Thread: Lots of issues
View Single Post
Old 10-13-2007, 07:31 PM   #3 (permalink)
tetonbob
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,228
OS: 2000 Pro; XP Pro; XP Home


Re: Lots of issues

Hello, and Welcome to TSF.

Yuck....you've got evidence of several inactive old infections, as well as a new one. What have you been doing on the internet?

Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe.

Before beginning the fix, read this post completely. If there's anything that you do not understand, kindly ask your questions before proceeding. Ensure that there aren't any opened browsers when you are carrying out the procedures below. Save the following instructions in Notepad as this webpage would not be available when you're carrying out the fix.

It is IMPORTANT that you don't miss a step & perform everything in the correct order/sequence.

---------------------------------------------------------------------------------------------

I see you have more than one Anti-Virus program installed, AVG and Avira. While this may seem like greater protection, it can cause problems including slowdowns and system hangs. It can also prevent the AV from doing it's job. Choose one to keep and uninstall the other.

Any antivirus program must be removed via add/remove program.
For any program that doesn't have an add/remove entry, you will have to do this:
re-install the program -> reboot -> uninstall
-----------------------------------------------------------------------
  1. Download this file - http://download.bleepingcomputer.com...a/ComboFix.exe

    * IMPORTANT !!! Place combofix.exe on your Desktop


  2. Disconnect from the internet....pull the plug!
  3. Open HijackThis and click on 'Do a System Scan Only'. Check the following entries if they exist (make sure you do not miss any) and click Fix Checked

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php...MjI6Ojg5&lid=2
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R3 - Default URLSearchHook is missing
    O2 - BHO: MSVPS System - {05F79890-CFA6-4D53-87BC-2F390DA6645E} - C:\WINDOWS\bndsrsvk.dll
    O2 - BHO: (no name) - {3C1F6EAF-612B-478F-BF2D-6ABD825905A8} - C:\WINDOWS\system32\awvtu.dll (file missing)
    O3 - Toolbar: The netadv - {899B0EF2-E0BE-41BA-BB41-0ABFB232813C} - C:\WINDOWS\netadv.dll
    O4 - HKLM\..\Run: [RoamMfcdLiesThis] C:\Documents and Settings\All Users.WINDOWS\Application Data\nurb surf roam mfcd\Hidepure.exe
    O4 - HKLM\..\Run: [{35-59-95-55-ZN}] c:\WINDOWS\system32\qpdsregs.exe FI002
    O4 - HKLM\..\Run: [w774c9b8.dll] RUNDLL32.EXE w774c9b8.dll,I2 00024aaf0774c9b8
    O4 - HKLM\..\Run: [win32069083-32483] C:\WINDOWS\win32069083-32483.exe
    O4 - HKLM\..\Run: [ms04839083-324] C:\WINDOWS\ms04839083-324.exe
    O4 - HKLM\..\Run: [ms0539083-3248] C:\WINDOWS\ms0539083-3248.exe
    O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
    O4 - HKLM\..\RunServices: [stratas] lockx.exe
    O4 - HKCU\..\Run: [stratas] lockx.exe
    O4 - HKCU\..\Run: [actx1.exe] C:\Documents and Settings\Larry.LARCOMP\Application Data\System Restore\actx1.exe
    O4 - HKCU\..\Run: [zqactx1.exe] C:\WINDOWS\System32\zqactx1.exe
    O4 - HKCU\..\Run: [Asbr] "C:\PROGRA~1\COMMON~1\ASKS~1\wuaclt.exe" -vt yax
    O4 - HKCU\..\Run: [Waj] C:\WINDOWS\APPATC~1\rundll32.exe
    O4 - HKCU\..\Run: [My Web Search Community Tools] "C:\Program Files\MyWebSearch\bar\1.bin\m3IMPipe.exe"
    O4 - HKLM\..\Policies\Explorer\Run: [ishost.exe] ishost.exe
    O4 - HKLM\..\Policies\Explorer\Run: [issearch.exe] issearch.exe
    O4 - HKLM\..\Policies\Explorer\Run: [kernel32.dll] C:\WINDOWS\system32\isnotify.exe
    O4 - HKLM\..\Policies\Explorer\Run: [vpnxgv] C:\DOCUME~1\LARRY~1.LAR\LOCALS~1\Temp\vpnxgv.exe
    O4 - HKCU\..\Policies\Explorer\Run: [{ECA35955-07CA-1033-0528-020326200001}] "C:\Program Files\Common Files\{ECA35955-07CA-1033-0528-020326200001}\Update.exe" mc-110-12-0000272
    O4 - Startup: Zeno.lnk = C:\WINDOWS\eliteunstall.exe
    O4 - Startup: Z_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...rch.jhtml?p=ZJ
    O15 - Trusted Zone: *.elitemediagroup.net
    O15 - Trusted Zone: http://click.getmirar.com (HKLM)
    O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
    O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
    O16 - DPF: sptbaxcab - http://www.try2find.com/toolbar/setup/sptbax.cab
    O16 - DPF: {0645D7F3-C20E-4E0B-A545-557527497C0B} (NMInstall Control) - http://a14.g.akamai.net/f/14/7141/1d...APANEL_USA.cab
    O16 - DPF: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - http://liveca06.rightnowtech.com/7020-b375h/rnl/java
    O16 - DPF: {26098EA2-C95D-48EA-89B4-63C5A63BD42F} - http://www.pacimedia.com/install/pcs_0002.exe
    O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://drivecleaner.com/.freeware/in...eanerstart.cab
    O16 - DPF: {41ACD49D-1974-791A-0981-AA9872721044} (Ganymede Board Games) - http://67.15.101.3/g_bin/eng/boards_2_0_0_24.cab
    O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} - http://cabs.elitemediagroup.net/cabs/mediaview.cab
    O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/Yazzl...cab?refid=1123
    O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/.../installer.exe
    O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://www.systemdoctor.com/download...reeInstall.cab
    O20 - Winlogon Notify: Telephony - C:\WINDOWS\system32\ktpul7791.dll (file missing)
    O20 - Winlogon Notify: winjks32 - winjks32.dll (file missing)
    O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - (no file)
    O21 - SSODL: msvb - {FFC17CE6-92F4-480A-9912-75B005FEA2E3} - C:\WINDOWS\msvb.dll
    O21 - SSODL: sysdx - {7A68DD46-B37E-405D-B25D-FDD99C6BC7C5} - C:\WINDOWS\sysdx.dll
    O22 - SharedTaskScheduler: {03413bf7-e34c-445b-bfc0-a2b127255871} - incestuously - (no file)
    O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm



    Close HijackThis now.

    ---------------------------------------------------------------------------------------------


  4. Go to -> Run -> paste in the following single line command & click OK

    "%userprofile%\desktop\combofix.exe" /killall



  5. Follow the prompts. Type "1" and press Enter to begin the scan.
  6. Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  7. When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

    ---------------------------------------------------------------------------------------------
  8. Re-establish an internet connection.
  9. Open HijackThis and click on 'Do a System Scan and save a Logfile'. Save the log file and post it here.

    ---------------------------------------------------------------------------------------------
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline