You will notice that I replaced my hard drive 2 days ago, re-installing the OS and all software. The local disk is now the F drive.
I have had no luck removing this trojan and I would appreciate any help that you could lend. Thank you, and I look forward to hearing from you soon!! :-)
Doug Lentz
DDS (Ver_10-03-17.01) - NTFSx86
Run by Lentz at 13:29:45.48 on Sat 10/02/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3071.2406 [GMT -5:00]
AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
F:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
F:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
F:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\Explorer.EXE
svchost.exe
F:\Program Files\Bonjour\mDNSResponder.exe
F:\Program Files\Java\jre6\bin\jqs.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
F:\WINDOWS\system32\nvsvc32.exe
F:\Program Files\Common Files\Java\Java Update\jusched.exe
F:\WINDOWS\system32\PnkBstrA.exe
F:\WINDOWS\system32\RUNDLL32.EXE
F:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
F:\Program Files\Pure Networks\Network Magic\nmapp.exe
F:\WINDOWS\system32\svchost.exe -k imgsvc
F:\WINDOWS\AGRSMMSG.exe
F:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
F:\Program Files\Alwil Software\Avast5\avastUI.exe
F:\WINDOWS\system32\ctfmon.exe
F:\WINDOWS\system32\SearchIndexer.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
F:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
F:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
F:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
F:\WINDOWS\System32\svchost.exe -k HTTPFilter
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\WINDOWS\system32\wuauclt.exe
F:\Program Files\Alwil Software\Avast5\AvastSvc.exe
F:\Documents and Settings\Lentz\Desktop\dds.scr
F:\Program Files\Skype\Toolbars\Shared\SkypeNames2.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://my.yahoo.com/
uWindow Title = Internet Explorer, optimized for Bing and MSN
uDefault_Page_URL = hxxp://www.msn.com
BHO: {0407ccf6-b9f0-4f1c-b2c5-6771e6dc9cd9} -
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - f:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: 8056bb9f: {37e14f9f-6942-05ce-5adc-83fc74d40e43} -
BHO: Search Toolbar: {9d425283-d487-4337-bab6-ab8354a81457} - f:\program files\search toolbar\SearchToolbar.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - f:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - f:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - f:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - f:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Search Toolbar: {9d425283-d487-4337-bab6-ab8354a81457} - f:\program files\search toolbar\SearchToolbar.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - f:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - f:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [ctfmon.exe] f:\windows\system32\ctfmon.exe
mRun: [SunJavaUpdateSched] "f:\program files\common files\java\java update\jusched.exe"
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE f:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE f:\windows\system32\NvCpl.dll,NvStartup
mRun: [nmctxth] "f:\program files\common files\pure networks shared\platform\nmctxth.exe"
mRun: [nmapp] "f:\program files\pure networks\network magic\nmapp.exe" -autorun -nosplash
mRun: [NeroFilterCheck] f:\windows\system32\NeroCheck.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [Acrobat Assistant 8.0] "f:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe"
mRun: [avast5] "f:\program files\alwil software\avast5\avastUI.exe" /nogui
StartupFolder: f:\docume~1\alluse~1\startm~1\programs\startup\adobea~2.lnk - f:\windows\installer\{ac76ba86-1033-0000-7760-000000000003}\_SC_Acrobat.exe
StartupFolder: f:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - f:\program files\adobe\acrobat 8.0\acrobat\AdobeCollabSync.exe
StartupFolder: f:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - f:\program files\windows desktop search\WindowsSearch.exe
IE: Append to existing PDF - f:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - f:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - f:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - f:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - f:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - f:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - f:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - f:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - f:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - f:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - f:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - f:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - f:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: %SYSTEMROOT%\system32\nvappfilter.dll
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {55963676-2F5E-4BAF-AC28-CF26AA587566} - hxxps://vpn.plattformad.com/CACHE/stc/1/binaries/vpnweb.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1285910187937
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - f:\program files\common files\pure networks shared\platform\puresp4.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - f:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - f:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: f025ebca1018 - f:\windows\system32\cmpbk3232.dll
AppInit_DLLs: f:\windows\system32\cmpbk3232.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - f:\program files\windows desktop search\MSNLNamespaceMgr.dll
============= SERVICES / DRIVERS ===============
R1 aswSP;aswSP;f:\windows\system32\drivers\aswSP.sys [2010-10-1 165584]
R2 aswFsBlk;aswFsBlk;f:\windows\system32\drivers\aswFsBlk.sys [2010-10-1 17744]
R2 avast! Antivirus;avast! Antivirus;f:\program files\alwil software\avast5\AvastSvc.exe [2010-10-1 40384]
R2 vpnagent;Cisco AnyConnect VPN Agent;f:\program files\cisco\cisco anyconnect vpn client\vpnagent.exe [2009-12-17 497856]
R3 avast! Web Scanner;avast! Web Scanner;f:\program files\alwil software\avast5\AvastSvc.exe [2010-10-1 40384]
S2 gupdate;Google Update Service (gupdate);f:\program files\google\update\GoogleUpdate.exe [2010-10-1 136176]
S3 avast! Mail Scanner;avast! Mail Scanner;f:\program files\alwil software\avast5\AvastSvc.exe [2010-10-1 40384]
S3 PciCon;PciCon;\??\e:\pcicon.sys --> e:\PciCon.sys [?]
=============== Created Last 30 ================
2010-10-02 18:24:33 0 ----a-w- f:\documents and settings\lentz\defogger_reenable
2010-10-02 02:02:03 56 ---ha-w- f:\windows\system32\ezsidmv.dat
2010-10-02 01:01:35 0 d-----r- f:\program files\Skype
2010-10-01 22:56:26 107888 ----a-w- f:\windows\system32\CmdLineExt.dll
2010-10-01 22:14:03 189520 ----a-w- f:\windows\system32\drivers\tmcomm.sys
2010-10-01 22:00:35 0 d-----w- f:\windows\pss
2010-10-01 21:16:28 38 ----a-w- f:\windows\system32\20a5eccd
2010-10-01 21:05:54 69 ----a-w- f:\windows\NeroDigital.ini
