Well, I had to get your attention somehow! ;o). Thought the subject title might do the trick!
I just wanted to mention that I am a regular user of HiJackThis!, Spybot, and AdAware. I've been a member here since my own PC got infected quite some time ago. Crunchie helped me through that time. This is my son's PC and I haven't been able to keep tabs on it, seeing as he is living with his dad currently. He is here for a visit. Anyway, I try to stay up to date and stay familiar with what is on my PC. Which I feel is probably important. Thanks so much for your help so far!!
Ok, I have MSN dialup. When I rclick Network Connections and select properties, I only have an "Advanced" tab with Firewall options. How to obtain DNS servers automatically? Should I move on with the next steps or wait to thoroughly complete all steps?
Well, I moved on.
Next... Flushed DNS cache w/ cmd "ipconfig /flushdns".
Fixed checked entries on HiJackThis.
Did cmd "sc delete msupdate"
Browsed to and deleted c:\windows\system32\msvcrtd.exe
Dwnloaded and ran CCleaner.
Dwnloaded and ran AVG.
(I'm scared I got infected more while online dwnloading AVG.)
Here's the fresh Logs. (Gulp! Yikes!)
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 9:19:41 PM 7/11/2007
+ Scan result:
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP1\A0000224.exe -> Backdoor.Agent.alm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP1\A0000256.exe -> Backdoor.Agent.alm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP1\A0000411.exe -> Backdoor.Agent.alm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP1\A0001001.exe -> Backdoor.Agent.alm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP1\A0001858.exe -> Backdoor.Agent.alm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP2\A0002005.exe -> Backdoor.Agent.alm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP5\A0002757.exe -> Backdoor.Agent.alm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0002826.exe -> Backdoor.Agent.alm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0002871.exe -> Backdoor.Agent.alm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0003428.exe -> Backdoor.Agent.alm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0003681.exe -> Backdoor.Agent.alm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0004709.exe -> Backdoor.Agent.alm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0005672.exe -> Backdoor.Agent.alm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0005688.exe -> Backdoor.Agent.alm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0006688.exe -> Backdoor.Agent.alm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0007688.exe -> Backdoor.Agent.alm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP7\A0007863.exe -> Backdoor.Agent.alm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP7\A0008019.exe -> Backdoor.Agent.alm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP7\A0008468.exe -> Backdoor.Agent.alm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP7\A0008469.exe -> Backdoor.Agent.alm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0003468.exe -> Downloader.Small.evw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0003654.exe -> Downloader.Small.evw : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\1AHJDBXB\loadadv735[1].exe -> Dropper.Small.ayg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP1\A0000243.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP1\A0001004.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP1\A0001859.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP2\A0001916.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP2\A0002006.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP5\A0002758.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0002827.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0002872.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0003443.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0003683.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0004711.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0005674.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0005690.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0006690.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0007689.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP7\A0007865.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP7\A0008295.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP7\A0008365.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP7\A0008647.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP7\A0008679.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP7\A0009677.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP7\A0009723.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP7\A0010021.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP7\A0012496.sys -> Rootkit.Agent.ex : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0003395.exe -> Trojan.Agent.aia : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0003444.exe -> Trojan.Agent.aia : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0003653.exe -> Trojan.Agent.aia : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0003678.exe -> Trojan.Agent.aia : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0004687.exe -> Trojan.Agent.aia : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0004712.exe -> Trojan.Agent.aia : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0005669.exe -> Trojan.Agent.aia : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0005675.exe -> Trojan.Agent.aia : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0005685.exe -> Trojan.Agent.aia : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0005691.exe -> Trojan.Agent.aia : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0006685.exe -> Trojan.Agent.aia : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0006691.exe -> Trojan.Agent.aia : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0007685.exe -> Trojan.Agent.aia : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP6\A0007691.exe -> Trojan.Agent.aia : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP7\A0007837.exe -> Trojan.Agent.aia : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{364799B5-FD74-436F-9734-73FB5B8BBF9C}\RP7\A0007864.exe -> Trojan.Agent.aia : Cleaned with backup (quarantined).
::Report end::
>>>>Username "Owner" - 2007-07-11 19:04:44 [Fixwareout edited 2007/07/05]
»»»»»Prerun check
System was rebooted successfully.
»»»»» Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"=""
....
....
»»»»» Misc files.
....
»»»»» Checking for older varients.
....
»»»»» Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\\WINDOWS\\System32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\System32\\hkcmd.exe"
"lanmanwrk.exe"="C:\\WINDOWS\\System32\\lanmanwrk.exe"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ttool"="C:\\WINDOWS\\9129837.exe"
....
Hosts file was reset, If you use a custom hosts file please replace it
»»»»» End report »»»»»
Logfile of HijackThis v1.99.1
Scan saved at 9:28:40 PM, on 7/11/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\qmhoepkf.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HiJackThis!\HijackThis.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [lanmanwrk.exe] C:\WINDOWS\System32\lanmanwrk.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/micr...?1184036107828
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/micr...?1184036016312
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Network helper Service (MSDisk) - Unknown owner - C:\WINDOWS\System32\irdvxc.exe" /service (file missing)
O23 - Service: Network Windows Service (MSWindows) - Unknown owner - C:\WINDOWS\System32\urdvxc.exe" /service (file missing)