Little Oscar
New member
Hi - thanks for looking at this! I have an older laptop (Win2000) that got infected. I ran AVG and it cleaned out 80+ infections. I was concerned when I got a pop-up stating that there were items were embedded in files and that the whole file would be quarrantined if selected. I didn't on the first scan but did on the next scans. There are 3 different AVG scan reports included and the HJT.
With the infections, I could not connect to the internet and kept getting a dial up box with an unknown ph# to connect with. Now, I am having trouble connecting to the internet (MSN9 dial-up) and running the Trend Micro anti-virus. I uninstalled both and tried to re-install. The MSN software hangs up when it is dialing the modem. I checked the modem and it is working properly. It was working properly before the infection as well.
With the Trend Micro, I uninstalled the 2006 vers and attempted to install the 2007. It appears to only partially install and there are several pop-ups saying that there are files that cannot open and will shut down. I queried some of them on the net and they pertain to TM. I also had to uninstall SpyBot before I could try to install Tm.
I don't know if there's still some infection or virus or if I just totally screwed up trying to fix things on my own. Would you review the reports and provide some guidance? Thank you!
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 5:28:50 PM 04/29/2007
+ Scan result:
C:\dnmc10.exe/tr.exe -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\0d9.exe/dsl.exe -> Downloader.Adload.j : Cleaned with backup (quarantined).
C:\dk9.exe/sl.exe -> Downloader.Adload.j : Cleaned with backup (quarantined).
::Report end
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 6:47:41 PM 04/28/2007
+ Scan result:
C:\dnmc10.exe/tr.exe -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\0d9.exe/dsl.exe -> Downloader.Adload.j : Cleaned with backup (quarantined).
C:\dk9.exe/sl.exe -> Downloader.Adload.j : Cleaned with backup (quarantined).
::Report end
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 11:01:04 AM 04/29/2007
+ Scan result:
HKU\S-1-5-21-1960408961-1383384898-1957994488-1000\Software\Microsoft\Internet Explorer\Keywords -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
C:\WINNT\inet20004\3.00.13.dll -> Adware.Ihbo : Cleaned with backup (quarantined).
C:\WINNT\inet20004\3.01.00.dll -> Adware.Ihbo : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : Cleaned with backup (quarantined).
C:\55.exe -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\dnmc10.exe/tr.exe -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\i66.exe -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\tr.exe -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\winmc0.exe -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\0d9.exe/dsl.exe -> Downloader.Adload.j : Cleaned with backup (quarantined).
C:\dk9.exe/sl.exe -> Downloader.Adload.j : Cleaned with backup (quarantined).
C:\WINNT\system32\vxh8jkdq2.exe -> Not-A-Virus.Hoax.Win32.Renos.az : Cleaned with backup (quarantined).
::Report end
Logfile of HijackThis v1.99.1
Scan saved at 9:17:36 PM, on 5/1/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
C:\WINNT\winlogon.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\WINNT\system32\NOTEPAD.EXE
C:\WINNT\system32\NOTEPAD.EXE
C:\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://nettools.usps.gov/proxy.pac
F3 - REG:win.ini: run=C:\WINNT\inet20004\winlogon.exe
O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE" /minimized
O4 - HKCU\..\Run: [System] C:\WINNT\winlogon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O20 - Winlogon Notify: msupdate - C:\WINNT\SYSTEM32\msupdate32.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: prxsvc - {7240FB1F-BCF7-4773-AC1A-4EFE254393FD} - prxsvc.dll (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Defragmentation Management Handler (FAT Defragmentation) - Unknown owner - C:\WINNT\system32\dfrgfat32.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
With the infections, I could not connect to the internet and kept getting a dial up box with an unknown ph# to connect with. Now, I am having trouble connecting to the internet (MSN9 dial-up) and running the Trend Micro anti-virus. I uninstalled both and tried to re-install. The MSN software hangs up when it is dialing the modem. I checked the modem and it is working properly. It was working properly before the infection as well.
With the Trend Micro, I uninstalled the 2006 vers and attempted to install the 2007. It appears to only partially install and there are several pop-ups saying that there are files that cannot open and will shut down. I queried some of them on the net and they pertain to TM. I also had to uninstall SpyBot before I could try to install Tm.
I don't know if there's still some infection or virus or if I just totally screwed up trying to fix things on my own. Would you review the reports and provide some guidance? Thank you!
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 5:28:50 PM 04/29/2007
+ Scan result:
C:\dnmc10.exe/tr.exe -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\0d9.exe/dsl.exe -> Downloader.Adload.j : Cleaned with backup (quarantined).
C:\dk9.exe/sl.exe -> Downloader.Adload.j : Cleaned with backup (quarantined).
::Report end
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 6:47:41 PM 04/28/2007
+ Scan result:
C:\dnmc10.exe/tr.exe -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\0d9.exe/dsl.exe -> Downloader.Adload.j : Cleaned with backup (quarantined).
C:\dk9.exe/sl.exe -> Downloader.Adload.j : Cleaned with backup (quarantined).
::Report end
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 11:01:04 AM 04/29/2007
+ Scan result:
HKU\S-1-5-21-1960408961-1383384898-1957994488-1000\Software\Microsoft\Internet Explorer\Keywords -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
C:\WINNT\inet20004\3.00.13.dll -> Adware.Ihbo : Cleaned with backup (quarantined).
C:\WINNT\inet20004\3.01.00.dll -> Adware.Ihbo : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : Cleaned with backup (quarantined).
C:\55.exe -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\dnmc10.exe/tr.exe -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\i66.exe -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\tr.exe -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\winmc0.exe -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\0d9.exe/dsl.exe -> Downloader.Adload.j : Cleaned with backup (quarantined).
C:\dk9.exe/sl.exe -> Downloader.Adload.j : Cleaned with backup (quarantined).
C:\WINNT\system32\vxh8jkdq2.exe -> Not-A-Virus.Hoax.Win32.Renos.az : Cleaned with backup (quarantined).
::Report end
Logfile of HijackThis v1.99.1
Scan saved at 9:17:36 PM, on 5/1/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
C:\WINNT\winlogon.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\WINNT\system32\NOTEPAD.EXE
C:\WINNT\system32\NOTEPAD.EXE
C:\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://nettools.usps.gov/proxy.pac
F3 - REG:win.ini: run=C:\WINNT\inet20004\winlogon.exe
O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE" /minimized
O4 - HKCU\..\Run: [System] C:\WINNT\winlogon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O20 - Winlogon Notify: msupdate - C:\WINNT\SYSTEM32\msupdate32.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: prxsvc - {7240FB1F-BCF7-4773-AC1A-4EFE254393FD} - prxsvc.dll (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Defragmentation Management Handler (FAT Defragmentation) - Unknown owner - C:\WINNT\system32\dfrgfat32.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe