After a few days of fun and games trying to clear my laptop of some nasties which appeared to have corrupted driver files on my system, I'm finally able to boot into normal mode. I've run full Symantec AV, Spybot, Spysweeper scans, which have all come up clean.
I've posted my current HJT scan below.
1) I'm assuming i should get rid of
a) the unknown file in winsock LSP
b) the first two BHO entries
Will deleting these items using HJT be sufficient to get rid of them, or should I be using another tool?
2) Using the Auto analyser the ctfmon.exe entry came up as bad - to remove. I thought this file is ok if running from \windows\system32
3) I've got some bad entries in my startup list, looked at from msconfig. Although I've unchecked them (in msconfig) so that they aren't run, they still appear there as options to re-select - how should I get rid of these once and for all?
Thanks,
Richard
---
Logfile of HijackThis v1.99.1
Scan saved at 22:09:12, on 13/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\atievxx.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\System32\msiexec.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Administrator\Desktop\Hjtscan.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.talktalk.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://bicfs/
O2 - BHO: (no name) - {602ec513-3645-4034-b244-6946aa248b27} - C:\WINDOWS\system32\dpn079.dll
O2 - BHO: C:\WINDOWS\system32\ldhje783.dll - {8D5849A2-93F3-429D-FF34-260A2068897C} - C:\WINDOWS\system32\ldhje783.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\Program Files\3Com\3Com OfficeConnect Wireless Utility\3Com Wireless 11g PC Card\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb0 4.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: 3Com Wireless 11g PC Card.lnk = C:\Program Files\3Com\3Com OfficeConnect Wireless Utility\3Com Wireless 11g PC Card\Monitor.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\erwgg.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\erwgg.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\erwgg.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\erwgg.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\erwgg.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\erwgg.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\erwgg.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\erwgg.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\erwgg.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\erwgg.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\erwgg.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\erwgg.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\erwgg.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\erwgg.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\erwgg.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\erwgg.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\erwgg.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\erwgg.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\erwgg.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\erwgg.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\erwgg.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\erwgg.dll
O14 - IERESET.INF: START_PAGE_URL=http://bicfs/
O15 - Trusted Zone: milestone.cognisco.com (HKLM)
O15 - Trusted Zone: milestone400.cognisco.com (HKLM)
O15 - Trusted Zone: *.cognisco.com (HKLM)
O15 - Trusted Zone: *.passport.net (HKLM)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = internal.cognisco.com
O17 - HKLM\Software\..\Telephony: DomainName = internal.cognisco.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = internal.cognisco.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = internal.cognisco.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = internal.cognisco.com
O20 - AppInit_DLLs:
O20 - Winlogon Notify: dpn079 - C:\WINDOWS\SYSTEM32\dpn079.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: rpcc - C:\WINDOWS\system32\rpcc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe


Reply With Quote
I ran vundo fix first - it found two file instances which i removed. The program then prompted a system restart and that was the end... BSOD very early in the boot process, both into normal mode and into any kind of safe mode.
The BSODs appeared early in the boot sequence and just flashed up for a split second before re-starting the machine, so I couldn't tell you what they said....
35.33, 15/05/2007