Hello,
I'm hoping you guys can help me out here. My father just bought a business and kept complaining that the office computer is infected. Over the weekend I installed spybot on the system and it flagged two problems, Smitfraud and Virtumonde. Spybot is not able to delete these two issues at all. The HJT report is as follows:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 8:47:55 AM, on 7/6/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
c:\ACS\Back office\Platform\BatchService.exe
C:\ACS\Server\Bin\NCRReceiveUpdatesSvc.exe
c:\ACS\Back office\Platform\SILService.exe
C:\ACS\Server\Bin\tm.exe
C:\WINNT\U2llcnJhIE5ldmFkYSBDYXNoIFJlZ2lzdGVy\command.exe
C:\WINNT\system32\crypserv.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\system32\svchost.exe
C:\ACS\Back Office\Platform\ASWRegistrationService.exe
C:\ACS\Server\Bin\cswitch.exe
C:\ACS\Server\Bin\tms32.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\System32\llssrv.exe
c:\Program Files\Microsoft SQL Server\MSSQL$ACS\Binn\sqlservr.exe
C:\ACS\Loader\Programs\acsapsrv.exe
C:\Program Files\NCR\FitClient\NCRTFTPs.exe
C:\Program Files\NCR\FitClient\FitClientLoader.exe
C:\WINNT\system32\ntfrs.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\locator.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\ACS\Server\Bin\aup.exe
C:\ACS\Server\Bin\svcupdate.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\RunDll32.exe
C:\WINNT\system32\tcpsvcs.exe
C:\WINNT\TEMP\cks3.tmp
C:\WINNT\System32\dns.exe
C:\ACS\Server\Bin\closemgr.exe
C:\ACS\Server\Bin\perl.exe
C:\ACS\Server\Bin\DeptReptExt.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\ACS\Server\Bin\posoffl.exe
c:\acs\Loader\Programs\acsapsrv.exe
C:\WINNT\System32\ismserv.exe
C:\WINNT\system32\msdtc.exe
C:\ACS\Server\Bin\perl.exe
C:\ACS\Back office\Platform\TLogAccumulator.exe
C:\ACS\Server\Bin\perl.exe
C:\ACS\Server\Bin\cmhost.exe
C:\ACS\server\bin\cmhostctf.exe
C:\ACS\Server\Bin\cmol.exe
c:\acs\Loader\Programs\acsapsrv.exe
C:\ACS\Loader\Programs\acsapsrv.exe
C:\ACS\Server\Bin\drpurge.exe
C:\ACS\Server\Bin\perl.exe
C:\ACS\Server\Bin\acsproc.exe
C:\ACS\Server\Bin\MRMServer.exe
C:\ACS\Server\Bin\mrmSqlServer.exe
C:\ACS\Server\Bin\PLUExceptionExtractHost.exe
C:\ACS\Server\Bin\resmgr.exe
C:\ACS\Server\Bin\logmgr.exe
c:\Program Files\Microsoft SQL Server\MSSQL$ACS\Binn\sqlagent.EXE
C:\ACS\Server\Bin\accmgr.exe
C:\ACS\Server\Bin\iftrpmgr.exe
C:\ACS\Server\Bin\corrmgr.exe
C:\ACS\Server\Bin\clubctf.exe
C:\ACS\Server\Bin\offmgr.exe
C:\ACS\Server\Bin\cmctf.exe
C:\ACS\Server\Bin\sopup.exe
C:\ACS\Server\Bin\hostmgr.exe
C:\ACS\Server\Bin\casmgr.exe
C:\WINNT\Explorer.EXE
C:\ACS\Server\Bin\timemgr.exe
C:\ACS\Server\Bin\sreqpipe.exe
C:\ACS\Server\Bin\srsppipe.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hkcmd.exe
C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\PROGRA~1\COMMON~1\rmku\rmkum.exe
C:\Program Files\Lynk\Integra\LynkIntegraServer.exe
C:\Program Files\Lynk\Integra\LynkIntegraClient.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\ACS\Back office\Platform\ASWShell.exe
C:\WINNT\system32\o02PrEz\o02PrEz1065.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\WINNT\explorer.exe
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\Program Files\Comodo\CBOClean\BOCORE.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Documents and Settings\Administrator\Desktop\spywareblastersetup351.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-CLDEB.tmp\is-PAVTT.tmp
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\PROGRA~1\Yahoo!\browser\ybrowser.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\PROGRA~1\COMMON~1\rmku\rmkua.exe
C:\Documents and Settings\Administrator\Desktop\HiJackThis_v2.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2A0D7F1D-BC3E-4BD8-9442-11FB2D0332AA} - C:\Program Files\WindowsUpdate\vixylex.dll
O2 - BHO: (no name) - {3E8EC2D9-806B-4C7F-AE7F-F44AD4ABE8B5} - C:\WINNT\system32\urqnkji.dll
O2 - BHO: (no name) - {5ADF3862-9E2E-4ad3-86F7-4510E6550CD0} - C:\WINNT\system32\ecptiyec.dll
O2 - BHO: (no name) - {6DD5F76E-FEAC-4343-9B5F-0E206296C73A} - C:\Program Files\WindowsUpdate\vixylex.dll
O2 - BHO: 0 - {7E125488-0D86-4490-908B-65EC811F44CC} - C:\Program Files\Accessories\zykifuzit.dll
O2 - BHO: (no name) - {B80D9931-0D93-42D0-96F3-8B0672CA7FA0} - C:\WINNT\system32\naoqqxay.dll
O2 - BHO: (no name) - {DBC7BB3A-CB27-4E2A-B62C-2E96A5A22BF7} - C:\WINNT\system32\naoqqxay.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINNT\system32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [{ZN}] C:\Documents and Settings\Administrator\Local Settings\Temp\TICHD003.exe CHD003
O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKLM\..\Run: [WinTouch] C:\Program Files\WinTouch\WinTouch.exe
O4 - HKLM\..\Run: [ntdll.dll] C:\WINNT\retadpu2000219.exe 61A847B5BBF72810329B385473F001F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310F3D1DC7E4638E8323A15806F9DA6EF604776CA6C1637FB11E3C281231B2CCE7003
O4 - HKLM\..\Run: [GPLv3] rundll32.exe "C:\WINNT\system32\xvjpegsa.dll",realset
O4 - HKLM\..\Run: [BOC-424] C:\PROGRA~1\Comodo\CBOClean\BOC424.exe
O4 - HKLM\..\RunOnce: [RemoveInstallPath] cmd.exe C:\WINNT\system32\cmd.exe /c rmdir /S /Q "C:\PROGRA~1\WinPop" > nul
O4 - HKLM\..\RunOnce: [SpybotDeletingA1239] command /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7143] cmd /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1210] command /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC464] cmd /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8629] command /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2632] cmd /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA567] command /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2685] cmd /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA3499] command /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5718] cmd /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9249] command /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1004] cmd /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9463] command /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5415] cmd /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1991] command /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7793] cmd /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [GoToMeeting] C:\Program Files\Citrix\GoToMeeting\190\g2mstart.exe "/Trigger RunAtLogon"
O4 - HKCU\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKCU\..\Run: [rmku] C:\PROGRA~1\COMMON~1\rmku\rmkum.exe
O4 - HKCU\..\Run: [ntdll.dll] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7433] command /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1074] cmd /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7485] command /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3228] cmd /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3247] command /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1011] cmd /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4921] command /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8518] cmd /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6488] command /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2947] cmd /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2232] command /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD210] cmd /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3123] command /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3778] cmd /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8890] command /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7907] cmd /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - .DEFAULT Startup: TA_Start.lnk = C:\Documents and Settings\Administrator\Local Settings\Temp\TICHD003.exe (User 'Default user')
O4 - Startup: TA_Start.lnk = C:\Documents and Settings\Administrator\Local Settings\Temp\TICHD003.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Lynk Integra Server.LNK = C:\Program Files\Lynk\Integra\LynkIntegraServer.exe
