping you and have not responded for 48 hours please send me a pm as I don't always get notifications.

My help is always free, however, if you would like to make a donation to me for the help I have provided please click here Posted Image

#5 doctec50

doctec50
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Ohio
  • Local time:04:51 AM

Posted 07 August 2008 - 04:57 PM

kahdah,

You sir, are my new hero. :thumbsup:

Please stand and take a bow for your adoring fans.........er......... fan.

All seemed to go well, no evidence that the nasty little bastard is still lurking in the bowels of this machine .

Happy boy here! (hums chorus from Beatfarmers " Happy Boy") :)

So happy , that I have collected all the change from under the couch AND the car seat. When I figure out how to shove them down

the modem, will send them off to the noble soldiers of The Malware Wars at Bleeping Computer.

Much Thanks,

the old doctor

#6 kahdah

kahdah

  • Security Colleague
  • 11,138 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:05:51 AM

Posted 08 August 2008 - 10:12 AM

You are welcome :thumbsup:


Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If your the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
Please do not pm for help, post it in the forums instead.

If I am helping you and have not responded for 48 hours please send me a pm as I don't always get notifications.

My help is always free, however, if you would like to make a donation to me for the help I have provided please click here Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users