2010-10-01 20:17:18 1901 ----a-w- f:\windows\GnuHashes.ini
2010-10-01 20:16:51 0 ---ha-w- f:\documents and settings\lentz\pienkacgtb.tmp
2010-10-01 20:10:08 149 --sha-w- f:\windows\system32\544586650
2010-10-01 20:10:07 1185 ----a-w- f:\windows\system32\6262966
2010-10-01 20:09:46 0 d-sh--w- f:\windows\system32\SysWoW32
2010-10-01 20:09:30 203776 --sh--w- f:\windows\system32\unrar.exe
2010-10-01 20:09:30 0 d-----w- f:\windows\system32\1108839597
2010-10-01 20:09:14 0 d-sh--w- f:\docume~1\lentz\applic~1\SysWin
2010-10-01 20:09:11 210944 ----a-w- f:\windows\system32\cmpbk3232.dll
2010-10-01 19:41:48 0 d-----w- f:\windows\system32\scripting
2010-10-01 19:41:47 0 d-----w- f:\windows\system32\en
2010-10-01 19:41:47 0 d-----w- f:\windows\system32\bits
2010-10-01 19:41:47 0 d-----w- f:\windows\l2schemas
2010-10-01 19:39:53 0 d-----w- f:\windows\network diagnostic
2010-10-01 18:59:22 0 d-----w- f:\windows\system32\URTTemp
2010-10-01 18:52:44 22328 ----a-w- f:\windows\system32\drivers\PnkBstrK.sys
2010-10-01 18:52:44 22328 ----a-w- f:\docume~1\lentz\applic~1\PnkBstrK.sys
2010-10-01 18:52:29 669184 ----a-w- f:\windows\system32\pbsvc.exe
2010-10-01 18:52:29 66872 ----a-w- f:\windows\system32\PnkBstrA.exe
2010-10-01 18:52:29 103736 ----a-w- f:\windows\system32\PnkBstrB.exe
2010-10-01 18:52:27 444776 ----a-w- f:\windows\system32\d3dx10_35.dll
2010-10-01 18:52:26 443752 ----a-w- f:\windows\system32\d3dx10_34.dll
2010-10-01 18:52:26 3727720 ----a-w- f:\windows\system32\d3dx9_35.dll
2010-10-01 18:52:26 1358192 ----a-w- f:\windows\system32\D3DCompiler_35.dll
2010-10-01 18:52:26 1124720 ----a-w- f:\windows\system32\D3DCompiler_34.dll
2010-10-01 18:52:25 3497832 ----a-w- f:\windows\system32\d3dx9_34.dll
2010-10-01 18:52:24 81768 ----a-w- f:\windows\system32\xinput1_3.dll
2010-10-01 18:33:51 0 d-----w- f:\program files\common files\Control Panels
2010-10-01 18:32:21 0 d-----w- f:\docume~1\alluse~1\applic~1\ALM
2010-10-01 18:24:33 2463976 ----a-w- f:\windows\system32\NPSWF32.dll
2010-10-01 18:24:33 190696 ----a-w- f:\windows\system32\NPSWF32_FlashUtil.exe
2010-10-01 18:19:55 0 d-----w- f:\program files\Bonjour
2010-10-01 18:16:28 0 d-----w- f:\program files\common files\Macrovision Shared
2010-10-01 17:48:22 49857 ------w- f:\windows\UNNMP.cfg
2010-10-01 17:48:21 2977792 ------w- f:\windows\UNNMP.exe
2010-10-01 17:46:37 155648 ----a-w- f:\windows\system32\NeroCheck.exe
2010-10-01 17:42:49 2973696 ------w- f:\windows\UNNeroVision.exe
2010-10-01 17:42:49 24064 ------w- f:\windows\system32\msxml3a.dll
2010-10-01 17:42:49 154568 ------w- f:\windows\UNNeroVision.cfg
2010-10-01 17:42:10 471040 ------w- f:\windows\system32\ImagXRA7.dll
2010-10-01 17:42:10 364544 ------w- f:\windows\system32\TwnLib4.dll
2010-10-01 17:42:09 476320 ------w- f:\windows\system32\ImagXpr7.dll
2010-10-01 17:42:09 262144 ------w- f:\windows\system32\ImagXR7.dll
2010-10-01 17:42:09 1568768 ------w- f:\windows\system32\ImagX7.dll
2010-10-01 17:42:08 38912 ------w- f:\windows\system32\picn20.dll
2010-10-01 17:42:08 106496 ----a-w- f:\windows\system32\TwnLib20.dll
2010-10-01 17:05:55 0 d-----r- f:\docume~1\lentz\applic~1\Brother
2010-10-01 17:05:03 419 ----a-w- f:\windows\BRWMARK.INI
2010-10-01 17:05:03 27 ----a-w- f:\windows\BRPP2KA.INI
2010-10-01 16:30:30 93 ----a-w- f:\windows\brpcfx.ini
2010-10-01 16:30:30 50 ----a-w- f:\windows\system32\bridf07a.dat
2010-10-01 16:30:30 225 ----a-w- f:\windows\Brpfx04a.ini
2010-10-01 16:30:06 54784 ----a-w- f:\windows\system32\brinsstr.dll