O4 - Global Startup: LynkIntegraClient.LNK = C:\Program Files\Lynk\Integra\LynkIntegraClient.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {8BBDC81D-81B3-49EE-87E8-47B7A707FAE8} (GoToMeeting/GoToWebinar Web Starter) - https://www.gotomeeting.com/default/applets/g2mdlax.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8771438C-67D3-4436-A649-0E405C31E072}: NameServer = 127.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{9104A1FA-F3D6-4354-90B3-A3A4C9014955}: NameServer = 127.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{FA535FC1-FBEF-4407-9755-E0470966C8B5}: NameServer = 68.94.156.1,68.94.157.1
O20 - Winlogon Notify: urqnkji - C:\WINNT\SYSTEM32\urqnkji.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINNT\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINNT\system32\browseui.dll
O23 - Service: ACS Batch Service - - c:\ACS\Back office\Platform\BatchService.exe
O23 - Service: ACS Receive Updates - NCR - C:\ACS\Server\Bin\NCRReceiveUpdatesSvc.exe
O23 - Service: ACS SIL Service - - c:\ACS\Back office\Platform\SILService.exe
O23 - Service: ACS Task Manager - NCR - C:\ACS\Server\Bin\tm.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINNT\SYSTEM32\crypserv.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Application Load Server (NCR Application Load Server) - NCR - C:\ACS\Loader\Programs\acsapsrv.exe
O23 - Service: NCR TFTP Service - NCR - C:\Program Files\NCR\FitClient\NCRTFTPs.exe
O23 - Service: NCR FitClient Loader (NCRFitClientLoader) - NCR - C:\Program Files\NCR\FitClient\FitClientLoader.exe
O23 - Service: RSH Daemon (rshd) - Unknown owner - C:\scot\bin\rshd.exe (file missing)
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: SvcUpdate - NCR - C:\ACS\Server\Bin\svcupdate.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Accessories\disososys.html
--
End of file - 15844 bytes
Any thoughts are appreciated!!
I'm hoping you guys can help me out here. My father just bought a business and kept complaining that the office computer is infected. Over the weekend I installed spybot on the system and it flagged two problems, Smitfraud and Virtumonde. Spybot is not able to delete these two issues at all. The HJT report is as follows:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 8:47:55 AM, on 7/6/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
c:\ACS\Back office\Platform\BatchService.exe
C:\ACS\Server\Bin\NCRReceiveUpdatesSvc.exe
c:\ACS\Back office\Platform\SILService.exe
C:\ACS\Server\Bin\tm.exe
C:\WINNT\U2llcnJhIE5ldmFkYSBDYXNoIFJlZ2lzdGVy\command.exe
C:\WINNT\system32\crypserv.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\system32\svchost.exe
C:\ACS\Back Office\Platform\ASWRegistrationService.exe
C:\ACS\Server\Bin\cswitch.exe
C:\ACS\Server\Bin\tms32.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\System32\llssrv.exe
c:\Program Files\Microsoft SQL Server\MSSQL$ACS\Binn\sqlservr.exe
C:\ACS\Loader\Programs\acsapsrv.exe
C:\Program Files\NCR\FitClient\NCRTFTPs.exe
C:\Program Files\NCR\FitClient\FitClientLoader.exe
C:\WINNT\system32\ntfrs.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\locator.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\ACS\Server\Bin\aup.exe
C:\ACS\Server\Bin\svcupdate.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\RunDll32.exe
C:\WINNT\system32\tcpsvcs.exe
C:\WINNT\TEMP\cks3.tmp
C:\WINNT\System32\dns.exe
C:\ACS\Server\Bin\closemgr.exe
C:\ACS\Server\Bin\perl.exe
C:\ACS\Server\Bin\DeptReptExt.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\ACS\Server\Bin\posoffl.exe
c:\acs\Loader\Programs\acsapsrv.exe
C:\WINNT\System32\ismserv.exe
C:\WINNT\system32\msdtc.exe
C:\ACS\Server\Bin\perl.exe
C:\ACS\Back office\Platform\TLogAccumulator.exe
C:\ACS\Server\Bin\perl.exe
C:\ACS\Server\Bin\cmhost.exe
C:\ACS\server\bin\cmhostctf.exe
C:\ACS\Server\Bin\cmol.exe
c:\acs\Loader\Programs\acsapsrv.exe
C:\ACS\Loader\Programs\acsapsrv.exe
C:\ACS\Server\Bin\drpurge.exe
C:\ACS\Server\Bin\perl.exe
C:\ACS\Server\Bin\acsproc.exe
C:\ACS\Server\Bin\MRMServer.exe
C:\ACS\Server\Bin\mrmSqlServer.exe
C:\ACS\Server\Bin\PLUExceptionExtractHost.exe
C:\ACS\Server\Bin\resmgr.exe
C:\ACS\Server\Bin\logmgr.exe
c:\Program Files\Microsoft SQL Server\MSSQL$ACS\Binn\sqlagent.EXE
C:\ACS\Server\Bin\accmgr.exe
C:\ACS\Server\Bin\iftrpmgr.exe
C:\ACS\Server\Bin\corrmgr.exe
C:\ACS\Server\Bin\clubctf.exe
C:\ACS\Server\Bin\offmgr.exe
C:\ACS\Server\Bin\cmctf.exe
C:\ACS\Server\Bin\sopup.exe
C:\ACS\Server\Bin\hostmgr.exe
C:\ACS\Server\Bin\casmgr.exe
C:\WINNT\Explorer.EXE
C:\ACS\Server\Bin\timemgr.exe
C:\ACS\Server\Bin\sreqpipe.exe
C:\ACS\Server\Bin\srsppipe.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hkcmd.exe
C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\PROGRA~1\COMMON~1\rmku\rmkum.exe
C:\Program Files\Lynk\Integra\LynkIntegraServer.exe
C:\Program Files\Lynk\Integra\LynkIntegraClient.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\ACS\Back office\Platform\ASWShell.exe
C:\WINNT\system32\o02PrEz\o02PrEz1065.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\WINNT\explorer.exe
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\Program Files\Comodo\CBOClean\BOCORE.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Documents and Settings\Administrator\Desktop\spywareblastersetup351.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-CLDEB.tmp\is-PAVTT.tmp
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\PROGRA~1\Yahoo!\browser\ybrowser.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\PROGRA~1\COMMON~1\rmku\rmkua.exe
C:\Documents and Settings\Administrator\Desktop\HiJackThis_v2.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2A0D7F1D-BC3E-4BD8-9442-11FB2D0332AA} - C:\Program Files\WindowsUpdate\vixylex.dll
O2 - BHO: (no name) - {3E8EC2D9-806B-4C7F-AE7F-F44AD4ABE8B5} - C:\WINNT\system32\urqnkji.dll
O2 - BHO: (no name) - {5ADF3862-9E2E-4ad3-86F7-4510E6550CD0} - C:\WINNT\system32\ecptiyec.dll
O2 - BHO: (no name) - {6DD5F76E-FEAC-4343-9B5F-0E206296C73A} - C:\Program Files\WindowsUpdate\vixylex.dll
O2 - BHO: 0 - {7E125488-0D86-4490-908B-65EC811F44CC} - C:\Program Files\Accessories\zykifuzit.dll
O2 - BHO: (no name) - {B80D9931-0D93-42D0-96F3-8B0672CA7FA0} - C:\WINNT\system32\naoqqxay.dll
O2 - BHO: (no name) - {DBC7BB3A-CB27-4E2A-B62C-2E96A5A22BF7} - C:\WINNT\system32\naoqqxay.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINNT\system32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [{ZN}] C:\Documents and Settings\Administrator\Local Settings\Temp\TICHD003.exe CHD003
O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKLM\..\Run: [WinTouch] C:\Program Files\WinTouch\WinTouch.exe
O4 - HKLM\..\Run: [ntdll.dll] C:\WINNT\retadpu2000219.exe 61A847B5BBF72810329B385473F001F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310F3D1DC7E4638E8323A15806F9DA6EF604776CA6C1637FB11E3C281231B2CCE7003
O4 - HKLM\..\Run: [GPLv3] rundll32.exe "C:\WINNT\system32\xvjpegsa.dll",realset
O4 - HKLM\..\Run: [BOC-424] C:\PROGRA~1\Comodo\CBOClean\BOC424.exe
O4 - HKLM\..\RunOnce: [RemoveInstallPath] cmd.exe C:\WINNT\system32\cmd.exe /c rmdir /S /Q "C:\PROGRA~1\WinPop" > nul
O4 - HKLM\..\RunOnce: [SpybotDeletingA1239] command /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7143] cmd /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1210] command /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC464] cmd /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8629] command /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2632] cmd /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA567] command /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2685] cmd /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA3499] command /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5718] cmd /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9249] command /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1004] cmd /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9463] command /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5415] cmd /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1991] command /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7793] cmd /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [GoToMeeting] C:\Program Files\Citrix\GoToMeeting\190\g2mstart.exe "/Trigger RunAtLogon"