2010-10-01 16:30:02 9 ----a-w- f:\windows\Brfaxrx.ini
2010-10-01 16:30:01 73728 ------w- f:\windows\system32\BRCrypt.dll
2010-10-01 16:30:01 61440 ------w- f:\windows\system32\BrMfNt.dll
2010-10-01 16:30:01 163840 ------w- f:\windows\system32\NSSearch.dll
2010-10-01 16:30:01 131072 ----a-w- f:\windows\brunin03.dll
2010-10-01 16:30:01 106496 ------w- f:\windows\system32\BrMuSNMP.dll
2010-10-01 16:30:01 0 d-----w- f:\program files\Brother
2010-10-01 16:29:50 0 d-----w- f:\docume~1\alluse~1\applic~1\Brother
2010-10-01 16:00:14 0 d-----w- f:\docume~1\lentz\applic~1\Windows Desktop Search
2010-10-01 15:58:42 0 d-----w- f:\windows\system32\GroupPolicy
2010-10-01 15:58:42 0 d-----w- f:\program files\Windows Desktop Search
2010-10-01 15:32:19 38848 ----a-w- f:\windows\avastSS.scr
2010-10-01 15:32:16 0 d-----w- f:\docume~1\alluse~1\applic~1\Alwil Software
2010-10-01 14:53:48 0 d-----w- f:\program files\Pure Networks
2010-10-01 14:53:22 0 d-----w- f:\program files\WebEx
2010-10-01 14:52:37 25392 ----a-w- f:\windows\system32\drivers\pnarp.sys
2010-10-01 14:52:36 26672 ----a-w- f:\windows\system32\drivers\purendis.sys
2010-10-01 14:52:34 0 d-----w- f:\program files\common files\Pure Networks Shared
2010-10-01 14:52:24 0 d-----w- f:\docume~1\alluse~1\applic~1\Pure Networks
2010-10-01 14:41:22 274288 ----a-w- f:\windows\system32\mucltui.dll
2010-10-01 14:41:22 16736 ----a-w- f:\windows\system32\mucltui.dll.mui
2010-10-01 14:26:16 3255 ----a-w- f:\windows\system32\wbem\Outlook_01cb61749b99dce6.mof
2010-10-01 13:34:24 0 d-----w- f:\program files\VideoLAN
2010-10-01 12:45:38 423656 ----a-w- f:\windows\system32\deployJava1.dll
2010-10-01 12:35:25 221184 ----a-w- f:\windows\system32\wmpns.dll
2010-10-01 05:42:29 0 d-----w- f:\program files\Marvell
2010-10-01 05:34:30 0 d-----w- f:\program files\Realtek Sound Manager
2010-10-01 05:34:29 0 d-----w- f:\program files\AvRack
2010-10-01 05:33:27 0 d-----w- f:\program files\NVIDIA Corporation
2010-10-01 05:19:39 0 d-sh--w- f:\documents and settings\all users\DRM
2010-10-01 05:19:24 0 d--h--w- f:\program files\WindowsUpdate
2010-10-01 05:18:35 0 d-----w- f:\program files\common files\MSSoap
2010-10-01 05:17:25 0 d-----w- f:\program files\Online Services
2010-10-01 05:17:20 0 d-----w- f:\program files\Messenger
2010-10-01 05:17:17 0 d-----w- f:\program files\MSN Gaming Zone
2010-10-01 05:16:44 0 d-----w- f:\program files\Windows NT
2010-10-01 04:53:17 0 d-----w- f:\program files\LimeWire
2010-10-01 04:29:13 0 d-----w- f:\program files\Cisco
2010-10-01 04:29:11 0 d-----w- f:\docume~1\alluse~1\applic~1\Cisco
2010-10-01 04:06:24 0 d-----w- f:\program files\Web
2010-10-01 04:06:24 0 d-----w- f:\program files\Resources
2010-10-01 04:03:03 0 d-----w- f:\program files\Search Toolbar
2010-10-01 03:45:24 0 d-----w- f:\temp\ext256
2010-09-30 22:08:22 0 d-----w- f:\program files\common files\ODBC
2010-09-30 22:08:20 0 d-----w- f:\program files\common files\SpeechEngines
2010-09-30 22:07:53 0 d-----r- f:\documents and settings\all users\Documents
==================== Find3M ====================
2010-10-01 05:17:45 21640 ----a-w- f:\windows\system32\emptyregdb.dat
2010-10-01 05:16:57 60416 ----a-w- f:\windows\ALCFDRTM.EXE
2010-08-17 13:17:06 58880 ----a-w- f:\windows\system32\spoolsv.exe
2010-07-22 15:49:15 590848 ----a-w- f:\windows\system32\rpcrt4.dll
2010-07-22 05:57:20 5120 ----a-w- f:\windows\system32\xpsp4res.dll
============= FINISH: 13:30:15.98 ===============