O4 - HKCU\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKCU\..\Run: [rmku] C:\PROGRA~1\COMMON~1\rmku\rmkum.exe
O4 - HKCU\..\Run: [ntdll.dll] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7433] command /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1074] cmd /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7485] command /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3228] cmd /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3247] command /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1011] cmd /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4921] command /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8518] cmd /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6488] command /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2947] cmd /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2232] command /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD210] cmd /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3123] command /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3778] cmd /c del "C:\WINNT\system32\gebya.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8890] command /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7907] cmd /c del "C:\WINNT\system32\ddayy.dll_tobedeleted_old_tobedeleted_old_tobedeleted_old_tobedeleted_old"
O4 - .DEFAULT Startup: TA_Start.lnk = C:\Documents and Settings\Administrator\Local Settings\Temp\TICHD003.exe (User 'Default user')
O4 - Startup: TA_Start.lnk = C:\Documents and Settings\Administrator\Local Settings\Temp\TICHD003.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Lynk Integra Server.LNK = C:\Program Files\Lynk\Integra\LynkIntegraServer.exe
O4 - Global Startup: LynkIntegraClient.LNK = C:\Program Files\Lynk\Integra\LynkIntegraClient.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {8BBDC81D-81B3-49EE-87E8-47B7A707FAE8} (GoToMeeting/GoToWebinar Web Starter) - https://www.gotomeeting.com/default/applets/g2mdlax.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8771438C-67D3-4436-A649-0E405C31E072}: NameServer = 127.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{9104A1FA-F3D6-4354-90B3-A3A4C9014955}: NameServer = 127.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{FA535FC1-FBEF-4407-9755-E0470966C8B5}: NameServer = 68.94.156.1,68.94.157.1
O20 - Winlogon Notify: urqnkji - C:\WINNT\SYSTEM32\urqnkji.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINNT\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINNT\system32\browseui.dll
O23 - Service: ACS Batch Service - - c:\ACS\Back office\Platform\BatchService.exe
O23 - Service: ACS Receive Updates - NCR - C:\ACS\Server\Bin\NCRReceiveUpdatesSvc.exe
O23 - Service: ACS SIL Service - - c:\ACS\Back office\Platform\SILService.exe
O23 - Service: ACS Task Manager - NCR - C:\ACS\Server\Bin\tm.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINNT\SYSTEM32\crypserv.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Application Load Server (NCR Application Load Server) - NCR - C:\ACS\Loader\Programs\acsapsrv.exe
O23 - Service: NCR TFTP Service - NCR - C:\Program Files\NCR\FitClient\NCRTFTPs.exe
O23 - Service: NCR FitClient Loader (NCRFitClientLoader) - NCR - C:\Program Files\NCR\FitClient\FitClientLoader.exe
O23 - Service: RSH Daemon (rshd) - Unknown owner - C:\scot\bin\rshd.exe (file missing)
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: SvcUpdate - NCR - C:\ACS\Server\Bin\svcupdate.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Accessories\disososys.html
--
End of file - 15844 bytes
Any thoughts are appreciated!!